NetSuite 2026.1 Login Compliance Notice: Setup and Audit Tracking

NetSuite 2026.1 lets administrators display a compliance notice that users must acknowledge before accessing their accounts. Learn who can configure it, how to test it, and how the Login Audit Trail supports acknowledgment reporting.

·8 min read·By NetSuite Changelog

The NetSuite 2026.1 login compliance notice displays a compliance message to all users upon login. Users must acknowledge it before accessing their accounts. Only users with the Administrator role can set up the notification, and administrators can review acknowledgment dates and times through the Login Audit Trail.

This article covers the compliance message presented during login—not security alerts about login activity.

Key takeaways

  • Starting in NetSuite 2026.1, administrators can establish account login notifications to support compliance requirements.
  • All users must acknowledge the compliance message before account access.
  • Setup involves composing and saving the message in account settings, followed by a logout-and-login test.
  • The Login Audit Trail supports acknowledgment review, including the date and time.
  • Treat acknowledgment as evidence that a user acknowledged the notice, not proof that every underlying compliance requirement has been satisfied.

What does the NetSuite 2026.1 login compliance notice do?

A login notification is a compliance message users encounter when signing in. The sequence is straightforward: a user logs in, encounters the message, and must acknowledge it before accessing the account.

The notice places compliance communication at the point of entry rather than relying entirely on separate employee communications. Because the message is displayed to all users, administrators should write it for the account's full user audience rather than for one department alone.

For example, an organization could use the notice to remind users that account information must be handled according to its approved data-use policy. That is a suggested use, not a supplied NetSuite template. The reminder appears before users begin their work, and administrators can subsequently review acknowledgment timing.

For a policy owner, the main planning question is what users need to understand before entering the account. For an Administrator, it is how to implement and verify the approved message. For an audit reviewer, it is what the acknowledgment record establishes. Separating those responsibilities makes the feature easier to implement without overstating its value.

Understand what the control proves

There are three distinct elements: the message communicates a requirement, mandatory acknowledgment places a condition on access, and the Login Audit Trail provides acknowledgment evidence.

An acknowledgment is not, by itself, evidence that someone understood every policy provision, completed training, or followed the policy afterward. The feature can support compliance awareness and standards-related work, including NIST-related efforts, but it should not be presented as a standalone certification of compliance.

Define the intended evidence before writing the notice. If the objective is awareness of account-use conditions, describe the record as acknowledgment of those conditions. If your organization also needs evidence of training or subsequent policy adherence, plan separate evidence for those objectives.

Who can configure login notifications in NetSuite?

Only users with the Administrator role can set up login notifications. Being responsible for compliance policy is not the same as having the NetSuite role required for setup. A practical division of work is for the policy owner to approve the wording and an Administrator to implement it.

This distinction is useful when a finance or compliance team owns the requirement but does not administer NetSuite. Have that team supply approved text and identify the intended policy outcome. The Administrator can then configure the notice and perform the login test.

Before configuration, agree on who approves the message, who performs the change, and who reviews the resulting acknowledgment evidence. These are recommended organizational responsibilities, not additional NetSuite permissions or workflow requirements.

Setup and verification

The source provides this setup sequence:

  1. Navigate to the account settings as an Administrator.
  2. Locate the option for setting up login notifications.
  3. Compose the compliance message you wish users to see.
  4. Save your changes and test the login notification by logging out and back in.

This is an account-settings-level procedure, not an exact menu breadcrumb. It does not establish a particular field ID or button name, so avoid adding those details to an implementation checklist without separately verifying them.

For a useful test, check the actual displayed wording rather than merely confirming that a message appears. Does it match the approved text? Does it state the intended requirement clearly? Is acknowledgment required before account access?

Then review the acknowledgment in the Login Audit Trail as a separate verification step. This checks both the user-facing communication and the evidence administrators intend to use later. Record your observations in the organization's change records so the configuration review has context.

If you maintain a broader account access-control checklist, keep this task alongside—but distinct from—NetSuite password policy administration. The login notice communicates compliance expectations; password policies address a different part of account access management.

Why must users acknowledge the login compliance message?

Users must acknowledge the message before they can access their accounts. This distinguishes the notice from a passive announcement: displaying the text is not the entire interaction. The user has to acknowledge it before proceeding.

For users, the instruction should be simple: expect a compliance message during login, read it, and acknowledge it to continue. Communicating that expectation before introducing or revising a notice can reduce confusion about why the message appears.

