A Sarbanes-Oxley Roadmap to Business Continuity
|
|
- Virgil Garrett
- 8 years ago
- Views:
Transcription
1 A Sarbanes-Oxley Roadmap to Business Continuity NEDRIX Conference June 23, 2004 Dr. Eric Schmidt Control Solutions International TECHNOLOGY ADVISORY, ASSURANCE & RISK MANAGEMENT GROUP
2 Background In July of 2002, U.S. Congress passed the Sarbanes - Oxley Act (SOX) mandating that all public companies (SEC registrants) make changes to the way their financial results are reported. Legislation was a response to the high profile failures experienced in the United States during and intended to be a massive restructuring to the regulatory system governing US capital markets that would improve the quality of financial reporting and disclosures. Public Company Accounting Oversight Board (PCAOB) was created to oversee the activities of the auditing profession.
3 The Sarbanes-Oxley Act contains two Sections (302, 404) dealing with management responsibility for controls and one Section (409) on real-time reporting Internal Controls and Procedures for Financial Reporting Disclosure Controls and Procedures Notes Cash Flow Income Statement Balance Sheet Financial Statements Financial Statements Business Properties Legal Proceeding s Annual Report on Form 10-K Section 404 Section 302
4 Three Sources of SOX Guidelines Frameworks Best Practices Future Standards CobiT COSO
5 Departments Impacted by SOX Finance IT Sales Human Resources Customer Service Marketing Other 100% 95.7% 43.5% 39.1% 30.4% 17.4% 8.7% Source: The Robert Francis Group
6 SOX-Driven Changes Which of the following is the company changing to address SOX? Source: Robert Francis Group Audit Procedures Reporting Procedures Financial Systems Re-training of Personnel Organizational Structure Reporting Frequency Reporting Technologies 78.3 % 52.2% 43.5% 26.1% 21.7% 21.7% 17.4%
7 Complexity of SOX for IT How does SOX compare with other compliance or regulatory projects in IT in terms of complexity and impact of resources and expense? Source: Robert Francis Group Higher Not sure/do Not Know Same Much Higher Lower Slightly Higher 30.4% 26.1% 17.4% 17.4% 4.3% 4.3% 48+% rated SOX impact as higher
8 Does SOX Mandate an Enterprise-wide Business Continuity Process? NO A BCP is not required by PCAOB (March 2004) SAS70 (type 2) 3 rd party service providers AICPA suspended BCP requirement during SOX Growing number of executives influenced by external auditors with knowledge of business continuity and potential risks Conclude they must have business continuity processes or show why they do not
9 Defining Internal Control (IC) Section 404 attestation is based on two assessments Adequate documentation of ICs Sufficient evidence (testing) A company must have a framework against which management can make assertions Completeness Accuracy Validation (authorization) Restriction
10 What s Required for Key Controls Five W s WHO performs the control? WHAT is being done and WHAT could go wrong? WHEN and WHERE is control being performed or occurring? WHY is control activity performed to prevent or detect what? What evidence is there?
11 Why are General Controls Important? Weak General Computer Controls Strong General Computer Controls Automated control procedures, and manual control procedures that use computer-generated information, are dependent on effectiveness of general computer controls.
12 COSO Framework Five Components The process which ensures that relevant information is identified and communicated in a timely manner The evaluation of internal and external factors that impact an organization s performance The process to determine whether internal control is adequately designed, executed, effective and adaptive The policies and procedures that help ensure that actions identified to manage risk are executed and timely The control conscience of an organization. The tone at the top All five components must be in place for a control to be effective
13 Tying It All Together Control Environment Executive Management IT Services OS/Data/Telecom/Continuity/Networks IT General Controls Application Controls Source: IT Governance Institute Business Process Finance Business Process Manufacturing Business Process Logistics Business Process Etc.
