ERP5 min readNetray Engineering Team

How to Run ERP User Access Reviews That Pass Audit

An ERP user access review, also called user access recertification, is a periodic control where business owners confirm that each user's ERP entitlements are still appropriate for their job. It is a core IT general control under SOX, a required practice under NIST SP 800-171 and CMMC, and one of the most commonly failed controls in manufacturing audits. Reviews fail for predictable reasons: the extract is incomplete, the reviewer is an IT administrator instead of a business manager, or approved revocations are never actually executed. This guide covers a review process that produces defensible evidence.

Building a Complete Entitlement Extract

The review is only as good as the data. Pull every account from the ERP security tables, not just interactive users, and join it to HR data for employment status, manager, department, and termination date. In SyteLine, that means users, groups, and object authorizations plus last login. In Infor LN, it means users, roles, companies, and session authorizations. Include integration and service accounts, contractor accounts, and any account with database-level access, since those are exactly the ones missed. Translate technical entitlements into plain language before the reviewer sees them, because no plant manager can meaningfully approve a list of IDO method names.

  • Join ERP accounts to the HR master by employee ID, not by name, to catch rehires and duplicates
  • Flag accounts with no login in 90 days as candidates for automatic disablement before review
  • List service and integration accounts separately with a named human owner for each
  • Present entitlements as business capabilities such as release payments, not as raw form or session codes

Choosing Reviewers and Setting the Cadence

The reviewer must be the person accountable for the business risk, normally the user's direct manager or the process owner for a sensitive function. IT should never certify its own grants. Run privileged and financially sensitive roles quarterly and standard users annually, which is what most external auditors expect. Give reviewers a hard two-week window with automated reminders at day seven and day twelve, and escalate to the next level up at day fifteen. Target 100 percent completion, because a 92 percent completion rate is a finding. Rubber-stamping is the real failure mode, so track approve-all behavior and challenge reviewers whose revocation rate is zero every cycle.

Closing the Loop on Revocations

Auditors test the end of the process, not the beginning. Every revocation decision must be traced from the review record to a ticket, to a timestamped change in the ERP security tables, and back to a post-review extract that proves the access is gone. Set a service level of ten business days for standard revocations and 24 hours for terminated employees. Retain the reviewer's approval artifact, the extract that was reviewed, and the confirmation extract together as one evidence package per cycle. If revocations sit open at the next review, the control is considered ineffective regardless of how good the review itself was.

  • Generate a ticket automatically for every revoke decision with the review cycle ID attached
  • Confirm removal with a fresh extract and diff, not with a screenshot of the ticket being closed
  • Escalate any revocation open past ten business days to the control owner and the CFO or CIO
  • Archive the reviewed extract, approvals, tickets, and confirmation diff as one immutable evidence package

Joiner, Mover, Leaver: Fixing the Root Cause

Access reviews are a detective control that cleans up what a broken provisioning process created. The expensive pattern is the mover: someone transfers from purchasing to production planning, gains new access, and keeps the old. Fix it by making role changes subtractive by default so a transfer removes all existing ERP roles and re-grants from the new job profile. Drive joiners and leavers from the HR system as the authoritative trigger rather than from an email to the help desk. Manufacturers who automate joiner, mover, and leaver typically see quarterly review exception counts drop by half within two cycles, which shrinks review effort permanently.

How Netray Automates ERP Access Recertification

Netray AI agents extract SyteLine or LN entitlements on a schedule, translate them into business language, join them to your HR feed, and route campaigns to the right managers with reminders and escalation built in. The agent pre-flags likely revocations by comparing granted access against what each user actually executed in the last 180 days, which typically cuts reviewer workload by 60 percent and raises revocation quality. At cycle close it produces the full evidence package, including the confirmation diff, in a format auditors accept without follow-up. Most clients move from a six-week manual review to a five-day cycle.

Frequently Asked Questions

How often should ERP user access reviews be performed?

Most auditors expect quarterly reviews for privileged, administrative, and financially sensitive roles, and at least annual reviews for all other users. Terminations are handled outside the review cycle and should be processed within 24 hours. If your organization is subject to SOX, align the cadence with your control testing calendar so each quarter has a completed, evidenced cycle before testing begins.

Who should approve ERP access during a recertification?

The user's direct manager or the process owner for the function, never the IT team that provisioned the access. IT can prepare the data and execute the revocations but cannot certify appropriateness, because that removes independence from the control. For service and integration accounts, assign a named business or application owner who confirms the account is still required and that its privileges are still minimal.

What evidence do auditors want from an access review?

Auditors want a complete population extract with a date and source, proof of who reviewed each user, the decision recorded per entitlement, tickets showing revocations were executed, and a follow-up extract proving the access is actually gone. They also test completeness, so be ready to show that the extract covered every account including service, contractor, and database-level accounts, not just interactive named users.

Key Takeaways

  • 1Building a Complete Entitlement Extract: The review is only as good as the data. Pull every account from the ERP security tables, not just interactive users, and join it to HR data for employment status, manager, department, and termination date.
  • 2Choosing Reviewers and Setting the Cadence: The reviewer must be the person accountable for the business risk, normally the user's direct manager or the process owner for a sensitive function. IT should never certify its own grants.
  • 3Closing the Loop on Revocations: Auditors test the end of the process, not the beginning. Every revocation decision must be traced from the review record to a ticket, to a timestamped change in the ERP security tables, and back to a post-review extract that proves the access is gone.

Turn your ERP access review from a six-week spreadsheet exercise into an automated, evidenced control cycle that closes in days.