Showing posts with label D365Finance. Show all posts
Showing posts with label D365Finance. Show all posts

Sunday, June 22, 2025

Enabling the Three Lines of Defense in Dynamics 365 Finance & Operations - LINE1: Operational Management











ENABLING THE THREE LINES OF DEFENSE IN DYNAMICS 365 FINANCE & OPERATIONS - LINE1: OPERATIONAL MANAGEMENT

CONTENT

Introduction
Why the Three Lines of Defense Matters in D365FO
LINE 1 Operational Management in D365FO
Role-Based Access Control
Segregation of Duties (SoD) Enforcement
Workflow Approvals in Core Processes
Field-Level Audit and Setup Change Monitoring
Sample Scenario
Conclusion

INTRODUCTION 

As regulatory expectations increase and ERP systems take a central role in financial reporting, organizations are under pressure to demonstrate effective governance within their core business applications. In the context of Microsoft Dynamics 365 Finance and Operations (D365FO), aligning system capabilities with the Three Lines of Defense (3LoD) framework has become a practical way to structure risk and control activities.

The Three Lines of Defense model is a well-established framework used to separate responsibilities for risk ownership, compliance oversight, and independent assurance:

  • First Line: Business operations responsible for executing controls
  • Second Line: Risk and compliance functions that guide and monitor control performance
  • Third Line: Internal audit functions that provide independent assurance

This article explains how D365FO can support all three lines of defense by leveraging built-in features such as workflow approvals, segregation of duties (SoD), security role configuration, audit trails, and external monitoring tools. It is written for consultants, compliance professionals, and ERP stakeholders who are responsible for strengthening internal controls, especially in regulated environments (e.g., SOX-compliant organizations).

By the end of this article, you will understand how to map D365FO features to each line of defense, what implementation activities to prioritize, and how to structure your environment to meet both compliance and operational needs. Screenshot indicators are included throughout the article to help you illustrate the guidance using your own sandbox data.

WHY THE THREE LINES OF DEFENSE MATTERS IN D365FO

Modern regulators and auditors expect ERP environments to reflect the Three Lines of Defense (3LoD) model:

  • LINE 1: Operational Management owns risk and executes controls.
  • LINE 2: Risk & Compliance oversees, advises, and monitors.
  • LINE 3: Internal Audit provides independent assurance.

Dynamics 365 Finance & Operations (D365FO) offers native functionality—augmented by common ISV tools such as Fastpath or RSM Guardian—to embed each line directly in the application. Implementing these capabilities up-front reduces external audit findings, accelerates SOX readiness, and lowers the cost of ongoing compliance.

LINE 1 | OPERATIONAL MANAGEMENT IN D365FO

The First Line of Defense is composed of operational users—those in finance, procurement, inventory, or accounts payable—who are responsible for executing daily business processes and applying system controls as part of their regular duties. These are the people who create journals, submit purchase orders, manage vendors, and approve transactions.

In Dynamics 365 Finance and Operations, these users can directly perform their responsibilities in a way that enforces preventive and detective controls, ensuring they own the associated risks while remaining compliant with internal policies and external regulations.

Let’s explore how this works in practice.

Role-Based Access Control: D365FO uses a security model based on the roles, duties, privileges, which allows you to strictly limit user access to only those tasks they are responsible for. This means each user can be aligned with the specific business function they perform—such as AP clerk, GL accountant, or procurement manager—without having unnecessary access to sensitive or conflicting tasks.

For example, an accounts payable clerk can be granted access to create and edit invoices, but not post journals or create vendors.

By enforcing least privilege access, this model helps organizations meet the core requirement of Line 1: enabling business users to operate efficiently while containing access risk. 

System administration > Security > Assign users to roles












Segregation of Duties (SoD) Enforcement: While access control is about what a user can do, SoD is about what combinations of access should not exist. D365FO provides built-in SoD rules and conflict-checking tools that help prevent users from having access to incompatible duties—such as being able to both create a vendor and approve a payment.

The system allows you to:

  • Define SoD rules between duties (e.g., "Vendor master maintenance" and "Vendor payment approval")
  • Check for violations when assigning roles
  • Enforce review and approval workflows for exceptions

SoD enforcement supports Line 1 by preventing control failures at the point of access assignment and ensuring business users are only responsible for the right set of tasks.

