A Sarbanes-Oxley Roadmap to Business Continuity
|
|
|
- Virgil Garrett
- 9 years ago
- Views:
Transcription
1 A Sarbanes-Oxley Roadmap to Business Continuity NEDRIX Conference June 23, 2004 Dr. Eric Schmidt Control Solutions International TECHNOLOGY ADVISORY, ASSURANCE & RISK MANAGEMENT GROUP
2 Background In July of 2002, U.S. Congress passed the Sarbanes - Oxley Act (SOX) mandating that all public companies (SEC registrants) make changes to the way their financial results are reported. Legislation was a response to the high profile failures experienced in the United States during and intended to be a massive restructuring to the regulatory system governing US capital markets that would improve the quality of financial reporting and disclosures. Public Company Accounting Oversight Board (PCAOB) was created to oversee the activities of the auditing profession.
3 The Sarbanes-Oxley Act contains two Sections (302, 404) dealing with management responsibility for controls and one Section (409) on real-time reporting Internal Controls and Procedures for Financial Reporting Disclosure Controls and Procedures Notes Cash Flow Income Statement Balance Sheet Financial Statements Financial Statements Business Properties Legal Proceeding s Annual Report on Form 10-K Section 404 Section 302
4 Three Sources of SOX Guidelines Frameworks Best Practices Future Standards CobiT COSO
5 Departments Impacted by SOX Finance IT Sales Human Resources Customer Service Marketing Other 100% 95.7% 43.5% 39.1% 30.4% 17.4% 8.7% Source: The Robert Francis Group
6 SOX-Driven Changes Which of the following is the company changing to address SOX? Source: Robert Francis Group Audit Procedures Reporting Procedures Financial Systems Re-training of Personnel Organizational Structure Reporting Frequency Reporting Technologies 78.3 % 52.2% 43.5% 26.1% 21.7% 21.7% 17.4%
7 Complexity of SOX for IT How does SOX compare with other compliance or regulatory projects in IT in terms of complexity and impact of resources and expense? Source: Robert Francis Group Higher Not sure/do Not Know Same Much Higher Lower Slightly Higher 30.4% 26.1% 17.4% 17.4% 4.3% 4.3% 48+% rated SOX impact as higher
8 Does SOX Mandate an Enterprise-wide Business Continuity Process? NO A BCP is not required by PCAOB (March 2004) SAS70 (type 2) 3 rd party service providers AICPA suspended BCP requirement during SOX Growing number of executives influenced by external auditors with knowledge of business continuity and potential risks Conclude they must have business continuity processes or show why they do not
9 Defining Internal Control (IC) Section 404 attestation is based on two assessments Adequate documentation of ICs Sufficient evidence (testing) A company must have a framework against which management can make assertions Completeness Accuracy Validation (authorization) Restriction
10 What s Required for Key Controls Five W s WHO performs the control? WHAT is being done and WHAT could go wrong? WHEN and WHERE is control being performed or occurring? WHY is control activity performed to prevent or detect what? What evidence is there?
11 Why are General Controls Important? Weak General Computer Controls Strong General Computer Controls Automated control procedures, and manual control procedures that use computer-generated information, are dependent on effectiveness of general computer controls.
12 COSO Framework Five Components The process which ensures that relevant information is identified and communicated in a timely manner The evaluation of internal and external factors that impact an organization s performance The process to determine whether internal control is adequately designed, executed, effective and adaptive The policies and procedures that help ensure that actions identified to manage risk are executed and timely The control conscience of an organization. The tone at the top All five components must be in place for a control to be effective
13 Tying It All Together Control Environment Executive Management IT Services OS/Data/Telecom/Continuity/Networks IT General Controls Application Controls Source: IT Governance Institute Business Process Finance Business Process Manufacturing Business Process Logistics Business Process Etc.
