atw: Re: Surf, sun, sand and SOX BABY <Pass the ammo>

Hi Steve
I'm about to start week 3 of a Sarbox contract, so I know how you feel. The big difference between your project and mine is that while yours is for IT, mine is for Finance, but the principles are the same.


The basics are really very simple; no-one has control of any one process and as you said, it's locked down by documentation. Once that was clear, we produced a set of testing sheets so that clerical staff can work through samples of the firm's transactions over the past three months and check that transaction documentation meets the Sarbox requirements. The auditors will be doing the same thing, essentially.

The internal test meets the Sarbox requirements in that there is a process 'owner' who is not the tester, but both must sign off on it. Exceptions are followed up and they get signed off too.

> If anyone can add to the core guts stuff ...
This is something we should discuss over a few beers. I'm not sure how much you've got, and I'm not sure how much I've got. One thing I'm certain of: it's the most important thing to face my employer or yours in decades. If the Sarbox audit fails, the result is reported directly to the stock exchange, and that is likely to affect the share price. No manager wants that on his head.


Suggestion: Assume that the auditors have been given a briefing about the Sarbanes-Oxley Act and its requirements. Assume that they, being auditors, want to check every form and see signatures so they can sign off on their forms. Then help them by writing up test forms so your empoloyer's staff can check that everything is double-signed for according to Sarbox principles. That test can ensure that by the time the auditors arrive everything will be OK.

Good luck!
Allan


************************************************** To post a message to austechwriter, send the message to austechwriter@xxxxxxxxxxxxxx

To subscribe to austechwriter, send a message to austechwriter-request@xxxxxxxxxxxxx with 
"subscribe" in the Subject field.

To unsubscribe, send a message to austechwriter-request@xxxxxxxxxxxxx with 
"unsubscribe" in the Subject field.

To search the austechwriter archives, go to 
www.freelists.org/archives/austechwriter

To contact the list administrator, send a message to 
austechwriter-admins@xxxxxxxxxxxxx
**************************************************

Other related posts: