Manufacturing IT Audit Software Consulting
IT audit software for manufacturers is the platform used to test IT general controls (ITGCs) — access management, change management, and IT operations — across a technology footprint that is wider and more fragmented than most other industries: the financial ERP, one or more manufacturing execution systems (MES) often differing by plant, PLM or engineering systems that own the bill-of-materials, and the interfaces connecting all of them. Because standard-cost accuracy depends on BOM data flowing correctly from PLM through the ERP's cost roll-up, and because inventory and WIP balances depend on MES transactions posting correctly to the general ledger, ITGC testing at a manufacturer has to extend beyond the ERP itself to cover access and change management over the systems that feed it — a scope generic IT audit tooling built around a single ERP instance often does not handle well.
Why ITGC scope at a manufacturer extends past the ERP
A conventional ITGC scoping exercise focuses on the financial ERP: who has access to post journal entries, who can change the chart of accounts, how application changes are tested and approved before deployment. At a manufacturer, that scope is necessary but insufficient, because financially relevant data — the BOM that drives standard cost, the production and material-issue transactions that drive inventory valuation — often originates and is controlled in systems outside the ERP entirely: a PLM system for engineering data, an MES for shop-floor transactions, sometimes a separate warehouse management system for cycle counts. Restricting ITGC testing to the ERP alone leaves the access and change controls over these upstream systems completely untested, even though a change to a BOM in the PLM system or an unauthorized edit to a standard-cost table has the same financial-statement impact as an unauthorized ERP change.
IT audit software needs to support a scoping methodology that identifies every system feeding financially relevant data into the ERP — not just the ERP's own configuration — and builds ITGC test plans for access management, change management, and computer operations at each one. This is a materially larger scope than a single-system ERP audit, and software that assumes a one-ERP-instance world tends to force awkward workarounds (treating the MES as 'out of scope' by default, for instance) that leave real risk untested.
Access and change management over BOM and standard-cost configuration
The specific ITGC that matters most for manufacturing costing accuracy is access to edit released BOMs, standard-cost tables, and overhead absorption rates — configuration that functions financially like a chart-of-accounts change but often sits in a PLM or MES module outside the ERP's own security model, and is therefore easy to leave out of a standard ERP-centric access review. IT audit software should support testing user access listings against a defined population of users who should have BOM or standard-cost edit rights, flagging any access outside that population, and testing whether changes to this configuration flow through the engineering-change-order approval workflow rather than being editable directly.
Change management testing needs a parallel scope extension: application changes to the MES (a new production-transaction type, a modified interface mapping to the ERP) or to the PLM system (a workflow change to the ECO approval sequence) should go through the same test-before-deploy, documented-approval discipline expected of ERP changes, because a defect introduced in an MES upgrade can misstate inventory just as effectively as an ERP defect. Software that only tracks ERP change tickets misses this population entirely.
Interface controls as a distinct ITGC test population
The interface between the MES and the ERP — and between the PLM system and the ERP for BOM data — is itself a control point that needs dedicated ITGC testing: who can modify the interface mapping configuration, is there a change-approval process for interface logic changes, and does a batch completeness check run automatically to catch dropped or duplicated transactions. IT audit software built for single-system environments often has no natural place to test interface-specific controls, treating them either as part of the source system's change management or ignoring them altogether, when in practice interface configuration changes are frequently made by a small technical team with broad access and limited oversight.
A well-configured ITGC test plan for a manufacturer therefore treats the interface layer as its own tested population — with its own access review (who can change mapping rules), its own change management sample (interface configuration changes in the period), and its own operations control (evidence that batch completeness monitoring ran and any exceptions were resolved) — rather than folding it silently into either the source or target system's test scope.
What actually differentiates the options
- ·Scoping methodology and workpaper structure that extends ITGC testing beyond the ERP to PLM, MES, and any other system feeding financially relevant BOM, cost, or production data.
- ·Access-review functionality that can test BOM and standard-cost edit rights specifically, against a defined population of authorized users, separate from general ERP access review.
- ·Change-management test templates covering MES and PLM application changes, not only ERP changes, with sampling and approval-trail testing consistent across all in-scope systems.
- ·Support for treating the MES-to-ERP and PLM-to-ERP interface layer as a distinct tested population — access, change management, and batch-completeness monitoring evidence.