14 IT Control Components IT Considerations in Control Environment Systems planning Governance Enterprise policies Operating style Collaboration Information Sharing Code of Conduct Fraud Prevention IT General Controls Systems Security / Access Change Management System Development Computer Operations Application Controls Authorization Configuration / account mapping Exception / edit reports Interface / conversion System access
15 Roadmap to Compliance Tone at the Top Engagement Walk-Thru Assertions (C, A, V, R) Definition of Materiality/Significance Significant Accounts and Processes Scope locations, cycles Control framework Remediation Testing Management certification
16 Roadmap to Compliance Phase I Tone at the Top Identify all relevant documents, policies, procedures and communications Audit Committee Charter Standards of Conduct Officer Code of Ethics Complaint Reporting Mechanisms Whistleblower Policies Assess adequacy of documentation and tone Internal audit monitoring and risk assessment
17 Roadmap to Compliance Phase II Entity Level Assessment Corporate Americas Region Europe Region Rest of World ID material reporting organizations South Carolina Mexico South Carolina Milan Erfurt Budapest Milan China India Thailand China Manufacturing ID material units within each organization Materiality based on: Mexico Sao Paolo San Diego Marseilles Copenhagen Erfurt India Thailand Australia Distribution Revenue / Assets Subjectivity of entries / reporting Chicago Prague Japan Extraordinary / one-time charges History of issues
18 Open Position Personnel Requisition Form Candidate interviewed Prepare Offer Letter Accept Offer Provide Benefits summary to employee Termination Voluntary? 04 No Director of HR Approve Yes Yes Accrued Benefits paid Proper notice given? No 05 Accrued Benefits not paid Create Employee Action Form (EAF) Other P/R changes Department Approval Review by HR 03 Verify Increases within $ pool, properly authorized Input in ADP PR System Annual Increases Included with Annual Review and Approved 02 To PR/PRO Roadmap to Compliance Department Phase III Process Mapping Human Resources Candidate Cycle reviews begin with the cycles selected being based on the legal entity assessment in Phase II. Documentation of each cycle: Narrative of key controls Process Map (Flow chart) Control Matrix including all control objectives (Excel or software tool) Documents aim to provide external audit firms with a complete understanding of the flow of transactions and controls in place.
19 Roadmap to Compliance Phase IV Overall Internal Control Effectiveness Evaluation of the overall effectiveness of internal controls, identification of matters for improvement and the establishment of monitoring systems. Management assessment of effectiveness of controls. Internal Audit provides a report detailing areas for improvement and recommendations for ensuring an environment of continuous monitoring to maintain the system of internal control and take corrective action in a timely manner when necessary. External Audit Firm will commence its Attestation Dry Run
20 Source: SOX Compliance Roadmap
21 Alignment with Business Continuity Management involvement Risk Management Process and Change Management IT role
22 Key Aspects of SOX Audit Segregation of Duties is Key IT roles separate from process owners, specifically those in Finance Hand off from process owners requires control duality Program & Application specific IT & Process owner Manual & Automated Preventative & Detective Change Management is Critical Records and document management Configuration management Business process and controls changes Access Restriction (Security) is Mandated
23 Program Development Project management standards are defined and used for all aspects of system development life cycle (SDLC) Project initiation Analysis and design Construction or package selection Testing and quality assurance Data conversion Go-live Documentation and training
24 Program Changes Project management standards are defined and used for all aspects of the program change cycle Specification, approval and tracking of change requests Construction Testing and quality assurance Authorization of transfers to live environment Including emergency fixes and access to live environment Documentation and training
25 Situational Assessment A recent Deloitte survey of Fortune 500 companies indicates that a significant amount of work remains* Activity Documentation Evaluation of design effectiveness Testing of operating effectiveness Remediation Percentage Complete 75% 47% 21% 21% *Source: Does Your SOX 404 Work Measure Up?, IIA webcast May 25, 2004
26 What Constitutes a Gap? Type Likelihood Magnitude Deficiency Remote and/or Inconsequential Significant Deficiency More than remote and More than Inconsequential or Quantitatively significant Material Weakness More than remote and Material to Financial Statements *Source: Does Your SOX 404 Work Measure Up?, IIA webcast May 25, 2004
27 A Word on Testing Plan carefully to avoid mixed results because tests are not well designed Program Testing Application Testing Infrastructure Testing IT Management and interaction with process owners and stakeholders Functional and transaction based for systems key to financial statements and reporting, plus critical systems Shared services and support systems; OS, networks, backup, etc. Benchmark Testing Slowly changing systems, COTS
28 Remediation Challenges Effective Decision & Governance Process Complex Program Management Initiatives Significant IT Environment Changes Impact on Human Resources Complex Re-testing, Roll-Forward Testing Activities Overall Need for Best Practices
29 Span of Enterprise Risk Management Credit Risk Operational Risk Market Risk Operational Risk Management (ERM) Overall compliance Compliance Integrated solutions SOX Compliance Requirements Sarbanes-Oxley Quarterly Certification by C-Level Management Control Documentation and Testing Control Assurance 409 Real-time Reporting Government Regulations HIPPA Patriot Basel II GLBA FFIEC NRC
30 Risk Management & Business Continuity Disciplines of business continuity and risk management often blurred Use similar tools and techniques, including risk assessment, business continuity planning, and BIAs Business continuity encompasses all processes necessary to restore business functionality during a time of crisis Risk management incorporates a wider variety of functions, including positive impact, negative impact, and business nonstoppage Inherent value of business continuity is clearer when we consider that not all risks can be managed Unless risk management and business continuity are institutionalized into day-to-day activities, organizations will find themselves exposed
31 Questions? Source: John Wehr Source: John Wehr
This article will provide background on the Sarbanes-Oxley Act of 2002, prior to discussing the implications for business continuity practitioners.
