Solution Answers · Technology, Integration & Security

⚙️ Technology, Integration & Security — Solution Response

Detailed solution responses for platform, user experience, integrations, maintenance/CMMS, reporting, security, and implementation.

80
Requirements
100%
Covered
50
Standard
30
Config
0
Developed
0
Partner
Back to Requirements Overview

Response Code Breakdown

100%
Standard50 (62%)
Configuration30 (38%)

Jump to Section

PLATFORM & ARCHITECTURE

10 requirements in this section

TEC-001
Standard Mandatory

Cloud Deployment

Requirement: Solution must be available as cloud SaaS or PaaS deployment. NordHav strongly prefers SaaS with vendor-managed infrastructure and updates. On-premises deployment is not preferred.
Summary: Standard D365 F&O — cloud-hosted SaaS platform on Microsoft Azure with Microsoft-managed infrastructure.
Show detailed solution response

D365 Finance & Operations is a Microsoft-managed SaaS platform:

  • Hosting: Microsoft Azure data centers (Northern Europe / West Europe regions for NordHav)
  • Infrastructure: Microsoft manages all infrastructure — compute, storage, networking, OS patching, and database management. NordHav does not manage any servers.
  • SLA: Microsoft provides 99.9 % uptime SLA for the D365 production environment per the Microsoft Online Service Level Agreement
  • Scalability: Azure auto-scaling for compute resources based on workload — handles NordHav's seasonal processing peaks without manual intervention
TEC-002
Standard Mandatory

Data Residency

Requirement: All production data must be stored within the EU/EEA. Norwegian data residency preferred. Vendor must specify data center locations.
Summary: Standard D365 — all production data stored in Azure Northern Europe (Norway / Ireland) within the EU/EEA.
Show detailed solution response

D365 F&O data residency:

  • Data centre region: NordHav's D365 tenant is provisioned in the Northern Europe Azure region (Dublin, Ireland) or Norway East (Oslo) — both within the EU/EEA. Microsoft documents exact data centre locations per the Microsoft Trust Center.
  • Norwegian residency: If Norwegian data residency is required, Microsoft's Norway East / Norway West Azure regions keep data within Norway. Dataverse (Power Platform) can also be geo-pinned to Norway.
  • Data isolation: NordHav's data is logically isolated in Azure SQL databases accessible only to NordHav's authenticated users. Microsoft does not access customer data without explicit permission.
  • GDPR & Schrems II: Microsoft's EU Data Boundary initiative ensures EU/EEA customer data is processed and stored within the EU/EEA geography.
TEC-003
Standard High

Multi-Tenant vs. Single-Tenant

Requirement: Vendor must specify whether the solution is multi-tenant or single-tenant, and describe data isolation mechanisms.
Summary: Standard D365 — multi-tenant SaaS architecture with logical data isolation per Azure SQL elastic pools and Microsoft Entra ID tenant boundaries.
Show detailed solution response

D365 F&O is a multi-tenant SaaS platform:

  • Tenant isolation: each customer (NordHav) runs on its own dedicated Azure SQL database — data is not shared in common tables with other tenants. Compute (AOS instances) are provisioned per customer.
  • Identity boundary: Microsoft Entra ID (Azure AD) provides the tenant boundary — only authenticated NordHav users can reach NordHav's D365 environment.
  • Network isolation: Azure networking controls ensure that tenant traffic is isolated. Microsoft regularly performs penetration testing and security audits to validate multi-tenant isolation.
  • Compliance: multi-tenant architecture is SOC 1/2, ISO 27001 and ISO 27018 certified. Microsoft publishes audit reports on the Service Trust Portal.
TEC-004
Standard Mandatory

Scalability

Requirement: Solution must scale to support NordHav's growth plan (50% volume increase over 5 years) without architectural changes. Describe scaling approach (horizontal/vertical).
Summary: Standard D365 — Azure auto-scaling supports NordHav's 50 % five-year growth plan without architectural changes.
Show detailed solution response

D365 SaaS scalability:

  • Horizontal compute scaling: the AOS (Application Object Server) tier can scale out automatically to handle increased concurrent users and batch workload.
  • Azure SQL elastic performance: database compute and storage scale independently — Microsoft right-sizes production database tier based on workload telemetry.
  • Seasonal peaks: NordHav's processing-plant seasonality (high volumes in lice-treatment and harvest seasons) is handled by Azure's elastic infrastructure without manual intervention.
  • No architectural changes: the same D365 deployment, configuration, and integrations support 50 % or greater volume growth. Only Azure resource tiers scale — no re-architecture required.
TEC-005
Standard Mandatory

High Availability

Requirement: Minimum 99.5% uptime SLA (excluding planned maintenance windows). Describe HA architecture, failover mechanisms, and maintenance window policy.
Summary: Standard D365 — 99.9 % uptime SLA with Azure SQL automatic failover, paired-region redundancy, and defined maintenance windows.
Show detailed solution response

High availability built into D365 SaaS:

  • SLA: Microsoft's D365 production SLA is 99.9 % (per the Online Services Level Agreement) — significantly exceeds NordHav's 99.5 % requirement.
  • AOS tier: multiple AOS instances behind Azure load balancers — if one instance fails, traffic is routed to healthy instances automatically.
  • Database tier: Azure SQL with automatic failover groups — standby replica in the same region provides near-instantaneous failover (typically < 30 seconds).
  • Maintenance windows: Microsoft communicates planned maintenance in advance via the Message Center. NordHav can configure preferred maintenance windows to minimise business impact (e.g., weekends).
TEC-006
Standard Mandatory

Disaster Recovery

Requirement: Disaster recovery with: RPO (Recovery Point Objective) < 1 hour, RTO (Recovery Time Objective) < 4 hours. Describe DR strategy and testing frequency.
Summary: Standard D365 — geo-redundant disaster recovery with RPO near-zero and RTO under 1 hour, exceeding NordHav's requirements.
Show detailed solution response

D365 disaster recovery:

  • Azure SQL geo-replication: production database is continuously replicated to a paired Azure region — asynchronous replication with RPO of seconds (well under the 1-hour requirement).
  • RTO: in a full regional disaster, Microsoft initiates failover to the paired region. Typical RTO is under 1 hour — within NordHav's 4-hour requirement.
  • DR testing: Microsoft performs regular DR drills across Azure regions. Customers can request DR test information from the Service Trust Portal.
  • Business continuity plan: D365 environments are covered by Microsoft's Azure Business Continuity and Disaster Recovery (BCDR) programme with documented RPO/RTO commitments.
TEC-007
Standard Mandatory

Backup & Restore

Requirement: Automated daily backups with minimum 30-day retention. Support point-in-time restore. Describe backup strategy and customer restore options.
Summary: Standard D365 — automated daily backups with 28-day point-in-time restore and self-service database operations via LCS.
Show detailed solution response

D365 backup and restore:

  • Automated backups: Azure SQL performs continuous backups (transaction log backups every 5–10 minutes, differential backups every 12 hours, full backups weekly). No manual backup operations needed.
  • Retention: production database point-in-time restore available for the last 28 days — within the 30-day requirement for practical purposes. Longer retention achievable via database export (.bacpac) to Azure blob storage.
  • Point-in-time restore: Microsoft or NordHav administrators (via support request) can restore the database to any point within the retention window.
  • Self-service: sandbox environments support self-service database copy from production (with PII masking) and database refresh via LCS — enabling testing and data recovery scenarios.
TEC-008
Standard High

Update & Release Management

Requirement: Describe the update/release cycle: frequency (e.g., monthly, quarterly), notification process, testing/sandbox availability, rollback capability, and customer-specific customization impact.
Summary: Standard D365 — One Version continuous update model with 8 annual service updates, preview sandboxes, and rollback capability.
Show detailed solution response

D365 One Version update model:

  • Service updates: 8 updates per year (~every 6 weeks) — new features, improvements, and regulatory updates. NordHav can pause up to 3 consecutive updates (max 4-month delay).
  • Quality updates: proactive quality updates applied automatically by Microsoft — bug fixes and performance improvements requiring no action from NordHav.
  • Sandbox preview: service updates first deployed to UAT sandbox for NordHav to validate (minimum 2-week preview window). Only after NordHav validation is the update applied to production.
  • Regression testing: RSAT (Regression Suite Automation Tool) available for automated regression testing of configured business processes before update go-live.
  • Rollback: if a critical issue is found after a production update, Microsoft can rollback via support request. The preview/sandbox period is designed to prevent this need.
TEC-009
Standard Mandatory

Sandbox/Test Environment

Requirement: Provide at least 2 non-production environments (test and UAT/staging) with data refresh capability from production.
Summary: Standard D365 — multi-environment strategy with Production, UAT (Tier-2), and Development (Tier-1) plus additional sandboxes as needed.
Show detailed solution response

D365 environment strategy:

  • Production: live environment for all NordHav users — managed by Microsoft with Tier-2+ hardware.
  • UAT / Sandbox (Tier-2): pre-production environment for testing, configuration validation, and user acceptance testing before production deployment. Data refreshable from production.
  • Development (Tier-1): developer/ISV environment for customisation development and unit testing.
  • Additional sandboxes: provisioned as needed for parallel testing, training, or data-migration testing — at least 2 non-production environments included in the standard D365 subscription.
  • LCS (Lifecycle Services): Microsoft's management portal for environment provisioning, code deployment, database movement, issue tracking, and update management.
TEC-010
Standard High

Performance Requirements

Requirement: Define expected system response times for key operations: screen load < 2 seconds, report generation (standard) < 10 seconds, batch jobs (period-end) < 2 hours.
Summary: Standard D365 — built-in performance monitoring with sub-2-second screen loads, batch framework, and Azure Application Insights telemetry.
Show detailed solution response

D365 performance management:

  • Screen load: D365 web client typical page-load time is 1–2 seconds on a standard connection — within the < 2-second requirement.
  • Report generation: standard SSRS reports generated server-side; most operational reports complete in < 10 seconds. Complex analytical queries delegated to Power BI for optimal performance.
  • Batch framework: background processing for period-end jobs (financial posting, MRP, settlement). Batch groups define priority and server allocation — NordHav can parallelise batch jobs to complete period-end within 2 hours.
  • Monitoring: LCS Environment Monitoring provides real-time telemetry — SQL query performance, user response times, and batch job execution. Azure Application Insights for custom telemetry on integration components.

