Sarbanes-Oxley IT Consulting
Sarbanes-Oxley (SOX) regulations affect several aspects of a business, including its IT environment. While most corporate business and accounting departments are all too familiar with financial reporting requirements and audit trails, many IT departments are finding themselves in the audit spotlight for the first time.
Many are struggling to define what their departments must do to comply and to implement the necessary procedures. The problems are compounded by a lack of qualified IT auditors to address IT departments’ needs.
How we can help
As part of our extended SOX-related services, we offer IT consulting services designed specifically to help you comply with SOX regulations. Based on our information systems controls review experience and knowledge of the Sarbanes-Oxley Act, we’ve developed an efficient and effective approach to help you build a risk-based, top-down approach for achieving compliance.
Our multi-phased approach is designed to assess and document your company’s internal controls and utilizes the Committee of Sponsoring Organizations (COSO) of the Treadway Commission guidelines — the standard for internal control. COSO is not only an integral component of our methodology, but is also built into our software tools. This approach includes four phases:
1. Planning
2. Assess design effectiveness
3. Assess operating effectiveness
4. Ongoing monitoring and strategy for compliance
While the importance of IT controls is embedded in the COSO framework, IT management requires more examples to identify, document and evaluate IT controls. We use the Institute for Internal Auditor’s Guide to the Assessment of IT General Controls Based on Risk (GAIT) and the IT Governance Institute’s Control Objectives for Information and related Technology (COBIT).
Why RSM McGladrey
Our consultants have extensive experience and knowledge of financial accounting packages,information security, change management and computer operation controls. And our organization is structured to align with key industries. This means we understand how your organization is staffed and can anticipate the issues you’ll face.
Our risk-based services aredesigned to help you retain the confidence of stakeholders, provide managementwith a better decision-making vantage point and often yield opportunities toidentify and mitigate threats to your business goals.