blubanyan logo

ERP Security Audit Guide for NetSuite Teams

ERP Security Audit Guide for NetSuite Teams

I use five steps to audit NetSuite security: scope, test, document, remediate, and retest. Start by defining the accounts, review period, and control owners. Then check access, financial duties, sensitive data, logs, recovery, and changes – not just current settings, but how controls worked during that period.

Here’s what I focus on:

  • Access: Who can view data, change records, approve payments, or manage integrations?
  • Proof: Do records support each test result? A 60-day log cannot establish six months of control performance.
  • Fixes: Which risks need containment, who owns each fix, and when is it due?
  • Follow-through: Does an independent retest confirm the fix, and when will the next review happen?

My rule: <u>no finding closes without retesting</u>. Keep the scope, test records, findings, and next review date together. An internal audit does not replace required independent assurance.

NetSuite Security Audit: The Five-Step Cycle
NetSuite Security Audit: The Five-Step Cycle

Review NetSuite Security Controls

Use the approved scope and review period to test the access, logging, recovery, and change controls that protect production data.

Test Access, Authentication, and Segregation of Duties

Access becomes a risk when permissions go beyond approved duties. Inventory every identity and role. Record the owner, function, assigned roles, subsidiary or location access, last login, authentication method, privileged permissions, and expiration date.

Compare access with approved duties and test joiner/mover/leaver samples. Review MFA, password rules, inactive users, shared credentials, emergency access, and token or OAuth grants. Review named administrator accounts separately. In an approved sandbox, test conflicting permissions, transaction paths, and approval bypasses through imports, scripts, and secondary roles.

Access reviewEvidence and testJustification and approvalExceptions and mitigating controlsRemediation owner
Administrator roleReview assignments, login history, and privileged activityWritten approval from the CFO or designated security ownerSeparate backup administrator; review privileged activity weeklyNetSuite administrator
Payment approvalCompare permissions, approval limits, and actual payment approvalsFinance owner confirms required approval thresholdIndependent payment-batch reviewController
Employee recordsTest compensation, bank, and tax-field visibilityHR owner confirms business needQuarterly access recertificationHR systems owner
Integration userInspect roles, tokens, OAuth grants, and execution logsApplication owner approves minimum required accessMonitor failed calls and rotate credentialsIntegration owner
Duty conflictTestJustification and approvalException and mitigating controlRemediation owner
Vendor creation and payment approvalTrace vendor edits to payment approvalsController approves any documented business needExpiring exception; independent payment-batch reviewController
Purchase-order creation and receipt approvalInspect PO and receipt approvalsFinance and operations approve authority limitsIndependent review of receipts and matchingProcurement owner
Employee bank changes and payroll processingCompare access and payroll activityHR and finance approve exceptionIndependent verification of bank changes before processingPayroll owner
Inventory adjustments and reconciliationCompare adjustment rights with reconciliation dutiesOperations and finance approve exceptionIndependent source-document reviewInventory owner

Record every exception, sample, and failed test in the evidence register.

Check Logs, Alerts, and Incident Response

Logging gaps can hide activity that wasn’t approved. System Notes are immutable, but they don’t cover everything. Users without the Administrator role may also see only their own changes.

Fill these gaps with role-history records, saved searches, configuration exports, and approval evidence. Match actors, record IDs, timestamps, and changes across NetSuite, identity-provider, and integration logs.

Run an annual tabletop exercise covering account suspension, token revocation, evidence preservation, stakeholder notification, transaction review, recovery decisions, and post-incident reporting.

The frequencies below are review targets. Record each source’s actual retention period and any coverage gaps.

EventDetection methodOwnerReview frequencyRetention evidenceEscalation
Administrator or role changeSystem notes and change reportNetSuite security ownerDaily or next business dayExported report and approved ticketSecurity lead and CFO
Failed or unusual loginLogin Audit Trail and identity-provider alertIdentity teamReal time or dailyLogin report and alert recordIncident response lead
Vendor, bank, or payment changeSystem notes, workflow alert, transaction reviewControllerDailyRecord history and approval evidenceController and fraud-response contact
Integration failure or privilege errorAPI, middleware, or script logsIntegration ownerEach business dayExecution and error logsApplication owner

Review Data Protection and Recovery

Recovery gaps can extend downtime or leave data incomplete. Test access to sensitive data through records, saved searches, dashboards, reports, attachments, and exports – not just forms. Check external sharing, recipient lists, downloaded-file protection, and retention/deletion rules.