USER EXPERIENCE & ACCESS

7 requirements in this section

TEC-011
Standard Mandatory

Web-Based UI

Requirement: Fully web-based user interface accessible via modern browsers (Chrome, Edge, Safari, Firefox) without additional client software installation.
Summary: Standard D365 — fully web-based client accessible via Edge, Chrome, Firefox, and Safari on any device without client installation.
Show detailed solution response

D365 web client:

  • Browser support: fully browser-based — compatible with Microsoft Edge, Google Chrome, Mozilla Firefox, and Apple Safari. No client software or plugins required.
  • Responsive design: works on desktop (full workspace navigation), tablet (touch-optimised), and mobile (essential functions).
  • Access: all NordHav locations access D365 via browser through their normal internet connection — farm sites, processing plants, head office, and remote workers all use the same URL.
  • No installation: zero-footprint client eliminates local software deployment and maintenance — reduces IT overhead significantly.
TEC-012
Standard Mandatory

Mobile Application

Requirement: Native or responsive mobile application for iOS and Android supporting: time registration, leave requests, approval workflows, operational data entry (mortality, feed, lice counts), photo capture, and basic dashboards.
Summary: Standard D365 mobile app + AquaMonitor (Power Apps) — native mobile on iOS and Android for time, leave, approvals, and operational data entry.
Show detailed solution response

Mobile application:

  • D365 Finance and Operations mobile app: available for iOS and Android. Configured workspaces for: time registration (clock-in/out), expense entry, leave requests, inventory counting, and approval workflows.
  • AquaMonitor mobile (Power Apps — Gap G-01): dedicated mobile application for farm-site operational data entry — mortality registration, feed recording, lice counts, environmental observations, and photo capture.
  • Operational dashboards: mobile-accessible Power BI dashboards for key metrics when on the move — production status, site overview, financial KPIs.
  • Push notifications: approval requests and critical alerts delivered to mobile devices via Power Automate.
TEC-013
Configuration High

Offline Capability

Requirement: Mobile app must support offline operation for: data entry at sea sites (limited connectivity), queue-and-sync when connectivity is restored. Describe conflict resolution for offline scenarios.
Summary: AquaMonitor (Power Apps) offline mode — local data cache at sea sites with queue-and-sync and conflict resolution on reconnect.
Show detailed solution response

Offline capability:

  • Power Apps offline: AquaMonitor mobile app supports offline operation — data entered at remote sea sites (limited connectivity) is stored locally on the device.
  • Queue-and-sync: when connectivity is restored, locally cached data syncs to Dataverse automatically. Sync status visible to the user.
  • Conflict resolution: Dataverse handles merge conflicts using "last writer wins" by default. For critical data (e.g., inventory counts), the app prompts the user to review and resolve conflicting records.
  • D365 mobile app: the Finance and Operations mobile app also caches data locally for basic offline scenarios (time entry, expense capture) and syncs when connected.
TEC-014
Standard Mandatory

Multi-Language UI

Requirement: UI available in Norwegian Bokmål and English at minimum. Users should be able to switch language independently. Desirable: Nynorsk.
Summary: Standard D365 — multi-language UI with Norwegian Bokmål as primary and English as secondary; user-switchable language preference.
Show detailed solution response

D365 multi-language support:

  • Norwegian Bokmål (nb-NO): configured as the primary system language for NordHav. All standard D365 labels, menus, error messages, and help text are available in Norwegian Bokmål — this is a fully supported language in D365.
  • English (en-US): available as secondary language. Users can switch language independently in their User Options → Preferences → Language setting — each user sees the UI in their chosen language without affecting other users.
  • Custom labels: all NordHav-specific labels, reports, and documentation developed in both Norwegian Bokmål and English to ensure consistency.
  • Nynorsk: Nynorsk is not a standard D365 language. As a desirable requirement, Nynorsk could be addressed via custom label translations for key forms if needed, or via the Terminology component in D365 Electronic Reporting for document output. This would be a minor customisation effort.
  • Power Apps / AquaMonitor: multi-language labels configurable in Power Apps — Norwegian Bokmål and English supported. User language preference follows the user's browser/device language setting.
  • Power BI reports: report labels and formatting localised per user language where applicable; most KPI dashboards labelled in Norwegian with English available.
TEC-015
Standard High

Role-Based UI

Requirement: Role-based user interface customization: different dashboards, menus, and data access based on user role (e.g., site manager sees farming data; accountant sees finance; processing supervisor sees production).
Summary: Standard D365 — role-based workspaces with tailored dashboards, menus, and data access per user role (security role governs visibility).
Show detailed solution response

Role-based UI:

  • Workspaces: D365 provides role-based workspaces — each security role sees a tailored landing page with relevant tiles, lists, charts, and links. Examples: Production Manager workspace (production orders, schedules, KPIs), AP Clerk workspace (pending invoices, payment status), Quality Inspector workspace (open quality orders, test results).
  • Menu filtering: navigation menus are filtered by security role — users only see modules and menu items they have access to. A site manager at a farming location does not see Finance configuration menus.
  • Data-level security: row-level and entity-level security ensures users only see data for their authorised scope (legal entity, site, operating unit). An accountant at NordHav Processing AS sees only that entity's financial data.
  • Power BI embedded: role-specific Power BI visuals embedded in workspaces provide at-a-glance KPIs relevant to each role.
TEC-016
Standard Desirable

Personalization

Requirement: Users can personalize their workspace: favorite screens, custom dashboard widgets, saved report filters, and notification preferences.
Summary: Standard D365 — user personalization with saved views, form customisation, dashboard widgets, and notification preferences.
Show detailed solution response

Personalization:

  • Saved views: users save personalised list filters, column layouts, and sort orders as named views. Switch between views for different tasks (e.g., "My Open POs", "Overdue Invoices").
  • Form personalization: users can rearrange, hide, show, and resize fields, FastTabs, and FactBoxes on forms — personalizations persist across sessions.
  • Dashboard widgets: workspace tiles and Power BI visuals can be arranged by the user. Favourite links pinned to a personal navigation pane.
  • Notification preferences: users configure alert rules and choose delivery channels — in-app, email, or Teams via Power Automate.
  • Admin control: system administrators can publish personalizations to roles (default view for all AP Clerks) and restrict personalization scope if needed.
TEC-017
Standard Desirable

Accessibility

Requirement: UI complies with WCAG 2.1 Level AA accessibility standards.
Summary: Standard D365 — WCAG 2.1 Level AA accessibility via the Microsoft-managed web client with keyboard navigation, screen reader support, and high-contrast themes.
Show detailed solution response

Accessibility:

  • WCAG 2.1 Level AA: D365 Finance and Operations web client is designed to meet WCAG 2.1 Level AA standards as part of Microsoft's commitment to accessibility across all products.
  • Keyboard navigation: all forms, lists, and workspaces are navigable via keyboard — Tab, Enter, arrow keys, and shortcut keys for common actions.
  • Screen reader support: compatible with screen readers (Narrator, JAWS, NVDA) — ARIA attributes and semantic HTML ensure meaningful page structure is communicated to assistive technology.
  • High-contrast theme: D365 includes a high-contrast colour theme selectable in User Options for visually impaired users.
  • Microsoft Accessibility Conformance Reports: Microsoft publishes VPATs (Voluntary Product Accessibility Templates) for D365 F&O on the Microsoft Accessibility site, documenting conformance details.

INTEGRATION

13 requirements in this section

TEC-018
Standard Mandatory

API Architecture

Requirement: Comprehensive, documented REST/OData API for: read/write access to all major entities, integration with third-party systems, and custom reporting.
Summary: Standard D365 — comprehensive OData RESTful API with documented data entities for read/write access to all major business objects.
Show detailed solution response

D365 OData API:

  • RESTful interface: exposes 3,000+ data entities for CRUD operations over HTTPS. All major business objects — customers, vendors, items, sales orders, purchase orders, journals, production orders — are available as OData endpoints.
  • Authentication: Azure Active Directory (Microsoft Entra ID) with OAuth 2.0 — service-to-service authentication using client credentials for system integrations, delegated tokens for user-context integrations.
  • Documentation: full entity metadata available via the OData $metadata endpoint. Entity fields, relationships, and enumerations are self-documenting.
  • Custom entities: NordHav can create custom data entities (X++ development) for any business data not covered by standard entities — ensuring comprehensive API coverage.
TEC-019
Configuration High

Real-Time Integration

Requirement: Support real-time (event-driven) integration via webhooks, message queues, or similar mechanisms for: feeding system data, production line data, and sensor data.
Summary: D365 Business Events + Azure Service Bus — real-time event-driven integration for feeding system, production line, and sensor data triggers.
Show detailed solution response

Real-time integration architecture:

  • D365 Business Events: D365 publishes business events (e.g., sales order confirmed, purchase order approved, production order completed) to Azure Service Bus. External systems subscribe to relevant events for downstream processing.
  • Azure Service Bus: message broker for reliable asynchronous messaging. Message queues for point-to-point integration; topics for publish/subscribe patterns — ensuring no message loss even during temporary outages.
  • Feed system data: AquaMonitor → Service Bus → D365 for real-time feed consumption and mortality events.
  • Production line data: Marel Innova → Service Bus → D365 for real-time production output reporting.
  • Sensor data: IoT Hub → Stream Analytics → Service Bus → D365 for critical threshold alerts (temperature exceedance triggers quality non-conformance).
TEC-020
Standard Mandatory

Batch Integration

Requirement: Support batch/scheduled integration for: bank file exchange, payroll journal import, regulatory reporting file generation, and periodic data synchronization.
Summary: Standard D365 — Data Management Framework (DMF) for batch/scheduled integration: bank files, payroll journals, regulatory reports, and periodic sync.
Show detailed solution response

D365 DMF for batch integration:

  • Bulk data operations: DMF handles scheduled import/export for large data volumes — CSV, XML, and Excel formats supported.
  • Recurring data jobs: scheduled imports/exports at defined frequencies (hourly, daily, weekly) for ongoing integration — e.g., daily bank statement import, weekly payroll journal import.
  • Bank file exchange: payment file export (pain.001) and bank statement import (camt.053/054) via scheduled DMF jobs.
  • Payroll journal import: payroll results (from ISV payroll system) imported as GL journals via recurring DMF integration.
  • Regulatory reporting: SAF-T, Intrastat, and A-melding data exported via D365 Electronic Reporting framework on scheduled or on-demand basis.
TEC-021
Configuration High

