Skip to main content

Risks & Compliance

When does VIM implementation fail?

VIM implementations fail on organizational and governance gaps more often than on the technology. The recurring causes we see are weak executive sponsorship, excessive customization, poor vendor master data, thin change management, under-trained users, and treating go-live as the finish line. Those gaps rarely crash a system. What they produce is a deployment that technically runs while users work around it: validation steps quietly skipped, approvals handled in email, reports that nobody opens, and a widening gap between the configured process and the real one.

PetSmart's original VIM environment had accumulated 235 custom objects before we reimplemented the platform and reduced that number to 27. Each object seemed justified when it was built; together they blocked upgrades, inflated support cost, and hid standard functionality that had caught up in the meantime. When a customization is genuinely needed, it should be built as a copy of the standard object rather than a modification of it, so upgrades stay possible. Vendor master data quality is the other common failure source, because bad master data manufactures exceptions no workflow design can absorb. Two more habits separate durable deployments from fragile ones: keeping design and as-built documentation somewhere the team of five years from now can find it, and planning hypercare plus a scheduled optimization review instead of releasing the delivery partner at go-live.


What audit trails does VIM create for invoices?

VIM creates a time-stamped audit trail covering every action taken on an invoice from receipt through posting. Each workflow step records who acted, what they did (approval, rejection, routing, edit), and any comments added along the way. The record builds automatically as the invoice moves, so audit documentation stops being a separate task someone assembles later. Even capture corrections are attributable, so an auditor can see who validated each field.

At the close of an invoice's lifecycle, VIM renders the workflow history into an audit-ready PDF that is attached to the process along with the invoice document, which gives auditors complete insight without querying SAP tables. Its history reporting shows how transactions moved through the system, including approval chains and exception handling. A Chart of Authority within VIM documents who holds financial approval rights at which thresholds, which supports SOX compliance and internal audit reviews; it needs an automated maintenance process, because an outdated authority chart both undermines the control it exists to prove and becomes a standing manual burden for AP administration. Invoice documents and their metadata are archived in the OpenText repository, creating a searchable record of every invoice processed.


What compliance risks remain after VIM goes live?

VIM automates audit trails, approval documentation, and workflow enforcement, but several compliance risks need ongoing ownership after deployment. Vendor due diligence and know-your-customer checks still require oversight, especially when you onboard suppliers across multiple jurisdictions. Master-data integrity needs regular review, because inaccurate vendor records raise the risk of duplicate payments, incorrect tax reporting, and audit findings no matter how well the workflow runs.

Capture accuracy drifts if the system is not maintained, since vendors change invoice layouts over time, and uncorrected extraction errors can flow into postings. Country-specific requirements, including e-invoicing mandates, tax retention rules, and document format standards, change on their own schedule, so the VIM configuration needs periodic updates to stay current. Watch for process workarounds as well: manual journal entries or off-system approvals that bypass VIM undermine the governance controls the system exists to enforce, and they tend to appear quietly wherever the configured process no longer fits how a team works. Treat that as a signal to revisit the design rather than as a discipline problem. A scheduled optimization review every 6 to 12 months is the practical mechanism for catching all of these before an auditor does.