ERP Cutover · Post-Migration Audit
90-day window · Population-level evidence

ERP Cutover Audit — post-migration controls, by the payment.

AP and billing controls fracture during ERP cutovers — and the failure surfaced in three different 10-Q and 10-K disclosures this year alone. VeraStream runs the same eight production detectors against every payment in the 90-day post-migration window, so a duplicate, threshold split, orphan PO, or vendor-master collision is flagged the day it posts — not the day your auditor opens the file three quarters later.

Why ERP cutovers break AP controls

Three filings, three flavors of post-cutover control failure

Each cite below is the actual filing language — pulled character-for-character from EDGAR — followed by the form type, period, and section reference.

Valvoline — material weakness disclosed after Jan 2024 SAP cutover

“In connection with the implementation of the new ERP system on January 1, 2024, a material weakness in internal control over financial reporting arose […] The material weakness relates to the Company’s January 2024 implementation of a new ERP system and its related impact on IT general controls. Specifically, the Company did not ensure adequate (a) system design for certain business processes, (b) segregation of duties reviews for a portion of time during the three-month period ended March 31, 2024, and (c) evidence to support the rigor of change management activities, sensitive access reviews, and design of user roles and application controls, including certain reports, automated jobs and interfaces.” Billing disruption followed: the same filing’s MD&A describes a lengthened collection cycle driven by ERP-related billing delays and disruptions to the timely processing of invoices and billings to franchisee, independent operator and fleet customers.

Source: Valvoline Inc., Form 10-Q for the quarter ended March 31, 2024 (filed 2024-05-10), Item 4 — Controls and Procedures

Schneider National — 2023 10-K flags ERP deployment risk

“We recently completed the deployment of a new ERP system, and challenges with the system may adversely impact our business and operations. In May 2023, we began the implementation of a new ERP system, which was completed in December, to support and streamline our core financial systems […] Any remaining open disruptions, deficiencies, or other problems associated with the implementation of our ERP system, such as quality issues, programming errors, or any cost increases could adversely affect our ability to operate our business, produce timely and accurate financial statements, or comply with applicable regulations.”

Source: Schneider National, Inc., Form 10-K for fiscal year ended December 31, 2023 (filed 2024-02-23), Item 1A — Risk Factors

Flowers Foods — DSD route-accounting ERP upgrade is cutover-in-progress

“The upgrade of the ERP system is designed to accurately maintain our financial records, enhance our operational functionality and provide timely information to our management team related to the operations of the business […] During the second quarter of Fiscal 2023, we began deploying the ERP upgrade. The deployment is anticipated to be completed in Fiscal 2026. We may not be able to deploy the ERP system upgrade successfully without experiencing delays, increased costs and other difficulties, including potential design defects, miscalculations, testing requirements, and the diversion of management’s attention from day-to-day business operations. If we are unable to deploy the ERP system upgrade as planned, the effectiveness of our internal control over financial reporting could be adversely affected, our ability to assess those controls adequately could be delayed, and our financial condition, results of operations and cash flows could be negatively impacted.”

Source: Flowers Foods, Inc., Form 10-K for fiscal year ended December 28, 2024 (filed 2025-02-18), Item 1A — Risk Factors

What breaks during and after cutover

Six specific failure modes that surface in the 90-day post-migration window

  • Duplicate vendor masters. The same supplier ends up under two vendor IDs in the new system — one carried from legacy, one created on go-live — and pays double until reconciled.
  • Split payments to evade approval thresholds. A single invoice is split into two or three payments below the new approver limit set at cutover. The eight production detectors trip on the cluster; quarterly sampling never sees it.
  • Misrouted approvals. The workflow migration maps the prior-ERP approver chain to the wrong role in the new approval matrix; POs clear under nobody or under the wrong person.
  • Orphaned POs. Purchase orders that existed in legacy and weren’t carried into target, or vice versa — receiving against them creates unmatched GR/IR balances that auditors find at year-end sample time.
  • Duplicate invoice numbers across old and new system. Two AP clerks post the same vendor invoice in parallel run; nothing in the system flags it because the two records carry different internal document IDs.
  • Currency rounding drift. FX rates re-baselined at cutover; invoices post with a constant off-by-a-few-cents rounding delta against legacy ledger reconciliation.

Detector → cutover risk → sample finding

How VeraStream maps each cutover failure to a production detector

Eight production detectors against the post-cutover population. Each row pairs the detector with the specific cutover-era risk it catches and a one-line sample finding from a population that mirrors a real cutover-era ledger.