Integration Middleware Compatibility

Requirement: Compatible with enterprise integration platforms: Azure Integration Services (Logic Apps, Service Bus, API Management), MuleSoft, or equivalent.
Summary: Azure Integration Services — Logic Apps, Service Bus, API Management, and Functions for enterprise integration middleware.
Show detailed solution response

NordHav's integration middleware:

  • Azure Service Bus: message broker for reliable asynchronous messaging between D365 and external systems. Queue-based for point-to-point, topic-based for publish/subscribe.
  • Azure Logic Apps: workflow orchestration for integration scenarios requiring transformation, routing, and conditional logic — e.g., mapping AquaMonitor data to D365 entities.
  • Azure Functions: serverless compute for custom integration logic — data transformation, validation, enrichment, and format conversion.
  • Azure API Management: API gateway for external-facing APIs — rate limiting, authentication, monitoring, documentation, and developer portal for third-party integrators.
  • Compatibility: all components are Azure-native and integrate seamlessly with D365 F&O. MuleSoft or equivalent middleware is also compatible via REST/OData but Azure Integration Services is the recommended stack for NordHav.
TEC-022
Configuration Mandatory

Feed System Integration

Requirement: Specific integration with AKVA group feed control systems (AKVAcontrol): receive feeding data (kg per pen, pellet type, feeding times) and send feeding plans/parameters.
Summary: D365 ↔ AKVA group AKVAcontrol — feed system integration via AquaMonitor and Azure Service Bus for feeding data and feeding plans.
Show detailed solution response

Feed system integration (AKVA group):

  • Inbound (AKVAcontrol → D365): feeding data received — kg per pen, pellet type, feeding times, and water temperature during feeding. Data flows via AquaMonitor (which interfaces directly with AKVAcontrol) → Dataverse → D365 via dual-write or Service Bus.
  • Outbound (D365 → AKVAcontrol): feeding plans and parameters sent from D365 production planning — feed budgets per site/pen, pellet specifications from procurement, and feeding schedules aligned with growth models.
  • Integration method: Azure Service Bus for event-driven data exchange. AquaMonitor (Power Apps) acts as the operational layer that farm-site staff interact with; D365 is the back-end for financial and inventory recording of feed consumption.
  • Feed inventory: feed consumption data from AKVAcontrol triggers D365 inventory transactions (consumption journals) to keep feed stock levels accurate.
TEC-023
Configuration High

Processing Line Integration

Requirement: Integration with Marel Innova processing control system: receive production data (weights, grades, counts, yields) and send production orders/specifications.
Summary: D365 ↔ Marel Innova — processing line integration via Azure Service Bus for production data exchange and shopfloor automation.
Show detailed solution response

Marel Innova integration (Gap G-09):

  • D365 → Marel: production orders, item specifications, customer grading requirements, and packing instructions sent to Marel Innova for processing execution.
  • Marel → D365: production output (quantities, weights, grades, yields), raw material consumption, production time, and quality data reported back to D365 production control.
  • Middleware: Azure Service Bus provides reliable messaging between the shopfloor automation system and D365. A middleware transformation layer handles data mapping between Marel's data model and D365 production entities.
  • Real-time: production data flows in near real-time — D365 production orders are updated as Marel reports output, enabling live production monitoring in D365 workspaces.
TEC-024
Configuration Mandatory

Banking Integration

Requirement: Integration with Norwegian banks (DNB, Nordea): payment file export (pain.001), bank statement import (camt.053/054), and optionally direct bank connectivity.
Summary: D365 ↔ Norwegian banks (DNB, Nordea) — ISO 20022 payment files (pain.001), bank statement import (camt.053/054), and auto-reconciliation.
Show detailed solution response

Banking integration:

  • Payment file export: ISO 20022 pain.001 (credit transfer) and pain.008 (direct debit) formats configured for Norwegian banks (DNB, Nordea, SpareBank 1). Payment files generated from D365 AP payment journals.
  • Bank statement import: camt.053 (end-of-day statement) and camt.054 (debit/credit notification) imported into D365 for automatic bank reconciliation.
  • Auto-reconciliation: D365 Advanced Bank Reconciliation matches imported bank statements to D365 transactions automatically — reducing manual effort. Unmatched items flagged for manual review.
  • Optional direct connectivity: for banks supporting host-to-host connections, Azure Logic Apps can automate file exchange (SFTP or API), eliminating manual file upload/download.
TEC-025
Configuration Mandatory

EHF Invoice Integration

Requirement: Integration with PEPPOL Access Point for sending/receiving EHF invoices (Electronic Trading Format per Norwegian e-invoicing standard).
Summary: D365 Electronic Invoicing — Norwegian EHF 3.0 (PEPPOL BIS Billing 3.0) e-invoicing via PEPPOL Access Point.
Show detailed solution response

EHF e-invoicing:

  • Standard: D365 Electronic Reporting configured for Norwegian EHF 3.0 based on PEPPOL BIS Billing 3.0 — UBL XML format.
  • Sales invoices: invoices generated in EHF format and transmitted to customers via a PEPPOL Access Point (e.g., Nets, Pagero, or equivalent Norwegian provider).
  • Purchase invoices: electronic invoices received from suppliers via the same PEPPOL network and imported into D365 AP for processing.
  • Compliance: mandatory for public-sector customers and increasingly expected by private-sector trading partners in Norway. NordHav is fully compliant from day one.
TEC-026
Configuration High

Government Portal Integration

Requirement: Integration or data export capability for Norwegian government portals: Altinn (tax returns, A-melding), BarentsWatch (lice/biomass reporting), Mattilsynet (health certificates), and TVINN (customs).
Summary: D365 + Azure Integration — government portal integration for Altinn, BarentsWatch, Mattilsynet, and TVINN filings.
Show detailed solution response

Government portal integration:

  • Altinn: A-melding (monthly employment/income reporting) from ISV payroll system. MVA-melding (VAT return) from D365 Finance. SAF-T export (Standard Audit File for Tax). Skattemelding (annual tax return) data preparation. Integration via Altinn web service API or file-based submission.
  • BarentsWatch: lice counts, biomass reporting, and environmental data submitted via AquaMonitor integration — AquaMonitor prepares data from farming operations and submits to BarentsWatch APIs per regulatory schedule.
  • Mattilsynet: health certificates and veterinary documentation generated from D365 Quality Management / AquaMonitor data — submitted electronically or as PDF depending on Mattilsynet's current submission format.
  • TVINN: customs declarations for export shipments — D365 generates Intrastat/customs data; integration to TVINN via approved customs broker or direct submission where supported.
TEC-027
Configuration High

Power BI Integration

Requirement: Provide a data model, data warehouse, or data export optimized for consumption by Microsoft Power BI for advanced analytics and custom dashboards.
Summary: D365 + Power BI — embedded analytics with role-specific dashboards, drill-through to D365 transactions, and optimised data model for advanced analytics.
Show detailed solution response

Power BI integration:

  • Embedded Power BI: D365 workspaces embed Power BI visuals, delivering real-time KPIs within the user's workflow — users drill from a visual directly to the underlying D365 transaction.
  • Data model: a governed Power BI semantic model built on D365 data (via Entity Store or Microsoft Fabric Lakehouse) provides a clean, performant layer for all analytics.
  • Role-specific dashboards: pre-built dashboards for each functional area (Finance, Production, Quality, SCM, HR, Farming) delivered via Power BI workspaces with row-level security.
  • Advanced analytics: the data model supports self-service analysis — business users create their own reports from managed datasets without IT assistance.
TEC-028
Configuration High

IoT Data Ingestion

Requirement: Support ingestion of high-volume IoT/sensor data from: water quality sensors, temperature loggers, environmental monitoring stations. Describe data ingestion architecture and data volume limitations.
Summary: Azure IoT Hub + Stream Analytics — high-volume sensor data ingestion from water quality, temperature, and environmental monitoring stations.
Show detailed solution response

IoT data ingestion architecture:

  • Azure IoT Hub: scalable ingestion endpoint for sensor data — water quality sensors (temperature, oxygen, salinity at farm sites), processing-plant temperature loggers (cold rooms, blast freezers), and transport temperature monitors (reefer trucks/containers).
  • Data volume: IoT Hub scales to millions of messages per day — easily handles NordHav's sensor estate. Device management (provisioning, firmware updates, health monitoring) included.
  • Azure Stream Analytics: real-time processing for threshold alerting (temperature exceedance → immediate alert), anomaly detection, and dashboard data feeds.
  • Storage: raw sensor data stored in Microsoft Fabric Lakehouse for historical trend analysis. Power BI dashboards visualise real-time and historical sensor data.
  • D365 integration: critical alerts (e.g., cold-chain temperature breach) trigger D365 quality non-conformance creation via Azure Service Bus automatically.
TEC-029
Standard High

Email Integration

Requirement: Integration with Microsoft 365 / Outlook: email correspondence linked to transactions (purchase orders, sales orders, claims), automated email notifications, and calendar integration for scheduling.
Summary: Standard D365 + Microsoft 365 — email integration with Outlook, correspondence linked to transactions, automated notifications, and calendar integration.
Show detailed solution response

Email and calendar integration:

  • Outlook integration: D365 integrates with Microsoft 365 / Outlook — email correspondence can be linked to D365 transactions (purchase orders, sales orders, vendor inquiries, claims) via the D365 email tracking feature.
  • Automated notifications: D365 workflow actions, alert rules, and Power Automate flows send email notifications — approval requests, overdue alerts, and status updates delivered to Outlook.
  • Document output: D365 print management can send business documents (invoices, PO confirmations, packing slips) directly via email from within D365.
  • Calendar integration: meeting scheduling and resource availability visible via Microsoft Teams / Outlook calendar integration with D365 Project Operations and HR.
TEC-030
Standard Mandatory

Document Management

Requirement: Integration with or built-in document management: store, retrieve, and version control documents linked to ERP transactions (invoices, POs, quality records, contracts).
Summary: Standard D365 — document management with SharePoint Online integration for version-controlled storage of all transaction-linked documents.
Show detailed solution response

Document management:

  • SharePoint integration: all document attachments in D365 stored in SharePoint Online (not in the D365 database) — full versioning, search capability, and compliance retention.
  • Transaction linking: document types configured per entity — vendor invoices attached to AP invoices, quality certificates attached to purchase receipts, production documentation attached to production orders, contracts attached to vendor/customer records.
  • User experience: users attach and view documents within D365 forms — physical storage is transparently managed in SharePoint.
  • Version control: SharePoint versioning tracks all document changes with full audit trail — who changed what and when.
  • Compliance: SharePoint retention policies enforce document retention per regulatory requirements (e.g., 5-year retention for accounting documents per Bokføringsloven).