Auditing the Business Continuity Process Dr. Eric Schmidt, Principal, Transitional Data Services, Inc. Business continuity audits are rapidly becoming one of the most urgent issues throughout the international
The Importance of IT Controls to Sarbanes-Oxley Compliance
Hosted by Deloitte, PricewaterhouseCoopers and ISACA/ITGI The Importance of IT Controls to Sarbanes-Oxley Compliance 15 December 2003 1 Presenters Chris Fox, CA Sr. Manager, Internal Audit Services PricewaterhouseCoopers
Using COBiT For Sarbanes Oxley. Japan November 18 th 2006 Gary A Bannister
Using COBiT For Sarbanes Oxley Japan November 18 th 2006 Gary A Bannister Who Am I? Who am I & What I Do? I am an accountant with 28 years experience working in various International Control & IT roles.
How To Ensure Internal Control Of Financial Reporting In India
PROTIVITI FLASH REPORT New Internal Control Requirements for Companies with Operations in India November 9, 2015 In the aftermath of major global financial frauds, several countries enacted legislation
Sarbanes-Oxley Compliance Workbook. From Zero to SOX. Sarbanes-Oxley Compliance Workbook. sensiba san filippo www.ssfllp.com sox@ssfllp.
From Zero to SOX Zero to SOX An Overview The goals of a program to meet SOX 404 requirements go far beyond compliance. The process of building a sustainable, comprehensive internal control environment
1. FPO. Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Second Edition
1. FPO Guide to the Sarbanes-Oxley Act: IT Risks and Controls Second Edition Table of Contents Introduction... 1 Overall IT Risk and Control Approach and Considerations When Complying with Sarbanes-Oxley...
TECK RESOURCES LIMITED AUDIT COMMITTEE CHARTER
Page 1 of 7 A. GENERAL 1. PURPOSE The purpose of the Audit Committee (the Committee ) of the Board of Directors (the Board ) of Teck Resources Limited ( the Corporation ) is to provide an open avenue of
COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE
COSO 2013: WHAT HAS CHANGED & STEPS TO TAKE TO ENSURE COMPLIANCE COMMITTEE OF SPONSORING ORGANIZATIONS (COSO) 2013 The Committee of Sponsoring Organizations (COSO) Internal Controls Integrated Framework,
Sarbanes-Oxley Section 404: Management s Assessment Process
Sarbanes-Oxley Section 404: Management s Assessment Process Frequently Asked Questions ADVISORY Contents 1 Introduction 2 Providing a Road Map for Management 3 Questions and Answers 3 Section I. Planning
Guide to the Sarbanes-Oxley Act: IT Risks and Controls. Frequently Asked Questions
Guide to the Sarbanes-Oxley Act: IT Risks and Controls Frequently Asked Questions Table of Contents Page No. Introduction.......................................................................1 Overall
Sarbanes-Oxley Section 404: Compliance Challenges for Foreign Private Issuers
Sarbanes-Oxley Section 404: Compliance s for Foreign Private Issuers Table of Contents Requirements of the Act.............................................................. 1 Accelerated Filer s...........................................................
Sarbanes-Oxley Control Transformation Through Automation
Sarbanes-Oxley Control Transformation Through Automation An Executive White Paper By BLUE LANCE, Inc. Where have we been? Where are we going? BLUE LANCE INC. www.bluelance.com 713.255.4800 [email protected]
The Role of Internal Audit In Business Continuity Planning
The Role of Internal Audit In Business Continuity Planning Dan Bailey, MBCP Page 0 Introduction Dan Bailey, MBCP Senior Manager Protiviti Inc. [email protected] Actively involved in the Information
WHITE PAPER. Sarbanes - Oxley Section 404: How BMC Software Solutions Address General IT Control Requirements
WHITE PAPER Sarbanes - Oxley Section 404: How BMC Software Solutions Address General IT Control Requirements TABLE OF CONTENTS Executive Summary 2 Sarbanes-Oxley Section 404 Internal Controls 3 IT Involvement
Antifraud program and controls assessment grid*
Advisory Services Antifraud program and * Fraud risks & controls February 2008 *connectedthinking 2008 PricewaterhouseCoopers LLP. All rights reserved. PricewaterhouseCoopers refers to PricewaterhouseCoopers
Self-Service SOX Auditing With S3 Control
Self-Service SOX Auditing With S3 Control The Sarbanes-Oxley Act (SOX), passed by the US Congress in 2002, represents a fundamental shift in corporate governance norms. As corporations come to terms with
Industry Sound Practices for Financial and Accounting Controls at Financial Institutions
Industry Sound Practices for Financial and Accounting Controls at Financial Institutions Federal Reserve Bank of New York January 2006 FINANCIAL AND ACCOUNTING CONTROLS: INDUSTRY SOUND PRACTICES FOR FINANCIAL
Guide to Internal Control Over Financial Reporting
Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).