14 IT Control Components IT Considerations in Control Environment Systems planning Governance Enterprise policies Operating style Collaboration Information Sharing Code of Conduct Fraud Prevention IT General Controls Systems Security / Access Change Management System Development Computer Operations Application Controls Authorization Configuration / account mapping Exception / edit reports Interface / conversion System access
15 Roadmap to Compliance Tone at the Top Engagement Walk-Thru Assertions (C, A, V, R) Definition of Materiality/Significance Significant Accounts and Processes Scope locations, cycles Control framework Remediation Testing Management certification
16 Roadmap to Compliance Phase I Tone at the Top Identify all relevant documents, policies, procedures and communications Audit Committee Charter Standards of Conduct Officer Code of Ethics Complaint Reporting Mechanisms Whistleblower Policies Assess adequacy of documentation and tone Internal audit monitoring and risk assessment
17 Roadmap to Compliance Phase II Entity Level Assessment Corporate Americas Region Europe Region Rest of World ID material reporting organizations South Carolina Mexico South Carolina Milan Erfurt Budapest Milan China India Thailand China Manufacturing ID material units within each organization Materiality based on: Mexico Sao Paolo San Diego Marseilles Copenhagen Erfurt India Thailand Australia Distribution Revenue / Assets Subjectivity of entries / reporting Chicago Prague Japan Extraordinary / one-time charges History of issues
18 Open Position Personnel Requisition Form Candidate interviewed Prepare Offer Letter Accept Offer Provide Benefits summary to employee Termination Voluntary? 04 No Director of HR Approve Yes Yes Accrued Benefits paid Proper notice given? No 05 Accrued Benefits not paid Create Employee Action Form (EAF) Other P/R changes Department Approval Review by HR 03 Verify Increases within $ pool, properly authorized Input in ADP PR System Annual Increases Included with Annual Review and Approved 02 To PR/PRO Roadmap to Compliance Department Phase III Process Mapping Human Resources Candidate Cycle reviews begin with the cycles selected being based on the legal entity assessment in Phase II. Documentation of each cycle: Narrative of key controls Process Map (Flow chart) Control Matrix including all control objectives (Excel or software tool) Documents aim to provide external audit firms with a complete understanding of the flow of transactions and controls in place.
19 Roadmap to Compliance Phase IV Overall Internal Control Effectiveness Evaluation of the overall effectiveness of internal controls, identification of matters for improvement and the establishment of monitoring systems. Management assessment of effectiveness of controls. Internal Audit provides a report detailing areas for improvement and recommendations for ensuring an environment of continuous monitoring to maintain the system of internal control and take corrective action in a timely manner when necessary. External Audit Firm will commence its Attestation Dry Run
20 Source: SOX Compliance Roadmap
21 Alignment with Business Continuity Management involvement Risk Management Process and Change Management IT role
22 Key Aspects of SOX Audit Segregation of Duties is Key IT roles separate from process owners, specifically those in Finance Hand off from process owners requires control duality Program & Application specific IT & Process owner Manual & Automated Preventative & Detective Change Management is Critical Records and document management Configuration management Business process and controls changes Access Restriction (Security) is Mandated
23 Program Development Project management standards are defined and used for all aspects of system development life cycle (SDLC) Project initiation Analysis and design Construction or package selection Testing and quality assurance Data conversion Go-live Documentation and training
24 Program Changes Project management standards are defined and used for all aspects of the program change cycle Specification, approval and tracking of change requests Construction Testing and quality assurance Authorization of transfers to live environment Including emergency fixes and access to live environment Documentation and training
25 Situational Assessment A recent Deloitte survey of Fortune 500 companies indicates that a significant amount of work remains* Activity Documentation Evaluation of design effectiveness Testing of operating effectiveness Remediation Percentage Complete 75% 47% 21% 21% *Source: Does Your SOX 404 Work Measure Up?, IIA webcast May 25, 2004
26 What Constitutes a Gap? Type Likelihood Magnitude Deficiency Remote and/or Inconsequential Significant Deficiency More than remote and More than Inconsequential or Quantitatively significant Material Weakness More than remote and Material to Financial Statements *Source: Does Your SOX 404 Work Measure Up?, IIA webcast May 25, 2004
27 A Word on Testing Plan carefully to avoid mixed results because tests are not well designed Program Testing Application Testing Infrastructure Testing IT Management and interaction with process owners and stakeholders Functional and transaction based for systems key to financial statements and reporting, plus critical systems Shared services and support systems; OS, networks, backup, etc. Benchmark Testing Slowly changing systems, COTS
28 Remediation Challenges Effective Decision & Governance Process Complex Program Management Initiatives Significant IT Environment Changes Impact on Human Resources Complex Re-testing, Roll-Forward Testing Activities Overall Need for Best Practices
29 Span of Enterprise Risk Management Credit Risk Operational Risk Market Risk Operational Risk Management (ERM) Overall compliance Compliance Integrated solutions SOX Compliance Requirements Sarbanes-Oxley Quarterly Certification by C-Level Management Control Documentation and Testing Control Assurance 409 Real-time Reporting Government Regulations HIPPA Patriot Basel II GLBA FFIEC NRC
30 Risk Management & Business Continuity Disciplines of business continuity and risk management often blurred Use similar tools and techniques, including risk assessment, business continuity planning, and BIAs Business continuity encompasses all processes necessary to restore business functionality during a time of crisis Risk management incorporates a wider variety of functions, including positive impact, negative impact, and business nonstoppage Inherent value of business continuity is clearer when we consider that not all risks can be managed Unless risk management and business continuity are institutionalized into day-to-day activities, organizations will find themselves exposed
31 Questions? Source: John Wehr Source: John Wehr
This article will provide background on the Sarbanes-Oxley Act of 2002, prior to discussing the implications for business continuity practitioners.
