SlideShare une entreprise Scribd logo
1  sur  10
Télécharger pour lire hors ligne
Sarbanes-Oxley (SOX) compliance

The Role of IT in the design and implementation of Internal
              Control over Financial Reporting



                                   Mahesh Patwardhan
                      maheshpatwardhan@rediffmail.com
SOX
• The Sarbanes–Oxley Act of 2002 commonly called SOX, is a United States
  federal law enacted on July 30, 2002. It is named after sponsors U.S.
  Senator Paul Sarbanes and U.S. Representative Michael G. Oxley

• The bill was enacted as a reaction to a number of major corporate and
  accounting scandals including those affecting Enron, Tyco International,
  Adelphia, Peregrine Systems and WorldCom.

• These scandals, which cost investors billions of dollars when the share
  prices of affected companies collapsed, shook public confidence in the
  nation's securities markets. The act was passed to safeguard the investors
  and restore confidence in the securities markets.

• The gist of the act is that a company ‘s top management has to certify by
  way of internal and external audits that there is sufficient internal control
  on all systems impacting financial reporting.
Definitions
• COSO
    • Committee of Sponsoring Organizations of the Treadway Commission
        •   Model for evaluating internal controls
        •   Generally accepted framework for internal control
        •   Definitive standard against which organizations measure effectiveness of internal controls


• Internal Control :
    • A process, effected by an entity’s board of directors, management and
      other personnel, designed to provide reasonable assurance of the
      achievement of objectives in the following categories:
        •   Effectiveness and efficiency of operations
        •   Reliability of financial reporting
        •   Compliance with applicable laws and regulations




•   Five Components of Internal Control System:
        •   Control Environment
        •   Risk Assessment
        •   Control Activities
        •   Information and Communication
        •   Monitoring
IT Compliance Roadmap



                                                  Prioritize
                                  Evaluate        and
                                  Control         Remediate
                       Document   Design and      Deficiencies
                       Controls   Operating
                                  Effectiveness
           Assess IT
           Risk

Plan and
Scope IT
Controls
Internal Control Framework
  Control               Risk               Control        Information and
Environment          Assessment           Activities      Communication         Monitoring

• Integrity and     • Company-wide     • Policies and    • Quality of         • Ongoing
  Ethical Values      objectives         Procedures        Information          Monitoring
• Commitment to
  competence        • Process-level    • Security        • Effectiveness of   • Separate
• Board of            objectives         (Applications     Communication        Evaluations
  Directors and                          and Network)
  audit             • Risk
  committee                                                                   • Reporting
                      Identification   • Application
• Managements                                                                   Deficiencies
                      and Analysis       Change
  Philosophy and                         Management
  Operating Style
                    • Managing
• Organizational      Change           • Business
  Structure
                                         Continuity /
• Assignment of                          Backups
  Authority and
  Responsibility
                                       • Outsourcing
• Human
  Resource
  Policies and
  Procedures
Control Activities



                          Security           Application
   Policies and                                                 Business
                      (Applications and       Change
   Procedures                                                  Continuity
                         Network)           Management
•IT-Security Policy   •Application        •Project         •IT-Infrastructure
•IT-Access Control     Authorization       Management       Management
 Policy                Matrix                              •Disaster
•IT-Appropriate       •End User                             Recovery
 Usage Policy          Computing Trace                     •Backup and
•Email-Internet        ability Matrix                       Recovery
 Policy               •IT – Landscape                       Procedures
•End-user              Diagram                             •Job Scheduling
 Computing            •ISO
IT Control Objectives for SOX

Acquire and Maintain    Manage Changes            Manage the
Application Software                              Configuration
                        Define and Manage
Acquire and Maintain    Service Levels            Manage Problems and
Technology                                        Incidents
Infrastructure          Manage Third Party
                        Services                  Manage Data
Enable Operations                                 Manage Operations
                        Ensure Systems Security
Install and accredit
solutions and changes
Types of Controls

   Entity Level            Application             IT General
    Controls                Controls                Controls
• Strategies and       • Completeness          • Program
  Plans                • Accuracy                Development
• Policies and         • Existence/Authoriz    • Programs Changes
  Procedures             ation                 • Access to Programs
• Risk Assessment      • Presentation/Disclo     and Data
  Activities             sure                  • Computer
• Training and                                   Operations
  Education
• Quality Assurance
• Internal Audit
Control Documentation

