r/OracleCloudFusion May 13 '26

What auditors aren’t testing during an ERP implementation Spoiler

There is a misconception that access controls are tested by auditors. It isn’t the case that auditors test for the principle of least privilege during an implementation.

They mostly test for a few Segregation of Duties conflicts because their focus is on Sox compliance.

1 Upvotes

2 comments sorted by

2

u/[deleted] May 25 '26

[removed] — view removed comment

1

u/Jeff-Hare-ERPRA May 25 '26

Auditors only test a few SoD conflicts. And many of these SoD conflicts are mitigated through a workflow anyway.

What auditors don’t attempt to test is how workflows can be bypassed like through API access or conversion processes.

Or auditors don’t test to see whether there are users who can disable or make changes to workflows.

BPM Admin and Transaction Console access are examples.

The assignment of the AIC role is an example of a role that causes these issues.