Role customization in NetSuite is a powerful tool for tailoring user access to align with specific job functions. It gives organizations the flexibility to control...
When people talk about Segregation of Duties (SoD), they often forget there are two flavors of risk:
Auditors care about this because regulators care. SOX 404 requires management to prevent incompatible duties in financial systems, AKA SoD risks, while frameworks like COSO and COBIT shape how auditors test SoD in practice. SOX requires management to establish and maintain adequate internal controls over financial reporting (ICFR). Because ERP systems often house the financial data and processes that flow into external reporting, weak or poorly designed access controls can create risks of unauthorized transactions, fraudulent activities, and material misstatements. Or, in other words, failure to identify and mitigate SoD risks where strong mitigating controls are not in place, can lead your organization to a house of trouble.
Here’s the catch: native ERP reports won’t give you the full picture. They can show what permissions a role has, or what roles a user holds, but they don’t automatically connect the dots across both layers. That’s where specialized GRC software tools and assessment services like ERP Armor: Assessments come in handy—they bring pre-built SoD rulesets, map them to your ERP’s object structure (e.g., permissions and access levels for NetSuite), and highlight the real conflicts management should look for.
A few NetSuite specific examples:
Each of these opens the door to fraud or material misstatement if left unchecked.
Not every conflict is worth chasing initially. It is best to start by mapping ERP security objects, like permissions in NetSuite, to your Risk & Controls Matrix so you can focus on financially significant conflicts from the jump. Think items like supplier maintenance, payments, journals, revenue recognition, workflow configurations, payroll, etc. From there, prioritize conflicts based on fraud potential and residual risk. A conflict covered by dual approval workflow, for example, may be acceptable, while one without mitigating controls may not be.
Cleaning this up requires structure:
SoD risk isn’t something you check once a year—it evolves with every patch, every new role, and every integration update. Continuous monitoring, supported by automated tools and robust sensitive access and SoD rulesets, is the only way to stay ahead of both auditors and real-world threats.
Role customization in NetSuite is a powerful tool for tailoring user access to align with specific job functions. It gives organizations the flexibility to control...
In JD Edwards World, user access is not determined by a single role, report, or table.