Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· Directory
· Downloads
· FAQ
· Forums
· Search
· Sox_Admin
· Statistics
· Submit News
· Surveys
· Top 10
· Your Account

Sarbox Compliance
The appropriately named Sarbanes-Oxley Compliance Toolkit includes a whole range of materials specifically put together to both introduce, and take you through this most important of legislation.

For detailed information see the toolkit's own website: Sarbanes-Oxley Compliance


SOX Act and Security
As security is such a major theme on the Act, many organizations are using the international ISO standards. The ISO 27001 Portal outlines these. A copy of the standards, and security policies, can be obtained via the ISO 17799 Toolkit.

The SOX email storage requirements can be fulfilled using the GFI MailArchiver


SOX Advertisers


Sarbanes What?
Our server logs indicate some interesting mis-spellings: Sarbannes Oxley, Sorbane Oxley, Sarbanne Oxley, Sarbaines Oxley, Sarbanesoxley, Sorbanes Oxley, Sabanes Oxley, Sarbane Oxley, and Sarbanes Oaxley, to name but a few!

Sarbanes-Oxley Act Forum: Forums

The Sarbanes Oxley Act :: View topic - Application controls testing for SOX
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Application controls testing for SOX

 
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: IT Issues
View previous topic :: View next topic  
Author Message
VENKAT
Newbie
Newbie


Joined: Jun 29, 2006
Posts: 4

PostPosted: Thu Aug 24, 2006 12:23 am    Post subject: Application controls testing for SOX Reply with quote

Hi,

I have 2 questions pertaining to Application Testing:

1st question - Is it required to test the integrity of the application for "Off-the-shelf" packages or well known ERP such as Oracle Financials / Peoplesoft that are identified as SOX critical applications? Is there any certificate received from the Vendor of the integrity of the product that will suffice to avoid an end-to-end application audit?

2nd question - In the event of any customisations done to the product, will the UAT testing documentation suffice to assure the Management on the integrity of the data processed? Further, if the customisations pertain to REPORT generation, will this UAT need to be considered for SOX testing?

Thanks.

Venkat.
Back to top
View users profile
Chhaava
MasterSoxer
MasterSoxer


Joined: Jan 30, 2006
Posts: 153
Location: Chicago

PostPosted: Fri Aug 25, 2006 7:42 am    Post subject: Reply with quote

Good Morning Venkat,

Any application that somehow facilitates financial reporting is having a SOX scope. Therefore, evidence of UAT and QC is required. Vendor's certificate although useful, is not a complete evidence of compliance.

To sum up, evidence of QC and UAT and benchmarking of the programming logic is required
Back to top
View users profile Send email
harrywaldron
SoxGuru
SoxGuru


Joined: Jan 12, 2006
Posts: 821
Location: Roanoke, Virginia

PostPosted: Fri Aug 25, 2006 11:35 am    Post subject: Reply with quote

Hi Venkat -- I agree with Chhaava's good points, as SOX compliancy standards don't deliniate as to whether an application is a vendor supplied package verses one that is custom built. As testing centers around workflow and financial controls, a poorly implemented vendor based system can have issues.
Back to top
View users profile Visit posters website
milan
SoxGuru
SoxGuru


Joined: Oct 17, 2005
Posts: 414
Location: NY

PostPosted: Mon Aug 28, 2006 12:33 pm    Post subject: Application Controls Testing Reply with quote

Q1. Is it required to test the integrity of the application for "Off-the-shelf" packages or well known ERP such as Oracle Financials / Peoplesoft that are identified as SOX critical applications?

A1. Yes, application controls testing must be conducted on the signifcant financial applications. Oracle Financials / Peoplesoft, SAP, etc., all have embedded processing controls. However, it is necessary to test input, processing, and output controls to obtain comfort in connection with transactions processed through the system.

Additionally, because these systems are not configured out of the box, the control configurations must be designed to suit your business processes and the controls might not be configured properly. For example, within an ERP System, it is possible to turn 'off' various control settings that may not be applicable to your business. If a control setting is inactivated, it may render the system ineffective in providing the intended controls necessary to ensure reliable and accurate financial reporting.

Q1a. Is there any certificate received from the Vendor of the integrity of the product that will suffice to avoid an end-to-end application audit?

A1a. Certainly, a software vendor's certificate can establish some trust that the application performs as designed. However, the certificate is generally not considered to be a substitute by the external auditor as assurance on the ICFR.


Q2. In the event of any customisations done to the product, will the UAT testing documentation suffice to assure the Management on the integrity of the data processed? Further, if the customisations pertain to REPORT generation, will this UAT need to be considered for SOX testing?

A2. Please refer to the other replies.

Hope this further helps,

Milan
Back to top
View users profile Send email
VENKAT
Newbie
Newbie


Joined: Jun 29, 2006
Posts: 4

PostPosted: Wed Aug 30, 2006 1:52 am    Post subject: Application controls testing for SOX Reply with quote

Thanks for the timely responses. These definitely are useful pointers for extent of Management testing required.

Cheers!

Venkat.
Back to top
View users profile


Display posts from previous:   
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: IT Issues All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©

 
Trademarks referenced on the SOX Act Forum are property of their respective owners. Comments are property of their respective posters.
Sarbanes-Oxley Act Implementation Portal: Sarbanes Oxley compliance, information, software, & internal audit committee resources. Sarbox.
Site source is copyright nuke (c)2003, and is Free Software under the GNU / GPL licence agreement. All Rights Are Reserved.