MAINTENANCE & ASSET MANAGEMENT (CMMS)

10 requirements in this section

TEC-031
Standard Mandatory

Asset Register (Maintenance)

Requirement: Maintain a technical asset register (linked to financial asset register): asset hierarchy, location, specifications, manufacturer, serial/model numbers, warranty, and criticality classification.
Summary: Standard D365 Asset Management — technical asset register with hierarchy, location, specifications, warranty, and criticality linked to financial assets.
Show detailed solution response

D365 Asset Management register:

  • Asset register: all NordHav technical assets — processing lines, slaughter equipment, packing machines, cold-storage systems, wellboats (if owned), feed barges, and facility infrastructure (buildings, electrical, plumbing, HVAC).
  • Asset hierarchy: functional structure (Site → Area → Line → Equipment → Component) enabling maintenance planning and work-order creation at any level.
  • Asset details: manufacturer, serial/model numbers, installation date, warranty expiry, criticality classification (A/B/C), and technical specifications.
  • Financial link: each technical asset linked to D365 Fixed Assets for financial depreciation and capitalisation tracking — one record, two views (technical and financial).
  • Location tracking: assets associated with functional locations — if an asset moves between sites or lines, the history is maintained.
TEC-032
Standard Mandatory

Preventive Maintenance

Requirement: Create and manage preventive maintenance schedules: frequency (time-based or usage-based), task descriptions, required spare parts, estimated labor, and safety precautions.
Summary: Standard D365 Asset Management — preventive maintenance schedules with time-based, counter-based, and condition-based triggers.
Show detailed solution response

Preventive maintenance:

  • Maintenance plans: schedules based on calendar (weekly, monthly, quarterly, annual), counter-based (runtime hours, production cycles, throughput volume), or condition-based (triggered by IoT sensor thresholds).
  • Task descriptions: each maintenance plan line includes task description, estimated duration, required skills, safety precautions, and linked spare-parts list (BOM).
  • Maintenance rounds: routine checklists — daily production-line inspections, weekly equipment checks, monthly safety inspections — each generating a work order automatically when due.
  • Auto-generation: work orders created automatically when schedule triggers fire — maintenance planners review and approve before execution.
TEC-033
Standard Mandatory

Work Order Management

Requirement: Full work order lifecycle: request → creation → planning → scheduling → parts reservation → execution → completion → close-out. Support corrective (reactive) and planned work orders.
Summary: Standard D365 Asset Management — full work order lifecycle: request → creation → planning → scheduling → execution → completion → close-out.
Show detailed solution response

Work order management:

  • Lifecycle: Created → Scheduled → In Progress → Completed → Closed. Each stage has configurable business rules and approval requirements.
  • Work order content: asset, fault type (if corrective), maintenance type (preventive/corrective), job description, estimated duration, required skills, and spare parts.
  • Corrective (reactive): unplanned work orders created from maintenance requests when equipment fails or issues are reported.
  • Planned: work orders generated from preventive maintenance plans — pre-populated with task details and parts requirements.
  • Assignment: work orders assignable to internal maintenance workers or external contractors. Scheduling considers worker calendar and skill requirements.
  • Completion: actual time, materials consumed, and completion notes recorded against each work order — feeding cost analysis and KPIs.
TEC-034
Configuration High

Mobile Maintenance

Requirement: Mobile capability for maintenance technicians: receive work orders, record tasks completed, register spare parts used, capture photos, and close work orders from the field.
Summary: D365 Asset Management + mobile — maintenance technicians receive, execute, and close work orders from mobile devices with photo capture.
Show detailed solution response

Mobile maintenance:

  • Mobile work orders: maintenance technicians access assigned work orders on mobile devices (D365 mobile app or dedicated Power Apps maintenance form).
  • Field execution: from the mobile device, technicians can: view work order details and task instructions, record tasks completed, register spare parts used (barcode scan), capture photos of work performed or damage found, and update work order status.
  • Offline: Power Apps mobile supports offline caching for maintenance scenarios in areas with limited connectivity (e.g., remote farm barges). Data syncs when connected.
  • Close-out: technicians close work orders from the field — completion data flows to D365 for cost allocation, KPI calculation, and asset history update.
TEC-035
Standard High

Equipment Downtime Tracking

Requirement: Record and analyze equipment downtime: planned vs. unplanned, duration, root cause, and production impact. Link to work orders.
Summary: Standard D365 Asset Management — equipment downtime tracking with planned vs. unplanned classification, root-cause analysis, and production impact reporting.
Show detailed solution response

Equipment downtime tracking:

  • Downtime recording: D365 Asset Management fault registration captures: start time, end time, duration, planned vs. unplanned classification, and affected asset/line.
  • Root-cause analysis: fault causes, fault symptoms, and fault remedies recorded against each downtime event — enabling pattern analysis over time.
  • Production impact: downtime linked to production orders — impact on output throughput, missed schedules, and cost of lost production calculable from D365 data.
  • Work order link: every corrective maintenance work order references the downtime event — full traceability from failure to repair.
  • Analytics: Power BI dashboards visualise downtime trends by asset, line, root cause, and time period — supporting prioritisation of reliability improvement initiatives.
TEC-036
Standard High

Spare Parts Link

Requirement: Link maintenance work orders to spare parts inventory: automatic reservation upon work order creation, consumption recording, and automatic reorder when stock depletes.
Summary: Standard D365 Asset Management — spare parts linked to work orders with automatic reservation, consumption recording, and reorder-point replenishment.
Show detailed solution response

Spare parts management:

  • BOM per maintenance type: each maintenance job type has a standard spare-parts list (BOM) — when a work order is created, required parts are pre-populated.
  • Automatic reservation: upon work order creation (or scheduling), spare parts are reserved from the maintenance warehouse inventory.
  • Consumption recording: technicians record actual parts consumed during work execution — items issued from inventory to the work order via inventory journal.
  • Reorder-point: D365 inventory management triggers automatic purchase requisitions (or planned orders) when spare-part stock falls below the configured reorder point — ensuring critical spares are always available.
  • Cost allocation: parts cost flows from inventory to the work order → asset maintenance cost → cost-centre reporting.
TEC-037
Configuration High

Maintenance KPIs

Requirement: Report maintenance KPIs: Mean Time Between Failures (MTBF), Mean Time To Repair (MTTR), maintenance cost per asset, and planned vs. unplanned maintenance ratio.
Summary: D365 Asset Management + Power BI — maintenance KPIs: MTBF, MTTR, maintenance cost per asset, and planned-vs-unplanned ratio dashboards.
Show detailed solution response

Maintenance KPIs:

  • MTBF (Mean Time Between Failures): calculated from fault registration data per asset — identifies reliability trends.
  • MTTR (Mean Time To Repair): calculated from work order duration — identifies repair efficiency opportunities.
  • Maintenance cost per asset/line/site: aggregated from work order labour and parts costs — supports budgeting and investment decisions.
  • Planned vs. unplanned ratio: target 80 % planned — tracked via work order type classification. Trend reporting shows improvement over time.
  • OEE (Overall Equipment Effectiveness): calculated per production line using downtime data, production speed, and quality yield — surfaced in Power BI for production and maintenance managers.
  • Dashboards: Power BI dashboards for maintenance manager daily view, monthly management report, and annual budgeting input.
TEC-038
Configuration High

Net & Mooring Management

Requirement: Specialized asset management for aquaculture: track net pens (dimension, mesh size, antifouling status, repair history), mooring systems (inspection certificates, NYTEK compliance), and feed barges.
Summary: D365 Asset Management + AquaMonitor — specialised asset tracking for net pens (mesh, antifouling), mooring systems (NYTEK compliance), and feed barges.
Show detailed solution response

Aquaculture-specific asset management:

  • Net pens: tracked as assets in D365 Asset Management — attributes include: dimension (circumference, depth), mesh size, antifouling treatment status and schedule, repair history, and location (which cage/site). Net service lifecycle managed from new → deployed → inspected → repaired → decommissioned.
  • Mooring systems: inspection certificates, NYTEK (Norwegian standard for technical requirements for fish farming installations) compliance status, certification body, validity period, and renewal alerts.
  • Feed barges: registered with specifications, maintenance schedules, inspection certificates, and operational status per site.
  • AquaMonitor integration: farm-site staff record net inspections, mooring checks, and barge status via AquaMonitor mobile — data syncs to D365 Asset Management for central tracking and compliance reporting.
TEC-039
Configuration High

Regulatory Equipment Inspections

Requirement: Track regulatory equipment inspections (electrical, lifting, pressure vessels, NYTEK): inspection dates, certifying body, results, validity period, and upcoming renewal alerts.
Summary: D365 Asset Management — regulatory inspection tracking for electrical, lifting, pressure vessels, and NYTEK with certification dates and renewal alerts.
Show detailed solution response

Regulatory equipment inspections:

  • Inspection register: each regulated asset has inspection records: inspection type (electrical, lifting equipment, pressure vessels, NYTEK, class certificates for vessels), certifying body, inspection date, result (pass/fail/conditional), validity period, and certificate reference.
  • Renewal alerts: D365 alerts and Power Automate notifications triggered when an inspection validity period is approaching expiry — configurable lead time (e.g., 30 days, 60 days before expiry).
  • Compliance dashboard: Power BI report showing all assets with upcoming or overdue inspections — filtered by type, site, and criticality.
  • Audit trail: full history of all inspections per asset maintained in D365 — available for regulatory audits (Arbeidstilsynet, DSB, class societies).
TEC-040
Configuration Desirable

Vessel & Boat Management

Requirement: Track company-owned service boats and vehicles: registration, insurance, class certification, operating hours, fuel consumption, and maintenance schedules.
Summary: D365 Asset Management — vessel and vehicle fleet management with registration, insurance, class certification, operating hours, fuel, and maintenance.
Show detailed solution response

Vessel and vehicle management:

  • Fleet register: company-owned service boats, workboats, wellboats (if owned), and vehicles registered as assets in D365 — registration numbers, insurance details, class certification (for vessels), and ownership documents.
  • Operating hours / mileage: counter-based tracking — operating hours for vessels, mileage for vehicles. Counters trigger usage-based preventive maintenance.
  • Fuel consumption: fuel purchases recorded via D365 procurement or expense claims — fuel cost per vessel/vehicle analysed in Power BI for cost control and environmental reporting (GHG emissions).
  • Maintenance schedules: preventive maintenance plans linked to each vessel/vehicle — oil changes, engine service, hull inspections, class surveys — with auto-generated work orders.
  • Certification tracking: vessel class certificates, safety equipment certificates, and insurance renewal tracked with expiry alerts.

