Relief from Sarbanes-Oxley on the way?

By Ed Frauenheim, CNET News.com
Friday, June 10, 2005 11:01 AM

StorageTek's Arnold suggested that the effort to comply with SOX last year was somewhat frenzied for the various parties involved--including regulators and auditors. "Everyone was in such a hurry," he said. "There was a lot of misunderstanding and misinterpretation."

At one point, independent auditors argued that when StorageTek clerks were confirming purchases with a computer keystroke, they should first print out the document that was on their screens. But that would have created a huge amount of paperwork with little SOX-related value, according to Arnold. "We said, 'absolutely not.'" The auditors backed off from the request.

Some IT departments seem to have responded to SOX by documenting a wide range of activities, including apparently trivial ones.

"Has anyone else's company gone off the deep end on (quality assurance) documentation supposedly to be in compliance with SOX?," Walter Robinson, a CNET News.com reader, wrote in response to a recent column.

"We're to the point that it takes about a day to produce the various change documentation for a one-line code change," Robinson wrote. "And the 'QA' department says that we are being told by third-party auditors that we have to be this inefficient in order to be in compliance with SOX. And it's not like these rules are only being applied on systems that maintain the (company's) financial data; it's being applied across the company. Why does SOX care if I widen the description field on the product table allowing them to have a 5-character longer style name for a pair of shoes?"

Consultant Steve DeLaCastro, though, has a different take on how much IT departments have done related to SOX. "I've actually noticed them doing less than they have to," said DeLaCastro, who focuses on outsourcing arrangements for professional services firm Tatum Partners. DeLaCastro argues that some IT shops have not gathered the proper evidence that their controls are in place and effective.

In addition, DeLaCastro suggested, companies using outsourcers may be out of compliance with SOX in part because controls aren't being audited. "They're not thinking about their outsourcing relationship, and what it means" for SOX, DeLaCastro said.

IT spending bonanza
DeLaCastro's group is one of many vendors of technology services or products that have stepped in to help companies comply with SOX. Vendor interest in SOX isn't surprising. AMR estimates that total spending on SOX compliance will rise from the US$5.7 billion shelled out last year to US$6.1 billion this year. The portion spent just on technology is expected to grow from 2004's US$1.1 billion to US$1.7 billion this year, according to AMR.

Hewlett-Packard offers SOX-related services such as "risk-management" consulting that assesses a company's IT controls. Ismail Pishori, director of HP's risk management and compliance practice for clients in the financial services industry, says that although CIOs may complain about SOX, they recognize that the scrutiny of operations helps them become more efficient, as well as better at preventing problems. "Even the most vocal opponents of SOX will admit there is some benefit," he said.

Thanks to new official guidance issued last month, CIOs may have even less to complain about when it comes to SOX. In the wake of feedback about Section 404, the SEC tried to clarify what needs to be tested when it comes to "general IT controls." General IT controls include controls over program development, program changes and access to programs and data.

"While the extent of documentation and testing requires the use of judgment, the (SEC) staff expects management to document and test relevant general IT controls in addition to appropriate application-level controls that are designed to ensure that financial information generated from a company's application systems can reasonably be relied upon," the SEC said last month. "For purposes of the Section 404 assessment, the staff would not expect testing of general IT controls that do not pertain to financial reporting."

In releasing the advice about IT controls, the SEC said compliance with Section 404 during its first year of implementation may have been costlier than needed, "due to excessive, duplicative or misfocused efforts."

StorageTek's Arnold welcomes the recent guidance from the SEC and additional advice from the new agency created by SOX to oversee auditing firms, the Public Company Accounting Oversight Board. The latest guidelines should let company management use greater discretion when it comes to key controls over financial information, Arnold said. He also said President Bush's appointee to take over the reins of the SEC, free market champion Christopher Cox, should help matters.

Still, Arnold said, much will depend on how auditing firms interpret the new directions.

In any event, he has positive feelings overall about SOX. That's partly because StorageTek--and Sun--may benefit by selling products that help companies comply, and partly because the rigors of the law help an IT department find its inefficiencies. There's still another benefit for tech operations, he said. In contrast to recent years of belt-tightening, the SOX era allows chief information officers to regain some clout in how a company runs, said Arnold.

"More than anything, (SOX) gives IT organizations a bigger say."


 Previous 1 2 

WORTHWHILE?

0

0 votes
Save to my library  Save to My Library  
Blog

Talkback 0 comments

There are currently no comments for this post.

Code concepts: Visual Studio's T4 templates

Web Development

The T4 templating system is used to programmatically generate artifacts. Here's an overview about why the templates are useful and how to work with them.


Read more »


Where have all the bosses gone?

Blog thumbnail

I've had dreams of opening my own cafe or bistro...cum music store...cum music school. But, I soon gave up that dream when I realized it would require significant investment and..... by Eileen Yu

Read more »

Tech Jobs Now!

 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Tags

  1. antivirus
  2. apple ipod
  3. cnet networks inc.
  4. desktop
  5. e - mail
  6. hard drive
  7. intuit inc.
  8. mcafee inc.
  9. microsoft corp.
  10. microsoft windows
  11. microsoft windows vista
  12. microsoft windows xp
  13. norton co.
  14. pc
  15. performance
  16. security
  17. software
  18. tool
  19. web
  20. web site