Chapter 14 · Governance & Audit
- 00 · Introduction
- 01 · The ConfigCompare Platform
- 02 · The Four Pillars
- 03 · Core Concepts
- 04 · ConfigCompare
- 05 · Comparison Engine
- 06 · Snapshots
- 07 · Comparison Types
- 08 · Rulesets
- 09 · AI Insights
- 10 · Monitoring & Alerts
- 11 · ConfigTrack
- 12 · ConfigAudit
- 13 · Application Lifecycle Management
- 14 · Governance & Audit
- 15 · Testing and Support
- 16 · Upgrades
- 17 · ConfigMigrate
- 18 · Central Command Center
- 19 · Legacy Dynamics AX
- 20 · Partner Managed Services
- 21 · Utilities
- 22 · Licensing
- 23 · Frequently Asked Questions
- 24 · Glossary
- 25 · Canonical Resources
- 26 · Roadmap
Technical reference · Chapter 14
Governance & Audit
Purpose
Governance & Audit is one of the four pillars of ConfigCompare.
It focuses on visibility, evidence, internal control, Configuration Drift detection, and responsibility for changes in Microsoft Dynamics 365 Finance & Supply Chain Management.
This chapter describes the pillar in practice, applying the concepts introduced in Chapters 03 to 10. The four pillars are introduced together in Chapter 02.
This chapter describes concepts and behaviour; step-by-step operating guidance sits outside this reference.
Configuration Governance
Configuration Governance is the process of maintaining, validating, monitoring, and controlling ERP configuration over time.
It includes knowing:
- What configuration exists.
- Where configuration differs.
- Where configuration matches when it should differ.
- When configuration changed.
- Whether a change was expected.
- Whether a change was authorised.
- Who or what group is responsible.
- Whether a Difference affects risk, compliance, testing, or operations.
Audit evidence
ConfigCompare supports audit evidence by preserving Snapshots and producing Deterministic Comparison results.
Evidence can support internal controls, SOX, J-SOX, internal audit, external audit preparation, and management review.
Configuration Drift
Configuration Drift occurs when environments, companies, templates, or points in time diverge.
Configuration Drift is not always undesirable: some divergence is planned. The governance problem is uncontrolled or invisible drift.
ConfigCompare helps organisations identify Configuration Drift and classify whether it is expected, acceptable, unauthorised, or requiring review.
Undesired Matches
Configuration Governance is concerned with similarities as well as Differences.
Some environments are expected to differ. When they do not, the Match itself is the governance concern; the classic case is a restore of Production into a downstream environment such as UAT that leaves production endpoints or integration settings in place.
ConfigCompare reports Matches alongside Differences so that these conditions can be identified, escalated, and remediated with the same attention as critical Differences.
High-risk configuration
Some configuration areas have a direct, and sometimes non-reversible, effect on financial, operational, or compliance outcomes.
Examples include:
- Inventory costing settings.
- Tax configuration.
- Posting profiles.
- Bank configuration.
- Workflow approvals.
- Security-related configuration.
- Warehouse execution settings.
- Production control parameters.
- Integration-related settings.
ConfigCompare allows organisations to monitor these areas and create evidence around configuration changes.
How the pillar is delivered
Governance & Audit draws on capabilities across the platform:
- Snapshots and Deterministic Comparison provide the factual evidence of what configuration exists and how it has changed (Chapters 04–07).
- Rulesets and Responsibility apply organisational policy to comparison results and route findings to accountable owners (Chapter 08).
- Monitoring & Alerts turn occasional manual review into continuous governance through Scheduled Snapshots, Scheduled Comparisons and alerting. Governance operates by exception; no dedicated reviewer is required (see the operating model in Chapter 10).
- ConfigTrack governs planned change through structured events, risk assessment, RACI responsibility and approval workflows (Chapter 11).
- ConfigAudit captures event-level changes within critical configuration areas, including transient changes that revert between Snapshots (Chapter 12).
Together these capabilities answer both governance questions: whether configuration changed as expected, and whether changes were authorised and appropriate.
Compliance support
Governance & Audit evidence supports compliance frameworks and activities including:
- SOX (Sarbanes-Oxley) internal control requirements.
- J-SOX governance and audit requirements.
- Internal audit procedures.
- External audit preparation.
- Management review.
Snapshots are immutable once captured. ConfigTrack events cannot be deleted, and closed events cannot be materially modified, supporting evidence integrity.
Business outcomes
Adoption of Governance & Audit is typically driven by the following outcomes:
- Continuous visibility: configuration change is observed as it happens rather than discovered after an incident.
- Controlled change: changes are expected, authorised and traceable to accountable owners.
- Audit readiness: evidence of configuration controls exists before an auditor asks for it.
- Reduced compliance effort: audit evidence is produced by the platform rather than assembled manually.
- Early detection of Configuration Drift: uncontrolled divergence is identified before it creates business impact.
- Fraud exposure: transient changes that revert before the next Snapshot are captured by ConfigAudit.