System administration > Security > Segregation of duties > Segregation of duties rules






Workflow Approvals in Core Processes: To ensure operational users follow proper approval paths before high-risk actions are taken, D365FO includes a Workflow engine for many key transaction types, such as:

  • Vendor edits
  • Purchase requisitions and purchase orders
  • General ledger journal entries
  • Expense reports
  • Vendor invoice journals
  • Vendor payment journals

Workflow ensures that a second individual reviews and approves key actions before the transaction is posted or finalized—enabling proper oversight without relying on manual follow-up. This is a critical component of Line 1, as it ensures controls are built into business processes, not applied reactively.

For example, a workflow can require that any purchase order over $25,000 must be approved by a finance manager, even if submitted by an authorized clerk. You can find this end-to-end scenario here.

Accounts payable > Setup > Accounts payable workflows







Field-Level Audit and Setup Change Monitoring: In many control environments, configuration data is just as sensitive as transactional data. The Database Log in D365FO allows you to track changes to high-risk fields—for example, when someone changes a vendor's bank account number or modifies the posting profile for a journal.

This capability supports Line 1 by creating transparency and accountability for operational teams responsible for configuration or master data. Once enabled, the database log tracks:

  • Who changed the field
  • When it was changed
  • What the old and new values were

Although this feature is often reviewed by the second or third line, its purpose is to empower operational users to self-monitor and prevent unintentional misconfigurations.

Enable database logging for a critical table such as VendBankAccount and show the change log after a test update.

System administration > Setup > Database log > Database log setup











Sample Scenario: Let’s walk through an end-to-end example that shows how Line 1 is supported in a real-life AP process:

1. Vendor clerk initiates a vendor change request via the Vendor changes workflow.

2. Workflow routes the request to an AP supervisor for approval.

3. The clerk creates a vendor invoice journal and submits it into Journal approval workflow.

4. The invoice is posted only after a second-level approver signs off.

5. Security roles and SoD rules ensure the same user cannot both create a vendor and approve their invoices.

6. Any change made to vendor bank info is recorded in the Database Log.

Each of these activities is completed by a business user—not the compliance or IT team—meaning risk is being managed where it originates: within business operations.

CONCLUSION

Operational users are the first line of defense in managing risk within Dynamics 365 Finance and Operations. As shown in this article, D365FO provides native capabilities—such as role-based security, segregation of duties enforcement, workflow approvals, and field-level logging—that enable these users to execute controls effectively as part of their daily responsibilities. Embedding such functionality directly into core processes ensures that risks are addressed where they originate: within business operations.

This article is the first in a three-part series on enabling the Three Lines of Defense in D365FO. The next installment will focus on Line 2: Risk and Compliance, and how system capabilities can support oversight, guidance, and control monitoring activities.

Thursday, May 22, 2025

Worker vs Vendor in Expense Management – Dynamics 365 Finance and Operations (D365FO)



WORKER VS VENDOR IN EXPENSE MANAGEMENT – DYNAMICS 365 FINANCE AND OPERATIONS (D365FO)

CONTENT

Introduction
Worker-Based Reimbursement
Vendor-Based Reimbursement
Process Flow Comparison
Expense Management Parameters
Multi-Legal Entity Considerations
Common Scenarios
Reporting and Auditing Considerations
Conclusion

Introduction

Expense Management in Dynamics 365 Finance and Operations (D365FO) enables organizations to track, process, and reimburse business-related expenses. Depending on who incurs the expense and how reimbursement is expected to occur, you may configure the system to reimburse either a worker (employee) or a vendor (third party). This article outlines the key differences between these two approaches and the practical implications for finance and compliance teams. This article intends to be an introductory knowledge based resource that provides a solution to initial expense management design discussions. 

Worker-Based Reimbursement

When to Use

  • This method is applicable when an employee has a business-related expense and submits an expense report for reimbursement. Common examples include travel, meals, lodging, or mileage expenses.