Auditing the Business Continuity Process Dr. Eric Schmidt, Principal, Transitional Data Services, Inc. Business continuity audits are rapidly becoming one of the most urgent issues throughout the international
More informationThe Importance of IT Controls to Sarbanes-Oxley Compliance
Hosted by Deloitte, PricewaterhouseCoopers and ISACA/ITGI The Importance of IT Controls to Sarbanes-Oxley Compliance 15 December 2003 1 Presenters Chris Fox, CA Sr. Manager, Internal Audit Services PricewaterhouseCoopers
More informationInternational Institute of Management
Executive Education Executive Action Learning Seminars Executive Seminars Executive Courses International Institute of Management Executive Education Courses CIO & Sarbanes Oxley Compliance SOX Implementation
More informationUsing COBiT For Sarbanes Oxley. Japan November 18 th 2006 Gary A Bannister
Using COBiT For Sarbanes Oxley Japan November 18 th 2006 Gary A Bannister Who Am I? Who am I & What I Do? I am an accountant with 28 years experience working in various International Control & IT roles.
More informationHow To Ensure Internal Control Of Financial Reporting In India
PROTIVITI FLASH REPORT New Internal Control Requirements for Companies with Operations in India November 9, 2015 In the aftermath of major global financial frauds, several countries enacted legislation
More informationSarbanes-Oxley Compliance Workbook. From Zero to SOX. Sarbanes-Oxley Compliance Workbook. sensiba san filippo www.ssfllp.com sox@ssfllp.
From Zero to SOX Zero to SOX An Overview The goals of a program to meet SOX 404 requirements go far beyond compliance. The process of building a sustainable, comprehensive internal control environment
More information1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition
1. FPO Guide to the Sarbanes-Oxley Act: IT Risks and Controls Second Edition Table of Contents Introduction... 1 Overall IT Risk and Control Approach and Considerations When Complying with Sarbanes-Oxley...
More informationTECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER
Page 1 of 7 A. GENERAL 1. PURPOSE The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Teck Resources Limited ( the Corporation ) is to provide an open avenue of
More informationCOSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE
COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,
More informationSarbanes-Oxley Section 404: Management s Assessment Process
Sarbanes-Oxley Section 404: Management s Assessment Process Frequently Asked Questions ADVISORY Contents 1 Introduction 2 Providing a Road Map for Management 3 Questions and Answers 3 Section I. Planning
More informationGuide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions
Guide to the Sarbanes-Oxley Act: IT Risks and Controls Frequently Asked Questions Table of Contents Page No. Introduction.......................................................................1 Overall
More informationSarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers
Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers Table of Contents Requirements of the Act.............................................................. 1 Accelerated Filer s...........................................................
