Summary
Provide an out-of-the-box, governed Audit History subject area in Oracle Fusion Data Intelligence (FDI) that makes Oracle Fusion Applications audit events available for enterprise reporting, compliance monitoring, control testing, and risk analytics across Fusion modules. The subject area should consolidate audit data configured through Manage Audit Policies and expose a consistent analytical model for changes to audited Fusion business objects and attributes including the user, timestamp, event type, business object, record context, changed attribute, and old/new values. This should be designed as a reusable, cross-functional capability not as isolated, module-specific audit extracts.
Business Problem / Opportunity
Oracle Fusion Applications provides configurable audit capabilities across many product areas. Customers can select auditable business objects and attributes using Manage Audit Policies, then review create, update, and delete activity through the operational Audit Reports work area. This is valuable for individual transaction investigations. However, the current audit-report experience is primarily operational and search-based, which limits organizations that need to monitor audit activity at enterprise scale or combine it with business, financial, supply-chain, workforce, and security context.
Today, organizations commonly face these challenges:
- Audit history is reviewed reactively, often only after an issue, control exception, investigation, or audit request occurs.
- Cross-module reporting requires separate searches, manual exports, and spreadsheet consolidation.
- Audit teams cannot easily establish enterprise dashboards, trends, thresholds, exception monitoring, or recurring control evidence from Fusion audit records.
- It is difficult to correlate a change event with its downstream business impact for example, the impact of a supplier, bank account, item, pricing, customer, user-role, payroll, or accounting setup change.
- Historical values and audit evidence can be difficult to analyze across business units, legal entities, organizations, product lines, regions, users, and time periods.
- Data-governance teams lack a common analytical framework to identify high-risk attributes, frequent overrides, repeated corrections, unusual change patterns, or segregation-of-duties concerns.
A unified FDI subject area would transform audit history from a transactional investigation tool into a proactive enterprise compliance, risk, and governance capability.
Proposed Enhancement
Create a standard Oracle Fusion Audit History subject area in FDI, populated from supported Oracle Fusion Applications audit history records. The model should expose a conformed audit-event fact that is reusable across available Fusion pillars and products, with module-specific extensions where needed.
Suggested Subject Area Name
Common: Enterprise Audit Events
Core Analytical Data Model
Audit Event Fact
Provide a detailed audit-event fact at the appropriate grain—ideally one row per audited attribute change, with the ability to summarize to the business-object event level.
Common Attributes
The subject area should include:
Category | Recommended attributes |
|---|
Audit event | Audit event ID, event date/time, event type, event description, source product/module, business object, qualified business object/internal name |
Change details | Attribute name, attribute internal name, attribute group/context, old value, new value, change action—create/insert, update, delete |
Actor and accountability | User display name, user ID/internal name, person/worker context where permitted, impersonator information where historically available |
Record identification | Business-object identifier, parent business object, child business object, object description, record number/name, and extended object identifier/context values |
Organization and enterprise dimensions | Business unit, legal entity, ledger, inventory organization, department, location, country, region, product category, and other applicable conformed dimensions |
Time | Date, time, day, week, month, quarter, fiscal period, year, and time since previous change |
Audit configuration and governance | Product/module, auditable object, tracked attribute, audit-enabled date, configuration status, attribute risk classification, and audit-policy ownership |
Security | Appropriate role-based access, masking, suppression, or restricted access for sensitive audit attributes and values |
The model should preserve old and new values for enabled and supported attributes, as these are essential for audit evidence, forensic review, and control testing.
Coverage Across Fusion Modules
The model should provide a common framework across Fusion pillars while enabling module-specific context and dimensions. Examples of high-value use cases include:
Financials and Enterprise Controls
- Changes to supplier profile, supplier site, payment method, remit-to details, and bank-account-related information
- Changes to customer master, customer sites, payment terms, credit-related attributes, and receivables setup
- Changes to chart-of-accounts-related configuration, accounting rules, tax configuration, approval configuration, and other control-sensitive setup
- Analysis of changes affecting invoice processing, payment processing, procure-to-pay controls, or record-to-report governance
Procurement and Supplier Management
- Supplier master and supplier-site changes
- Procurement setup and approval-related configuration changes
- Changes to supplier classifications, qualifications, addresses, contacts, payment terms, and tax or banking-related details
- Identification of high-risk supplier changes made immediately before invoices or payments
Supply Chain Management, Product Hub, and PLM
- Item, item attribute, extensible flexfield, item revision, organization association, category, structure, component, and attachment history
- Changes to product classifications, tariff/customs attributes, country-of-origin fields, regulatory attributes, controlled-material indicators, or other compliance-sensitive data
- Changes to sourcing, inventory, planning, manufacturing, quality, logistics, and trade-related master data where supported by Fusion auditing
- Correlation of item-master changes to procurement, inventory, supply, cost, fulfillment, and compliance impact
HCM and Payroll
- Changes to workforce data, employment attributes, compensation-related data, payroll configuration, payroll calculation cards, and other configured HCM business objects
- Monitoring of sensitive employee-data changes with the necessary privacy, role-based-access, and masking controls
- Control evidence for changes to pay-related attributes or key workforce records
Risk Management, Security, and Application Administration
- Changes to auditable enterprise setup and control-related business objects
- Visibility into user-driven changes to sensitive configuration data
- Support for governance and control monitoring when combined with available security, role, and workflow datasets
The initial delivery can prioritize products and business objects already supported by the standard Fusion audit framework, then expand coverage incrementally.
