Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: Segregating Conflicting Duties in Smaller Companies

08/04/06

Permalink 07:05:39 am, Categories: CISA Exam, 263 words   English (US)

Segregating Conflicting Duties in Smaller Companies

Segregation of duties has an important bearing on the overall control
environment of an organization. Though I have talked about segregation
of duties recently here and here, the term segregation of duties takes a
whole new meaning in terms of a smaller company. I say this because of
a number of reasons. One major reason is smaller companies generally do
not have as many resources to segregate each and every conflicting
function. Also, the management has a direct role in the day to day affairs of the company.

At one of our smaller clients, many conflicting functions were being
handled by the same person. This I feel is quite normal in many small company set-ups.So whats the solution to addressing segregation of duties in smaller companies. Well, there are compensating controls and alternative control approaches which smaller companies can adopt to address segregation of duties issues. I have listed a few of such
compensating SOD controls below:

Segregation-of-Duties-Sarbanes-Oxley-COSO-SOD

1. Periodic review of system reports. These could cover reviewing
details of transactions by managers or supervisors.

2. Conducting periodic physical counts of inventory, assets, equipment etc and matching them with book stock.

3. Reviewing supporting documentation for high risk transactions or
transactions with a likelihood of material mis-statement.

4. Account reconciliations by independent individuals. Reconciliation
of accounts
can form an important compensating control for segregation of duty inadequacy.

5. Finally, smaller companies need to build alert mechanisms, flags,
control violation indicators in their business processes to address SOD
issues.

Related Posts

Continuing Material Weaknesses SOX
SOX Application and Data Owners
Multi-Disciplinary Audit Teams for SOX Audit
Application Level Controls

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

October 2009
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Misc

Syndicate this blog XML

What is RSS?