Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Sarbanes Oxley Section 404 Software - Technology Tools

12/15/05

Permalink 11:13:43 pm, Categories: Sarbanes Oxley, 412 words   English (US)

Sarbanes Oxley Section 404 Software - Technology Tools

Some of our clients approached us for help with complying with Section 404 of the SOX monster. Now, in any 404 implementation, the first and foremost requirement Documenting Processes and Controls. This is the most time consuming task of the whole process. However, I have personally done some research on the tech tools available to facilitate 404 documentation. Our clients demanded that such software which could help in 404 documentation should enable collection, tracking, support multiple users accross locations and be web based. I am discussing some of such softwares available for Section 404 compliance.

Paisley Consulting's Risk Navigator is a excellent product for 404 implementation. It allows user to identify significant accounts & processes. These can be documented with help of a word processor, spreadsheet ir flowchart. Information stored can be retieved by user in multiple views such as location wise, COSO framework or financial statement account wise. This is a very good product and I have worked on it personally. I would give it a rating of 4 out of 5.

Open text corporation has a software called Livelink which helps in documenting process controls. It allows users to document controls on the basis of five areas namely, risk assessment; control activities; information and communication; control team and roles; and monitoring and audit. These are nothing but COSO componenets. I would give it a rating of 3 out of 5.

Oracle Corp.’s Internal Control Manager is another excellent 404 software. The IC Manager works along with Oracle Tutor. Tutor is the central location for process documentation, which is organized by process flow. The advantage of IC Manager is that it covers ERP specific processes. Even customized processes can be defined. Once all data is entered, variables such as GL accounts, process risk etc can be taken from the software on basis of which potential mitigating controls can be identified. I have not used this product, however companies using it are very satisfied. Rating of 4 out of 5.

Microsoft Corporation’s SharePoint Portal Server, a document-sharing intranet portal developed and marketed by the company, can be used to organize internal control documentation and to facilitate quarterly updates. In fact, Microsoft Corp also uses the product internally to organize control documentation under transaction billing cycles. This gives it a rating of 4 out of 5.

My advise is any product that you go for make sure it suits your company's requirements. It's easy to get lost with so many products available. So ask for demos. And finally, Consider your company's practical scenarios before choosing one.

Comments:

Comment from: Kamlesh [Visitor]
I think DOcumenting the controls and storing them in some cold storage is an effective way to adopt the theory to communicate internally and externally. THe Organization who have laid huge investments in ERP Infrastructure and IT investments need to consider the tools that not only let you document but merge with the ERP and Legacy Systems to automate the test of COntrols.
One Such tool is VIRSA CONFIDENT COMPLIANCE SUITE.
Permalink 03/14/06 @ 19:04

Official Websites

Search

Google

Web Big4Guy.com

January 2009
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Misc

Syndicate this blog XML

What is RSS?