Key Business Use Cases
1. Enterprise Compliance Monitoring
Enable compliance teams to monitor sensitive changes across Fusion from a unified dashboard rather than manually extracting audit reports product by product.
Examples:
- What sensitive supplier, item, customer, payroll, or finance setup changes occurred this month?
- Which high-risk attributes were changed, by whom, and in which legal entity or business unit?
- Which changes require evidence of an associated approval or change process?
2. Internal and External Audit Evidence
Provide repeatable, filterable audit evidence showing:
- Who made a change
- What business object and attribute changed
- When the change occurred
- What the old and new values were
- Where the change applies, such as business unit, organization, legal entity, item, supplier, customer, worker, or transaction context
This reduces manual report generation, spreadsheet reconciliation, and repeated requests to application administrators.
3. Risk-Based Exception Detection
Allow customers to define exception rules and dashboards for patterns such as:
- High-volume changes by a user, team, organization, or period
- Repeated changes to the same record or attribute
- Changes made outside expected business hours or control windows
- Changes made after an approval, release, close, activation, or effective date
- Changes to sensitive fields without a corresponding change order, approval, workflow, or service request where applicable
- Multiple sensitive changes performed by the same user within a short period
- Frequent reversals from one value to another and back again
4. Data Governance and Data Quality
Provide analytics that identify:
- Frequently changed or unstable master-data attributes
- Attributes with high correction or override rates
- Business units, organizations, product categories, or teams with recurring data-quality issues
- Gaps in audit coverage for critical objects or attributes
- Trends in data stewardship performance over time
5. Root-Cause and Business-Impact Analysis
Allow audit events to be analyzed alongside available FDI operational and financial data.
Examples:
- Supplier master or banking changes correlated with invoice, payment, or spend activity
- Item classification or tariff changes correlated with inventory, sourcing, purchasing, shipping, cost, or trade exposure
- Customer master changes correlated with orders, credit, receivables, or collections
- Payroll or workforce changes correlated with payroll results and retroactive adjustments
Example Metrics and KPIs
Provide prebuilt measures such as:
- Total audit events
- Create, update, and delete events
- Distinct changed records
- Distinct changed attributes
- Distinct users making changes
- Sensitive-attribute change count
- High-risk change count
- Repeated change count
- After-hours or non-business-window change count
- Changes without linked approval/change context, where linkage is available
- Average changes per user, object, organization, or business unit
- Time between successive changes to the same record or attribute
- Audit coverage rate: critical objects/attributes configured for audit versus defined governance baseline
Prebuilt Dashboard and Report Templates
Oracle should provide starter content that customers can extend:
- Enterprise Audit Activity Overview
- Change volume by Fusion module, business object, event type, user, and time.
- High-Risk Changes Dashboard
- Sensitive attributes, high-risk objects, repeated changes, and exception trends.
- User Activity and Change Patterns
- Audit activity by user, role, organization, object type, and attribute.
- Master Data Governance Dashboard
- Supplier, customer, item, and reference/master-data change monitoring.
- Audit Evidence Detail Report
- Exportable, filterable detailed report containing record context, changed attributes, old/new values, user, and timestamp.
- Control Exception Monitoring
- Configurable rules for changes outside defined policies, approval processes, or expected timing.
Security, Privacy, and Data Retention Requirements
Because audit history can contain sensitive personal, payroll, financial, supplier, customer, and security-related information, the FDI offering must support:
- Role-based access controls aligned to Fusion audit security and functional data access.
- Attribute- and value-level masking or suppression for sensitive data.
- Secure access to old and new values.
- Customer-configurable access by module, business object, data domain, and organization.
- Clear support for data retention, purge, archival, and historical-audit requirements.
- Documentation of refresh frequency, latency, supported objects, and audit-history retention dependencies.
The objective is not to expose all audit content broadly; it is to make audit data securely governed and analytically usable by authorized compliance, audit, risk, security, and data-governance users.
Expected Outcomes / Success Criteria
This enhancement is successful when customers can:
- Analyze audit records from multiple Fusion modules through a common FDI subject area and consistent semantic model.
- Report on create, update, and delete events, including actor, timestamp, business object, record context, attribute, old value, and new value.
- Filter and trend audit events by enterprise dimensions such as business unit, legal entity, ledger, organization, region, product category, and time.
- Build dashboards and alerts for sensitive changes, unusual activity, and policy/control exceptions.
- Combine audit history with operational, financial, supply-chain, workforce, and customer analytics available in FDI.
- Produce repeatable audit evidence without manual, module-by-module Audit Reports exports.
- Maintain appropriate security, privacy, masking, and access controls over audit data.
Why This Matters
Oracle Fusion already provides a configurable audit framework: customers select business objects and attributes to audit, and audit history captures operations such as create, update, and delete. Fusion’s Audit Reports and supported audit APIs can return essential details, including event date, user, event type, business object, contextual identifiers, and when requested attribute-level old and new values. FDI is the natural platform to make this data usable at enterprise scale. A unified Audit History subject area would help customers move from reactive, manual audit-report searches to proactive compliance monitoring, continuous controls assessment, risk detection, data-governance measurement, and business-impact analysis.