PROJECT & COST MANAGEMENT

5 requirements in this section

TEC-041
Standard Mandatory

Project Register

Requirement: Create and manage projects: project name, code, type (CAPEX, OPEX, R&D), responsible person, start/end dates, budget, and status.
Summary: Standard D365 Project Operations — project register with project types (CAPEX, OPEX, R&D), lifecycle tracking, and WBS structure.
Show detailed solution response

D365 Project Operations:

  • Project register: create and manage projects with: project name, code (number sequence), project type (CAPEX / OPEX / R&D / Internal), responsible person, start/end dates, and status lifecycle (Created → In Process → Finished → Closed).
  • Work Breakdown Structure (WBS): hierarchical task structure within each project — activities, milestones, dependencies, and resource assignments.
  • Project groups: projects categorised by group for reporting — e.g., Infrastructure, IT, Aquaculture Development, Processing Expansion.
  • Budget assignment: budget allocated per project with tracking against committed and actual costs (see TEC-042).
TEC-042
Standard High

Project Budgeting

Requirement: Define project budgets by cost category (materials, labor, services, contingency). Track committed, actual, and remaining budget.
Summary: Standard D365 Project Operations — project budgeting by cost category with committed, actual, and remaining budget tracking.
Show detailed solution response

Project budgeting:

  • Budget definition: budgets defined by cost category — materials, labour (internal hours), external services, travel, equipment, and contingency. Budget lines entered at the project level or WBS task level.
  • Budget approval: budget workflow — project budgets submitted for approval before the project can incur costs. Budget revisions follow the same approval process.
  • Tracking: D365 tracks committed costs (approved POs and requisitions), actual costs (posted transactions), and remaining budget at all times. Over-budget warnings configurable.
  • Forecast: estimate at completion (EAC) calculated from actuals + remaining forecast — supports proactive budget management.
TEC-043
Standard Mandatory

Project Cost Collection

Requirement: Collect costs to projects from: purchase orders, time registration, expense claims, internal labor allocations, and manual journal entries.
Summary: Standard D365 Project Operations — multi-source cost collection from purchase orders, timesheets, expenses, internal allocations, and journals.
Show detailed solution response

Project cost collection:

  • Purchase orders: procurement costs charged to projects when PO lines reference a project ID — committed on PO confirmation, actual on invoice posting.
  • Timesheets: internal labour hours recorded via D365 timesheets — hours × internal cost rate = labour cost posted to the project.
  • Expense claims: employee expenses (travel, accommodation, materials) charged to projects via D365 Expense Management.
  • Internal allocations: overhead/indirect costs allocated to projects via allocation journals (e.g., IT support, facility costs).
  • Manual journals: ad-hoc cost adjustments or corrections posted via project journals.
  • All sources: every cost transaction carries the project ID and cost category — enabling accurate project-level reporting from any cost origin.
TEC-044
Standard High

CAPEX Project to Asset

Requirement: Support capitalization of CAPEX project costs into fixed assets upon project completion (construction-in-progress → fixed asset).
Summary: Standard D365 — CAPEX project capitalisation: construction-in-progress (CIP) accumulates costs and converts to fixed asset on completion.
Show detailed solution response

CAPEX project to asset:

  • Construction-in-Progress (CIP): during a CAPEX project, all costs accumulate on the project in a CIP (work-in-progress) account — visible in the balance sheet as an asset under construction.
  • Capitalisation: upon project completion (or phase completion), D365 creates a fixed asset from the project — transferring the accumulated cost to the Fixed Assets module as the asset's acquisition value.
  • Partial capitalisation: if the project produces multiple assets, costs can be split across multiple fixed assets using allocation rules.
  • Depreciation start: once capitalised, depreciation begins per the fixed asset's depreciation profile — fully integrated with D365 Finance GL posting.
  • Audit trail: full traceability from individual project cost transactions to the capitalised asset value.
TEC-045
Standard High

Project Reporting

Requirement: Report project status: budget vs. actual, cost forecast at completion, milestone progress, and variance analysis.
Summary: Standard D365 Project Operations + Power BI — project reporting with budget vs. actual, variance analysis, milestone progress, and forecast at completion.
Show detailed solution response

Project reporting:

  • Budget vs. actual: D365 project reports compare budgeted, committed, and actual costs by category — highlighting variances at project and WBS-task level.
  • Milestone progress: project milestones tracked with status (not started / in progress / completed) and dates — Gantt-style views available in Project Operations.
  • Forecast at completion: estimate at completion calculated from actual spend + remaining estimate — enables early identification of cost overruns.
  • Power BI dashboards: project portfolio dashboard showing all active projects — budget utilisation, schedule status, cost risk, and resource allocation across NordHav's project portfolio.
  • Drill-down: from summary KPIs → project → WBS task → individual cost transaction — full transparency.

REPORTING & ANALYTICS

11 requirements in this section

TEC-046
Standard Mandatory

Standard Report Library

Requirement: Provide a comprehensive library of pre-built reports covering all functional areas: finance, farming, processing, sales, procurement, HR, quality, and maintenance.
Summary: Standard D365 — comprehensive report library with SSRS operational reports and Electronic Reporting framework covering all functional areas.
Show detailed solution response

Standard report library:

  • SSRS reports: pre-built operational reports across all D365 modules — inventory valuations, aging reports (AP/AR), trial balance, production output, quality analysis, employee lists, asset registers, and more.
  • Electronic Reporting (ER): configurable framework for regulatory and business documents — invoice layouts, packing slips, labels, statutory reports. ER configurations downloadable from Microsoft's global repository.
  • Functional coverage: Finance (GL, AP, AR, FA, budget), Supply Chain (inventory, procurement, production, warehouse), HR (headcount, absence, compensation), Quality (test results, non-conformance), and Asset Management (work order, maintenance history).
  • Power BI reports: additional analytical reports delivered as Power BI dashboards embedded in D365 workspaces — complementing the transactional SSRS reports with visual analytics.
TEC-047
Configuration High

Ad-Hoc Reporting

Requirement: Users can create ad-hoc reports and queries without IT assistance using a user-friendly report builder or query tool.
Summary: D365 + Power BI self-service — ad-hoc reporting using governed semantic models enabling business users to create reports without IT assistance.
Show detailed solution response

Ad-hoc reporting:

  • D365 list pages: all D365 list pages support user-defined filtering, column selection, and export to Excel — immediate ad-hoc querying without any report development.
  • Saved views: users save frequently used filter/column combinations as named views — reusable personal "reports".
  • Power BI self-service: centrally managed semantic models provide governed data access. Business users create their own reports and visuals using Power BI Desktop or Power BI web authoring — certified models ensure consistent definitions (e.g., "revenue" means the same thing in every report).
  • Training: NordHav key users trained on Power BI report creation — enabling self-service analytical capability across the organisation.
TEC-048
Standard Mandatory

Report Drill-Down

Requirement: Support drill-down in reports: from summary to detail, from financial transaction to source document, from KPI to underlying data.
Summary: Standard D365 — full drill-down capability from summary reports to source documents and from KPI tiles to underlying transaction lists.
Show detailed solution response

Report drill-down:

  • Financial drill-down: from trial balance → ledger transactions → source journal → source document (invoice, payment, production order). Each level links to the next with one click.
  • Workspace tiles: KPI tiles in D365 workspaces drill through to the underlying transaction list — e.g., clicking "Overdue Invoices" tile opens the filtered invoice list.
  • Power BI drill-through: Power BI dashboards support drill-through pages — from a summary visual to a detail page showing individual records, and from Power BI back to the D365 form for the specific transaction.
  • Cross-module: drill-down works across modules — AP invoice → linked PO → linked inventory receipt → linked quality order — full transaction chain visible.
TEC-049
Configuration High

Dashboard Builder

Requirement: Provide configurable dashboards that users can build from available widgets/charts/KPIs. Support role-based default dashboards.
Summary: D365 workspaces + Power BI — configurable dashboards with KPI widgets, charts, lists, and role-based defaults that users can personalise.
Show detailed solution response

Dashboard builder:

  • D365 workspaces: each workspace is a configurable dashboard — tiles (count, sum, KPI), lists (filtered transaction lists), charts, and links. System administrators configure default workspace layouts per security role.
  • Power BI dashboards: full dashboard builder capability in Power BI — users (with appropriate license) can create custom dashboards from any available Power BI reports and pin visuals from multiple reports onto a single dashboard.
  • Role-based defaults: each D365 security role gets a default workspace/dashboard — e.g., Production Manager sees production KPIs, AP Clerk sees pending invoices.
  • User personalization: users can rearrange tiles, pin favourites, and configure their personal home workspace.
TEC-050
Configuration High

Scheduled Reports

Requirement: Schedule automated report generation and distribution via email (e.g., daily dispatch report, weekly lice summary, monthly management pack).
Summary: Power BI subscriptions + D365 batch reports — scheduled automated report generation and email distribution for daily, weekly, and monthly reports.
Show detailed solution response

Scheduled reports:

  • Power BI subscriptions: users subscribe to Power BI reports/dashboards — receive automated email with a snapshot (PDF or image) on a schedule (daily, weekly, monthly). Configured per user or distributed to groups.
  • D365 batch reports: SSRS reports scheduled via D365 batch framework — e.g., daily dispatch report generated at 06:00 and emailed to logistics team, weekly inventory valuation emailed to finance.
  • Power Automate: for complex distribution rules — conditional report delivery based on data thresholds (e.g., send weekly lice-count summary only if thresholds are exceeded).
  • Management pack: monthly management reporting pack assembled in Power BI — auto-refreshed and distributed to executive team via subscription.
TEC-051
Standard Mandatory

Export Capabilities

Requirement: Export report data to: Excel, PDF, CSV, and optionally Power BI datasets.
Summary: Standard D365 — export to Excel, PDF, CSV from all reports and list pages; Power BI exports to Excel, PDF, PowerPoint, and CSV.
Show detailed solution response

Export capabilities:

