For ERP Implementation Consultants ·
What you'll accomplish
Segregation-of-duties rules and approval workflows in finance modules usually exist specifically to satisfy Sarbanes-Oxley controls, and someone still has to confirm the built configuration actually matches the client's control matrix. A dedicated Claude Project holding the control matrix gives you a structured first pass before your own verification, catching obvious mismatches earlier instead of at the external auditor's review.
What you'll need
This is the most sensitive workflow in this guide. SOX-relevant approval workflows and segregation-of-duties configuration describe who can approve what, at what threshold, and whether the same person can both create and approve a transaction. Rather than exporting the client's actual access control list or role permissions table, write out the control matrix's requirements in plain sentences (for example, "no single user may both create and approve a purchase order over the client's approval threshold"), and describe the configured workflow the same way. Never paste real employee names, user IDs, or the live access export into a personal Claude account. Check with the client's controls owner or your engagement lead before treating anything more specific than that as fair game for an AI tool, even inside an approved workspace.
What you should see: Both documents listed in the project's knowledge panel.
Click the edit icon on the instructions panel and add:
You are cross-checking a configured ERP approval workflow against a SOX control matrix, both described in the uploaded knowledge files. Flag any approval routing or segregation-of-duties rule in the configured workflow that appears inconsistent with the control matrix. For each flag, state which control it conflicts with and why. Do not draw a final conclusion about compliance. Every flag needs human verification against the live system before it is reported as a finding.
Save the instructions.
Start a new chat inside the project and ask for a review of the current module's workflow against the matrix.
Example prompt to copy-paste:
Review the Procure-to-Pay approval workflow against our control matrix. Flag any routing rule or segregation-of-duties requirement that looks inconsistent, and explain which control it conflicts with.
What you should see: A list of specific flagged items, each tied to a named control, rather than a general statement that the workflow "looks fine" or "has some issues."
Here's our control requirement: [plain-language description]. Here's the configured workflow: [plain-language description]. Do they conflict?List every approval role in this workflow description and who each one reports to.Flag any step in this workflow where the same role both creates and approves a transaction.Summarize which controls in our matrix don't yet have a corresponding configured rule.Compare this quarter's workflow description against last quarter's. What changed?