Configuration Requirements

  • The individual must exist as a worker in the Human Resources module and be associated with a legal entity.
  • A vendor account must be linked to the worker. This can be created automatically (if system parameters are configured accordingly) or linked manually via the Employee > Expense tab > Employee mapping and per diem rates.


  • Expense Management parameters must be set to reimburse through Accounts Payable using the linked vendor account.

Accounting Impact

  • When the expense report is posted, the expense is debited to the designated expense account (e.g., travel expense).
  • A liability is posted to the worker’s vendor account, which becomes eligible for payment through the standard AP payment process.

Note

  • The vendor account must have valid bank account details if electronic payments are used.
  • The system uses standard payment methods (such as checks or AC or WIRE) to pay the worker, just as it would for a regular vendor.

Vendor-Based Reimbursement

When to Use

This method is used when when the expense is incurred by a third-party vendor or when a company directly pays an external party for goods or services, such as hotel bookings made by a travel agency or outsourced consulting services.

Configuration Requirements

  • The external party must be created as a vendor record in the Accounts Payable module.
  • Expense categories can be configured to allow vendor selection when appropriate.
  • No linkage to a worker record is required.

Accounting Impact

  • The system posts the expense to the designated expense account.
  • The liability is posted directly to the vendor, and payment is processed through standard AP procedures.

Note

  • This configuration avoids involving employees in expense-related payments when the service or product is procured directly by the organization.
  • Ideal for scenarios where centralized procurement or travel teams handle bookings.

Process Flow Comparison

Worker Reimbursement Flow:

1. Worker creates an expense report via self-service or mobile app.

2. Report follows the approval hierarchy.

3. After final approval, a vendor transaction is created against the worker’s vendor account.

4. Payment is processed through Accounts Payable, based on standard payment proposal functionality.

Vendor Payment Flow:

1. An expense or invoice from a vendor is entered (e.g., from a travel agency or external consultant).

2. The document is reviewed and approved as required.

3. A vendor liability is created.

4. The payment is processed like any other vendor invoice..

Expense Management Parameters

Expense Management behavior can be configured in:

Expense Management > Setup > Expense Management parameters

Under the Reimbursement tab, there are key settings:

  • Reimburse through Accounts Payable: When selected, the system expects a vendor account to be associated with each worker.
  • Create vendor account automatically: If enabled, D365FO creates a vendor record for each worker, reducing manual setup.

⚠️ It’s recommended to review your number sequences and vendor groups before enabling automatic creation, as these will determine the structure and grouping of generated vendor accounts.

Multi-Legal Entity Considerations

In organizations operating across multiple legal entities, a single worker may be associated with more than one legal entity. In such cases:

  • A vendor account must be created for each legal entity where the worker is submitting expenses.
  • The system does not share vendor records across entities by default, as financial transactions and payments are managed independently per legal entity.

Failure to configure the appropriate vendor account for each entity may result in failed postings or blocked payments.

Common Scenarios

The table below outlines typical business cases and whether a worker-based or vendor-based configuration is appropriate. This helps clarify when each method should be used, based on who incurs the expense and how reimbursement or payment is expected to occur. Using the correct setup avoids confusion in AP processing and supports clean financial postings.



Reporting and Auditing Considerations

Accurate configuration of worker and vendor expense flows is critical for:

  • Maintaining audit trails: Clear identification of payee (worker vs. vendor) ensures traceability.
  • Simplifying month-end processes: Vendor liabilities are easier to reconcile when correctly segmented.
  • Internal control compliance: Separating employee reimbursements from vendor payments supports proper delegation of authority (DOA) enforcement and SOX compliance.
  • Financial dimension tracking: Both configurations allow for financial dimensions to be captured per line item (e.g., department, cost center), enabling accurate reporting.

Conclusion

D365FO offers flexible options to support different expense reimbursement scenarios through either worker-linked vendor accounts or standard vendor records. Selecting the appropriate configuration depends on who incurred the expense, how the payment will be processed, and the internal policies around employee reimbursements and vendor procurement.

Use worker-based configuration when employees pay out-of-pocket and expect to be reimbursed. Use vendor-based configuration when the organization pays third-party service providers directly. Properly configuring these options will result in clean accounting entries, better workflow control, and alignment with internal compliance frameworks.