More informationSarbanes-Oxley Control Transformation Through Automation
Sarbanes-Oxley Control Transformation Through Automation An Executive White Paper By BLUE LANCE, Inc. Where have we been? Where are we going? BLUE LANCE INC. www.bluelance.com 713.255.4800 info@bluelance.com
More informationThe Role of Internal Audit In Business Continuity Planning
The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. dan.bailey@protiviti.com Actively involved in the Information
More informationWHITE PAPER. Sarbanes - Oxley Section 404: How BMC Software Solutions Address General IT Control Requirements
WHITE PAPER Sarbanes - Oxley Section 404: How BMC Software Solutions Address General IT Control Requirements TABLE OF CONTENTS Executive Summary 2 Sarbanes-Oxley Section 404 Internal Controls 3 IT Involvement
More informationAntifraud program and controls assessment grid*
Advisory Services Antifraud program and * Fraud risks & controls February 2008 *connectedthinking 2008 PricewaterhouseCoopers LLP. All rights reserved. PricewaterhouseCoopers refers to PricewaterhouseCoopers
More informationIFRS in Asia 2008 Driving the Capital Markets of Tomorrow 10-11 October 2008, Beijing, China
International Accounting Standards Committee Foundation, Ministry of Finance (PRC), and Shulun Pan Certified Public Accountants IFRS in Asia 2008 Driving the Capital Markets of Tomorrow 10-11, Beijing,
More informationSelf-Service SOX Auditing With S3 Control
Self-Service SOX Auditing With S3 Control The Sarbanes-Oxley Act (SOX), passed by the US Congress in 2002, represents a fundamental shift in corporate governance norms. As corporations come to terms with
More informationIndustry Sound Practices for Financial and Accounting Controls at Financial Institutions
Industry Sound Practices for Financial and Accounting Controls at Financial Institutions Federal Reserve Bank of New York January 2006 FINANCIAL AND ACCOUNTING CONTROLS: INDUSTRY SOUND PRACTICES FOR FINANCIAL
More informationGuide to Internal Control Over Financial Reporting
Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).
More informationAuditing Standard 5- Effective and Efficient SOX Compliance
Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the
More informationAdministrative Guidelines on the Internal Control Framework and Internal Audit Standards
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page
More informationSarbanes-Oxley Compliance: Section 404-Past, Present, and Future
Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future BADM 590/395 IT Governance MS1 Professor Michael Shaw Submitted by: Amy Smith BA in MIS University of Illinois at Urbana-Champaign Smith
More informationSTANDING ADVISORY GROUP MEETING
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202)862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING BROKER-DEALER AUDIT CONSIDERATIONS JULY 15, 2010 Introduction
More information[RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06]
SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting
More informationImpact of New Internal Control Frameworks
Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region Bob.Jacobson@mcgladrey.com
More informationTen Steps to SOX Compliance for Smaller Public Companies
Presented by: Bob Benoit Lord & Benoit, LLC One West Boylston St. Worcester, MA 01605 (508) 853-6404 Ten Steps to SOX Compliance for Smaller Public Companies Team IT Controls Timeline Effectiveness Of
More informationIT Governance Dr. Michael Shaw Term Project
IT Governance Dr. Michael Shaw Term Project IT Auditing Framework and Issues Dealing with Regulatory and Compliance Issues Submitted by: Gajin Tsai gtsai2@uiuc.edu May 3 rd, 2007 1 Table of Contents: Abstract...3
More informationSarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers
Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers As of March 14, 2005 Table of Contents Requirements of the Act.............................................................. 1 Accelerated
More informationSOX 404 Compliance Challenges for Small Companies
A SOX2007.com White Paper SOX 404 and Small Companies: A Cost Effective Approach to 2007 Compliance Background The Sarbanes-Oxley Act (SOX) was passed by Congress in July 2002 to address corporate mismanagement
More informationSpecial Considerations Audits of Group Financial Statements (Including the Work of Component Auditors)
Special Considerations---Audits of Group Financial Statements 607 AU-C Section 600 Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors) Source: SAS No.
More informationCharter of the Audit Committee of the Board of Directors
Charter of the Audit Committee of the Board of Directors Dated as of April 27, 2015 1. Purpose The Audit Committee is a committee of the Board of Directors (the Board ) of Yamana Gold Inc. (the Company
More informationInternal Control over Financial Reporting Guidance for Smaller Public Companies
Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked Questions Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked
More informationCOSO 2013 Internal Control Framework
COSO 2013 Internal Control A Guide to Implementation July 24, 2014 Justin Adamson Agenda COSO Background Changes to the Roadmap to Implementation Implementation Considerations & Lessons Learned 2 1 Who/What
More informationImpact of the Sarbanes-Oxley Act on the System of Internal Controls and IS Audit
Impact of the Sarbanes-Oxley Act on the System of Internal Controls and IS Audit Eva Šimková Hewlett-Packard s.r.o. Vyskočilova 1/1410 14021 PRAHA eva.simkova@hp.com Abstract: The purpose of this paper
More informationSarbanes-Oxley and Sage MAS 90, 200, and 500. www.sagemas.com
Sarbanes-Oxley and Sage MAS 90, 200, and 500 www.sagemas.com Table of Contents Introduction... 3 Separating Truth From Fiction... 3 Impact of Sarbanes-Oxley... 5 Integrated Systems... 5 Security by Design...