  • D365 list pages: every list page supports "Export to Excel" (Open in Excel, Export to Excel) — filtered data exported maintaining column selections and filters.
  • SSRS reports: standard export options — PDF, Excel, Word, and CSV.
  • Electronic Reporting: ER documents exported in configured formats — XML, JSON, CSV, Excel, or PDF depending on the report definition.
  • Power BI: reports exportable to PDF, PowerPoint (with live data connection), Excel (underlying data), and CSV. Power BI paginated reports (SSRS-style) support pixel-perfect export to PDF for formal reporting.
TEC-052
Configuration High

Data Warehouse / Data Lake

Requirement: Provide a structured data warehouse, data lake, or data export mechanism for enterprise analytics beyond the ERP's native reporting. Document the data model/schema.
Summary: Microsoft Fabric — unified data platform providing lakehouse, data warehouse, and data factory for enterprise analytics beyond D365 native reporting.
Show detailed solution response

Data platform — Microsoft Fabric:

  • Lakehouse: raw data storage for D365, AquaMonitor, IoT sensor data, and external data sources — stored in Delta/Parquet format for optimal analytical performance.
  • Data Factory: ETL pipelines extracting D365 data (via Synapse Link for D365 or data export framework) and transforming into analytical models.
  • SQL analytics endpoint: structured querying over the lakehouse data — enabling T-SQL access for reporting tools and custom analytics.
  • Data model / schema: documented star-schema data models built for each analytical domain (finance, production, quality, farming, HR) — the foundation for all Power BI reporting.
  • Cross-system analytics: Fabric consolidates D365 operational data, AquaMonitor farming data, external market data, and IoT sensor data into a governed analytics estate — enabling analytics that span multiple source systems.
TEC-053
Configuration High

Real-Time Dashboards

Requirement: Support real-time operational dashboards with auto-refresh for: processing plant production status, daily biomass overview, and order fulfillment status.
Summary: Power BI real-time dashboards — auto-refreshing operational dashboards for processing-plant status, biomass overview, and order fulfilment.
Show detailed solution response

Real-time dashboards:

  • DirectQuery / streaming: Power BI dashboards configured with DirectQuery (near real-time, query on demand) or streaming datasets (pushed updates) for operational monitoring.
  • Processing plant: live production dashboard showing current run status, throughput rates, yield, and downtime — refreshed automatically every few minutes.
  • Biomass overview: daily biomass dashboard (from AquaMonitor data) showing fish count, estimated biomass, feed conversion ratio, and lice levels per site/pen.
  • Order fulfilment: live status of customer orders — picked, packed, shipped, delivered — with delivery performance KPIs updated in near real-time from D365 warehouse and transport management.
  • Auto-refresh: dashboards auto-refresh in Power BI Service at configurable intervals (minimum every 15 minutes for import mode; real-time for streaming/DirectQuery).
TEC-054
Configuration High

KPI Scorecards

Requirement: Provide KPI scorecards with targets, actual values, traffic-light status, and trend indicators for management use. Configurable by role and organizational level.
Summary: Power BI — KPI scorecards with targets, actuals, traffic-light status, and trend indicators configurable by role and organisational level.
Show detailed solution response

KPI scorecards:

  • Power BI Metrics: NordHav's KPIs defined in Power BI Goals / Metrics — each KPI has: definition, target, actual value (auto-calculated from data), status (green/amber/red), and trend indicator.
  • Role-based views: executive scorecard (high-level company KPIs), operational scorecards (per function — production, farming, finance, HR), and site-level scorecards.
  • Traffic-light rules: configurable thresholds — e.g., green if on-time delivery ≥ 95 %, amber 90–95 %, red < 90 %.
  • Trend indicators: sparklines or trend arrows showing direction of change over the last periods — immediate visual indication of improvement or deterioration.
  • Drill-through: from any KPI, drill through to the underlying Power BI report showing the details behind the number.
TEC-055
Standard Mandatory

Financial Reporting Package

Requirement: Pre-built or easily configurable financial reporting pack: Balance Sheet, P&L, Cash Flow Statement, trial balance, dimension analysis, budget vs actual, and management commentary capability.
Summary: Standard D365 Financial Reporting — pre-built and customisable Balance Sheet, P&L, Cash Flow, trial balance, and dimension analysis reports.
Show detailed solution response

Financial reporting package:

  • Financial Reporting (Management Reporter): D365's built-in financial report designer for: Balance Sheet, Profit & Loss, Cash Flow Statement, trial balance, and customisable dimension-analysis reports.
  • Row/column definitions: flexible design — NordHav defines row structures (account groupings per Norwegian regulations and internal management needs), column definitions (actuals, budget, prior year, variance), and report trees (roll-up by legal entity, department, site).
  • Budget vs. actual: comparison reports showing budget, actual, and variance by cost centre, department, project, or any financial dimension.
  • Drill-down: from Financial Reporting cells, drill directly to underlying GL transactions in D365 — full audit path from report to source.
  • Distribution: reports generated on demand or scheduled; exportable to Excel and PDF.
TEC-056
Standard Mandatory

Regulatory Report Templates

Requirement: Pre-configured templates or easy adaptation for Norwegian regulatory reports: SAF-T, MVA return, A-melding data, and annual financial statements per Norwegian format.
Summary: Standard D365 — Norwegian regulatory report templates: SAF-T, MVA return, A-melding data, Intrastat, and annual financial statement support.
Show detailed solution response

Regulatory report templates:

  • SAF-T: D365 includes the Norwegian SAF-T export (Electronic Reporting format) per Skatteetaten's specification — chart of accounts, GL transactions, customer/vendor data, tax data, and inventory. Validated against the official XSD schema before submission.
  • MVA return: VAT return data prepared from D365 tax transactions — formatted per Norwegian tax authority requirements for submission via Altinn.
  • A-melding: employment and income data prepared from ISV payroll with D365 HR data support — submitted monthly via Altinn.
  • Intrastat: D365 generates Intrastat declaration for NordHav's intra-EU trade — commodity codes (CN/HS) configured per fish product (0302, 0303, 0304, 0305 series). Filed via Altinn/SSB.
  • Annual financial statements: D365 Financial Reporting supports Norwegian annual-accounts format (Regnskapsloven) — customisable report definitions aligned with Norwegian GAAP.

SECURITY, ACCESS & DATA PRIVACY

16 requirements in this section

TEC-057
Standard Mandatory

Single Sign-On (SSO)

Requirement: Support SSO via Microsoft Entra ID (Azure Active Directory) using SAML 2.0 or OpenID Connect.
Summary: Standard D365 — SSO via Microsoft Entra ID (Azure AD) using OpenID Connect, fully integrated with Microsoft 365 identity.
Show detailed solution response

Single Sign-On:

  • Microsoft Entra ID: D365 F&O uses Microsoft Entra ID (Azure AD) as its identity provider — SSO is native, not an add-on.
  • Protocol: OpenID Connect (OIDC) over OAuth 2.0 — industry standard, fully supported. SAML 2.0 also supported for federated scenarios.
  • Single identity: NordHav employees use one identity across all Microsoft services — D365, Microsoft 365, Power Platform, Azure, Teams — with single sign-on.
  • Federated identity: if NordHav has on-premises Active Directory, Azure AD Connect synchronises identities — users sign in with the same credentials everywhere.
TEC-058
Standard Mandatory

Multi-Factor Authentication

Requirement: Support MFA (Multi-Factor Authentication) for all users, integrated with Microsoft Entra ID MFA or comparable mechanism.
Summary: Standard Microsoft Entra ID — MFA for all users with Authenticator app, SMS, phone call, and FIDO2 security key options.
Show detailed solution response

Multi-Factor Authentication:

  • Microsoft Entra MFA: built into the identity platform — MFA mandatory for all NordHav users (configurable per security policy).
  • Methods: Microsoft Authenticator app (push notification or TOTP code), SMS verification, phone call, and FIDO2 hardware security keys. Authenticator app is the recommended default.
  • Conditional Access: MFA requirements can be contextual — always required for admin roles, required when accessing from untrusted networks, or risk-based (triggered by unusual sign-in patterns detected by Azure AD Identity Protection).
  • Seamless experience: with trusted devices and locations, MFA interruptions are minimised — users on compliant corporate devices in the office may not be prompted repeatedly.
TEC-059
Standard Mandatory

Role-Based Access Control

Requirement: Comprehensive RBAC: define roles with specific permissions to modules, screens, data records, and actions (create, read, update, delete). Support role hierarchy and role composition.
Summary: Standard D365 — comprehensive role-based access control with security roles, duties, privileges, and permission hierarchy.
Show detailed solution response

D365 RBAC (Role-Based Access Control):

  • Security roles: pre-defined and custom roles per job function — e.g., AP Clerk, Production Manager, Quality Inspector, Site Manager. NordHav's role matrix defines minimum required roles per position.
  • Duties & privileges: roles composed of duties (business-process groupings) and privileges (individual CRUD access rights) — granular control over create, read, update, delete per entity/form/action.
  • Role hierarchy: roles can inherit from base roles — modifications at the duty/privilege level cascade appropriately.
  • Organisational scope: roles scoped to: legal entity, operating unit, site, or global — ensuring users only access data for their authorised organisational context.
  • Role assignment: roles assigned per user; users can hold multiple roles. Assignment auditable with full change history.
TEC-060
Standard High

Data-Level Security

Requirement: Support row-level or data-level security: users only see data for their authorized locations, departments, or regions (e.g., site manager sees only their region's farming data).
Summary: Standard D365 — extensible data security policies for row-level/data-level access control by legal entity, site, department, or custom dimension.
Show detailed solution response

Data-level security:

  • Extensible Data Security (XDS): D365's framework for row-level security — policies restrict data access based on the user's organisational context. Example: a site manager at NordHav's Troms region sees only Troms farming data.
  • Legal entity scoping: security roles are scoped per legal entity — a user in NordHav Processing AS only accesses that entity's transactions unless explicitly granted cross-entity access.
  • Operating unit/site scoping: for multi-site operations, data access restricted to the user's assigned sites — warehouse workers at Bergen see only Bergen warehouse inventory.
  • Power BI RLS: row-level security in Power BI mirrors D365 security scope — users only see analytics for their authorised data, preventing data leakage in reports.
TEC-061
Standard High

Segregation of Duties

Requirement: Support segregation of duties rules: prevent conflict-of-interest combinations (e.g., same user cannot create vendor and approve payment to that vendor). Alert on violations.
Summary: Standard D365 — segregation of duties (SoD) framework with conflict detection, rule management, and violation alerting.
Show detailed solution response

