ERP Managed Services Pro — Enterprise ERP consulting. No software sold, no legal advice given.
APMLifecycleROI Book Assessment

SOX: Erp Support Services

EnterpriseTier BSOXCompliance

The Sarbanes-Oxley Act (SOX) requires public companies to maintain internal controls over financial reporting (ICFR). Section 404 requires management to assess these controls annually and external auditors to attest to that assessment.

How SOX affects ERP managed services

The ERP is the primary system of record for financial data. SOX control objectives — segregation of duties, access controls, change management, and audit trail — all have direct ERP configuration implications. A managed services provider operating your ERP must understand your SOX control environment and must not take actions that create control deficiencies.

Controls

Managed services controls for SOX compliance

Control areaManaged services requirementEvidence type
Access managementProvider access to production must follow least-privilege principle. Privileged access must be time-limited and logged.Access logs, PAM tool reports
Change managementEvery change to production configuration must go through an approved change process with before/after documentation.Change tickets, approval records
Audit trail integrityThe provider must not modify or delete audit log data. Log integrity must be demonstrable (hash or WORM storage).Log integrity reports
Incident responseSecurity incidents (or potential SOX breaches) must follow a documented escalation path with defined notification timelines.Incident records, notification evidence
Subcontractor managementIf the provider uses subcontractors with access to in-scope data, those relationships must be disclosed and governed.Subprocessor list, flow-down agreements

What to include in your managed services contract for SOX

  • A right-to-audit clause allowing your auditors (or external auditors) to review the provider's controls relevant to your environment
  • A breach/incident notification SLA aligned to SOX timelines
  • An obligation to maintain SOC 2 Type II certification (or equivalent) and provide reports annually
  • A prohibition on using your data to train models or for purposes beyond service delivery
  • A data return/deletion clause at contract termination
This page covers compliance considerations for managed services contracting only. It is not legal advice. Engage a qualified legal or compliance professional for decisions about your specific SOX obligations.

Ready to assess your ERP managed services options?

Our specialists work with IT directors and finance leads at organisations managing one or more ERP platforms. An assessment takes 45 minutes and produces a written summary you can share with your steering committee.