Entity Policy   IT Policies and
                                  Narratives
 Manuals          Procedures


                                  Procedural
Flowcharts      Decision Tables
                                  Write-ups


                 Completed
                Questionnaires
Control Documentation

         Entity Level                      Activity Level                      Activity Level
• Assessment of entity level       • Description of the processes      • Description of the control
  controls including evidence to     and related sub-processes           activity(ies) designed and
  support the responses and          (may be in narrative form,          performed to satisfy the
  opinions of management             more effective to illustrate as     control objective related to
                                     a flowchart)                        the process or subprocess.
                                                                         This should include the type of
                                   • Description of the risk             controls (preventive or
                                     associated with the process or      detective) and the frequency
                                     subprocess, including an            they are performed.
                                     analysis of its impact and
                                     probability of occurrence         • Description of the approach
                                                                         followed to confirm (test) the
                                   • Statement of the control            existence and operational
                                     objective designed to reduce        effectiveness of the control
                                     the risk of the process or          activities.
                                     subprocess to an acceptable
                                     level and a description of its    • Conclusions reached about
                                     alignment to the COSO               the effectiveness of controls,
                                     framework.                          as a result of testing.

Contenu connexe

Tendances

ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
PECB
 
ITIL and ISO 20000: Fundamentals and necessary compliance Synergies
ITIL and ISO 20000: Fundamentals and necessary compliance SynergiesITIL and ISO 20000: Fundamentals and necessary compliance Synergies
ITIL and ISO 20000: Fundamentals and necessary compliance Synergies
PECB
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties Solutions
Ahmed Abdul Hamed
 
IT Audit methodologies
IT Audit methodologiesIT Audit methodologies
IT Audit methodologies
genetics
 

Tendances (20)

Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)Control and audit of information System (hendri eka saputra)
Control and audit of information System (hendri eka saputra)
 
ITGC audit of ERPs
ITGC audit of ERPsITGC audit of ERPs
ITGC audit of ERPs
 
Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing Basics in IT Audit and Application Control Testing
Basics in IT Audit and Application Control Testing
 
Sox Compliance Presentation
Sox Compliance PresentationSox Compliance Presentation
Sox Compliance Presentation
 
SOX compliance - Understanding Sarbanes-Oxley
SOX compliance - Understanding Sarbanes-OxleySOX compliance - Understanding Sarbanes-Oxley
SOX compliance - Understanding Sarbanes-Oxley
 
Understanding IT Governance and Risk Management
Understanding IT Governance and Risk ManagementUnderstanding IT Governance and Risk Management
Understanding IT Governance and Risk Management
 
Introduction to it auditing
Introduction to it auditingIntroduction to it auditing
Introduction to it auditing
 
ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?ISO/IEC 27001:2022 – What are the changes?
ISO/IEC 27001:2022 – What are the changes?
 
CISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of ITCISA DOMAIN 2 Governance & Management of IT
CISA DOMAIN 2 Governance & Management of IT
 
SOX- IT Perspective
SOX- IT PerspectiveSOX- IT Perspective
SOX- IT Perspective
 
Cybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoDCybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoD
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ITIL and ISO 20000: Fundamentals and necessary compliance Synergies
ITIL and ISO 20000: Fundamentals and necessary compliance SynergiesITIL and ISO 20000: Fundamentals and necessary compliance Synergies
ITIL and ISO 20000: Fundamentals and necessary compliance Synergies
 
ITGCs.pdf
ITGCs.pdfITGCs.pdf
ITGCs.pdf
 
Segregation of Duties Solutions
Segregation of Duties SolutionsSegregation of Duties Solutions
Segregation of Duties Solutions
 
It audit methodologies
It audit methodologiesIt audit methodologies
It audit methodologies
 
5.4 it security audit (mauritius)
5.4  it security audit (mauritius)5.4  it security audit (mauritius)
5.4 it security audit (mauritius)
 
IT Audit methodologies
IT Audit methodologiesIT Audit methodologies
IT Audit methodologies
 
Cisa domain 4
Cisa domain 4Cisa domain 4
Cisa domain 4
 
ISMS Part I
ISMS Part IISMS Part I
ISMS Part I
 

En vedette

Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002
Syed Shah
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
les561
 
