ERP Audit Logs and Access Reviews: A Traceable Evidence Chain
Define mandatory events, viewers, retention and review so access and critical changes are verifiable.
Learning objective
Implement an event catalogue, protected logs, investigations and periodic reviews.
Roles
Business owners, finance, IT, consultants and audit
Prerequisites
- Critical fields are complete and time is consistent.
- Gaps trigger alerts.
- Review decisions trace to access changes.
Completion checks
- Critical fields are complete and time is consistent.
- Gaps trigger alerts.
- Review decisions trace to access changes.
Common errors
- Logging successes only.
- Allowing silent deletion.
- Omitting service accounts.
Thailand project note
For Thailand, confirm multilingual data, THB and foreign currency, Asia/Bangkok time, segregation and retention; VAT, WHT, customs, BOI and statutory accounting require qualified Thai review.
Related modules
Steps
- 01
Catalogue login, failure, access, master, configuration, approval, posting, export and integration events.
- 02
Define time, user, role, organisation, object, action, before/after, source and result.
- 03
Display Asia/Bangkok consistently while retaining original time and zone.
- 04
Prevent silent administrator changes and monitor gaps and unusual export.
- 05
Assign alerts, owners, targets and investigation templates to high-risk events.
- 06
Business owners review users, conflicts, dormant and temporary access quarterly.
- 07
Trace sampled transactions to approvals, access and interface logs.
Implementation notes
- Critical fields are complete and time is consistent.
- Gaps trigger alerts.
References
- U9 cloud 全链路数据分析能力 ↗用友 U9 cloud · Accessed: 2026-08-21 · Applicable version: 公开数据模型、权限和分析能力
- YonSuite 客户成功服务 ↗用友 · Accessed: 2026-08-21 · Applicable version: 公开迁移、巡检与上线后服务范围