Friday, March 28, 2025

Practical Guide to General Ledger Allocations in Dynamics 365 Finance and Operations












PRACTICAL GUIDE TO GENERAL LEDGER ALLOCATIONS IN DYNAMICS 365 FINANCE AND OPERATIONS

CONTENT

Introduction
How to fit into month-end process
Use cases
Allocation rule types
Real Business Scenario
Conclusion

INTRODUCTION

In Dynamics 365 Finance and Operations (D365FO), allocation journals are used to systematically distribute general ledger (GL) account balances across multiple accounts, departments, or financial dimensions based on predefined rules. These rules can support both fixed and variable allocations, helping automate routine distribution processes. 

This article explains the logic of the allocation process, its types, and provides an end-to-end demonstration through a real business scenario.

Let's get started.

HOW TO FIT INTO MONTH-END PROCESS

Allocation journals are used to distribute amounts from one financial dimension or account to others based on a defined logic (e.g., percentages, fixed amounts). They’re often created and posted during the month-end close for the following reasons:

  • Accurate Departmental Reporting: You want each department or project to reflect its fair share of corporate costs.
  • Consistent and Repeatable Process: Allocation journals can be automated using predefined rules and run at each month-end.
  • Auditability: D365FO lets you post allocations as actual ledger journal entries, which helps with transparency and audit trails.

ALLOCATION RULE TYPES










1. Fixed Percentage

Distributes the source amount based on predefined percentages.

  • Use case: You know the exact percentage split (e.g., 40% to Department A, 60% to Department B).
  • Setup: You define a list of destination accounts/dimensions and assign a percentage to each.

Example:

You allocate $1,000 from the IT expense account:

  • Dept A: 40% → $400
  • Dept B: 60% → $600

2. Fixed Weight

Distributes the source amount based on weight factors, which are not percentages. D365FO calculates the distribution ratio based on the relative weights.

  • Use case: You have proportional metrics (e.g., square footage, number of PCs) but not exact percentages.
  • Setup: You assign weight values (like 2, 3, 5) to each destination, and D365FO does the math.

Example:

You allocate $1,000 based on weights:

  • Dept A: 2
  • Dept B: 3
  • Dept C: 5
  • Total weight = 10
  • Allocated: A: $200, B: $300, C: $500

3. Equally

Splits the source amount evenly across all specified destinations.

  • Use case: You want a simple equal split across all recipients.
  • Setup: You list the destination dimensions, and D365FO splits the amount evenly.

Example:

You allocate $900 equally to three departments:

  • Dept A: $300
  • Dept B: $300
  • Dept C: $300

4. Basis

Distribute the source amount based on the selected main account and/or financial dimension balances. If the account is a statistical account, the balance may reflect figures such as the total number of employees or the square footage of a facility.

  • Use case: You want to distribute marketing expenses across departments based on their head counts.
  • Setup: You define statistical accounts, and D365FO splits the amount based on the account balances (head counts).

Example:

You allocate $1,000 marketing expenses based on number of department employees:

  • Dept A: 7 people  → $233
  • Dept B: 13 peopl → $433
  • Dept C: 10 peopl → $333

USE CASES

Here are some common use cases:

1. Monthly Overhead Allocation

Use Case: Allocate indirect costs (e.g., utilities, rent, insurance or administrative salaries) to cost centers or departments.

Example: Rent of $50,000 is allocated to departments based on square footage.

2. Marketing or Sales Campaign Cost Allocation

Use Case: Allocate campaign expenses to various products, business lines, or regions.

Example: A $100,000 campaign is split among 5 product lines based on projected revenue contribution.

3. Intercompany Cost Allocations

Use Case: Allocate costs between different legal entities within the same organization.

Example: Corporate headquarters costs are allocated to subsidiaries.

4. Statistical Allocation Based on Ledger or Statistical Accounts

Use Case: Allocate costs based on statistical measures like machine hours, labor hours, or square footage.

Example: Maintenance costs are distributed based on machine usage hours tracked in statistical accounts.

5. Period-End Accruals and Adjustments

Use Case: Perform recurring allocations for accruals, amortizations, or revenue/cost deferrals.

