New Webinar and New LinkedIn Group focusing on GRC issues for Oracle’s ERP Cloud software
ERP Risk Advisors is excited to present our ERP Cloud Risk Advisory Series....
“The definition of insanity is doing the same things over and over again but expecting different results”, attributed to Albert Einstein. I am writing this six-part article series about Why ERP Implementations Fail – to help you avoid a failed or a ‘less than optimal’ implementation. In part 1, 2, 3, and 4 we have covered the following topics:
If you missed any of the first four articles, I encourage you to read them before starting this article as they lay the foundation for key concepts we will discuss next.
To achieve a successful ERP implementation, you must overcome these six common biases:
Having complete and accurate logging of activities is essential for establishing and monitoring all controls – IT, compliance, cybersecurity, fraud, and operational risks.
When management licenses an ERP system, they expect that the activities that need to be logged ARE being logged and that those logs will be retained for as long as they are needed. Management’s needs for such logs may be in conflict with a SaaS software provider’s goal of maximizing profits. A SaaS software provider has to consider the ‘overhead’ / performance impact of creating the logs and the cost of storing the logs both in quantity and duration.
Let’s look at the types of logs that management needs. Some of their ‘needs’ are actually critical requirements to fulfill regulatory requirements such as Sarbanes-Oxley, GDPR, and the TSA directives for oil and gas companies and airports.
They include such things as:
Then there are logging requirements set by Data Privacy regulations, such as GDPR and CCPA, that broadly focus on what data is stored, who can access it, who has accessed it, when it is purged, and how long the data is retained.
Management needs to be aware of these requirements and make sure they understand what data is captured by the software provider.
The following are examples of logs and retention policies related to these requirements from ERP systems that we have evaluated:
Keep in mind that most modern SaaS systems are NOT extensible; meaning that logging is not provided. And retention of the logs sufficient to meet your objectives may not be guaranteed by the software provider. This will likely mean that you need to add to the scope of your ERP project by adding a custom archive and retention process for these key logs.
Not retaining the logs for a sufficient period of time could also result in the inability to:
Put yourself and your organization in the best position for success by NOT assuming that all your logging requirements will be met AND that the software provider will retain necessary logs.
As we have been emphasizing is each of these “Why ERP Implementations Fail” articles – buyer beware –you cannot count on the software providers or their preferred implementation partners to be honest with you about these gaps during the courting and contract phase.
If you want to avoid the pitfalls that of why ERP implementations fail, we’re here to help.
📩 Contact us at sales@erpra.net to schedule a consultation with one of our ERP risk experts.
ERP Risk Advisors is excited to present our ERP Cloud Risk Advisory Series....
Greeley, Colorado, April 2, 2020 – ERP Risk Advisors, a practical thought leader for managing ERP Risk, providing content and consulting services related to compliance,...