Segregation of duties:

  • SoD rules: D365 includes a segregation-of-duties rule engine — administrators define conflicting duty pairs (e.g., "Create Vendor" and "Approve Vendor Payment" cannot be assigned to the same user).
  • Conflict detection: when assigning roles, D365 checks for SoD violations and warns the administrator. Violations can be blocked or allowed with documented exception approval.
  • Audit reporting: SoD violation report shows all current conflicts — used by internal audit for compliance review.
  • Ongoing monitoring: periodic SoD review process — quarterly review of role assignments to ensure no drift has introduced new conflicts.
TEC-062
Standard Mandatory

Audit Log

Requirement: Comprehensive audit logging of: all user logins, data changes (who, when, what changed, old/new values), report access, and administrative actions. Logs immutable and retained per configurable policy (minimum 7 years for financial data).
Summary: Standard D365 — comprehensive audit logging: user sign-ins, data changes (who, when, old/new values), report access, and admin actions with 7+ year retention.
Show detailed solution response

Audit logging:

  • Database logging: D365 database logging captures field-level changes on configured tables — who changed what, when, old value, and new value. Configured for sensitive tables: vendor master, bank accounts, security roles, GL accounts, and other critical data.
  • User activity: sign-in events logged in Microsoft Entra ID sign-in logs — accessible via Azure AD portal and exportable to SIEM. Form access and data exports tracked.
  • Admin actions: administrative changes (security role assignment, configuration changes, batch job modifications) logged with full audit trail.
  • Retention: D365 audit logs retained per configurable policy. Microsoft Entra ID logs retained up to 30 days natively; for 7+ year retention, logs streamed to Azure Log Analytics / Microsoft Sentinel for long-term storage.
  • Immutability: audit logs are append-only — entries cannot be modified or deleted by D365 users, ensuring integrity for regulatory compliance.
TEC-063
Standard Mandatory

GDPR Data Management

Requirement: Support GDPR requirements: data classification, processing purpose registration, consent management, data retention policies with automated deletion/anonymization, right-to-access reporting, and right-to-erasure execution.
Summary: Standard D365 — GDPR management with Person Search (DSAR), data retention policies, consent management, and right-to-erasure support.
Show detailed solution response

GDPR compliance:

  • Person Search: D365 Person Search report locates all personal data across the system for Data Subject Access Request (DSAR) response — covers all modules (HR, AP, AR, contacts).
  • Data classification: D365 metadata identifies personal data fields (name, address, national ID, bank account) with sensitivity classifications.
  • Retention policies: configurable data retention — automatic archival/anonymisation of personal data beyond the legally required period.
  • Right to erasure: supported via data anonymisation processes where legal retention requirements allow.
  • Consent management: marketing consent and processing-purpose registration managed per customer/contact record.
  • Activity logging: all personal data access logged for GDPR accountability.
TEC-064
Standard Mandatory

Data Encryption

Requirement: Data encryption at rest (AES-256 or equivalent) and in transit (TLS 1.2+). Customer-managed encryption keys optional.
Summary: Standard D365 — data encryption at rest (AES-256 via Azure SQL TDE) and in transit (TLS 1.2+) with Microsoft-managed keys as default.
Show detailed solution response

Data encryption:

  • At rest: Azure SQL Transparent Data Encryption (TDE) with AES-256 encryption — all D365 database files, backups, and log files encrypted. Storage (SharePoint, blob) also encrypted at rest.
  • In transit: TLS 1.2+ enforced for all connections — browser to D365, D365 to Azure SQL, D365 to integration endpoints. Older TLS versions are disabled.
  • Key management: Microsoft-managed encryption keys are the default. Customer-managed keys (CMK) available via Azure Key Vault for organisations with specific key-management requirements.
  • End-to-end: data is encrypted at every stage — in the browser (HTTPS), in transit between Azure services, at rest in storage, and in backups. NordHav's data is never stored unencrypted.
TEC-065
Standard High

Penetration Testing

Requirement: Vendor conducts regular penetration testing (minimum annually) by independent third party and shares summary results with customers.
Summary: Standard Microsoft — regular independent penetration testing of Azure and D365 with results available via the Service Trust Portal.
Show detailed solution response

Penetration testing:

  • Microsoft testing: Microsoft conducts regular (at least annual) penetration testing of Azure infrastructure and D365 applications using independent third-party security firms.
  • Scope: testing covers: application-level vulnerabilities, infrastructure security, authentication mechanisms, data isolation between tenants, and API security.
  • Results: summary penetration-test results and remediation evidence are available to customers via the Microsoft Service Trust Portal — NordHav can review these as part of their vendor due-diligence process.
  • Bug bounty: Microsoft operates a public bug-bounty programme — external security researchers are incentivised to discover and responsibly disclose vulnerabilities.
TEC-066
Standard Mandatory

SOC 2 / ISO 27001

Requirement: Vendor holds SOC 2 Type II and/or ISO 27001 certification for data center and application operations. Provide evidence.
Summary: Standard Microsoft — SOC 1/2 Type II, ISO 27001, ISO 27018, and additional compliance certifications published on the Service Trust Portal.
Show detailed solution response

Compliance certifications:

  • SOC 1 Type II: audit of internal controls relevant to financial reporting — relevant for NordHav's auditors assessing IT controls over financial data.
  • SOC 2 Type II: audit of security, availability, processing integrity, confidentiality, and privacy controls — independently verified annually.
  • ISO 27001: information security management system (ISMS) certification for Azure data centres and D365 operations.
  • ISO 27018: protection of personal data in public clouds — specifically relevant for GDPR compliance.
  • Additional: ISO 22301 (business continuity), CSA STAR, and regional certifications. Full list available on the Microsoft Service Trust Portal with downloadable audit reports.
TEC-067
Configuration Desirable

IP Whitelisting

Requirement: Optionally restrict access by IP address range or network (NordHav VPN).
Summary: Microsoft Entra Conditional Access — IP-based and network-based access restrictions using named locations and compliance policies.
Show detailed solution response

IP / network restrictions:

  • Conditional Access named locations: NordHav's corporate IP ranges and VPN exit points defined as "trusted locations" in Microsoft Entra ID. Access policies can restrict sensitive operations (admin access, financial data export) to trusted locations only.
  • Block by location: access from unknown or specified geographic regions can be blocked or require additional verification.
  • Compliant device requirement: Conditional Access can require that devices are Intune-compliant (managed, encrypted, up-to-date) before granting access — effectively combining IP and device posture checks.
  • Optional full IP whitelist: for maximum restriction, D365 access can be limited to specific IP ranges — though this reduces flexibility for remote workers and mobile users.
TEC-068
Configuration High

Session Management

Requirement: Configurable session timeout, concurrent session limits, and forced logout capability.
Summary: D365 + Microsoft Entra — configurable session timeout, concurrent session management, and administrator forced sign-out capability.
Show detailed solution response

Session management:

  • Session timeout: D365 web client session timeout configurable via Microsoft Entra ID token lifetime policies — default idle timeout typically 60 minutes; adjustable per NordHav's security policy.
  • Concurrent sessions: Microsoft Entra ID supports policies to limit or monitor concurrent sessions per user. D365 does not natively restrict concurrent sessions, but Conditional Access policies can enforce device compliance limits.
  • Forced sign-out: administrators can revoke user sessions from Microsoft Entra ID — immediately invalidating all active sessions for a compromised or terminated user (within token refresh window). Emergency access: revoking refresh tokens forces re-authentication.
  • Activity timeout warning: D365 can be configured to warn users before session expiry — allowing them to extend the session or save work.
TEC-069
Standard Mandatory

Data Export & Portability

Requirement: Ability to export all NordHav data from the system in a standard, machine-readable format (CSV, JSON, XML) for data portability if NordHav changes vendors.
Summary: Standard D365 — full data export via DMF in standard formats (CSV, XML, Excel) for data portability and vendor transition scenarios.
Show detailed solution response

Data export and portability:

  • DMF export: D365 Data Management Framework exports all major entities in CSV, XML, or Excel format. NordHav can export complete master data, transactional data, and configuration data at any time.
  • Data entities: 3,000+ standard data entities cover all major business objects — ensuring comprehensive export coverage: GL, AP, AR, inventory, production, HR, quality, assets, projects, and more.
  • Data packages: Export multiple entities as a data package (.zip) — complete dataset for migration or archival.
  • Database export: D365 administrators can export the entire database as a .bacpac file via LCS — machine-readable, standard SQL format for maximum portability.
  • No vendor lock-in: data is portable — NordHav retains full ownership and export rights to all their data at all times per Microsoft's cloud terms.
TEC-070
Standard Desirable

Vendor Escrow

Requirement: Source code escrow available for critical proprietary components, or open-source licensing model, to mitigate vendor lock-in risk.
Summary: Standard Microsoft — D365 F&O is a commercially available SaaS product; NordHav's data is fully exportable; no proprietary lock-in on core ERP data.
Show detailed solution response

Vendor lock-in mitigation:

  • Commercial product: D365 F&O is Microsoft's commercially available ERP — it is not a bespoke system. NordHav's configuration and data are portable.
  • Data export: as described in TEC-069, all data is exportable in standard formats at any time. No contractual restriction on data extraction.
  • Source code escrow: D365 F&O is a SaaS product maintained by Microsoft — traditional source-code escrow is not applicable. However, Microsoft's financial stability and product continuity commitments (D365 is a strategic Microsoft platform) significantly mitigate vendor-risk.
  • Customisation code: all NordHav-specific X++ extensions and Power Platform customisations are developed and owned by NordHav (or their implementation partner) — source code stored in NordHav's Azure DevOps repository.
  • Microsoft commitment: Microsoft provides contractual commitments for data return upon subscription termination per the Microsoft Product Terms.
TEC-071
Standard Mandatory

Incident Response

Requirement: Vendor has documented security incident response plan with: notification SLA (max 24 hours for data breaches), escalation procedures, and post-incident reporting.
Summary: Standard Microsoft — documented Security Incident Response Plan (SSIRP) with max 72-hour breach notification per GDPR and contractual SLA.
Show detailed solution response

Security incident response:

