Organisations should map existing controls to the new platform before switching off the legacy system, then validate each control against a current ERP snapshot. The safest path is to preserve evidence, keep owners assigned, and test that access, configuration, and transaction controls still cover the same business risks after migration. This reduces control drift and avoids gaps in auditability.
Why This Matters for Security Teams
Replacing legacy ERP access controls is not just a technical cutover. It is a control transfer problem, and audit teams will usually care less about the platform change than whether the same business risks remain covered throughout the transition. If entitlements, approvals, logging, and evidence trails do not move cleanly, the organisation can end up with duplicate controls, blind spots, or an inability to prove who had access at a specific point in time.
The risk is amplified because ERP environments often sit behind business-critical finance, procurement, and order-processing workflows. A migration plan that focuses only on user provisioning misses the broader control set, including segregation of duties, privileged actions, and transaction-level oversight. Current guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls and NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives both point to the same operational principle: controls must be evidenced continuously, not reconstructed after the fact.
In practice, many security teams discover control drift only after auditors ask for legacy and target-system evidence side by side.
How It Works in Practice
The safest migration pattern is to treat the old ERP and the new ERP as overlapping control environments until each control has been mapped, tested, and signed off. Start by building a control inventory that covers access, configuration, transaction approvals, exception handling, and monitoring. Then map each legacy control to its equivalent in the target platform, including the evidence source that will prove it is working.
For identity controls, retain owner assignments, approval paths, and privileged role definitions during the transition. For auditability, preserve logs from the legacy system and verify that the new system captures comparable events with the same retention, time synchronisation, and immutability expectations. This is where NIST Cybersecurity Framework 2.0 helps structure the work around govern, identify, protect, detect, and recover outcomes, while Ultimate Guide to NHIs is useful when ERP automation relies on service accounts, API keys, or integration credentials that also need ownership and rotation.
- Freeze a baseline snapshot of the legacy ERP roles, permissions, and approval chains before cutover.
- Map each legacy control to a target control and assign a named control owner for both systems.
- Run parallel testing to confirm access, configuration, and transaction evidence is complete in the new ERP.
- Retain legacy audit logs and tickets until the target system has demonstrated equivalent control operation.
- Validate exceptions, break-glass access, and SoD conflicts under real business scenarios, not only in design reviews.
Where organisations use integrations or automation, control transfer must include non-human identities as well as human roles. If a migration resets secrets, changes API scopes, or rebinds workflow accounts, the audit trail can fail even when user access looks correct on paper. These controls tend to break down when parallel legacy and target processes diverge for too long because evidence ownership becomes ambiguous and exceptions start routing around the designed approval flow.
Common Variations and Edge Cases
Tighter migration controls often increase testing, documentation, and change-management overhead, so organisations must balance audit assurance against cutover speed. That tradeoff is especially visible in global ERP rollouts, where business units want rapid decommissioning of the old platform while auditors require retained evidence and a demonstrable control bridge.
There is no universal standard for every ERP migration, but best practice is evolving toward phased cutovers, control-by-control validation, and short-lived coexistence. If the legacy system contains custom approvals or country-specific tax controls, those items may not map cleanly to the target platform and should be documented as residual risk until remediated. The NHIMG Ultimate Guide to NHIs — Key Challenges and Risks highlights how easily visibility and credential ownership degrade when environments are in transition, which is directly relevant when ERP integrations depend on service accounts and scheduled jobs.
For regulated environments, align the migration plan with OWASP Non-Human Identity Top 10 and audit-focused control testing so that access drift, stale secrets, and orphaned automation do not create post-cutover findings. Organisations that postpone decommissioning until evidence is complete usually avoid the hardest audit gap, which appears when the old ERP is shut down before the new one has a provable control history.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC, PR.AA, DE.CM | ERP migration needs governance, access assurance, and continuous monitoring. |
| NIST SP 800-53 Rev 5 | AC-2, AC-6, AU-2, AU-6, CM-6 | These controls cover account management, least privilege, logging, and configuration control. |
| OWASP Non-Human Identity Top 10 | NHI-01 | ERP integrations often rely on service accounts and secrets that can create audit gaps. |
| CSA MAESTRO | Identity, access, and policy lifecycle | Migration changes control lifecycles and requires policy continuity across systems. |
| NIST AI RMF | GOVERN | Governance is needed to keep accountability and auditability intact during transformation. |
Inventory non-human identities, assign owners, and validate secret rotation before decommissioning legacy access.
Related resources from NHI Mgmt Group
- How should organisations replace physical ID cards without creating new access control gaps?
- How should organisations run ISO 27001 user access reviews without creating audit noise?
- How should organisations implement identity orchestration without creating new access gaps?
- How should organisations modernise workforce access reviews without creating more audit overhead?