8 requirements evaluated: 2 supported, 6 partial.
Supported
Requirement evaluated: The solution must maintain a complete, timestamped audit trail for every invoice action, including capture, coding change, approval, rejection, and payment, stored in a way that can be exported and cross-referenced against the corresponding NetSuite transaction record, supporting the internal audit and compliance requirements common in entertainment businesses with investor or studio reporting obligations.
For an entertainment business running NetSuite with investor and studio reporting obligations, Medius maintains a continuous, timestamped audit record across the full invoice lifecycle. Starting at capture, every invoice is automatically archived and its entire processing history is logged: AI extraction decisions, coding changes, routing steps, approvals, rejections, exceptions flagged by fraud detection, and payment execution are all captured as system events. As Medius documents: 'auditors can quickly access timestamped records of every action — from submission to approval to payment' (Medius e-invoicing blog, May 2025). …
Limitations: Publicly available documentation describes the export path primarily through invoice search gadget exports to Excel and hyperlinked report fields, rather than a documented single-click structured export that pairs every raw Medius event record side-by-side with the corresponding NetSuite internal transaction ID in one …
Partial
Requirement evaluated: The system must enforce role-based access controls (RBAC) at a granular level, limiting each user's visibility and action permissions to only the invoices, vendors, GL accounts, cost centers, and approval queues relevant to their role. Permission assignments and any changes to them must be logged with the identity of the administrator who made the change and the timestamp, so that access creep and unauthorized permission escalation are detectable during a SOX audit.
For a PE-backed company on NetSuite preparing for SOX, Medius (via MediusGo) provides a structured role-based permission model administered through its Administration Tool. <cite index="15-4,15-5,15-6">Invoices and permissions are managed through users and roles, where a user represents a personal login with all activity linked to that login, and roles control which functions and permissions each user has.</cite> <cite index="6-10,6-11,6-12,6-13,6-14,6-15">Role permissions are set per company entity and cover approval rights (which amounts and coding values the role may approve), report and search access rights, special approval rules, coding rights, and administration tool rights.</cite> <c …
Limitations: The material gap for this SOX buyer is the second half of the requirement: no documented mechanism was found showing that permission assignments and changes to them are logged with the identity of the administrator who made the change and a timestamp, which is the specific evidence SOX auditors need to detect access cr …
Partial
Requirement evaluated: The system must maintain an immutable, timestamped, per-action audit log covering every discrete event in the AP lifecycle: invoice receipt, data extraction, coding, each approval action, exception handling, payment initiation, and ERP posting to NetSuite. No event may be deleted, overwritten, or backdated after it is written; the log must be append-only and cryptographically or architecturally protected against alteration by any user including administrators. This directly addresses the buyer's stated requirement that no action in the AP lifecycle is unrecorded or editable after the fact.
For a PE-backed company on NetSuite preparing for SOX readiness, Medius delivers a meaningful lifecycle-spanning audit trail that covers the pre-processing journey from invoice receipt through payment execution. On the supporting side: <cite index='21-7,21-8'>Medius states that 'all risk is automatically flagged, mitigated and logged across the AP lifecycle' and that 'AI-powered extraction removes the need for manual data entry, while every invoice is automatically archived, ensuring accuracy, traceability, and audit confidence at any time.'</cite> A Medius e-invoicing blog confirms that <cite index='29-7,29-8'>e-invoicing combined with Medius AP Automation 'provides a clear digital audit tr …
Limitations: Medius documents a comprehensive, timestamped, lifecycle-spanning audit trail, but it makes no public claim that the log is architecturally or cryptographically protected against post-write alteration by administrators: the critical distinction between 'comprehensive logging' and 'immutable logging' that SOX auditors a …
Partial
Requirement evaluated: The system must enforce configurable segregation of duties (SoD) controls at the role level, ensuring that no single user can perform conflicting actions across the AP lifecycle; for example, the same user who enters or approves an invoice must be structurally prevented from also authorizing or executing the corresponding payment. SoD rules must be enforced by the system architecture, not by policy alone, so that violations are impossible rather than merely prohibited, supporting the buyer's SOX readiness requirements ahead of IPO.
For a PE-backed NetSuite company preparing for IPO-level SOX scrutiny, Medius provides a layered but configuration-dependent SoD architecture rather than an architectural guarantee that conflicting roles are impossible to assign. The core mechanism operates at three levels. First, role-based approval rights (administered under Organization-Roles) control which users can approve which GL coding dimensions and up to what dollar amounts; <cite index="45-3,45-4">approval rights are governed by Approval rules set up in the administration tool, and the system prevents a user from approving rows where they lack permission (the approval box is grayed out).</cite> Second, the AllowInspectAndAttest sy …
Limitations: The critical gap for this buyer's SOX requirement is that SoD enforcement depends on correct administrative configuration rather than architectural immutability: an admin who assigns a user to both an invoice-approval role and the Pay Approver Role is not structurally blocked from doing so, and the AllowInspectAndAttes …
Showing the 4 most recent of 8. The rest are in the comparisons listed below.