4 requirements evaluated: 4 partial.
Partial
Requirement evaluated: The system must maintain an immutable, timestamped, per-action audit log covering every discrete event in the AP lifecycle: invoice receipt, data extraction, coding, each approval action, exception handling, payment initiation, and ERP posting to NetSuite. No event may be deleted, overwritten, or backdated after it is written; the log must be append-only and cryptographically or architecturally protected against alteration by any user including administrators. This directly addresses the buyer's stated requirement that no action in the AP lifecycle is unrecorded or editable after the fact.
For a PE-backed company on NetSuite preparing for IPO, SAP Concur Invoice provides a per-action, timestamped audit trail at both the invoice header level and the line-item level. <cite index="38-1,38-2,38-3">It is possible to review the audit trail history for an invoice; this information is read-only and for viewing purposes only, and the trail captures date and time, the name of the user who updated the audit trail, the action, and a description of the action.</cite> <cite index="38-4">The information cannot be edited.</cite> <cite index="10-3,10-10">Automatic audit trails are described as helping reduce bottlenecks and maintain accountability.</cite> <cite index="10-16">Internal controls …
Limitations: The audit trail is application-layer read-only but Concur does not publish cryptographic or architectural immutability guarantees that block administrator-level alteration, which is the specific bar this buyer's SOX readiness requirement sets. …
Partial
Requirement evaluated: The system must provide full chain-of-custody documentation for every invoice, capturing: the identity of the person or system that received it, every individual who viewed, acted on, approved, rejected, or escalated it, and the exact timestamp of each action. This chain must be exportable in a format suitable for auditor review and must remain intact and retrievable for the retention period required by SOX (minimum seven years), without dependency on the vendor's continued storage of archived data.
For a PE-backed NetSuite company preparing for IPO and SOX readiness, Concur Invoice does maintain a dedicated Invoice Audit Trail that is explicitly read-only, recording per-action events by both users and the system across the invoice lifecycle. <cite index="45-1,45-2,45-3">The audit trail presents a read-only history for each invoice, capturing samples of actions that generate entries; the documented list does not include every action that creates an entry.</cite> Supporting documentation confirms that granular actions are logged: <cite index="19-1">Concur Invoice creates an audit trail entry when a receipt image is deleted,</cite> and <cite index="13-12,13-13,13-14,13-15">when a user add …
Limitations: The audit trail's long-term retrievability depends entirely on continued access to the Concur platform; no documented native bulk-export of invoice audit events to an independent archive exists, which directly conflicts with the buyer's stated requirement for retention independent of vendor storage. …
Partial
Requirement evaluated: The system must enforce configurable segregation of duties (SoD) controls at the role level, ensuring that no single user can perform conflicting actions across the AP lifecycle; for example, the same user who enters or approves an invoice must be structurally prevented from also authorizing or executing the corresponding payment. SoD rules must be enforced by the system architecture, not by policy alone, so that violations are impossible rather than merely prohibited, supporting the buyer's SOX readiness requirements ahead of IPO.
For a PE-backed company on NetSuite preparing for IPO-level SOX readiness, Concur Invoice provides structurally distinct named roles across the AP lifecycle: Invoice AP User (invoice entry and submission), Invoice Processor (final approval and processing), and Invoice Pay Manager (monitoring and releasing payment batches). <cite index="24-3,24-4">The Invoice Pay functionality role allows a user to monitor and adjust Invoice Pay batches and invoices scheduled for payment.</cite> <cite index="24-9">The Invoice Processor role cannot create and submit invoices.</cite> When an administrator assigns these roles to different users, functional separation across the approval chain exists. …
Limitations: Concur Invoice does not contain a native SoD conflict-detection or conflict-blocking engine: a Company Administrator can assign both invoice-entry and payment-release roles to the same user without any system-level warning or hard stop, and the 'Allow Invoice Processors to Process Their Invoices' setting provides an ex …
Partial
Requirement evaluated: The system must enforce role-based access controls (RBAC) at a granular level, limiting each user's visibility and action permissions to only the invoices, vendors, GL accounts, cost centers, and approval queues relevant to their role. Permission assignments and any changes to them must be logged with the identity of the administrator who made the change and the timestamp, so that access creep and unauthorized permission escalation are detectable during a SOX audit.
For a PE-backed company on NetSuite preparing for SOX readiness, Concur Invoice's RBAC model delivers functional-area role segregation but falls short of the granular, auditor-ready permission-change logging the buyer requires. On the access-control side, Concur uses predefined 'Permission Sets' or 'Roles' mapped to licensed modules (Expense, Travel, Invoice, Request), assigned per user record by a Company Administrator via Administration > Company > User Administration (Stitchflow SAP Concur User Management Guide). …
Limitations: The permission-change log does not natively capture before/after field values for all administrative changes, and delegate removals are explicitly not logged — both gaps that SOX auditors at a pre-IPO company will flag. …