DetectorCutover-Era RiskSample Finding
findDuplicateInvoices
Duplicate invoice numbers across old and new system during parallel runSame vendor, two invoice numbers under different vendor IDs in legacy vs. target ERP — held for reconciliation under the new master.
detectThresholdGaming
Payments split to evade new approval thresholds introduced at cutover$48,900 ($24,450 × 2) wired to the same vendor within 4 hours, both below the new $25,000 approver threshold set post-go-live.
detectExpenseAnomalies
Currency rounding drift and round-dollar entries after cutoverSame vendor invoice $10,000.00 USD ↔ $13,341.55 CAD in legacy ledger vs. $13,341.55 CAD in target — FX rounding off by a constant post-currency revaluation.
detectVendorRisk
Duplicate vendor masters / typosquats at master-data migration“Acme Logistics LLC” (legacy) and “ACME Logistix LLC” (target) paid the same week for overlapping shipments — flagged as master-data collision.
evaluatePolicy
Misrouted approvals and orphaned POs after workflow migrationThree POs totaling $212,400 routed to the prior-ERP approver chain — held pending re-routing in the new approval matrix.
detectRoundDollar
Round-dollar disbursements introduced by new master-data / template-laden AP flows$50,000 wire to "Helix Industrial Services" with the same memo template as a pre-cutover legacy-tier batch — flagged as a one-line tamper pattern from the migrated AP workflow.
detectGhostEmployee
Ghost-employee / SOD weakness — new vendor on a new approver in the same week as a master-data changeA new vendor was added to the master and a new approver was granted sign-off rights within the same 48-hour window — flagged as ghost employee.
detectDuplicatePayment
Same vendor + same or near amount clustered in a short window during cutover — recurring SaaS/rent and refund reversals auto-suppressedTwo $40,000 wires to "Cypress Mechanical LLC" posted on consecutive days after the parallel-run switchover — flagged as near-duplicate cluster.

How VeraStream fits a 90-day post-cutover audit plan

Three bands: scan, monitor, deliver

The post-cutover window is 90 days. Each band runs the same eight production detectors against the same population — the format of the output shifts as the engagement moves from baseline to formal findings.

Week 0–2

Baseline scan

Run the eight production detectors against the full parallel-run ledger — legacy + target. Output: a baseline finding map and a master-data reconciliation report on day 14. The baseline scan establishes the population state before live monitoring begins.

Week 3–8

Monitored detection

Streaming connectors to the new ERP and corporate card feed on day 15 onward. New transactions hit the same eight detectors in under five seconds from posting; weekly finding roll-ups with workpapers are delivered to internal audit and the control owner.

Week 9–13

Formal findings package

Population-level evidence package: every finding with the receipt, the rule that tripped, the override applied, and a methodology appendix. Sized to hand to external auditors under PCAOB AS 2315 — feeds directly into the post-cutover SOX 404(b) assessment.

Frequently asked

Common questions from teams right after cutover

What to do in the 90 days after go-live — plain HTML answers, no JavaScript required to read.

We just cut over to NetSuite/SAP/Oracle — can we import last quarter’s spend?

Yes. VeraStream accepts CSV exports from the legacy system (and from the new ERP side-by-side during parallel run), reconciles vendor masters via fuzzy match, and runs the same eight production detectors against the combined history. Historical loads accept up to several million rows per file; streaming connectors pick up new transactions from cutover day forward.

Do you integrate with our new ERP?

Live deploys use pre-built connectors to NetSuite, SAP, Oracle, Concur, Expensify, Brex, and Ramp. If your ERP is a different platform, the /audit page lets you drop a CSV of yesterday’s disbursements and see the same detectors run in the browser — no integration required to see signal on your cutover population.

What if we have data in both the old and new systems during parallel run?

VeraStream reconciles overlapping vendor masters and invoice numbers across both instances. Duplicate-detection logic treats an invoice that landed in the legacy AP ledger and the new ERP ledger as an immediate flag — exactly the failure mode parallel run is designed to surface, and the one most teams miss without a population-level audit.

Can this help us avoid a material-weakness disclosure after cutover?

The detectors ship with the same workpaper an external auditor needs under PCAOB AS 2315: the receipt, the rule that tripped, and the override applied. Running them continuously during the 90-day post-cutover window surfaces control failures the day they occur, gives remediation a documented evidence trail, and feeds the auditor’s population-level testing rather than relying on a quarterly sample — see /solutions/sox-controls.

How long does a 90-day post-cutover audit engagement take, and what does it cost?

The same eight production detectors — evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — run against every payment in the 90-day post-cutover window. A baseline scan against a full 90-day AP export returns flagged findings in under 90 seconds in the browser. A monitored live deployment — connectors to both legacy and target ERP during parallel run, weekly finding roll-ups — typically launches within two weeks of data access. Use /roi to estimate your post-cutover exposure.

Test it on your own post-cutover ledger

Catch the post-cutover control failure the day it posts

Drop a CSV from your new ERP — or your legacy + target reconciliations — at /audit, or browse a worked sample report at /sample-report. Use /roi to estimate your post-cutover exposure.