More informationHALOZYME THERAPEUTICS, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS ORGANIZATION AND MEMBERSHIP REQUIREMENTS
HALOZYME THERAPEUTICS, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS I. STATEMENT OF POLICY The Audit Committee (the Committee ) of the Board of Directors (the Board ) of Halozyme Therapeutics,
More information26 February 2007. Ms. Nancy M. Morris, Secretary Securities and Exchange Commission 100 F Street NE Washington, DC 20549-1090
3701 Algonquin Road, Suite 1010 Telephone: 847.253.1545 Rolling Meadows, Illinois 60008, USA Facsimile: 847.253.1443 Web Sites: www.isaca.org and www.itgi.org 26 February 2007 Ms. Nancy M. Morris, Secretary
More informationInternal Control Strategies. A Mid to Small Business Guide
Brochure More information from http://www.researchandmarkets.com/reports/2325460/ Internal Control Strategies. A Mid to Small Business Guide Description: Praise for Internal Control Strategies A Mid to
More informationConsultation Response
Consultation Response PROPOSED AUDITING STANDARD AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING PERFORMED IN CONJUNCTION WITH AN AUDIT OF FINANCIAL STATEMENTS PCAOB Rulemaking Docket Matter No.
More informationCOSO Internal Control Integrated Framework (2013)
COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)
More informationAn Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements
Examination of an Entity s Internal Control 1403 AT Section 501 An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Source:
More informationSARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners
SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners The Institute of Internal Auditors
More informationInternal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
More informationAN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN
More informationOUTSOURCING AND SERVICE AUDITOR S REPORTS
OUTSOURCING AND SERVICE AUDITOR S REPORTS FREEDOM TO DO BUSINESS Outsourcing and service Auditor s Reports 3 OUTSOURCING AND SERVICE AUDITOR S REPORTS SERVICE AUDITOR S REPORTS ARE GROWING IN IMPORTANCE,
More informationMORRISON I FOERSTER. Legal Updates & News. A Guide to the Impact of SAS 70 on Outsourcing Projects January 2008 by Alistair Maughan, Susan McLean
MORRISON I FOERSTER Legal Updates & News Legal Updates A Guide to the Impact of SAS 70 on Outsourcing Projects January 2008 by Alistair Maughan, Susan McLean Related Practices: Sourcing The worlds of outsourcing
More informationAUDIT COMMITTEE CHARTER
AUDIT COMMITTEE CHARTER Purpose The Audit Committee ( Committee ) shall assist the Board of Directors (the Board ) in the oversight of (1) the integrity of the financial statements of the Company, (2)
More informationDTZ Corporate Finance Limited Pillar 3 Disclosures as at 30 April 2009
DTZ Corporate Finance Limited Pillar 3 Disclosures as at 30 April 2009 16 March 2010 Contents OVERVIEW 1 Introduction 1 Structure and principal activities 1 Basis of disclosures 1 Frequency of disclosures
More informationAudit of the Test of Design of Entity-Level Controls
Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents
More informationBOTTOMLINE TECHNOLOGIES (DE), INC. AUDIT COMMITTEE CHARTER
BOTTOMLINE TECHNOLOGIES (DE), INC. AUDIT COMMITTEE CHARTER A. Purpose The purpose of the Audit Committee is to assist the Board of Directors oversight of: the Company s accounting and financial reporting
More informationNavigating the Standards for Information Technology Controls
Navigating the Standards for Information Technology Controls By Joseph B. O Donnell and Yigal Rechtman JULY 2005 - Pervasive use of computers, along with recent legislation such as the Sarbanes- Oxley
More informationSaldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology
Inclusive of, framework, procedures and methodology Contents 1 Introduction 1 1.1 Legislative Framework and best practice 1 1.2 Purpose of Enterprise Risk Management 2 1.3 Scope and Applicability 3 1.4
More informationThomas Ray, Deputy Chief Auditor (202/207-9112; rayt@pcaobus.org), Laura Phillips, Associate Chief Auditor (202/207-9111; phillipsl@pcaobus.org).
