Let's talk about one of our favorite subjects: Sarbanes-Oxley compliance combined with on-premises Oracle EPM / Hyperion.
Auditors and IT Risk Management departments tend to frown on running SOX-relevant financial applications on systems where a vendor's Extended Support has expired. Plain English: no ongoing defect remediation via patches, and no new security vulnerability patches.
As I wrote in a prior post, this ship has already sailed for:
- Oracle EPM 184.108.40.206 and prior versions
- Microsoft Windows Server 2008 R2
- Microsoft SQL Server 2008 (all Service Packs)
- Java 6 and prior versions
- JRockit 6
- Oracle EPM 220.127.116.11
- Microsoft Windows Server 2012 R2
- Microsoft SQL Server 2012 SP3
- Java 7
What readers need to consider is their timeline to either upgrade to EPM 11.2 (once released), or migrate to the Oracle EPM Cloud.
December 2021 seems like a long time away, but let's again re-visit SOX.
Let's say your fiscal year aligns with the calendar year: Jan:Dec. In this scenario, SOX-relevant applications only get 2 windows per year to complete upgrades and do a go-live cutover to a new system: May and September. Shoot for May, and use September as your fall-back position. Going live during either your fiscal 1st Quarter or 4th Quarter will trigger a red flag in your SOX audit.
So keep these dates in mind and then start counting backward. Don't wait until late in 2021 to either upgrade or move to the cloud. By then most EPM consulting partners, such as the firm I work for, will likely be slammed trying to hit that Sept 2021 SOX deadline. I'm reminded of when Microsoft revoked support for browsers older than IE11... we were insanely busy because many customers were still on EPM 18.104.22.168 or older, and IT Risk Management departments forced Finance to upgrade to remain compliant.
One final thought: I've recently been contacted by a competitor promising cheaper support rates than Oracle's. I want to discourage people from considering this, unless you intend to completely retire Hyperion and switch to a different platform on or before Q3 2021. A 3rd party partner/consultant will face legal problems if they are discovered installing patches or upgrades a former Oracle customer is no longer entitled to receive.