SOX · NetSuite ERP
ITGC-004 — Privileged access reviewed quarterly
Quarterly review of privileged NetSuite roles by the IT Security Manager, with removal of inappropriate access within five business days.
Control attributes
- Type
- ITGC
- Nature
- Manual
- Frequency
- Quarterly
- Key control
- Yes
- Assertions
- All
- System
- NetSuite
- Owner
- IT Security Manager
- SOX scope
- In scope
- Last tested
- Sep 15, FY26
- Testing status
- Exception
- Samples tested
- 26
- Exceptions
- 2
AI scoping reasoning
Morgan · Audit Manager Agent
In scope — supports all automated controls in NetSuite
Linked risk
R-07High
Segregation of duties conflicts in ERP
312 open SoD conflicts, 41 without documented mitigating controls.
Evidence
1 requests
EV-2044Validated
NetSuite privileged role listing with change history
System-generated with parameters screenshot; IPE criteria met.
Exceptions
0 identified
No exceptions identified.
Review notes
1 on this control
RN-503Cleared
Dev (Senior Auditor) → Rowan (Senior Auditor)
Evidence of completeness for the privileged role listing needs a parameters screenshot.