Example: Amortizing an annual insurance cost monthly across the fiscal year.

6. Allocation of Payroll Costs

Use Case: Allocate salaries and wages to projects, departments, or cost centers.

Example: A project manager's salary is split 50/50 between two active projects.

7. Budget Allocations

Use Case: Distribute budgeted amounts across accounts or dimensions for planning and analysis.

Example: A marketing budget is allocated to various campaigns or geographies.

REAL BUSINESS SCENARIO

The company has $12,000 of IT expenses posted to a shared IT department. The goal is to reallocate this cost to three departments based on fixed percentages:

  • Dept A – 20%
  • Dept B – 30%
  • Dept C – 50%

We’ll create a ledger allocation rule, and run it to generate a journal that moves the expense from the shared IT department to the other three.

Step 1: Create the Ledger Allocation Rule

Navigate to General ledger >> Allocations >> Ledger allocation rules.

Click +New.

Rule name: IT_ALLOC_FIXED.

Description: IT cost allocation by fixed percentage.

Switch to General tab.

Select the allocation method Fixed percentage.

Select the allocation journal name.

Click Source.

Click +New.

Select IT Expense Account.


Click destination.



Click +New.

Enter the Fixed percentage value as 20.

Select To account as 601410.

Select the first department.


Activate the allocation rule.


Step 2: Run the Allocation Rule

Navigate to General ledger >> Allocations >> Process allocation request.

Select the rule.



Click OK.

Step 3: Review the Allocation Journal

Navigate to General ledger >> Allocations >> Allocation journals


Note that New button is not active since an allocation journal cannot be created manually. It has to be generated by the system based on the allocation rules.

Click Lines.


Review the journal lines. These entries mean:

You’re debiting Dept A/B/C for the new allocated amounts

You’re crediting the IT Dept to remove the cost

All is happening within account 601410 in our example.

Step 4: Post the Allocation Journal

Click Validate (to check for errors) and then click Post.




Done! The allocation is now posted in your GL.

CONCLUSION

Allocation journals in Dynamics 365 Finance and Operations are essential for systematically distributing costs across financial dimensions based on predefined logic. They support a wide range of allocation methods, including fixed percentage, weight-based, equal, and basis-driven approaches, allowing organizations to align cost distribution with operational drivers. When integrated into the month-end process, these journals improve reporting accuracy, support auditability, and reduce manual adjustments. A well-defined allocation setup ensures consistency, simplifies recurring entries, and enhances the transparency of financial data across departments or legal entities.

Monday, February 17, 2025

Optimizing Financial Operations with Microsoft 365 Copilot for Finance in Excel




OPTIMIZING FINANCIAL OPERATIONS WITH MICROSOFT 365 COPILOT FOR FINANCE IN EXCEL

CONTENT

Introduction
Microsoft 365 Copilot for Finance: Key components
Customer Reconciliation with Microsoft 365 Copilot for Finance in Excel
Conclusion

INTRODUCTION

As organizations strive for greater efficiency in financial operations, AI-driven capabilities play a key role in enhancing decision-making and reducing manual effort. Microsoft 365 Copilot for Finance extends AI into ERP systems, enabling finance teams to streamline workflows and improve data accuracy.

This article focuses on Microsoft 365 Copilot for Finance in Excel, highlighting its role in automating data reconciliation, generating reports, and providing actionable insights. Building on the previous discussion of vendor reconciliation, this article broadens the scope to cover data reconciliation from a more comprehensive perspective.

Let's get started.

MICROSOFT 365 COPILOT FOR FINANCE: KEY COMPONENTS

Microsoft 365 Copilot for Finance consists of two key components:

  • Microsoft 365 Copilot for Finance in Excel – Designed to automate financial data reconciliation and generate reports with insights.
  • Microsoft 365 Copilot for Finance in Outlook – Enhances email-based financial processes (covered in a separate article).

Using these features requires a Copilot license and Copilot Finance Agent setup.

By integrating with ERP systems, Copilot for Finance Agent helps finance teams make informed decisions faster while minimizing manual effort. Embedded within everyday productivity tools, it enhances efficiency by automating routine tasks and delivering AI-driven insights where they are needed most.

