ERP5 min readNetray Engineering Team

Third-Party Risk Management for ERP Vendors and Partners

Third-party risk management for ERP is the process of evaluating and controlling the security risk introduced by vendors who host, implement, support, or integrate with your ERP system. A typical manufacturer running Infor SyteLine or LN has a software vendor, a hosting or cloud provider, an implementation partner, an MSP, a tax engine, an EDI provider, and several integration vendors, most with some form of privileged access. Attackers know that compromising one partner grants access to dozens of manufacturers. This guide covers assessment, access control, contract terms, and continuous monitoring for ERP third parties.

Building an ERP-Specific Vendor Inventory

Start by listing every party that can reach ERP data, not just those with a signed master services agreement. The inventory that matters includes anyone with an ERP login, database access, VPN or jump host credentials, an API key, or a copy of production data in a test environment. That last category is chronically missed: implementation partners routinely hold refreshed copies of production databases containing customer pricing and employee data. Rank each vendor by data sensitivity and access level rather than by contract value, because a small integration vendor with write access to your item master carries more risk than a large supplier with none.

  • Record for each vendor: data accessed, access method, privilege level, and named internal owner
  • Flag every vendor holding a copy of production data outside your environment and require deletion evidence
  • Separate vendors with standing access from those with brokered, time-boxed access and drive the first group to zero
  • Re-validate the inventory at least annually and whenever a project ends, since project access rarely gets revoked

Reading SOC 2 Reports and Cloud Shared Responsibility

Collecting a SOC 2 Type II report is not the control; reading it is. Check the audit period covers the last twelve months, check the scope actually includes the service you buy, and read the exceptions section rather than the cover letter. Most importantly, read the complementary user entity controls, which list the things the report assumes you are doing. For cloud ERP such as Infor CloudSuite running on AWS, the provider covers infrastructure, platform patching, and physical security while you retain user provisioning, role design, segregation of duties, data classification, and integration credential management. Document that boundary explicitly so nothing falls in the gap.

Controlling Partner Access to Production

The default arrangement at most manufacturers is that the implementation partner and the MSP hold permanent, shared, highly privileged ERP and server accounts. Replace this with named individual accounts, no shared credentials, MFA enforced, access granted per ticket with an expiry, and sessions recorded through a jump host. Consultants should work in a non-production environment by default with production access requiring an approved change record. Refresh test environments with masked data so a partner copy of the database does not contain real employee bank details or customer pricing. These controls are also increasingly required by cyber insurers and by defense prime contractors.

  • Issue named individual partner accounts with expiry dates; ban shared consultant logins entirely
  • Broker all partner access through a jump host with MFA and session recording, never direct VPN to servers
  • Mask sensitive fields when refreshing non-production environments from a production copy
  • Disable partner accounts automatically at project close and verify with a post-project access extract

Contract Clauses and Compliance Flowdown

Your leverage is at contract renewal, so use it. Require breach notification within 24 to 72 hours of discovery, not of confirmation. Require MFA for all access to your data, a right to audit or to receive current attestations annually, defined subcontractor disclosure, and documented data return and destruction at termination. Defense manufacturers must flow down DFARS 252.204-7012 obligations and the applicable CMMC requirement to any subcontractor or service provider handling controlled unclassified information, including cloud and managed service providers. Make security requirements an exhibit to the contract rather than an email, because only the exhibit survives account team turnover.

How Netray Reduces ERP Third-Party Risk

Netray inventories every account, integration key, and data copy connected to your Infor environment, including the ones your vendor list does not show. Our AI agents monitor partner accounts continuously, flagging standing privileges, dormant consultant logins, unexpired project access, and integration credentials that exceed the permissions their interface actually uses. We convert findings into a remediation plan and a contract requirements exhibit you can reuse with every partner. As an implementation partner ourselves, we work under the same controls we recommend: named accounts, time-boxed access, masked non-production data, and recorded sessions.

Frequently Asked Questions

What should you check in an ERP vendor's SOC 2 report?

Confirm it is a Type II covering at least twelve months, that the scope includes the specific service and data center you use, and that the report is current rather than two years old. Read the testing exceptions and management responses, and study the complementary user entity controls, which describe obligations the auditor assumed you perform. Those assumed controls are where most real gaps live.

Should ERP implementation partners have production access?

Only by exception, through a named individual account with an expiry, multi-factor authentication, and an approved change record. Routine development, configuration, and testing should happen in a non-production environment refreshed with masked data. Permanent shared consultant credentials are a frequent audit finding and a common breach path, because they outlive the project and nobody owns their revocation.

Does CMMC apply to my ERP hosting provider?

If your hosting or managed service provider stores, processes, or transmits controlled unclassified information on your behalf, the requirements flow down to them under DFARS 252.204-7012 and the CMMC program. That includes cloud ERP hosting, backup providers, and MSPs with administrative access. Get written confirmation of their status and scope in the contract rather than relying on marketing claims about compliance readiness.

Key Takeaways

  • 1Building an ERP-Specific Vendor Inventory: Start by listing every party that can reach ERP data, not just those with a signed master services agreement. The inventory that matters includes anyone with an ERP login, database access, VPN or jump host credentials, an API key, or a copy of production data in a test environment.
  • 2Reading SOC 2 Reports and Cloud Shared Responsibility: Collecting a SOC 2 Type II report is not the control; reading it is. Check the audit period covers the last twelve months, check the scope actually includes the service you buy, and read the exceptions section rather than the cover letter.
  • 3Controlling Partner Access to Production: The default arrangement at most manufacturers is that the implementation partner and the MSP hold permanent, shared, highly privileged ERP and server accounts. Replace this with named individual accounts, no shared credentials, MFA enforced, access granted per ticket with an expiry, and sessions recorded through a jump host.

Inventory and lock down every partner, consultant, and integration account touching your ERP before a supplier compromise becomes yours.