Why Configuration Pages Matter and Must Be Controlled
When it comes to auditing NetSuite, many organizations assume their change control processes are solid. The tickets are created, the approvals are documented, and the audit logs are in place. Yet controls often fail not because change management is absent, but because organizations have not built a complete inventory of setup and configuration pages that must be subject to change control. Without this inventory, users and roles frequently end up with unauthorized access to sensitive settings. Any page deemed as one that needs to be subject to the change management process should be restricted to IT administrators or senior business process owners — not left open to general business users. These are the quiet, foundational screens like Accounting Preferences, Fiscal Calendars, Accounting Periods, and General Preferences that directly influence financial reporting, security posture, and compliance standing. Overlooking them is where real audit gaps appear.
The danger is that these pages usually sit in the background. They’re “set it and forget it” until someone tweaks them, intentionally or accidentally, and suddenly your financial statements look different, your approvals stop firing, or a malicious actor gains unauthorized access to your environment. Any configuration page that has a high impact on financial reporting, financial or data privacy controls, or operations should be subject to change control. Building an inventory of these high-risk pages is critical. Without it, you’re essentially guessing what pages need to be controlled, and when the auditors arrive, “we didn’t know that page existed” is not an excuse anyone wants to use.
The way forward might take some work, but it is structured and will protect your environment: export a complete list of NetSuite setup and configuration pages, classify each one by impact — financial, operational, or security — and flag the highest-risk ones that should be limited to IT administrators and IT configuration roles. Once you know what needs control, you can govern it with tickets, approvals, and audit logging, and update the list after every NetSuite upgrade to keep it current.
This is exactly where ERP Armor and ERP Risk Advisors add value. Our assessments scan NetSuite permissions and can particularly flag every setup page we believe should be subject to change control and limited to IT personnel, making it easy to see which users can update sensitive pages. With a ruleset that has evaluated and mapped every standard permission, remediation and documentation are faster and less painful, and you end up with evidence that auditors can use right away.
The bottom line is this: without a complete inventory of NetSuite’s setup pages, your change control is running blind. And if you’re blind, the auditors will find the gaps. By taking the time to build that inventory, lock down access to IT-only roles, and embed these pages into your change-management process, you’ll prevent oversights, pass audits easier, and strengthen your ability to control changes.
If you would like an inventory of configuration pages that should be subject to change control in NetSuite, email support@erpra.net.
Why Configuration Pages Matter and Must Be Controlled
Perhaps the most important control organizations implement is the control related to the review and approval of journal entries. Most organizations using ERP Cloud...