Enterprise Technology - CIOInsight
Home arrow Enterprise Technology arrow Page 2 - Technology: Sarbanes-Oxley
RECENT NEWS



CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

  Enterprise Technology


Technology: Sarbanes-Oxley



By Gary Bolles


  Table of Contents:
  1. Technology: Sarbanes-Oxley
  2. ' Comply With Me'
  3. ' Get Involved'
  4. ' Avoid Garbage '
  5. ' Get a Plan '

In the 12 months since the passage of the Sarbanes-Oxley Act in July 2003, corporations both public and private have been put through a wrenching exercise in self-examination about information security and integrity. And it's not over yet.

Rate This Article:
Add This Article To:

Technology: Sarbanes-Oxley - ' Comply With Me'


( Page 2 of 5 )

Step 1: Get Educated

The effects of the Sarbanes-Oxley Act of 2002 may ripple throughout your IT organization. Not a public company? You may still have to worry—and even if you don't, you need to learn more about compliance.

Decision-making processes in your company are no doubt a mishmash of manual and electronic steps. Determining who's responsible for which information and what decisions, and making sure the system contains checks and balances to guarantee that those decisions are justified, can be a hair-pulling exercise for the most straightforward tasks in business-process analysis.

But getting the process down cold is no longer simply an intellectual exercise. Driven by laws such as the Sarbanes-Oxley Act, your CEO and CFO are now personally responsible for ensuring the accuracy of processes like financial reporting. That means they'll be breathing down IT's neck to guarantee the company's information systems are helping accuracy, not hurting it.

IT is responding. According to a survey conducted in April by AMR Research Inc., about 85 percent of all public companies intend to change their IT systems as part of their efforts to comply with the law. And those companies are planning to spend $2.5 billion in 2003 alone on projects related to compliance.

Why the worry? Born out of post-Enron angst, the Sarbanes-Oxley Act, variously called SOA, SOX or Sarbox, defines a set of standards for tracking and reporting requirements intended to hold top executives' feet to the fire on corporate financial statements. CEOs and CFOs of publicly traded companies must attest to the accuracy of those statements, and anything that looks fishy may elicit sweat-inducing questions from the Securities and Exchange Commission—and, potentially, penalties ranging from personal fines to jail time.

What makes top executives and board members wake up in a cold sweat is worrying about the shakiness of the foundation of financial controls on which their companies sit. In a nutshell, Sarbanes-Oxley says public businesses have to vet every internal process that feeds into a financial statement. The challenge is "walking the dog" through all the information sources that roll up into those reports, especially where any kind of information technology is involved.

In small public companies with uncomplicated products or services, those processes may be relatively straightforward. In large multinational companies, however, financial reporting may have its roots deep in the supply chain, or be buried in a customer relationship management system, or managed differently, depending on your company's global locations and the kind of software each location uses. Those intricacies can make the financial reporting excavation process a complicated exercise at best—and at worst, a minefield fraught with potential financial explosions.

Public companies are the act's main targets, but that doesn't mean all private companies are immune. If your company could be acquired by another that's already public, the CFO of the new parent is responsible as soon as the first dollar flows through the combined entity. And that means substantial—and potentially deal-breaking—risk if the acquiree isn't already following deep financial discipline.

So how clear are the ramifications of Sarbanes-Oxley for most companies? "It's probably not very clear to the CIO yet," says Melinda Litherland, an audit partner at Deloitte & Touche. "It's probably very clear to the CFO."

Questions for Your CFO:

  • What are the major issues for our company on compliance with Sarbanes-Oxley?
  • Do we know if we have any internal processes that can potentially create risk for us?
  • How many of those processes are supported by software?


     
     
    >>> More Enterprise Technology Articles          >>> More By Gary Bolles
     


  • FEATURED SPONSORED VIDEOS

    FEATURED SPONSORED ARTICLES

    Erasable E-Paper Saves Trees, Cuts Costs

    Why Smart Companies Should Adopt the Lessons of Gaming

    Interest in Mobile WiFi Hotspots Fuels New Solutions

    A Closer Look at Public Cloud Security

    View More Articles

      Brought to You By
    Click Here




    EDITORS' PICKS

    LATEST STORIES


    Advertisement
    FEEDBACK
    Ziff Davis Enterprise RSS Feeds

    Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks