Management remains accountable for control design, operating effectiveness, and recurring testing, even when auditors or third parties support the work. Finance leaders, control owners, and process owners need clear responsibility for policy decisions, evidence collection, and remediation. External auditors assess the result, but they do not replace management’s duty to run the control environment well.
Why This Matters for Security Teams
UK SOX reporting fails when ERP controls are treated as an annual audit exercise instead of a continuously owned management responsibility. The core risk is not just missing evidence, but weak control design, inconsistent operation, and undocumented remediation across finance and IT. NIST’s Security and Privacy Controls are useful here because they frame accountability around owned, testable controls rather than auditor review alone.
That matters because ERP environments concentrate approval workflows, posting rights, interfaces, and privileged access in a small number of systems that can affect financial statements quickly. NHIMG research shows that 97% of NHIs carry excessive privileges, and 71% are not rotated within recommended time frames, which is a warning sign for control environments that depend on stale access and weak evidence discipline. The same pattern appears in incidents such as Schneider Electric credentials breach and JetBrains GitHub plugin token exposure, where credential exposure created downstream governance and assurance problems.
In practice, many security teams encounter missing ERP evidence only after the reporting calendar is already under pressure, rather than through intentional control readiness testing.
How It Works in Practice
Accountability sits with management, but it must be broken down into named operational ownership. Finance leadership should own the reporting assertions, control owners should own the design and operation of each control, and process owners should own the evidence trail for their activities. Third-party implementers can support testing or documentation, but they cannot substitute for management’s obligation to maintain the control environment.
For UK SOX readiness, the practical question is whether each key ERP control can be shown to operate consistently, with evidence that is complete, time-stamped, and linked to the relevant process. That includes user provisioning, segregation of duties, journal approval, interface monitoring, change management, and privileged access review. Current guidance suggests treating evidence as part of the control, not as an afterthought collected only during audit fieldwork. NIST’s control families and the Ultimate Guide to NHIs — Standards are useful for translating this into an operating model that includes ownership, rotation, and review discipline.
- Assign one accountable owner per key ERP control, with a documented backup and escalation path.
- Define evidence requirements at the point of control execution, not at year-end.
- Test both design and operating effectiveness on a recurring basis.
- Track remediation with dates, owners, and proof of closure.
- Review privileged and non-human access to ERP systems as part of the same control set.
If ERP controls depend on service accounts, integrations, or API keys, the evidence burden expands to include non-human access governance. NHIMG data shows only 5.7% of organisations have full visibility into their service accounts, and that gap can undermine the reliability of any financial control that relies on automated ERP processing. These controls tend to break down when ERP evidence is spread across multiple teams and no single function owns the end-to-end control narrative.
Common Variations and Edge Cases
Tighter control ownership often increases coordination overhead, requiring organisations to balance audit readiness against operational speed. In practice, the biggest tradeoff is between centralised governance and local process knowledge: finance wants consistency, while ERP and engineering teams often hold the evidence needed to prove it.
There is no universal standard for this yet, but current guidance suggests a few common edge cases. In outsourced ERP or managed service models, the provider may operate the platform, yet management still remains accountable for the controls that affect financial reporting. In shared-service environments, evidence can be valid even when produced across regions, but only if ownership, timing, and completeness are explicit. For high-change environments, the control challenge is often not the absence of policy but the inability to prove that approvals, access reviews, and configuration changes were actually performed.
UK SOX teams should also watch for compensating controls that are assumed rather than tested. A manual review may exist on paper, but if the reviewer lacks independence, the evidence is inconsistent, or privileged access is not recertified, the control may fail even when the ERP transaction itself appears correct. The lesson from recurring exposure events is simple: weak evidence usually means weak control, not just weak documentation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV | Governance and oversight map to management accountability for ERP controls. |
| NIST SP 800-53 Rev 5 | CM-3 | Configuration management supports ERP control design and change evidence. |
| NIST Zero Trust (SP 800-207) | DA | Zero trust reinforces continuous verification for privileged ERP access. |
| OWASP Non-Human Identity Top 10 | NHI-02 | Non-human identities often underpin ERP automation and evidence gaps. |
| NIST AI RMF | GOVERN | AI RMF governance principles apply to accountable control ownership and oversight. |
Assign control ownership, evidence duties, and remediation tracking under a formal governance cadence.
Related resources from NHI Mgmt Group
- How should organisations prepare ERP controls for UK SOX using lessons from US SOX?
- Who is accountable when ERP controls are missing or poorly aligned across finance, IT, and audit teams?
- Who is accountable for access governance when ERP cloud controls fail an audit?
- Who is accountable when privileged ERP access allows an inappropriate change to financial or supplier data?