Here is an uncomfortable pattern every controller knows. A vendor’s bank account details change in March. Payments start flowing to the new account in April. Somebody notices in July, usually because the real vendor calls asking where their money is. By then it’s not an exception on a report. It’s a recovery effort, a disclosure conversation, and a very long memo.
The control that should have caught it probably existed. It was tested last quarter. It may even have passed. The problem wasn’t the control’s design. It was the ninety days of darkness between the moments anyone actually looked.
That gap is what Sentinel is built to close.
What is Sentinel?
Sentinel is a continuous controls monitoring system for NetSuite, built by Sikich for finance teams carrying SOX 404(b) obligations, as well as any team that would rather find out about a control exception this week than next quarter.
It runs entirely inside your own NetSuite account. There is no external server, no integration middleware, no data leaving your tenant. Sentinel is deployed into your environment like any other NetSuite customization, and everything it observes, records, and reports stays in your system, under your roles and permissions.
From there, it continuously watches across 38 monitoring patterns spanning the areas where control exceptions actually happen:
- Journal entries – entries approved by their own creator (including approvals applied through workflows, a path most detection misses), backdated postings, round dollar entries above thresholds, high value entries with no approval, manual entries to sensitive or revenue accounts, and after-hours activity.
- Vendors and payments – bank-detail changes followed by payments (the classic ACH fraud pattern), payments to newly created vendors, duplicate vendors sharing a Tax ID, duplicate bills, bills without purchase orders, 3 way match variances, vendor addresses that match employee addresses.
- Access and change management – terminated employees who still have active access, privileged roles granted, dormant accounts, repeated failed logins, reactivated users, and changes to script deployments and system configuration, including Sentinel’s own. If someone switches off a piece of the monitoring, that is itself an exception. Somebody has to watch the watchman; Sentinel watches itself.
- Period Close Management and Revenue – postings into locked periods, credit memos above thresholds or approved by their creator, AR write-offs, manual price overrides, sales-order holds released, and book and reverse patterns.
Detection runs in three layers: real time checks the moment records are saved, daily sweeps for patterns no single save can reveal, and a nightly re-scan that re-checks the records it monitors no matter how they entered NetSuite; CSV imports, integrations, mass updates, workflows—so activity routed around the user interface still comes under the same monitoring.
Every exception is written to a structured, timestamped ledger inside NetSuite: what was detected, on which record, involving which users and amounts, with the supporting evidence captured at detection time and a severity that reflects the risk: a self-approved journal entry and a payment following a bank change are treated as critical; hygiene findings are labeled as such.
A dashboard where green actually means something
Most monitoring dashboards share a quiet flaw: when a control shows no exceptions, you can’t tell why. Did it run and find nothing? Did it have nothing to look at? Did it silently fail three weeks ago? The screen looks the same in all three cases, and for a SOX tool, a green light that means nothing is worse than no light at all.
Sentinel takes a stricter view. Every monitoring run records what it did: when it ran, how many records it evaluated, and what it did and did not identify. The dashboard says “No exceptions identified (4,120 evaluated)”, not just “passing.” If a control couldn’t fully run in your environment, it says so, and says why. If it was deferred, or disabled, or had nothing in scope, each of those is its own visible state. Nothing is allowed to fail silently and look like success.
We think that honesty is the difference between a dashboard you glance at and one you can actually rely on.
What this means when the auditors arrive
If you own SOX 404(b) compliance, you know the quarter end rhythm: the PBC list lands, and someone spends days pulling journal entry populations, user access listings, and vendor change reports out of NetSuite by hand.
Sentinel produces these on demand. One-click exports of the journal entry testing population, current user access listings, vendor master changes, three way match and duplicate bill detail, and a period summary of monitoring activity per control including how many times it ran, how many records it evaluated, what it identified, and on which days it couldn’t fully operate.
Two things matter about these reports. First, they are generated by your own NetSuite account from your own data; information produced by the entity, supporting management’s monitoring activity, all in a form your audit team can work with. Second, they say exactly what they are. Every export states plainly that it is system-generated activity and exception data. Not an audit, not an opinion on control effectiveness, and not an attestation by anyone. Detection is limited to the configured patterns; judgments about control design and operating effectiveness remain where they belong, with management and your independent auditor.
That’s not fine print to us; it’s the design philosophy. A monitoring tool that overstates what it knows is a liability. One that states precisely what it evaluated and what it found is genuinely useful, to you and to the people who audit you.
The value of Sentinel
- Time to detection collapses. Exception patterns that surface at quarter-end testing (or later) now surface in hours or days, while records are fresh, amounts are recoverable, and fixes are cheap.
- Fraud-shaped patterns can surface while they’re still unfolding. Bank detail changes before payments, self-approvals, ghost-vendor indicators; all of the sequences that cost real money are exactly the ones Sentinel is built to catch early.
- Audit preparation gets shorter. Populations, listings, and monitoring summaries that used to take days of manual pulls are standing exports.
- Your compliance posture becomes observable. Not “we tested it last quarter,” but a running, evidenced record of what has been monitored, every day, with the gaps visible instead of silent.
- Nothing leaves your NetSuite account. No new vendor-risk questionnaire, no data-processing addendum, no new external attack surface.
Who is Sentinel for?
Sentinel fits public companies on NetSuite carrying SOX 404(b) obligations as well as private companies heading toward an exit, an IPO, or simply a lower tolerance for finding out about problems last. It’s configured to your environment: your materiality thresholds, your sensitive accounts, your privileged roles, your approval workflows, with each monitoring pattern enabled deliberately rather than by default.
If some part of your controls environment currently depends on hoping nothing happened between quarterly looks, we should talk.
If some part of your controls environment currently depends on hoping nothing happened between quarterly looks, we should talk.
Sentinel is a monitoring layer over your existing controls—it complements, and does not replace, control design, management’s own review, or the work of your independent auditor. Sentinel is a management tool: it is not an audit, examination, or attestation, and Sikich expresses no opinion through it on the design or operating effectiveness of any control. Where Sikich also serves as a company’s independent auditor, applicable independence standards govern whether Sentinel can be provided—a determination made through our independence process.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.