For administrators and policy owners, mandatory acknowledgment creates a reason to keep the text focused. A notice that applies to everyone should clearly state what the organization expects from everyone. Consider handling specialized departmental instructions through separate communications rather than making the shared message difficult for other users to interpret.

Draft a message that supports the audit objective

An illustrative message might read: “Access to this account is subject to our approved information-handling policy. Acknowledge this notice before continuing.” This is suggested wording, not a NetSuite-provided template or legal recommendation. Your policy owner should approve the final language.

Review proposed wording against three questions:

  • Audience: Is the message understandable to the account's full user audience?
  • Purpose: Does it identify the expectation users are being asked to acknowledge?
  • Evidence: Can the organization accurately describe the resulting event as acknowledgment of that message?

Do not label the resulting evidence “training completed” if the interaction only asked users to acknowledge a notice. Likewise, avoid wording that implies acknowledgment establishes compliance with every requirement in a broader policy.

Keep acknowledgment and authentication separate in your planning. Review permissions requiring two-factor authentication independently. A compliance message and an authentication requirement address different questions: what the user acknowledges versus how account access is protected.

How do administrators track acknowledgments in the Login Audit Trail?

Administrators can monitor when users acknowledge the compliance message through the Login Audit Trail, including the date and time of acknowledgment. These details support compliance reporting and audits by providing acknowledgment evidence rather than only an assertion that the notice was configured.

Ask a review question the information can answer. “When did this user acknowledge the compliance message?” fits the described record. “Did this user follow every policy requirement afterward?” requires evidence beyond the acknowledgment.

A practical review process is:

  1. Identify the users whose acknowledgments are relevant to the review.
  2. Review the Login Audit Trail for their compliance-message acknowledgments.
  3. Check the recorded date and time against the period being reviewed.
  4. Document the conclusion as acknowledgment evidence, alongside any separate policy or training evidence your organization maintains.

This is a recommended review process, not a claim about a particular report layout, filter, or export function. Keep the conclusion limited to what you actually reviewed.

Separate configuration evidence from acknowledgment evidence

Use this distinction when preparing an audit package:

Review question Evidence or action What it establishes
What did the organization intend to communicate? Retain the approved notice wording in your change records The intended compliance message
Was the notice presented during login? Test by logging out and back in after saving The observed user-facing message
Did a user acknowledge the message? Review the Login Audit Trail The user's acknowledgment event
When did acknowledgment occur? Review the recorded date and time The timing of that acknowledgment

Retaining approved wording is an organizational recommendation. Do not assume the acknowledgment entry alone provides a complete policy-version history. If a review concerns a wording change, retain the approved text and implementation record to explain the context of the acknowledgment dates.

For example, a reviewer examining a revised information-handling notice may need both the approved revision and the relevant acknowledgment timing. Keeping those materials together supports a clearer review without claiming that the Login Audit Trail itself stores every detail of the notice.

Maintaining the notice without overstating its coverage

Treat the notice as maintained compliance communication, not a one-time setup task. The source recommends regularly updating the message to reflect current regulations and standards, along with training employees on the importance of compliance messages and how to handle them during login.

A practical change process starts with policy-owner review, followed by Administrator implementation and another logout-and-login test. Keep a record of the approved wording and when your team implemented it. That provides context for later reviews without assuming that the Login Audit Trail preserves the message text or its revision history.

Several boundaries matter when planning the control:

  • The described audience is all users. Do not build your process around an assumed role-targeted notice.
  • The described evidence is acknowledgment with date and time. Do not promise a particular export format, retention period, or message-version linkage based on this description.
  • Do not promise how often acknowledgment will be requested after an edit without separately verifying that behavior.

Use the notice alongside other administrative controls, not as a substitute for them. For example, NetSuite password expiration settings and PCI rules belong in their own policy review. Keeping those responsibilities separate makes it easier to explain what the notice contributes: compliance communication, mandatory acknowledgment before access, and acknowledgment timing for audit review.

FAQ

Which role can set up login notifications in NetSuite?

Only users with the Administrator role can set up login notifications.

Do users have to acknowledge the compliance notice before accessing their accounts?

Yes. The message is displayed to all users upon login, and users must acknowledge it before accessing their accounts.

How can administrators track when users acknowledge the message?

Administrators can review acknowledgments through the Login Audit Trail, including the date and time of acknowledgment.

When were login compliance notifications introduced?

Administrators can establish account login notifications starting in NetSuite 2026.1.

Related reading