Part of: Why your month-end close keeps getting slower
Most ERP implementations get audit-readiness wrong in both directions. Teams over-engineer controls the auditor will never look at, and skip configuration choices that will determine the audit outcome in year one.
After running implementations across financial services, healthcare, real estate, restaurant, and eCommerce businesses, the pattern is consistent. Four configuration choices materially affect audit outcomes. Three commonly-engineered controls produce almost no audit value.
The four that matter.
User access controls and segregation of duties. The auditor will sample roles and pull a report of who has access to what. If the controller can create vendors and also approve payments, the auditor flags it. The fix is at configuration time — role definitions that separate creation from approval, with documentation explaining the design intent.
Audit trail completeness. Every transaction should carry the user, the timestamp, and the original and modified values. ERPs support this natively but it requires configuration choices about log retention and the granularity of change capture.
Journal entry approval workflow. Manual journal entries — adjustments, accruals, reclassifications — need an approval workflow with a documented rationale field. The auditor samples these. Entries without rationale or approval history are findings.
Period lock enforcement. Periods should lock after close. If the ERP allows posting to prior periods without CFO sign-off, the auditor will find it.
The three that produce almost no audit value.
Automated transaction matching as a control (it is a productivity tool, not an audit control), custom reporting dashboards for auditor use (auditors do not use them — they export to Excel), and vendor due diligence workflows inside the ERP (auditors check the vendor file, not the workflow).
Four choices. One week each to configure. The audit outcome is determined before implementation goes live.
Filed under





