Digital Signature in Audit
Management
The SAP System provides the digital signature tool to sign (authenticate) and approve digital data. The digital signature ensures that certain tasks are only performed by specially authorized users. In the signed document, the name of the undersigned person, the date, and the time are documented.
In Audit Management, you can use digital signature for the following objects:
● Audit
● Corrective/preventive actions related to an audit
In the SAP System, the digital signature is implemented in the Basis component Secure Store and Forward (SSF). This provides you with various signature methods. If you use the user signature as your signature method, you need an external security product that is connected to your SAP system by using SSF.
For more
information about digital signatures, see
Approval Using Digital
Signatures.
●
You have made the
general settings for a digital signature (see
Approval Using Digital
Signatures).
● You have activated digital signature for Audit Management in Customizing for Cross-Application Components → Audit Management.
○ To do this, you have defined the settings under Control → Digital Signature.
○
You have also
defined when a digital signature is necessary for each audit type (for example
when evaluating an audit or when closing an audit), by choosing Audit Definition
→ Audit Type.
This setting also means that you can search for audits that are not completely
signed in the audit monitor.
● You have released the audit.
You can use digital signatures to sign off audits and their corrective/preventive actions for the following process steps:
● Evaluation of an audit
● Completion of an audit
● Confirmation of a corrective/preventive action
● Completion of a corrective/preventive action
If you perform a process step that requires a signature, a dialog box appears automatically, so that you can enter the digital signature.
Once you have evaluated and signed off audits, you can no longer change the evaluation. Once you have closed and signed off audits or actions, you can no longer change the properties of the audits or actions.
If there are still outstanding actions, you can only assign the status Completed with Outstanding Actions to the audit, and you must sign off the audit. When the last outstanding action is closed, the status Closed is set automatically. There is no need to sign off the audit again.
If you revoke the status Closed, the system also revokes the signature. If you close an audit or action again, the signature process is automatically triggered again.
In the digital signature log, you can display the signature history of each audit and each action.
You can use the PDF-based forms PLM_AUDIT and PLM_AUDITACTION to print audits and actions with their digital signatures.
If at least one signature strategy is specified in Customizing for an audit type, you can select audits with incomplete signatures in the audit monitor and monitor the incomplete signature processes for completion in the hit list.
For more information, see Working with Digital Signatures in Audit Management.