Skip the navigation
Opinion

Is Sarbanes-Oxley All Bad?

By Steven Lindseth
April 15, 2004 12:00 PM ET

Computerworld - Finding the Sarbanes-Oxley Act as difficult to swallow as bad-tasting medicine, many companies question the need for it. They might better question why it took an act of Congress to get companies to list and track the performance of their material risks and associated control procedures, activities that are fundamental to running a good business.
Sarbanes-Oxley raises even bigger questions: Is your company really organized when it comes to managing overall governance, risk and compliance (GRC)? Doesn't compliance encompass more than accounting controls? (Enron wasn't an accounting problem; it was a business and ethics problem. Accounting was just the means to perpetrate the crime.) And once a company is organized to manage GRC, how does it leverage technology that enables truly effective and efficient GRC management?
Seize the Opportunity
Is Sarbanes-Oxley all bad? Not when it makes compliance management visible at the highest organizational levels. The COSO framework, the underpinning of Sarbanes-Oxley's internal control requirements, isn't a vast conspiracy to enrich accounting firms. Many, if not most, risk-related processes in a company may be poorly run for the simple reason that they have been viewed as a burden and not a driver of revenue. As a result, most compliance activities have been seen as bothersome necessities rather than as strategic imperatives. COSO provides the guidelines to enhance compliance processes.
Rather than railing about compliance and regulatory requirements, companies should use this time to define a GRC strategy. Companies that execute this strategy as rapidly as possible can increase competitive advantage, whereas companies mired in risk avoidance will be left far behind.
Compliance is friction in your organization, and the friction has gotten bad -- more regulations, more scrutiny and enforcement, and more time spent by your employees doing what for most is an adjunct to their primary job of attracting and retaining customers. But companies with well-run compliance processes (with applied resources and executive commitment) enjoy share-price premiums, competitive advantage, improved morale and reduced risk of being tomorrow's corporate scandal headline. How do successful companies transform GRC management into a real driver of business performance? They leverage the substantial effort and cost tied to Sarbanes-Oxley for all compliance issues.
Richard Steinberg, the founder of Steinberg Governance Advisors Inc., was one of the principal PricewaterhouseCoopers authors of the COSO Internal Control -- Integrated Framework and is an internationally recognized expert on corporate governance, internal control and enterprise risk management. According to Steinberg, "Some of the companies I'm working with are not seeking merely to comply with the Sarbanes-Oxley requirements and viewing



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Management and Careers White Papers
The CFO Guide to Budgeting Software
A mid-sized business needs the same financial performance control and measurement capabilities as a large corporation, but in a solution that's affordable, easy...
Transition from Spreadsheet Budgets to Packaged Application
This white paper details the problems that go with spreadsheet-based budgeting as well as the advantages of packaged applications. It also proposes a...
Better Cash Flow Management: Recession-Proof Your Business
Cash is the lifeblood of most small to mid-sized organizations. So why rely on error-prone spreadsheets for forecasting cash flow and risk making...
Centage/IOMA Budgeting Survey: Benchmarks and Issues
How are other financial professionals dealing with the issues you face? This report offers you an inside peak into what the minds at...
Is Your Database Ready For Your Company's Future?
This brochure is targeted to executives and will cover all the business benefits of DB2.
All Management and Careers White Papers
Management and Careers Webcasts
Live Webcast
A Geek's Guide to Presenting to Business People
Live Webcast: Wednesday, June 20th at 1:00 PM EDT

Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to...
Operational Analytics - Changing the Competitive Dynamics of the Business
Date/Time: June 5, 2012, 11:00 a.m., EDT, 4:00 p.m. BST / 3:00 p.m. UTC

Please join us for this webcast, as Dr. Barry...
A Geek's Guide to Presenting to Business People
Live Webcast: Wednesday, June 20th at 1:00 PM EDT

Join this live webinar with Paul Glen, author of Leading Geeks, to learn how to...
Shifting Application Dynamics Impact Performance Management
Curtis Franklin, Contributing Editor at InformationWeek, interviews Alain Cohen, OPNET's President and CTO, regarding trends in application performance management (APM), how organizations are...
Integrated IT Operations Management in the Cloud
Join award-winning technology editor Stan Gibson and Andrew White, CMO at BMC, to learn how asset management and service management are converging and...
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
All Management and Careers Webcasts
IT Salaries 2012
2012 Salary Survey

How does your salary compare with your peers? Find out using our Smart Salary Tool.

Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs