Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Content
· Directory
· Downloads
· FAQ
· Forums
· Search
· Sox_Admin
· Statistics
· Submit News
· Surveys
· Top 10
· Your Account

Sarbox Compliance
The appropriately named Sarbanes-Oxley Compliance Toolkit includes a whole range of materials specifically put together to both introduce, and take you through this most important of legislation.

For detailed information see the toolkit's own website: Sarbanes-Oxley Compliance


SOX Act and Security
As security is such a major theme on the Act, many organizations are using the international ISO standards. The ISO 27001 Portal outlines these. A copy of the standards, and security policies, can be obtained via the ISO 17799 Toolkit.

The SOX email storage requirements can be fulfilled using the GFI MailArchiver


SOX Advertisers


Sarbanes What?
Our server logs indicate some interesting mis-spellings: Sarbannes Oxley, Sorbane Oxley, Sarbanne Oxley, Sarbaines Oxley, Sarbanesoxley, Sorbanes Oxley, Sabanes Oxley, Sarbane Oxley, and Sarbanes Oaxley, to name but a few!

Sarbanes-Oxley Act Forum: Forums

The Sarbanes Oxley Act :: View topic - Findings Framework - process to aggregate deficiencies
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Findings Framework - process to aggregate deficiencies

 
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: Audit Issues
View previous topic :: View next topic  
Author Message
jt_clark
Newbie
Newbie


Joined: Mar 28, 2008
Posts: 2
Location: San Jose, CA

PostPosted: Fri Mar 28, 2008 12:02 pm    Post subject: Findings Framework - process to aggregate deficiencies Reply with quote

Hello All,

I work in the Corporate Finance / SOX Compliance group for a public company in Silicon Valley.

We are refining our internal Findings Ranking Framework. We have built it upon the old (but last published edition) Big9 2004 framework, SEC / AS5 guidance, and IIA GAIT guidance.

As SOX audit test result findings come up we rank each individually (with no consideration to mitigating controls) as deficiency, minor finding, or process improvement. We then do a quarterly aggregation on deficiencies to rank as Defic, Sig Defic, or MW and we also consider at this point the mitigating controls and collective deficiencies by account class (revenue, cogs, etc).

Section 404 states that determination should be made that controls are operating effectively "as of year-end". So my question is, if deficiencies were identified during the course of the year but since remediated and retested with a "pass" then should we no longer include these in the periodic aggregations (since they are operating effectively as of "year-end"? IE, aggregations should technically only be done on "open" deficiencies?

Thanks for your opinions on this...
Back to top
View users profile Send email
Igor13
SeniorSoxer
SeniorSoxer


Joined: Oct 03, 2006
Posts: 63
Location: USA

PostPosted: Mon Apr 07, 2008 3:06 pm    Post subject: Reply with quote

Yes, if I understand this scenario correctly, once an issue has been remediated it no longer needs to be evaluated and ranked.
Back to top
View users profile
kymike
SoxGuru
SoxGuru


Joined: Jun 02, 2004
Posts: 636
Location: USA

PostPosted: Tue Apr 08, 2008 6:45 am    Post subject: Reply with quote

I agree
Back to top
View users profile
Denis
SoxGuru
SoxGuru


Joined: Nov 25, 2004
Posts: 787
Location: London, UK

PostPosted: Tue Apr 08, 2008 7:49 am    Post subject: Reply with quote

seconded
_________________
"The art of life is to deal with problems as they arise, rather than destroy one's spirit by worrying about them too far in advance" - Cicero
Back to top
View users profile


Display posts from previous:   
Post new topic   Reply to topic    The Sarbanes Oxley Act Forum Index -> Sarbanes-Oxley: Audit Issues All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©

 
Trademarks referenced on the SOX Act Forum are property of their respective owners. Comments are property of their respective posters.
Sarbanes-Oxley Act Implementation Portal: Sarbanes Oxley compliance, information, software, & internal audit committee resources. Sarbox.
Site source is copyright nuke (c)2003, and is Free Software under the GNU / GPL licence agreement. All Rights Are Reserved.