Exports are not complete account backups. They may leave out configuration dependencies, workflows, scripts, roles, tokens, attachments, system history, sequencing, and other dependencies.

Separate Oracle’s contracted recovery duties from customer-managed rebuilding. In nonproduction, test both RTO and RPO, then reconcile records, approvals, attachments, and integration behavior.

AssetResponsible partyObjectiveRecovery methodLast test and resultEvidence
Transactions and master dataOracle/customer, according to contracted service modelDefined RTO/RPO for critical operationsProvider recovery plus customer validation and documented exportsDate, scope, and reconciliation resultTest report and reconciliation
Roles and permissionsCustomer NetSuite ownerRecreate approved access quicklyRole matrix, configuration records, and approvalsDate and sample roles restoredRole baseline and approval tickets
Scripts and workflowsCustomer development ownerRestore approved application behaviorVersion-controlled source and controlled deploymentDate and deployment test resultRepository and deployment record
Attachments and documentsCustomer or backup providerPreserve critical project and contractual recordsTested document backup and restoreDate and file-integrity resultRestore log and hash or checksum where used
Integrations and credentialsIntegration ownerResume critical data flows securelyRebuild endpoints, rotate credentials, and reconcile queuesDate and end-to-end test resultCredential rotation and reconciliation evidence

Test Integrations, Customizations, and Change Controls

Uncontrolled changes can expose data or disrupt processing. Inventory every inbound and outbound flow: APIs, middleware, file transfers, SuiteScript, RESTlets, workflows, custom records, mobile apps, and installed SuiteApps.

For each item, record the owner, data exchanged, authentication method, privileged access, approval record, monitoring location, error-handling process, and evidence repository. Test whether each credential is assigned to one identity or purpose, stored securely, rotated, limited to minimum permissions, and revoked when no longer needed.

Verify encryption in transit, duplicate or missing-record handling, reconciliation totals, retry behavior, dead-letter or exception queues, and alert escalation. Review procedures for development, testing, approval, deployment, emergency changes, and rollback.

Include only deployed Blu Banyan components. You can reference Blu Banyan for NetSuite implementation, customization, and integration services. But deployment by Blu Banyan does not, by itself, prove that permissions, authentication, monitoring, recovery, or change controls are secure. Confirm each component’s actual version, configuration, and responsibilities.

For deployed Blu Banyan components, document the same fields once: owner, data handled, authentication, privileged access, approvals and changes, monitoring, and evidence location.

Record each flow test, approval, and exception in the evidence register and findings log.

Collect Evidence and Record Test Results

After testing controls, record the evidence that supports each result. Link each audit objective through risk, control, test, evidence, result, exception, and conclusion. Assign evidence and test IDs so reviewers can trace every conclusion back to its source.[2] This trail gives findings a clear basis.

Build an Evidence Register

Request evidence covering both configuration and actual activity during the review period. For each item, record its source, review period, actual extraction timestamp, filters, exclusions, record counts, preparer, reviewer sign-off, and storage location. Every item must support a specific control test and outcome.

Mark completeness as complete, partial, or missing.

ControlEvidence request and sourcePeriod and extraction detailsReviewerCompleteness statusTest/finding reference
Privileged-access approvalRole assignments, System Notes, approval tickets; production NetSuite account and ticketing systemApproved review dates; actual extraction timestamp in UTCAccess reviewerAssign after verificationLinked test ID; finding ID if needed
Controlled changesWorkflow configurations, deployment records, change tickets; production NetSuite account and release repositoryApproved review dates; actual extraction timestamp in UTCChange-control reviewerAssign after verificationLinked test ID; finding ID if needed
Recovery readinessRecovery-test report and reconciliation records; recovery repositoryTests within approved review dates; actual collection timestamp in UTCRecovery reviewerAssign after verificationLinked test ID; finding ID if needed

Before sampling, reconcile export counts and dollar totals to the source report. Check date boundaries, subsidiaries, record types, and search parameters, and preserve the search definition.

Store originals read-only and keep working copies separate. Encrypt files in transit and at rest, limit sharing, and redact secrets from copies. Under the approved retention policy, record integrity checks, the custodian, retention class, and destruction date.

Use the register to select samples and document each test result.

Test Control Design and Operating Effectiveness

Use the evidence register to check whether each control was designed well and worked as intended. Document design separately from operating effectiveness. Define the population, verify completeness, and record the sample method, size, IDs, expected result, actual result, tester, and review date.

Select samples based on risk, and test every item in small, high-risk populations. Current settings and management statements do not prove how a control performed in the past.[2] Add each result to the findings register and retest plan, as applicable.

