The audit risk from ERP configuration errors is not always apparent in day-to-day operations. The system is processing transactions correctly: run reports, and then the cycle closes. The problems come when an FDA investigator or external auditor or investor diligence team looks at the records that the system has been producing.
By then, the configuration gap has often been creating audit risk for months or years. Remediation includes fixing the configuration, documenting the change and in some cases, rebuilding records that should have been built differently.
The ones that don’t face this scenario actively manage configuration risk.
Why Configuration Errors Matter for Compliance
In an unregulated environment, an ERP configuration error usually shows up as an operational problem: a workflow that does not route correctly, a report that does not show accurate data, a process that requires a workaround. These are costs but not compliance exposures.
In a regulated environment, the same configuration error could have a compliance impact. The electronic record will have gaps due to an audit trail that was not set up to capture all relevant events. Allowing a user to approve his own transactions is a violation of segregation of duties access control. Non-cGMP compliant inventory status that does not prevent consumption of quarantined materials generates a cGMP compliance gap.
That is why ERP configuration in regulated environments requires specific domain expertise at the design stage, the difference between operational and compliance consequences.
Audit trail gaps
Audit trail configuration is one of the most common sources of regulatory risk in NetSuite environments implemented without life sciences domain expertise.
21 CFR Part 11 requirement for electronic records: The audit trails must capture the date, time, and identity of the operator for every creation and modification of a record. You can change audit trail settings by record type in NetSuite. If you don't review what is captured for regulated records and use the platform defaults, you will have gaps that are only visible when someone tries to reconstruct the history of a specific record.
The configuration review for audit trail completeness should confirm that electronic records subject to regulatory requirements have full audit trail capture enabled, that the captured information includes all elements required by the applicable framework, and that the audit trail records are retained for the required period.
Failures of segregation of duties and access control
Access control configurations that were created at implementation and never reviewed later are one of the most common sources of compliance exposure in multi-year NetSuite environments.
Personnel changes. The user that needed some permissions may have changed role at implementation time. Permissions should now be changed. Often, they weren't. Over time, users accumulate access that reflects their past with an organization, not their current roles.
Segregation of duties configurations that worked in a smaller organization may not be appropriate as the organization grows. A company with 5 finance team members may not have had much ability to enforce segregation at implementation. With 20 team members, segregation is possible – but only if the role structure has been updated to require it.
An access control review should identify users who have access that is not appropriate for their current role, segregation of duties violations where a single user can both initiate and approve the same type of transaction, and system administrator access granted to users who do not need it.
Errors configuring revenue recognition
Revenue recognition configuration errors are one of the most financially material ERP mistakes in life sciences organizations. They don’t typically cause operational issues—transactions go through, reports run, and the close cycle completes—but they create revenue that is recognized in the wrong period, at the wrong amount, or against the wrong performance obligation.
Most common configuration errors include recognition rules built for a previous contract model that no longer reflects the organization’s current contracts, milestone payment rules that do not properly evaluate the constraint test under ASC 606, and bundled performance obligations that are not allocated properly when the contract price changes.
An organization that finds errors in revenue recognition in audited financial statements risks having to restate. They are addressed in a controlled and documented manner when identified by organizations during a proactive configuration review.
Set up gaps of inventory and traceability
Examples of gaps in inventory configuration leading to audit risk:
- Lot tracking is enabled at receipt but not maintained at work order consumption
- Quarantine inventory statuses are set but do not prevent consumption or shipment
- FEFO picking rules are set but not enforced at the pick level
- Incoming inspection workflows are set with inspection status but do not prevent production release
Each such gap leaves a paper trail that does not reflect what actually happened. The material was handled under cGMP, the document says. The real operations weren’t.
Record Lifecycle and Data Retention
NetSuite data retention settings can be configured and are not always aligned to regulatory requirements. Retention periods of 3, 5, 7 or more years may be required by 21 CFR Part 11, cGMP and other records retention requirements. If the system archiving or purge settings do not meet these requirements, records to be retained may not be available.
The retention configuration review should verify that system settings align with the longest applicable retention requirement for each record type, and that archived records are accessible in a readable, auditable format for the required period.
How to detect and fix configuration risk
Each of the above areas is covered by a systematic configuration risk review. The review should be against the current state of the system, not the original design documentation—configuration drift between documented design and actual system state is common in environments that have been running for several years.
The review will result in a prioritized remediation plan to address the highest risk gaps first with documentation of each change implemented. In regulated environments, changes to configuration should themselves be subject to change control documentation