1666 K Street, N.W. Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING PERFORMED IN CONJUNCTION WITH AN AUDIT
More informationAsset Manager Guide to SAS 70. Issue Date: October 7, 2007. Asset
Asset Manager Guide to SAS 70 Issue Date: October 7, 2007 Asset Management Group A s s e t M a n a g e r G u i d e SAS 70 Table of Contents Executive Summary...3 Overview and Current Landscape...3 Service
More informationHigh Value Audits: An Update on Information Technology Auditing. Robert B. Hirth Jr., Managing Director
High Value Audits: An Update on Information Technology Auditing Robert B. Hirth Jr., Managing Director The technology landscape and its impact on internal audit Technology is playing an ever-growing role
More informationAssessing the Adequacy and Effectiveness of a Fund s Compliance Policies and Procedures. December 2005
Assessing the Adequacy and Effectiveness of a Fund s Compliance Policies and Procedures December 2005 Copyright 2005 Investment Company Institute. All rights reserved. Information may be abridged and therefore
More informationB o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
More informationFraud and Role of Information Technology. September 2008
Fraud and Role of Information Technology September 2008 Agenda IT Value Proposition Slide 2 Prior Interpretations of Internal Control Structure Have Addressed Three Separate Parts Which Were Audited Somewhat
More informationSarbanes-Oxley Section 404 Implementation Practices of Leading Companies
Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Dr. Robert A. Howell Distinguished Visiting Professor of
More informationGuide to Public Company Auditing
Guide to Public Company Auditing The Center for Audit Quality (CAQ) prepared this Guide to Public Company Auditing to provide an introduction to and overview of the key processes, participants and issues
More informationRegulatory Compliance Management (RCM) (formerly Legislative Compliance Management (LCM))
Guideline Subject: Category: (RCM) (formerly Legislative Compliance Management (LCM)) Sound Business & Financial Practices No: E-13 Date: November 2014 I. Purpose and Scope of the Guideline The purpose
More informationFebruary 2015. Sample audit committee charter
February 2015 Sample audit committee charter Sample audit committee charter This sample audit committee charter is based on observations of selected companies and the requirements of the SEC, the NYSE,
More informationWhat Should IS Majors Know About Regulatory Compliance?
What Should IS Majors Know About Regulatory Compliance? Working Paper Series 08-12 August 2008 Craig A. VanLengen Professor of Computer Information Systems/Accounting Northern Arizona University The W.
More informationAchieving Business Imperatives through IT Governance and Risk
IBM Global Technology Services Achieving Business Imperatives through IT Governance and Risk Peter Stremus Internet Security Systems, an IBM Company Introduction : Compliance Value Over the past 15 years
More informationSOX and its effects on IT Security Governance
SOX and its effects on IT Security Governance Rosslin John Robles 1, Min-kyu Choi 1, Sung-Eon Cho 2, Yang-seon Lee 2, Tai-hoon Kim 1 School of Multimedia, Hannam University, Daejeon, Korea 2 Dept of Information
More informationCommunicating Internal Control Related Matters Identified in an Audit
Communicating Internal Control 1843 AU Section 325 Communicating Internal Control Related Matters Identified in an Audit (Supersedes SAS No. 112.) Source: SAS No. 115. Effective for audits of financial
More informationAudit of the Policy on Internal Control Implementation
Audit of the Policy on Internal Control Implementation Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council of Canada February 18, 2013 1 TABLE OF
More informationSarbanes-Oxley 404. Sarbanes-Oxley Background. SOX 404 Internal Controls. Goals of Sarbanes-Oxley
Sarbanes-Oxley Background Sarbanes-Oxley 404 Internal Controls in Financial Reporting: Implications for Actuaries Legislation passed July 30, 2002 Applies to GAAP financial statements filed with SEC Effective
More informationengage. empower. evolve. SARBANES-OXLEY COMPLIANCE
engage. empower. evolve. SARBANES-OXLEY COMPLIANCE engage. empower. evolve. OVERVIEW OF THE SARBANES-OXLEY ACT The Sarbanes-Oxley Act of 2002 is the single most important piece of legislation affecting
More informationCharter of the Audit Committee of the Board of Directors of Woodward, Inc.
