Back to blog

Why ERP Implementations Fail: UNBIASED (5 of 6)

The definition of insanity is doing the same things over and over again but expecting different results”, attributed to Albert Einstein. I am writing this six-part article series about Why ERP Implementations Fail – to help you avoid a failed or a ‘less than optimal’ implementation. In part 1, 2, 3, and 4 we have covered the following topics:

  1. Software is often released before it is mature
  2. System integrators rarely propose a complete ERP implementation
  3. System integrators do not understand the complex compliance and cybersecurity requirements for today’s modern systems
  4. Compliance and cybersecurity requirements are often misunderstood by software engineers

If you missed any of the first four articles, I encourage you to read them before starting this article as they lay the foundation for key concepts we will discuss next.

The Six Biases in ERP Implementations

To achieve a successful ERP implementation, you must overcome these six common biases:

  1. Software is often released before it is mature
  2. System integrators rarely propose a complete ERP implementation
  3. System integrators often do not understand the complex compliance and cybersecurity requirements for today’s modern systems
  4. Compliance and cybersecurity requirements are often misunderstood by software engineers
  5. SaaS application software providers tend to be greedy with system storage because it affects their margins
  6. Auditors are often not trained in the specifics of the ERP system they are auditing.

The Importance of Logging in ERP Systems

Having complete and accurate logging of activities is essential for establishing and monitoring all controls – IT, compliance, cybersecurity, fraud, and operational risks.

When management licenses an ERP system, they expect that the activities that need to be logged ARE being logged and that those logs will be retained for as long as they are needed.  Management’s needs for such logs may be in conflict with a SaaS software provider’s goal of maximizing profits.  A SaaS software provider has to consider the ‘overhead’ / performance impact of creating the logs and the cost of storing the logs both in quantity and duration.

Key Logs Management Needs

Let’s look at the types of logs that management needs. Some of their ‘needs’ are actually critical requirements to fulfill regulatory requirements such as Sarbanes-Oxley, GDPR, and the TSA directives for oil and gas companies and airports.

They include such things as:

  • All types of logins and their IP addresses – for applications, servers, firewalls, operating systems, and databases
  • creation and maintenance of new administrative accounts
  • IDP configurations
  • Password configurations
  • Firewall configurations
  • Login restrictions such as IP, location, and time zones
  • Changes to role configurations – within the applications, database, operating systems, etc.

Then there are logging requirements set by Data Privacy regulations, such as GDPR and CCPA, that broadly focus on what data is stored, who can access it, who has accessed it, when it is purged, and how long the data is retained.

Management needs to be aware of these requirements and make sure they understand what data is captured by the software provider.

Examples of Logging and Retention Gaps

The following are examples of logs and retention policies related to these requirements from ERP systems that we have evaluated:

  • Only retains sign-on for all users for 7 days.
  • Only retains who has accessed PII for 30 days.
  • Does not track insert, updates, and deletes for any configurations.
  • Allows for the disabling and re-enabling of workflows without any logging.
  • Allows for the delegation of a user’s login to another user without any logging. This is the equivalent of providing another user access to the roles assigned to them without needing to provide them their password.
  • Provides the ability to do object oriented development with retention of each version of the code – no source code control.
  • Allows a user to post journal entries outside the approval workflow, without any clear way to differentiate which entries bypassed the approval control and which followed the standard workflow. Allows a user to delegate a role assigned to them to another user without any logging.

The Hidden Risks of Limited ERP Logging

Keep in mind that most modern SaaS systems are NOT extensible; meaning that logging is not provided.  And retention of the logs sufficient to meet your objectives may not be guaranteed by the software provider.  This will likely mean that you need to add to the scope of your ERP project by adding a custom archive and retention process for these key logs.

Not retaining the logs for a sufficient period of time could also result in the inability to:

  • Meet internal compliance requirements such as quality assurance over your change management process and monitoring cybersecurity risks.
  • Meet external compliance requirements such as GDPR and Sarbanes-Oxley
  • Monitor changes to key configurations that impact compliance, cybersecurity, fraud, data security, and operational risks

Buyer Beware: Don’t Assume Compliance

Put yourself and your organization in the best position for success by NOT assuming that all your logging requirements will be met AND that the software provider will retain necessary logs.

As we have been emphasizing is each of these “Why ERP Implementations Fail” articles – buyer beware –you cannot count on the software providers or their preferred implementation partners to be honest with you about these gaps during the courting and contract phase.

Schedule a Consultation

If you want to avoid the pitfalls that of why ERP implementations fail, we’re here to help.

📩 Contact us at sales@erpra.net to schedule a consultation with one of our ERP risk experts.