Hris data management
Hris data managementHris data management
Hris data management
alexhuq2010
 
Human Resource Information System - HRIS
Human Resource Information System - HRIS Human Resource Information System - HRIS
Human Resource Information System - HRIS
antonyjosephtharayil
 

En vedette (20)

Sarbanes-Oxley act
Sarbanes-Oxley actSarbanes-Oxley act
Sarbanes-Oxley act
 
Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)Sarbanes-Oxley Act (SOX)
Sarbanes-Oxley Act (SOX)
 
Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002Sarbanes-Oxley Act 2002
Sarbanes-Oxley Act 2002
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
 
Sarbanes Oxley Act
Sarbanes Oxley ActSarbanes Oxley Act
Sarbanes Oxley Act
 
Automating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and FinancialsAutomating PeopleSoft Segregation of Duties: HCM and Financials
Automating PeopleSoft Segregation of Duties: HCM and Financials
 
Sox
SoxSox
Sox
 
Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23Effective Segregation of Duties for PeopleSoft 2011-02-23
Effective Segregation of Duties for PeopleSoft 2011-02-23
 
HRIS-The Road Map For A Successful Transition
HRIS-The Road Map For A Successful TransitionHRIS-The Road Map For A Successful Transition
HRIS-The Road Map For A Successful Transition
 
HRIS
HRISHRIS
HRIS
 
Hris data management
Hris data managementHris data management
Hris data management
 
Government and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP SystemsGovernment and SOX Compliance for ERP Systems
Government and SOX Compliance for ERP Systems
 
Human Resource Information System - HRIS
Human Resource Information System - HRIS Human Resource Information System - HRIS
Human Resource Information System - HRIS
 
Hris ppt
Hris pptHris ppt
Hris ppt
 
Human Resource Information System (HRIS) – Implementation and Control
Human Resource Information System (HRIS) – Implementation and ControlHuman Resource Information System (HRIS) – Implementation and Control
Human Resource Information System (HRIS) – Implementation and Control
 
Hris
HrisHris
Hris
 
Data Analysis for Audit Training (2016.06)
Data Analysis for Audit Training (2016.06)Data Analysis for Audit Training (2016.06)
Data Analysis for Audit Training (2016.06)
 
internal audit function ans controller's role in investors relation
 internal audit function ans controller's role in investors relation internal audit function ans controller's role in investors relation
internal audit function ans controller's role in investors relation
 
Internal audit
Internal auditInternal audit
Internal audit
 
Fraud Detection Techniques
Fraud Detection TechniquesFraud Detection Techniques
Fraud Detection Techniques
 

Similaire à IT Control Objectives for SOX

Quality Management Services
Quality Management ServicesQuality Management Services
Quality Management Services
RCM Technologies
 
Better security through IT operations
Better security through IT operationsBetter security through IT operations
Better security through IT operations
slighltyanon
 
E-Mail Compliance Frameworks in the Real World
E-Mail Compliance Frameworks in the Real WorldE-Mail Compliance Frameworks in the Real World
E-Mail Compliance Frameworks in the Real World
Chris Byrne
 
Service catalogue
Service catalogueService catalogue
Service catalogue
Alex Rea
 
The Coming Age of Continuous Auditing
The Coming Age of Continuous AuditingThe Coming Age of Continuous Auditing
The Coming Age of Continuous Auditing
carlabrut
 
Maetrics One Sheet Overview1 4
Maetrics One Sheet Overview1 4Maetrics One Sheet Overview1 4
Maetrics One Sheet Overview1 4
TRynkiewicz
 

Similaire à IT Control Objectives for SOX (20)

Migrating data: How to reduce risk
Migrating data: How to reduce riskMigrating data: How to reduce risk
Migrating data: How to reduce risk
 
Quality Management Services
Quality Management ServicesQuality Management Services
Quality Management Services
 
Better security through IT operations
Better security through IT operationsBetter security through IT operations
Better security through IT operations
 
Risk Management Methodology
Risk Management MethodologyRisk Management Methodology
Risk Management Methodology
 
Pm Toolbox Nlr Final
Pm Toolbox Nlr FinalPm Toolbox Nlr Final
Pm Toolbox Nlr Final
 
E-Mail Compliance Frameworks in the Real World
E-Mail Compliance Frameworks in the Real WorldE-Mail Compliance Frameworks in the Real World
E-Mail Compliance Frameworks in the Real World
 
