Big4GuyWelcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.
|
Some of our clients approached us for help with complying with Section 404 of the SOX monster. Now, in any 404 implementation, the first and foremost requirement Documenting Processes and Controls. This is the most time consuming task of the whole process. However, I have personally done some research on the tech tools available to facilitate 404 documentation. Our clients demanded that such software which could help in 404 documentation should enable collection, tracking, support multiple users accross locations and be web based. I am discussing some of such softwares available for Section 404 compliance.
Paisley Consulting's Risk Navigator is a excellent product for 404 implementation. It allows user to identify significant accounts & processes. These can be documented with help of a word processor, spreadsheet ir flowchart. Information stored can be retieved by user in multiple views such as location wise, COSO framework or financial statement account wise. This is a very good product and I have worked on it personally. I would give it a rating of 4 out of 5.
Open text corporation has a software called Livelink which helps in documenting process controls. It allows users to document controls on the basis of five areas namely, risk assessment; control activities; information and communication; control team and roles; and monitoring and audit. These are nothing but COSO componenets. I would give it a rating of 3 out of 5.
Oracle Corp.’s Internal Control Manager is another excellent 404 software. The IC Manager works along with Oracle Tutor. Tutor is the central location for process documentation, which is organized by process flow. The advantage of IC Manager is that it covers ERP specific processes. Even customized processes can be defined. Once all data is entered, variables such as GL accounts, process risk etc can be taken from the software on basis of which potential mitigating controls can be identified. I have not used this product, however companies using it are very satisfied. Rating of 4 out of 5.
Microsoft Corporation’s SharePoint Portal Server, a document-sharing intranet portal developed and marketed by the company, can be used to organize internal control documentation and to facilitate quarterly updates. In fact, Microsoft Corp also uses the product internally to organize control documentation under transaction billing cycles. This gives it a rating of 4 out of 5.
My advise is any product that you go for make sure it suits your company's requirements. It's easy to get lost with so many products available. So ask for demos. And finally, Consider your company's practical scenarios before choosing one.
| Mon | Tue | Wed | Thu | Fri | Sat | Sun |
|---|---|---|---|---|---|---|
| << < | > >> | |||||
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | 31 | |