Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Sarbanes Oxley 404 Requirement - Internal Controls Maturity Framework

01/16/06

Permalink 09:31:12 pm, Categories: Sarbanes Oxley, 294 words   English (US)

Sarbanes Oxley 404 Requirement - Internal Controls Maturity Framework

Internal Controls form an integral part of the overall control environment in the organization. Recently, many organizations have started to consider internal controls based on a maturity framework much more like the maturity models for software process commonly known as CMM levels. I have an interesting theory that the maturity levels in the software processes can also be applied to Sarbanes Oxley Internal Control too. The maturity levels namely Initial, Repeatable, Defined, Managed and Optimized can be tailored to suit Internal Controls. Here is what I consider would be the maturity levels for internal controls in a Sarbanes Oxley scenario:

Initial - This is the most basic maturity level where control activities are not even designed. It is represented by an unpredictable control environment.

Repeatable or Informal - In the second maturity level, controls are mostly dependent on people. Controls are designed and are in place but the same have not been documented. Also, there is a lack of awareness and communication of the control activities.

Defined or Standardized - Here, controls are designed and documented. Control activities are communicated to employees. However, deviations from such control activities will probably not be detected.

Managed or Monitored - This maturity level is represented by standard controls with periodic testing plans, reporting to management. Documentation software, Sarbanes Oxley automation tools may be used to a limited extent.

Optimized - The last and final maturity level corresponds to an integrated internal control framework. Efforts are made for continous improvements in internal controls with stress on enterprise wide risk management. Real time disclosure controls are a part of this maturity level. Software tools are used extensively to document, test, report, analyze and communicate internal control data within the enterprise.

More on Sarbanes Oxley >>

Identifying Company Level Controls , IT Best Practices for Sarbanes OXley

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

January 2009
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Misc

Syndicate this blog XML

What is RSS?