AUDIT COMMITTEE CHARTER Charter of the Audit Committee of the Board of Directors of Woodward, Inc. Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors to oversee the accounting
More informationMACQUARIE INFRASTRUCTURE CORPORATION AUDIT COMMITTEE CHARTER
MACQUARIE INFRASTRUCTURE CORPORATION AUDIT COMMITTEE CHARTER A. Purpose The Audit Committee (the Committee ) has been established by the Board of Directors (the Board ) of Macquarie Infrastructure Corporation
More informationTransmittal Letter... 1. Objectives and Scope... 2. Approach... 3-7. Financial System... 8. Permitting Application... 9
Internal Audit Committee of Information Technology Risk Assessment Public Report Prepared By: Internal Auditors of Brevard County September 30, 2009 Table of Contents Transmittal Letter... 1 Objectives
More informationSTANDING ADVISORY GROUP MEETING INITIATIVES TO IMPROVE AUDIT QUALITY ROOT CAUSE ANALYSIS, AUDIT QUALITY INDICATORS, AND QUALITY CONTROL STANDARDS
1666 K Street, NW Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING INITIATIVES TO IMPROVE AUDIT QUALITY ROOT CAUSE ANALYSIS, AUDIT
More informationCALADRIUS BIOSCIENCES, INC. AUDIT COMMITTEE CHARTER
I. STATEMENT OF POLICY CALADRIUS BIOSCIENCES, INC. AUDIT COMMITTEE CHARTER The Audit Committee shall assist the Board of Directors (the "Board") of Caladrius Biosciences, Inc. ("Caladrius ") in fulfilling
More informationPwC Advisory Internal Audit. PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley*
PwC Advisory Internal Audit PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley* Table of Contents Overview 02 As demands on internal audit escalate,
More informationAudit Committee Charter Altria Group, Inc. In the furtherance of this purpose, the Committee shall have the following authority and responsibilities:
Audit Committee Charter Altria Group, Inc. Membership The Audit Committee (the Committee ) of the Board of Directors (the Board ) of Altria Group, Inc. (the Company ) shall consist of at least three directors
More informationRisk Management Advisory Services, LLC Capital markets audit and control
Risk Management Advisory Services, LLC Capital markets audit and control November 14, 2003 Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, D.C., 20006-2803
More informationCOSO Enterprise Risk Management. Establishing Effective Governance, Risk, and Compliance (GRC) Processes. 2nd Edition. Wiley Corporate F&A
Brochure More information from http://www.researchandmarkets.com/reports/2220031/ COSO Enterprise Risk Management. Establishing Effective Governance, Risk, and Compliance (GRC) Processes. 2nd Edition.
