XML Feeds

Search Big4Guy

Custom Search

Sponsored

« Account Generator Creating Flexfield Combinations in Oracle GL TutorialTesting Protocols for Sarbanes Oxley 404 »

Evaluating Third Party Controls for SOX Compliance

Evaluating Third Party Controls for SOX Compliance

Many organizations outsource some of their core processes to third party companies. These might be business or knowledge process outsourcing units. A relevant question here is that how does such outsourcing of critical business activities affect Sarbanes Oxley compliance. The new auditing standard 5 issued by the PCAOB requires the statutory auditor to obtain a SAS 70 report i.e. a service auditor's report on controls placed in operation and their operating effectiveness. The auditor needs to
evaluate thereport to see whether it provides sufficient evidence in support of his opinion.

While the auditor evaluates this report, it is important that the auditor considers certain important factors such as:

1. The scope of the controls and the applications covered, the controls that were tested and the way in which such controls relate to the company's controls.

2. Time period covered by the SAS 70 report, and its relation to the date of management's assessment of internal control.

3. The final opinion given in the SAS 70 report i.e. the results of the test of controls and the service auditors opinion on the operating effectiveness of controls.

Related Posts

How to Conduct SAS 70 Audits
SAS 70 Type II Report
SOX Document Retention Requirements
SOX Research Papers


Permalink 01/11/07 06:58:58 am , by big4guy Email , 266 views, Sarbanes Oxley, Leave a comment »

Feedback awaiting moderation

This post has 30 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)