Is Sarbanes-Oxley All Bad?
Computerworld -
Finding the Sarbanes-Oxley Act as difficult to swallow as bad-tasting medicine, many companies question the need for it. They might better question why it took an act of Congress to get companies to list and track the performance of their material risks and associated control procedures, activities that are fundamental to running a good business.
Sarbanes-Oxley raises even bigger questions: Is your company really organized when it comes to managing overall governance, risk and compliance (GRC)? Doesn't compliance encompass more than accounting controls? (Enron wasn't an accounting problem; it was a business and ethics problem. Accounting was just the means to perpetrate the crime.) And once a company is organized to manage GRC, how does it leverage technology that enables truly effective and efficient GRC management?
Seize the Opportunity
Is Sarbanes-Oxley all bad? Not when it makes compliance management visible at the highest organizational levels. The COSO framework, the underpinning of Sarbanes-Oxley's internal control requirements, isn't a vast conspiracy to enrich accounting firms. Many, if not most, risk-related processes in a company may be poorly run for the simple reason that they have been viewed as a burden and not a driver of revenue. As a result, most compliance activities have been seen as bothersome necessities rather than as strategic imperatives. COSO provides the guidelines to enhance compliance processes.
Rather than railing about compliance and regulatory requirements, companies should use this time to define a GRC strategy. Companies that execute this strategy as rapidly as possible can increase competitive advantage, whereas companies mired in risk avoidance will be left far behind.
Compliance is friction in your organization, and the friction has gotten bad -- more regulations, more scrutiny and enforcement, and more time spent by your employees doing what for most is an adjunct to their primary job of attracting and retaining customers. But companies with well-run compliance processes (with applied resources and executive commitment) enjoy share-price premiums, competitive advantage, improved morale and reduced risk of being tomorrow's corporate scandal headline. How do successful companies transform GRC management into a real driver of business performance? They leverage the substantial effort and cost tied to Sarbanes-Oxley for all compliance issues.
Richard Steinberg, the founder of Steinberg Governance Advisors Inc., was one of the principal PricewaterhouseCoopers authors of the COSO Internal Control -- Integrated Framework and is an internationally recognized expert on corporate governance, internal control and enterprise risk management. According to Steinberg, "Some of the companies I'm working with are not seeking merely to comply with the Sarbanes-Oxley requirements and viewing
Additional Resources


White Papers & Webcasts
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
The Shortcut Guide to Managing Certificate Lifecycles
(Source: Thawte) If you have ever shopped for a certificate, you know that there is a wide selection of products and vendors from...
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
MarketVibe: Communications and Collaboration Needs at Business Organizations
In April 2009, IT and business leaders were invited to participate in a survey on business communications and collaboration solutions. The goal of...
Modernizing the IT Infrastructure
(Source: Oracle) There is a lot of legacy in many government IT systems today - legacy hardware, legacy software platforms, and legacy skills...
The Value of Network and Application Visibility by Aberdeen
This survey-based paper analyzes best practices for improving application visibility and analysis. This paper can help serve as a guideline for organizations looking...
Taking the Service Desk to the Next Level
Listen to this conversation with Doug Mueller to learn how standards and processes have evolved to bring us the service desk of today...
Subscribe to Computerworld