IaaS
IaaSIaaS
IaaS
 
Steps in it audit
Steps in it auditSteps in it audit
Steps in it audit
 
Computerized System Validation Business Intelligence Solutions
Computerized System Validation Business Intelligence SolutionsComputerized System Validation Business Intelligence Solutions
Computerized System Validation Business Intelligence Solutions
 
Service catalogue
Service catalogueService catalogue
Service catalogue
 
Service catalogue
Service catalogueService catalogue
Service catalogue
 
CA Quality Management System
CA Quality Management SystemCA Quality Management System
CA Quality Management System
 
SuprTEK Continuous Monitoring
SuprTEK Continuous MonitoringSuprTEK Continuous Monitoring
SuprTEK Continuous Monitoring
 
Agiliance Wp Key Steps
Agiliance Wp Key StepsAgiliance Wp Key Steps
Agiliance Wp Key Steps
 
Agiliance Whitepaper - Six Key Steps
Agiliance Whitepaper - Six Key StepsAgiliance Whitepaper - Six Key Steps
Agiliance Whitepaper - Six Key Steps
 
Ch2 2009 cisa
Ch2 2009 cisaCh2 2009 cisa
Ch2 2009 cisa
 
The Coming Age of Continuous Auditing
The Coming Age of Continuous AuditingThe Coming Age of Continuous Auditing
The Coming Age of Continuous Auditing
 
Maetrics One Sheet Overview1 4
Maetrics One Sheet Overview1 4Maetrics One Sheet Overview1 4
Maetrics One Sheet Overview1 4
 
Entitlement and Access Manegement
Entitlement and Access ManegementEntitlement and Access Manegement
Entitlement and Access Manegement
 
SharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle ManagementSharePoint for Pharma - Computer System Life Cycle Management
SharePoint for Pharma - Computer System Life Cycle Management
 

Plus de Mahesh Patwardhan

Social Media in Sports - some Case Studies
Social Media in Sports - some Case StudiesSocial Media in Sports - some Case Studies
Social Media in Sports - some Case Studies
Mahesh Patwardhan
 

Plus de Mahesh Patwardhan (16)

Model Information Office
Model Information OfficeModel Information Office
Model Information Office
 
Digital Landscape
Digital LandscapeDigital Landscape
Digital Landscape
 
Social Media Publishing & Aggregation
Social Media Publishing & AggregationSocial Media Publishing & Aggregation
Social Media Publishing & Aggregation
 
Social Media Metrics
Social Media MetricsSocial Media Metrics
Social Media Metrics
 
Social Media For A Sporting Event
Social Media For A Sporting EventSocial Media For A Sporting Event
Social Media For A Sporting Event
 
A Real Time Web Analytics System
A Real Time Web Analytics SystemA Real Time Web Analytics System
A Real Time Web Analytics System
 
Revenue Reconciliation System
Revenue Reconciliation SystemRevenue Reconciliation System
Revenue Reconciliation System
 
Business Analytics System
Business Analytics SystemBusiness Analytics System
Business Analytics System
 
The Information Office
The Information OfficeThe Information Office
The Information Office
 
Concept for a Facebook App for a Mexican Restaurant
Concept for a Facebook App for a Mexican RestaurantConcept for a Facebook App for a Mexican Restaurant
Concept for a Facebook App for a Mexican Restaurant
 
A concept for a facebook app
A concept for a facebook appA concept for a facebook app
A concept for a facebook app
 
Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0Digital And New Media Strategy using Web 2.0
Digital And New Media Strategy using Web 2.0
 
Digital And New Media Consultancy Services
Digital And New Media Consultancy ServicesDigital And New Media Consultancy Services
Digital And New Media Consultancy Services
 
Lets Build A Story
Lets Build A StoryLets Build A Story
Lets Build A Story
 
Social Media in Sports - some Case Studies
Social Media in Sports - some Case StudiesSocial Media in Sports - some Case Studies
Social Media in Sports - some Case Studies
 
Social Media - some case studies
Social Media - some case studiesSocial Media - some case studies
Social Media - some case studies
 

Dernier

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Dernier (20)

MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 

IT Control Objectives for SOX

  • 1. Sarbanes-Oxley (SOX) compliance The Role of IT in the design and implementation of Internal Control over Financial Reporting Mahesh Patwardhan maheshpatwardhan@rediffmail.com
  • 2. SOX • The Sarbanes–Oxley Act of 2002 commonly called SOX, is a United States federal law enacted on July 30, 2002. It is named after sponsors U.S. Senator Paul Sarbanes and U.S. Representative Michael G. Oxley • The bill was enacted as a reaction to a number of major corporate and accounting scandals including those affecting Enron, Tyco International, Adelphia, Peregrine Systems and WorldCom. • These scandals, which cost investors billions of dollars when the share prices of affected companies collapsed, shook public confidence in the nation's securities markets. The act was passed to safeguard the investors and restore confidence in the securities markets. • The gist of the act is that a company ‘s top management has to certify by way of internal and external audits that there is sufficient internal control on all systems impacting financial reporting.
  • 3. Definitions • COSO • Committee of Sponsoring Organizations of the Treadway Commission • Model for evaluating internal controls • Generally accepted framework for internal control • Definitive standard against which organizations measure effectiveness of internal controls • Internal Control : • A process, effected by an entity’s board of directors, management and other personnel, designed to provide reasonable assurance of the achievement of objectives in the following categories: • Effectiveness and efficiency of operations • Reliability of financial reporting • Compliance with applicable laws and regulations • Five Components of Internal Control System: • Control Environment • Risk Assessment • Control Activities • Information and Communication • Monitoring
  • 4. IT Compliance Roadmap Prioritize Evaluate and Control Remediate Document Design and Deficiencies Controls Operating Effectiveness Assess IT Risk Plan and Scope IT Controls
  • 5. Internal Control Framework Control Risk Control Information and Environment Assessment Activities Communication Monitoring • Integrity and • Company-wide • Policies and • Quality of • Ongoing Ethical Values objectives Procedures Information Monitoring • Commitment to competence • Process-level • Security • Effectiveness of • Separate • Board of objectives (Applications Communication Evaluations Directors and and Network) audit • Risk committee • Reporting Identification • Application • Managements Deficiencies and Analysis Change Philosophy and Management Operating Style • Managing • Organizational Change • Business Structure Continuity / • Assignment of Backups Authority and Responsibility • Outsourcing • Human Resource Policies and Procedures
  • 6. Control Activities Security Application Policies and Business (Applications and Change Procedures Continuity Network) Management •IT-Security Policy •Application •Project •IT-Infrastructure •IT-Access Control Authorization Management Management Policy Matrix •Disaster •IT-Appropriate •End User Recovery Usage Policy Computing Trace •Backup and •Email-Internet ability Matrix Recovery Policy •IT – Landscape Procedures •End-user Diagram •Job Scheduling Computing •ISO
  • 7. IT Control Objectives for SOX Acquire and Maintain Manage Changes Manage the Application Software Configuration Define and Manage Acquire and Maintain Service Levels Manage Problems and Technology Incidents Infrastructure Manage Third Party Services Manage Data Enable Operations Manage Operations Ensure Systems Security Install and accredit solutions and changes
  • 8. Types of Controls Entity Level Application IT General Controls Controls Controls • Strategies and • Completeness • Program Plans • Accuracy Development • Policies and • Existence/Authoriz • Programs Changes Procedures ation • Access to Programs • Risk Assessment • Presentation/Disclo and Data Activities sure • Computer • Training and Operations Education • Quality Assurance • Internal Audit
  • 9. Control Documentation Entity Policy IT Policies and Narratives Manuals Procedures Procedural Flowcharts Decision Tables Write-ups Completed Questionnaires
  • 10. Control Documentation Entity Level Activity Level Activity Level • Assessment of entity level • Description of the processes • Description of the control controls including evidence to and related sub-processes activity(ies) designed and support the responses and (may be in narrative form, performed to satisfy the opinions of management more effective to illustrate as control objective related to a flowchart) the process or subprocess. This should include the type of • Description of the risk controls (preventive or associated with the process or detective) and the frequency subprocess, including an they are performed. analysis of its impact and probability of occurrence • Description of the approach followed to confirm (test) the • Statement of the control existence and operational objective designed to reduce effectiveness of the control the risk of the process or activities. subprocess to an acceptable level and a description of its • Conclusions reached about alignment to the COSO the effectiveness of controls, framework. as a result of testing.