- ·Multi-system, multi-plant scoping support so ITGC testing can reflect different technology stacks at different plants without forcing a one-size-fits-all test plan.
Requirement, control, evidence
| Requirement | Control | Evidence |
|---|---|---|
| Access to financially relevant systems must be appropriately restricted and reviewed (ITGC, Section 404) | Periodic access review of BOM and standard-cost edit rights in the PLM/ERP against an authorized-user population, with exceptions remediated and documented. | Access review workpaper showing user population tested, exceptions identified, and remediation evidence for the period. |
| Application changes to financially relevant systems must be tested and approved before deployment (ITGC, Section 404) | Change-management process requiring documented testing and approval for MES and PLM application changes, not only ERP changes, sampled each period. | Change-ticket sample showing test evidence, approval sign-off, and deployment date for a sample of MES/PLM changes in the period. |
| Interface configuration between MES/PLM and ERP must be controlled and monitored (ITGC, Section 404) | Restricted, logged access to interface mapping configuration, with a change-approval process and automated batch-completeness monitoring for interface transfers. | Interface access-log review and batch-completeness monitoring report showing exceptions identified and resolved for the period. |
| IT operations supporting financial close must be reliable and monitored (ITGC, Section 404) | Scheduled job monitoring for batch interfaces and cost roll-up processes, with failure alerting and documented resolution before affected data is used in close. | Job-scheduler log and incident record showing any failed batch or roll-up job and its resolution prior to close, for the period. |
What this actually costs
| Cost driver | Low | High | What moves it |
|---|---|---|---|
| ITGC scoping and test-plan design across ERP, PLM, and MES | $55,000 | $170,000 | Scales with number of distinct systems and plants in scope; manufacturers with a single consolidated ERP/MES trend toward the low end. |
| Access and change-management remediation across BOM/costing configuration | $60,000 | $260,000 | Driven by how unrestricted current BOM/standard-cost edit access is and whether formal change-management processes exist for MES/PLM changes. |
| Ongoing ITGC testing across ERP, PLM, MES, and interface layers | $40,000/yr | $175,000/yr | Higher end reflects accelerated-filer 404(b) rigor across multiple plants with distinct system instances requiring separate test cycles. |
- · Ranges assume a mid-market to large-enterprise manufacturer with one financial ERP and one to several MES/PLM instances across plants.
- · Figures are illustrative estimates based on typical manufacturing ITGC engagements, not a quote for a specific organization.
- · External audit attestation fees under 404(b) are excluded — this reflects ITGC-scoped advisory and remediation labor only.
A representative scenario
Consider a hypothetical publicly-traded automotive-parts manufacturer running a single financial ERP shared across three plants, each with its own MES instance and a separate PLM system owning the master BOM. Its ITGC testing program, built years earlier around the ERP alone, covers ERP user access and change management thoroughly but has never scoped the PLM system where BOMs actually originate, nor the interface that pushes approved BOM changes into the ERP for cost roll-up. During a 404(b) readiness assessment, the external auditor identifies that PLM access to edit released BOMs is granted to roughly forty engineering users with no periodic review, and that BOM changes flow into the ERP through an interface with no completeness check — meaning a dropped transfer could leave the ERP's standard cost stale relative to the actual approved BOM. A typical remediation path involves extending ITGC scope formally to the PLM system, implementing a quarterly access review specifically for BOM-edit rights, and building a completeness reconciliation on the PLM-to-ERP interface with alerting on failed transfers. This pattern — ITGC scope frozen around a single ERP while the actual control-relevant systems evolved outward into PLM and MES — recurs often enough across manufacturing ITGC programs to describe here as illustrative, not as a specific organization's outcome.
Common questions
They need to cover any system that produces or controls financially relevant data flowing into the ERP, which for most manufacturers includes the PLM system (BOM and standard-cost-relevant engineering data) and the MES (production and material-issue transactions). Scoping ITGC testing to the ERP alone leaves the actual origination point of costing and inventory data untested, which is a common finding when a first-time accelerated filer's ITGC program was originally built around a single-system assumption.
Book an assessment
Get a scoping call on manufacturing it audit software for your organisation's platform and entity structure.
Book an Assessment →