The primary use case explored in this article is customer reconciliation using the data reconciliation feature of the Copilot Finance Agent. This capability automates data comparison, identifies discrepancies, and generates reports for streamlined financial analysis.


MICROSOFT 365 COPILOT FOR FINANCE IN EXCEL INSTALLATION

Navigate to the Dynamics 365 Finance homepage and select Copilot for Finance (Preview).


Choose Install Microsoft 365 Copilot for Finance (Preview) in Excel.


Click Get it now to initiate the installation.



Once installed, Copilot for Finance (Preview) will be available in Excel.


DATA RECONCILIATION PROCESS

Microsoft 365 Copilot for Finance in Excel simplifies financial reconciliation through below flow:

  • Export relevant financial data
  • Combine relevant exported data
  • Auto categorize and align data
  • Review and adjust column assignments
  • Generate data reconciliation report
  • Investigate discrepancies

CUSTOMER RECONCILIATION WITH MICROSOFT 365 COPILOT FOR FINANCE IN EXCEL

Customer reconciliation ensures that transactions recorded in subledger align with ledger transactions. This is an internal reconciliation. Microsoft 365 Copilot for Finance in Excel streamlines this process by automating data comparison, identifying discrepancies, and generating reconciliation reports with minimal manual effort.

This section demonstrates how to perform customer reconciliation using the data reconciliation feature of Copilot for Finance in Excel.

Step 1: Exporting Customer-Related Financial Data

To begin, export the necessary financial data from Dynamics 365 Finance. Two key datasets are required:

  • Customer Posting Profile Transactions
  • Customer Transactions

Let's export the relevant financial data.

Extracting Customer Posting Profile Transactions

Navigate to General ledger >> Inquiries and reports >> Voucher transactions.

Enter the account numbers related to customer posting profiles and specify a date range.

Review the filtered results and export all rows.

Download the excel file.

Rename the worksheet as Voucher Transactions.

Extracting Customer Transactions

Second relevant data is customer transactions. 

Navigate to D365FO table browser and find CustTrans table and filter customer transactions the specified date range.

Review the filtered data and export all rows.

Download the Excel file.

Rename the worksheet as CustTrans.

Step 2: Combining Data in Excel

Once both datasets are extracted, combine them into a single workbook.

Open the Excel file containing Voucher Transactions

Insert the CustTrans worksheet into the same workbook

Ensure that both datasets are structured properly before proceeding with reconciliation

Step 3: Running Data Reconciliation with Copilot for Finance in Excel

Next section is about the Copilot for Finance in Excel.

Click the Copilot for Finance (Preview) icon in Excel.

Select Reconcile data.

The system will automatically recognize the first worksheet (Voucher Transactions).

Click + Add to include the second dataset (CustTrans).

Select CustTrans worksheet.

Review the auto generated column mappings and ensure correctness.

Click Keep to confirm the mappings.

Step 4: Executing Reconciliation Analysis

Click reconcile data to initiate the analysis.

Copilot for Finance will compare transactions, highlight discrepancies (if any), and generate a structured reconciliation report. If no differences are detected, the system confirms that all customer transactions are aligned with financial records.

Expand the Insights section to review additional analysis details and ensure financial data integrity.

CONCLUSION

Automation reduces manual reconciliation efforts, allowing finance teams to focus on exception handling rather than routine data comparison. AI-driven analysis enhances accuracy, ensuring that financial records align with customer balances. Streamlined reporting improves audit readiness, providing clear visibility into transaction consistency.

By leveraging Microsoft 365 Copilot for Finance in Excel, organizations can enhance the efficiency, accuracy, and reliability of customer reconciliation, strengthening financial governance and compliance. 

Full account reconciliation along with insights will be possible in the near future via Account reconciliation agent workspace that will be released very soon.

Understanding Telemetry Pricing for Dynamics 365 Finance & Operations (D365FO)

UNDERSTANDING TELEMETRY PRICING FOR DYNAMICS 365 FINANCE AND OPERATIONS (D365FO) CONTENT Introduction D365FO Telemetry Capabilities Key Pric...