More informationThe Upside of Risk: Enterprise Risk Management and Public Real Estate Companies
The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies James Barkley, Simon Property Group, Inc. and David E. Weiss, DDR Corp. Introduction: As lawyers, particularly real estate
More informationGuidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
More informationCVS HEALTH CORPORATION A Delaware corporation (the Company ) Audit Committee Charter Amended as of September 24, 2014
CVS HEALTH CORPORATION A Delaware corporation (the Company ) Audit Committee Charter Amended as of September 24, 2014 Purpose The Audit Committee (the Committee ) is created by the Board of Directors of
More informationVendor Risk Management Financial Organizations
Webinar Series Vendor Risk Management Financial Organizations Bob Justus Chief Security Officer Allgress Randy Potts Managing Consultant FishNet Security Bob Justus Chief Security Officer, Allgress Current
More informationBAKER HUGHES INCORPORATED. CHARTER OF THE AUDIT/ETHICS COMMITTEE OF THE BOARD OF DIRECTORS (as amended and restated October 24, 2012)
BAKER HUGHES INCORPORATED CHARTER OF THE AUDIT/ETHICS COMMITTEE OF THE BOARD OF DIRECTORS (as amended and restated October 24, 2012) The Board of Directors of Baker Hughes Incorporated (the Company ) has
More informationDeveloping Effective Internal Controls Using the COSO Model
Developing Effective Internal Controls Using the COSO Model Office of State Controller Internal Controls in a COSO Environment Seminar Raleigh, North Carolina March 2007 Mark S. Beasley Director, ERM Initiative
More informationEnterprise risk management: A pragmatic, four-phase implementation plan
Enterprise risk management: A pragmatic, four-phase implementation plan Prepared by: John Brackett, Managing Director, Risk Advisory Services, RSM McGladrey, Inc. 704.442.3820, john.brackett@mcgladrey.com
More informationFIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE
FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE As amended, restated, and approved by the Boards of Directors on July 28, 2015 This Charter sets
More informationImplementing Internal Controls over Executive Compensation Creating a Sustainable Compensation Control Environment
NASPP Implementing Internal Controls over Executive Compensation Creating a Sustainable Compensation Control Environment Michael S. Kesner, Principal Sustainable Compensation Control Environment Tone At
More informationEstablishing a Quality Assurance and Improvement Program
Chapter 2 Establishing a Quality Assurance and Improvement Program O v e rv i e w IIA Practice Guide, Quality Assurance and Improvement Program, states that Quality should be built in to, and not on to,
More informationPolicy 10.105: Enterprise Risk Management Policy
Name: Responsibility: Complements: Enterprise Risk Management Framework Coordinator, Enterprise Risk Management Policy 10.105: Enterprise Risk Management Policy Date: November 2006 Revision Date(s): January
More informationCFE 2. Enterprise Risk Management. Study Guide - Supplemental Background Material
P a g e 1 CFE 2 Enterprise Risk Management Study Guide - Supplemental Background Material The passing score for this test is 74% Reference Guides: Enterprise Risk Management Best Practices: From Assessment
More informationOutsourcing & Regulatory Compliance Risks
Outsourcing & Regulatory Compliance Risks By Matthew Sullivan Today s marketplace dictates that Financial Services Institutions (FSIs) consider using offshore IT services to remain competitive. However,
More informationSECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT
SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT Through CGIAR Financial Guideline No 3 Auditing Guidelines Manual the CGIAR has adopted the IIA Definition of internal auditing
More informationSarbanes-Oxley Section 404 Compliance: A Guiding Framework using igrafx SOX Accelerator
Sarbanes-Oxley Section 404 Compliance: A Guiding Framework using igrafx SOX Accelerator 2007 Corel Corporation. All Rights Reserved. Table of Contents Introduction...P - 1 Using igrafx for SOX Compliance...P
More informationRISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
More informationGovernance SPICE. ISO/IEC 15504 for Internal Financial Controls and IT Management. By János Ivanyos, Memolux Ltd. (H)
Governance SPICE ISO/IEC 15504 for Internal Financial Controls and IT Management By János Ivanyos, Memolux Ltd. (H) 1. Evaluating Internal Controls against Governance Frameworks Corporate Governance is
More informationHow Perforce Can Help with Sarbanes-Oxley Compliance
How Perforce Can Help with Sarbanes-Oxley Compliance C. Thomas Tyler Chief Technology Officer, The Go To Group, Inc. In collaboration with Perforce Software Perforce and Sarbanes-Oxley The Sarbanes-Oxley
More informationOceaneering International, Inc. Audit Committee Charter
Oceaneering International, Inc. Audit Committee Charter Purpose The Audit Committee of the Board of Directors (the Committee ) is appointed by the Board of Directors (the Board ) to assist the Board in
More informationSarbanes-Oxley: Challenges and Opportunities in the New Regulatory Environment
Doculabs White Paper Sarbanes-Oxley: Challenges and Opportunities in the New Regulatory Environment The Sarbanes-Oxley Act of 2002 (Sarbanes-Oxley) has ushered in sweeping changes to corporate governance,
More informationAMPLIFY SNACK BRANDS, INC. AUDIT COMMITTEE CHARTER. Adopted June 25, 2015
AMPLIFY SNACK BRANDS, INC. AUDIT COMMITTEE CHARTER Adopted June 25, 2015 I. General Statement of Purpose The purposes of the Audit Committee of the Board of Directors (the Audit Committee ) of Amplify
More information