ObjectiveDesign procedureOperating-effectiveness procedureEvidenceConclusion to record
Remove access promptlyReview the documented offboarding workflow, responsible owner, timing requirement, and escalation pathCompare termination dates with access-removal timestampsOffboarding procedure, HR termination population, user status history, system notesEffective, exception, or unable to conclude
Approve privileged accessDetermine whether approval is required from an appropriate owner before role assignmentVerify dated approval preceded each selected assignmentRole permissions, approval tickets, system notesEffective, exception, or unable to conclude
Authorize production changesAssess whether changes require testing, approval, and segregation of dutiesMatch selected deployments to prior approvals, test results, and deployment timestampsChange tickets, test records, deployment historyEffective, exception, or unable to conclude

Use “unable to conclude” when evidence is insufficient. Record an exception only when reliable evidence proves a failure. Missing documentation may be a separate deficiency.

Expand testing when deviations point to a broader issue, evidence conflicts, or the population is incomplete. State each limitation and its effect. NetSuite saved-search execution logs cover the preceding 60 days, so those logs alone cannot support a six-month conclusion. Seek archived or alternative evidence and identify any months that remain untested.

Prioritize Findings, Fix Issues, and Retest

Use the findings register to move each issue from testing to remediation. Prioritize business exposure – not exception counts. Keep one corrective-action register for owners, deadlines, interim safeguards, and retest requirements. Send the approved audit report to finance, IT, and executive leadership. Include major risks, testing limits, open findings, accepted risks, and items that need executive approval.

Rate Risks and Identify Root Causes

Rate each finding based on likelihood, financial and operational impact, exposure duration, and proven mitigating controls. Lower a rating only when compensating controls have been shown to work. Pay particular attention to permissions for vendor bank details, payments, journal entries, and sensitive data.[12][16]

Classify each issue as a control deficiency, policy violation, documentation gap, isolated exception, or confirmed incident. Send confirmed incidents to incident response. Verify the facts with control owners, but retain supported findings even when management disputes their severity or wording. Identify the root cause – not just the affected account or transaction – and check whether it also affects other roles, subsidiaries, workflows, or integrations.[12][16]

RatingCriteriaEscalationSuggested response target
CriticalActive or readily exploitable access, exposed credentials, terminated-user access to sensitive data, or a high-probability weakness that could cause material financial or operational harmCFO, CIO, incident-response lead, executive leadershipContain immediately; action plan within 5 business days
HighSignificant excess privilege, major segregation-of-duties conflict, ineffective privileged-access review, or an integration weakness affecting financial dataFinance, IT, control owner, executive risk ownerContain within 10 business days; remediate generally within 30–60 days
MediumA control operates inconsistently, a recurring documentation gap exists, or exposure is limited by effective compensating controlsProcess owner and control owner; include in management reportingRemediation generally within 60–90 days
LowIsolated exception with limited impact, minor documentation issue, or an improvement opportunityControl owner and audit coordinatorCorrect during the next scheduled control cycle, commonly within 90–180 days

These are planning targets, not regulatory deadlines. Adjust them for contractual duties, risk appetite, and the financial close calendar. Suspected compromise must not sit in a routine ticket queue.[11]

Track the following required fields in the findings register. Change tickets alone aren’t enough to track remediation.

Register fieldRequired detail
Finding ID and dateA distinct identifier, discovery date, and audit period
Control and scopeControl objective, NetSuite account or subsidiary, roles, integrations, and population tested
Condition and evidenceExact exception, affected records or users, evidence location, and testing limitation
Rating and rationaleSeverity, likelihood, impact, duration, mitigating controls, and escalation decision
Root causeProcess, people, technology, governance, or third-party cause
Corrective actionSpecific design or operating change, dependencies, milestones, and interim safeguards
AccountabilityControl owner, action owner, executive risk owner, and approver
Deadline and statusTarget date, overdue status, blockers, and management updates
ValidationRetest procedure, sample or period, before-and-after evidence, reviewer, and closure decision
Risk acceptanceApprover, rationale, compensating controls, expiration date, and reassessment date

Contain Risks and Verify Fixes

After rating a finding, contain urgent exposure before making a permanent fix. Disable improper or terminated-user access, rotate exposed credentials or tokens, remove unnecessary privileges, and separate high-impact conflicting duties. Preserve relevant evidence where possible, but don’t delay containment. Coordinate suspected compromise with incident-response owners.[11][15][16]

