Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· Directory
· Downloads
· FAQ
· Forums
· Search
· Sox_Admin
· Statistics
· Submit News
· Surveys
· Top 10
· Your Account

Sarbox Compliance
The appropriately named Sarbanes-Oxley Compliance Toolkit includes a whole range of materials specifically put together to both introduce, and take you through this most important of legislation.

For detailed information see the toolkit's own website: Sarbanes-Oxley Compliance


SOX Act and Security
As security is such a major theme on the Act, many organizations are using the international ISO standards. The ISO 27001 Portal outlines these. A copy of the standards, and security policies, can be obtained via the ISO 17799 Toolkit.

The SOX email storage requirements can be fulfilled using the GFI MailArchiver


SOX Advertisers


Sarbanes What?
Our server logs indicate some interesting mis-spellings: Sarbannes Oxley, Sorbane Oxley, Sarbanne Oxley, Sarbaines Oxley, Sarbanesoxley, Sorbanes Oxley, Sabanes Oxley, Sarbane Oxley, and Sarbanes Oaxley, to name but a few!

Sarbanes-Oxley Act Forum: Forums

The Sarbanes Oxley Act :: View topic - Entity Level Controls
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Entity Level Controls

 
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> General Sarbanes Oxley Discussion
View previous topic :: View next topic  
Author Message
loverofsoxgal
Soxer
Soxer


Joined: Oct 25, 2007
Posts: 15
Location: Arkansas

PostPosted: Tue Mar 25, 2008 4:02 pm    Post subject: Entity Level Controls Reply with quote

AS 5 points out that management and external auditors should place more reliance on entity level controls. However, I am having trouble identifying more than two! I am referring to controls that have a direct impact on a specific financial statement risk and not the indirect controls such as an ethics policy. Has anyone identified any entity-level controls and how are you benefiting from them in your 404 work?
Back to top
View users profile
kymike
SoxGuru
SoxGuru


Joined: Jun 02, 2004
Posts: 636
Location: USA

PostPosted: Tue Mar 25, 2008 4:44 pm    Post subject: Reply with quote

Here is my take on this - I think sometimes it is a matter of semantics. We have classified our controls into these buckets -

Entity-level (policies, general corporate tone of mgmt)
Company-level common controls (account reconciliations, JEs, SOD, system access, period close analytics) which are tested on a combined basis over all processes
Process-specific controls (specific reviews of judgmental reserves, spreadsheets, etc)
ITCG

I also have not found any of our ELCs that provide FS assertion coverage. We do rely on the company-level controls to cover FS assurance at a high level.
Back to top
View users profile
loverofsoxgal
Soxer
Soxer


Joined: Oct 25, 2007
Posts: 15
Location: Arkansas

PostPosted: Mon Mar 31, 2008 1:32 pm    Post subject: Reply with quote

Thanks for your comments. I was hoping you could provide specifics on how you have linked the CLC account reconciliations to your processes to allow you to eliminate key controls and/or reduce testing around process-specific controls. I am interested in balance sheet reconciliation and review controls as a company-level control but am concerned with the result of "failing" the control. Balance sheet reconciliations are such an important control, what if you find exceptions in testing? Do you fail the entire control? How does that impact other exceptions that you feel are not a significant deficiency due to the compensating control "balance sheet reconcilations are performed, etc?"

Your comments are appreciated.
Back to top
View users profile
kymike
SoxGuru
SoxGuru


Joined: Jun 02, 2004
Posts: 636
Location: USA

PostPosted: Mon Mar 31, 2008 5:18 pm    Post subject: Reply with quote

There is some judgment required when looking at test exceptions as to whether or not to fail a control. When we look at reconciliations, we review to ensure that they include preparer and review signatures and dates work performed, tie back to supporting information (gl, subledger, excel control file, bank statement, etc.), schedule foots, outstanding items aged and cleared timely. If there is a lack of signatures or dates, we do not fail the control as we can generally determine that they were prepared / reviewed. Other exceptions may cause us to increase our sample size to help in our judgment as to operating effectively or deficient.

If this control fails, then other controls that failed which rely on reconciliations would also fail.

In general, we rely on (from top to bottom) -

Period/quarter reviews (very detailed)
SOD
Access Controls
Account Reconciliations
Account-specific controls for validity of supporting balances (generally the manually-calculated support such as lease reserves, AFDA, OAL, etc.)
Back to top
View users profile
kymike
SoxGuru
SoxGuru


Joined: Jun 02, 2004
Posts: 636
Location: USA

PostPosted: Fri Feb 11, 2011 3:25 pm    Post subject: Reply with quote

Here is a link to a decent article on assessing entity-level controls.

www dot journalofaccountancy.com/Issues/2005/Jun/AssessingCompanyLevelControls
Back to top
View users profile
harrywaldron
SoxGuru
SoxGuru


Joined: Jan 12, 2006
Posts: 849
Location: Roanoke, Virginia

PostPosted: Tue Feb 22, 2011 9:39 am    Post subject: Reply with quote

^ Thanks Kymike for sharing the link above - EXCELLENT resource
Back to top
View users profile Visit posters website


Display posts from previous:   
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> General Sarbanes Oxley Discussion All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©

 
Trademarks referenced on the SOX Act Forum are property of their respective owners. Comments are property of their respective posters.
Sarbanes-Oxley Act Implementation Portal: Sarbanes Oxley compliance, information, software, & internal audit committee resources. Sarbox.
Site source is copyright nuke (c)2003, and is Free Software under the GNU / GPL licence agreement. All Rights Are Reserved.