Unsupported controls create risk because they stop evolving as ERP processes, threat patterns, and audit expectations change. Over time, that leaves control defects, weaker detection of segregation of duties issues, and more manual audit work. When the platform no longer matches the application landscape, organisations lose confidence that their controls are still complete and defensible.
Why This Matters for Security Teams
Unsupported GRC controls are more than an administrative nuisance in ERP environments. They create a gap between the control design that auditors expect and the way business processes actually run today. As ERP modules, custom workflows, integrations, and access models change, stale controls stop reflecting real segregation of duties, approval paths, and exception handling. That weakens both compliance evidence and operational resilience.
This matters because ERP systems sit at the centre of financial reporting, procurement, order fulfilment, and master data governance. If a control no longer tracks current process logic, it can miss a toxic access combination or flag the wrong activity while the real risk goes undetected. NIST’s Cybersecurity Framework 2.0 and SP 800-53 Rev. 5 both assume controls are maintained as part of an operating discipline, not left to drift.
NHIMG’s Ultimate Guide to NHIs and Regulatory and Audit Perspectives makes the same point in adjacent terms: once governance mechanisms fall out of sync with the environment, assurance becomes harder to defend. In practice, many security teams discover unsupported controls only after audit evidence starts failing or a SoD issue has already moved into production.
How It Works in Practice
An ERP control is supported when it is tied to a living owner, a defined review cadence, test procedures, and a change process that tracks ERP configuration updates. Unsupported controls usually fail in one of three ways: the control logic no longer matches the underlying transaction flow, the evidence source has changed, or the reviewer no longer understands the control objective. Any of those breaks the chain between design, operating effectiveness, and audit defensibility.
Practitioners should treat each control as part of a lifecycle, not a one-time implementation. NHIMG’s Lifecycle Processes for Managing NHIs is written for NHI governance, but the same operational principle applies here: ownership, review, refresh, and retirement must be explicit. In ERP environments, that means mapping controls to current business roles, system roles, interface accounts, and automated job identities, then validating whether the control still detects the actual risk it was designed to catch.
- Revalidate the control against current ERP configuration, custom code, and workflow exceptions.
- Check whether the evidence source still exists and whether it is still trustworthy.
- Confirm that the control owner can explain the control objective in current business terms.
- Retest segregation of duties rules after every major upgrade, integration change, or role redesign.
- Track unsupported controls separately so they are either remediated, replaced, or formally retired.
Where this becomes especially important is in automated access paths and service accounts that interact with ERP data outside normal human workflows. NHIMG’s Top 10 NHI Issues reinforces that unmanaged identities and stale entitlements quickly create blind spots. These controls tend to break down when the ERP landscape includes heavy customisation, frequent releases, or third-party integrations because the control logic cannot keep pace with the application surface.
Common Variations and Edge Cases
Tighter control support often increases maintenance overhead, requiring organisations to balance audit confidence against the effort needed to keep ERP controls current. Best practice is evolving here: there is no universal standard for how quickly an ERP control becomes “unsupported,” but guidance consistently favours documented ownership, recurring validation, and formal retirement criteria rather than indefinite carryover.
Some environments have stable core ERP processes but a large number of local extensions, regional variants, or bolt-on platforms. In those cases, a control can remain technically active while being functionally obsolete in one business unit and effective in another. That creates inconsistent assurance and can lead to false positives in one area and missed exposures in another. The Key Challenges and Risks section of NHIMG’s research is a useful parallel: visibility gaps and stale governance artifacts compound quickly when systems are fragmented.
Another edge case is when controls are partially supported by tooling but no longer by process ownership. In that situation, automation can create a false sense of completeness. Organisations should not assume that a passing test means the control is still fit for purpose. Where ERP access is tightly coupled to third-party connectors or non-human identities, a control review should also consider whether the evidence and exception handling still capture those pathways. ISO/IEC 27002:2022 supports this lifecycle view by emphasising ongoing control operation, not static documentation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and ISO-IEC-27001 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Unsupported controls weaken continuous oversight of ERP risk and control performance. |
| NIST SP 800-53 Rev 5 | CA-7 | ERP controls need continuous monitoring, not one-time validation, to stay defensible. |
| ISO-IEC-27001 | 9.1 | Performance evaluation requires controls to stay aligned with changing ERP operations. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Stale access logic around non-human identities often creates unsupported ERP control paths. |
| CSA MAESTRO | GOV-2 | Governance must track control ownership and lifecycle to avoid blind spots in ERP assurance. |
Monitor ERP control effectiveness continuously and fix or retire controls that no longer work.
Related resources from NHI Mgmt Group
- Why do agentic AI environments increase the risk of policy drift between compliance and operational reality?
- Why do manual internal controls increase compliance and security risk in regulated environments?
- Why do third-party service relationships increase operational and compliance risk in financial environments?
- Why do non-human identities create audit risk in modern environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org