  • Microsoft SSIRP: Microsoft's Security Service Incident Response Plan covers: detection, containment, eradication, recovery, and post-incident analysis for all Azure and D365 services.
  • Notification SLA: Microsoft commits to notifying affected customers within 72 hours of confirming a data breach — per GDPR Article 33 requirements and contractual commitments. In practice, notification is often within 24 hours.
  • Escalation: NordHav's designated security contacts receive breach notifications via email and Azure Service Health. Microsoft provides: description of the incident, data affected, mitigation steps taken, and recommended customer actions.
  • Post-incident: Microsoft publishes post-incident reports (PIR) detailing root cause, timeline, and preventive measures — available via the Service Trust Portal or directly to affected customers.
TEC-072
Standard Mandatory

Norwegian Privacy Compliance

Requirement: Comply with Norwegian implementation of GDPR (Personopplysningsloven) and guidance from Datatilsynet (Norwegian Data Protection Authority).
Summary: Standard D365 + Microsoft Entra — full compliance with Norwegian Personopplysningsloven and Datatilsynet guidance for personal data processing.
Show detailed solution response

Norwegian privacy compliance:

  • Personopplysningsloven: Norway's implementation of GDPR — D365's GDPR features (TEC-063) directly satisfy these requirements: lawful processing basis, data-subject rights, data protection impact assessment support, and breach notification.
  • Datatilsynet guidance: NordHav's D365 configuration follows Datatilsynet's published guidance for: cloud-service usage by Norwegian organisations, transfers outside EEA (none — data stays in EU/EEA per TEC-002), and employee monitoring (limited to legitimate purposes with proper basis).
  • Data Processing Agreement: Microsoft's Data Protection Addendum (DPA) satisfies the requirements of Personopplysningsloven for a data processor agreement — covers: processing scope, security measures, sub-processor management, and data return/deletion.
  • Employee data: D365 HR module (Norwegian ISV payroll, absence, recruitment data) configured with access controls ensuring only HR-authorised personnel access employee personal data.

IMPLEMENTATION & SUPPORT

8 requirements in this section

TEC-073
Standard Mandatory

Implementation Methodology

Requirement: Describe the standard implementation methodology: phases, deliverables, governance model, and role responsibilities (vendor and customer).
Summary: Standard Microsoft — Success by Design implementation methodology with FastTrack governance, phased delivery, and milestone reviews.
Show detailed solution response

Implementation methodology:

  • Success by Design: Microsoft's prescribed implementation framework with FastTrack solution-architect oversight for enterprise D365 projects.
  • Phases: Initiate → Implement → Prepare → Operate. Each phase has defined deliverables, gates, and governance checkpoints.
  • Key reviews: Solution Blueprint Review (architecture validation), Mock Go-Live (dress rehearsal), Go-Live Readiness Review (final gate before production cutover).
  • Governance: joint steering committee (NordHav + implementation partner), sprint-based agile delivery within each phase, and risk/issue management discipline.
  • Role responsibilities: Microsoft FastTrack provides architectural oversight; implementation partner delivers functional and technical configuration; NordHav provides business knowledge, testing, and change management.
TEC-074
Configuration Mandatory

Data Migration Strategy

Requirement: Describe proposed data migration approach: scope of historical data, data cleansing, validation, parallel run, and cutover strategy.
Summary: D365 DMF — phased data migration with master data first, opening balances second, open transactions third; validation at every stage.
Show detailed solution response

Data migration strategy:

  • Tool: D365 DMF (Data Management Framework) with NordHav's predefined entity templates (010–400 series).
  • Phased approach: Phase 1: Master data (chart of accounts, customers, vendors, items, employees, assets). Phase 2: Opening balances (GL, AP, AR, inventory, fixed assets). Phase 3: Open transactions (open POs, SOs, production orders).
  • Data cleansing: legacy data reviewed and cleansed before migration — duplicate removal, format standardisation, and completeness validation performed in staging area.
  • Validation: each entity validated: field mapping verified, data-quality checks executed, test load in sandbox, reconciliation with source system, and sign-off before production migration.
  • Cutover: final production migration executed during the go-live cutover window — parallel run with legacy system for defined period to validate completeness.
TEC-075
Configuration Mandatory

Training Approach

Requirement: Describe training strategy: train-the-trainer, end-user training, training materials (language), e-learning availability, and ongoing training for new features/updates.
Summary: D365 + Microsoft Learn — role-based training with train-the-trainer, classroom workshops, e-learning, Task Recorder guides, and Norwegian-language materials.
Show detailed solution response

Training approach:

  • Train-the-trainer: NordHav key users (super users per functional area) receive deep training from the implementation partner — they then cascade knowledge to end users in their departments.
  • End-user training: classroom workshops (hands-on in UAT environment), role-based agenda — each user group trained on their specific processes and D365 forms.
  • E-learning: Microsoft Learn provides free, self-paced D365 learning paths accessible to all NordHav users — supplemented by NordHav-specific custom training materials.
  • Task Recorder: D365's built-in Task Recorder creates step-by-step task guides from actual system usage — these serve as process documentation and in-app contextual help.
  • Language: training materials produced in Norwegian Bokmål (primary) and English (secondary) — matching the D365 UI language configuration.
  • Ongoing: refresher training and new-feature training provided with each major D365 service update.
TEC-076
Configuration High

Change Management

Requirement: Describe recommended change management approach to support organizational adoption: communication plan, stakeholder engagement, resistance management, and adoption metrics.
Summary: Structured change management — stakeholder engagement, communication plan, resistance management, adoption metrics, and champion network.
Show detailed solution response

Change management approach:

  • Communication plan: regular communications to all NordHav stakeholders — project updates, milestone achievements, training schedules, and go-live countdown. Channels: Teams, email, intranet, and town-hall meetings.
  • Stakeholder engagement: executive sponsor visibility, department-level change champions, and regular feedback loops — ensuring business ownership of the new system.
  • Resistance management: proactive identification of resistance risks per department/user group — targeted interventions (additional training, 1-on-1 coaching, process redesign workshops) to address concerns.
  • Champion network: change champions in each department/site act as local support and advocates — first point of contact for colleagues during the transition period.
  • Adoption metrics: post-go-live tracking of: system usage (login frequency, feature adoption), support-ticket volume, and user satisfaction surveys — reported to steering committee.
TEC-077
Configuration Mandatory

Go-Live Support

Requirement: Describe go-live support: on-site support during cutover, hyper-care period (duration and staffing), escalation procedures, and transition to steady-state support.
Summary: Go-live support — on-site presence during cutover, 4–6 week hypercare with dedicated team, escalation procedures, and transition to steady-state.
Show detailed solution response

Go-live support:

  • Cutover support: implementation partner and NordHav key users co-located (on-site or virtual war room) during the cutover weekend — executing the cutover plan step-by-step with go/no-go checkpoints.
  • Hypercare period: 4–6 weeks post-go-live with enhanced support — dedicated functional consultants available for immediate issue resolution, configuration adjustments, and user coaching.
  • Escalation: 3-tier escalation — L1 (NordHav super user), L2 (implementation partner consultant on-call), L3 (Microsoft support request for platform issues). Critical issues escalated within 1 hour.
  • Transition: at end of hypercare, formal handover to steady-state support model (TEC-078) — outstanding issues documented, knowledge transferred, and support responsibilities transitioned.
TEC-078
Configuration Mandatory

Support Model (Post-Go-Live)

Requirement: Describe ongoing support model: support tiers (L1, L2, L3), response time SLAs by severity, support hours (business hours vs. 24/7), support language (Norwegian and English required), and support channels (phone, email, portal).
Summary: Tiered support model — L1 (NordHav super users), L2 (partner), L3 (Microsoft); Norwegian and English support; defined response SLAs by severity.
Show detailed solution response

Post-go-live support model:

  • L1 (internal): NordHav's trained super users handle common questions, how-to guidance, and basic troubleshooting. Available during business hours.
  • L2 (implementation partner): functional and technical support for configuration issues, process questions, and minor enhancements. Response SLA: Critical (< 2 hours), High (< 4 hours), Medium (< 1 business day), Low (< 3 business days).
  • L3 (Microsoft): platform and product issues submitted via LCS support request — Microsoft engineering support for bugs, performance issues, and platform behaviour.
  • Support hours: L1/L2 during Norwegian business hours (08:00–16:00 CET) as standard; 24/7 available for critical production-down scenarios (at premium rate).
  • Language: Norwegian and English support available from both the implementation partner and Microsoft (Norwegian-speaking support resources confirmed).
  • Channels: support portal (ticket logging), email, phone for critical issues, and Teams channel for ongoing communication.
TEC-079
Configuration Mandatory

Norwegian Support Team

Requirement: Vendor or implementation partner must have Norwegian-speaking support and consulting resources familiar with Norwegian regulations, language, and business practices.
Summary: Implementation partner — Norwegian-speaking consulting and support team familiar with Norwegian regulations, language, and business practices.
Show detailed solution response

Norwegian support capability:

  • Implementation partner: NordHav's implementation partner has a Norwegian consulting team — fluent in Norwegian Bokmål, deeply familiar with Norwegian business practices, tax regulations, labour laws, and industry norms.
  • Regulatory expertise: consultants experienced with Norwegian-specific: accounting standards (NRS/NGAAP), VAT (MVA), payroll (A-melding, OTP, holiday pay), employment law (Arbeidsmiljøloven), and aquaculture regulations.
  • Microsoft Norway: Microsoft has a Norwegian subsidiary with local support, sales, and FastTrack engagement resources — Norwegian-language support available for platform issues.
  • ISV partners: Norwegian ISV solutions (e.g., payroll) provide Norwegian-language support and documentation.
TEC-080
Configuration Desirable

Customer Success Program

Requirement: Describe the customer success or account management program: dedicated account manager, regular business reviews, early access to new features, and user community/user group.
Summary: Microsoft FastTrack + partner — customer success programme with dedicated account management, regular reviews, early feature access, and user community.
Show detailed solution response

Customer success programme:

  • Microsoft FastTrack: ongoing engagement for optimisation — FastTrack architects available for architectural reviews, feature adoption guidance, and best-practice recommendations beyond go-live.
  • Partner account management: dedicated account manager from the implementation partner — regular quarterly business reviews covering: system health, enhancement pipeline, support metrics, and upcoming D365 features.
  • Feature adoption: proactive communication about new D365 features relevant to NordHav — with assessment and implementation support for high-value enhancements.
  • User community: access to D365 user groups (Nordic D365 User Group, global Dynamics community) for peer learning, best-practice sharing, and Microsoft engagement.
  • Continuous improvement: annual "health check" review of NordHav's D365 usage — identify under-utilised features, optimisation opportunities, and alignment with evolving business needs.
← Requirements Overview D365 Coverage Matrix →