Test changes in a sandbox or another controlled environment before moving them to production. Then repeat the original control test, checking both permitted and prohibited actions. For recurring controls, collect evidence that they work over a suitable period. Keep before-and-after records, and require independent review for critical and high-risk fixes.[11][15][16]

If the permanent fix is delayed, keep the finding open. Record the approved residual risk, rationale, interim controls, expiration date, and reassessment date instead of silently extending the deadline.[11][15][16]

Schedule Routine and Event-Driven Reviews

Use the schedule below as a minimum baseline. Don’t postpone reviews after an acquisition, reorganization, incident, or material NetSuite change. Keep control owners, evidence locations, and remediation history up to date. Report overdue actions separately from accepted risks. Track repeat findings, average days to closure, accepted-risk expirations, and the percentage of fixes that pass independent retesting.[15][16]

Once a fix is verified, add the control to routine and event-driven monitoring.

Control areaPost-audit monitoringEvent-driven triggersOwnerRequired evidence
Privileged and administrator accessCheck for recurring excess privilege and unapproved assignmentsAdministrator turnover, suspected misuse, major role redesign, or security incidentNetSuite security administrator and IT securityUser-to-role export, approval records, activity review, exceptions, and sign-off
Financial permissions and segregation of dutiesVerify mitigating controls and check for recurring conflictsAcquisition, reorganization, new entity, fraud alert, or finance-system redesignController and finance systems ownerRole matrix, conflict analysis, compensating controls, and remediation history
Integrations, tokens, and service accountsMonitor credential scope and recurring interface exceptionsNew integration, credential exposure, vendor change, outage, or API redesignIntegration owner and securityIntegration inventory, credential scope, logs, data-flow review, and change approval
Standard roles and inactive usersCheck for restored excess access and missed terminationsWorkforce reduction, department change, identity-platform change, or audit findingHR/identity owner and NetSuite administratorUser population, termination reconciliation, role review, and exception approvals
Workflows, scripts, SuiteApps, and customizationsVerify fixes remain effective after changesNetSuite release, major customization, acquisition, incident, or failed deploymentApplication owner and change advisory groupRequirements, code or configuration review, test results, deployment approval, and rollback plan

Conclusion: Repeat the Audit Cycle

A completed NetSuite audit should leave a reusable audit package. Store the approved scope, control matrix, evidence, findings, remediation plan, retest results, and next review date in a restricted repository. Use that package to start the next review without rebuilding the audit file. Carry the cycle forward: scope, test, document, remediate, retest, repeat.

Every finding needs an owner and deadline. Every closure needs retesting. Schedule the next review before the audit ends. Before sign-off, use this checklist as the final control check:

  • Plan: Confirm objectives, scope, period, owners, NetSuite professional services deliverables, and exclusions.
  • Inventory: Reconcile users, service accounts, roles, permissions, integrations, customizations, logging sources, and recovery controls with their owners.
  • Test: Link system notes and transaction audit trails to the controls tested.
  • Document: Index evidence by control, source, timestamp, reviewer, and retention location. Record testing limitations.
  • Remediate: Record each finding’s risk, root cause, owner, deadline, fix, interim safeguards, and residual risk.
  • Validate: Require an independent retest with post-fix evidence before closing a finding.[19]
  • Repeat: Record the next review date, scope owner, evidence window, and early-review triggers. Set review frequency by risk, including finding severity and event-driven triggers. Update the audit calendar immediately using the next cycle’s scope and triggers.

FAQs

How long should a NetSuite security audit take?

NetSuite security audits have no single required duration. Review access at least quarterly to find and remove inactive accounts or redundant roles [1].

Assess broader processes at least annually. During the first year of use or after major system changes, conduct these assessments every three to six months [2].

For critical security events, aim to review 100% within 24 hours.

How can small teams manage segregation of duties?

Use Role-Based Access Control (RBAC) to give each user access only to the data and tools their job requires. Assign reviews to someone other than the workflow owner, and keep ERP administration separate from audit-log administration.

Use NetSuite’s stage-gate workflows to require approvals and check required data before a process moves forward. Review roles regularly – ideally every quarter – to prevent permission drift as your business changes.

Who qualifies to independently retest audit fixes?

Audit fixes must be retested by someone independent of the original workflow owner to verify the results objectively [1]. This separation of duties lowers the risk of missed errors or issues when process owners review their own fixes [1]. Independent retesting also checks that corrective and preventive actions work as intended and that security controls remain strong [1].

Illustration: Community with energy efficient buildings, solar panel array, wind turbines, trees, flowers, and people riding bicycles.