Auditing Standard 5- Effective and Efficient SOX Compliance
Auditing Standard 5- Effective and Efficient SOX Compliance September 6, 2007 Presented to: The Dallas Chapter of the Institute of Internal Auditors These slides are incomplete without the benefit of the
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards
Administrative Guidelines on the Internal Control Framework and Internal Audit Standards GCF/B.09/18 18 February 2015 Meeting of the Board 24 26 March 2015 Songdo, Republic of Korea Agenda item 24 Page
Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future
Sarbanes-Oxley Compliance: Section 404-Past, Present, and Future BADM 590/395 IT Governance MS1 Professor Michael Shaw Submitted by: Amy Smith BA in MIS University of Illinois at Urbana-Champaign Smith
[RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06]
SECURITIES AND EXCHANGE COMMISSION 17 CFR PART 241 [RELEASE NOS. 33-8810; 34-55929; FR-77; File No. S7-24-06] Commission Guidance Regarding Management s Report on Internal Control Over Financial Reporting
Impact of New Internal Control Frameworks
Impact of New Internal Control Frameworks Webcast: Tuesday, February 25, 2014 CPE Credit: 1 0 With You Today Bob Jacobson Principal, Risk Advisory Services Consulting Leader West Region [email protected]
Ten Steps to SOX Compliance for Smaller Public Companies
Presented by: Bob Benoit Lord & Benoit, LLC One West Boylston St. Worcester, MA 01605 (508) 853-6404 Ten Steps to SOX Compliance for Smaller Public Companies Team IT Controls Timeline Effectiveness Of
IT Governance Dr. Michael Shaw Term Project
IT Governance Dr. Michael Shaw Term Project IT Auditing Framework and Issues Dealing with Regulatory and Compliance Issues Submitted by: Gajin Tsai [email protected] May 3 rd, 2007 1 Table of Contents: Abstract...3
Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors)
Special Considerations---Audits of Group Financial Statements 607 AU-C Section 600 Special Considerations Audits of Group Financial Statements (Including the Work of Component Auditors) Source: SAS No.
Charter of the Audit Committee of the Board of Directors
Charter of the Audit Committee of the Board of Directors Dated as of April 27, 2015 1. Purpose The Audit Committee is a committee of the Board of Directors (the Board ) of Yamana Gold Inc. (the Company
Internal Control over Financial Reporting Guidance for Smaller Public Companies
Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked Questions Internal Control over Financial Reporting Guidance for Smaller Public Companies Frequently Asked
COSO 2013 Internal Control Framework
COSO 2013 Internal Control A Guide to Implementation July 24, 2014 Justin Adamson Agenda COSO Background Changes to the Roadmap to Implementation Implementation Considerations & Lessons Learned 2 1 Who/What
HALOZYME THERAPEUTICS, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS ORGANIZATION AND MEMBERSHIP REQUIREMENTS
HALOZYME THERAPEUTICS, INC. CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS I. STATEMENT OF POLICY The Audit Committee (the Committee ) of the Board of Directors (the Board ) of Halozyme Therapeutics,
Internal Control Strategies. A Mid to Small Business Guide
Brochure More information from http://www.researchandmarkets.com/reports/2325460/ Internal Control Strategies. A Mid to Small Business Guide Description: Praise for Internal Control Strategies A Mid to
COSO Internal Control Integrated Framework (2013)
COSO Internal Control Integrated Framework (2013) The Committee of Sponsoring Organizations of the Treadway Commission (COSO) released its updated Internal Control Integrated Framework (2013 Framework)
An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements
Examination of an Entity s Internal Control 1403 AT Section 501 An Examination of an Entity s Internal Control Over Financial Reporting That Is Integrated With an Audit of Its Financial Statements Source:
SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners
SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners SARBANES-OXLEY SECTION 404: A Guide for Management by Internal Controls Practitioners The Institute of Internal Auditors
Internal Auditing Guidelines
Internal Auditing Guidelines Recommendations on Internal Auditing for Lottery Operators Issued by the WLA Security and Risk Management Committee V1.0, March 2007 The WLA Internal Auditing Guidelines may
AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN AUDIT OF FINANCIAL STATEMENTS:
1666 K Street, NW Washington, D.C. 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STAFF VIEWS AN AUDIT OF INTERNAL CONTROL OVER FINANCIAL REPORTING THAT IS INTEGRATED WITH AN
OUTSOURCING AND SERVICE AUDITOR S REPORTS
OUTSOURCING AND SERVICE AUDITOR S REPORTS FREEDOM TO DO BUSINESS Outsourcing and service Auditor s Reports 3 OUTSOURCING AND SERVICE AUDITOR S REPORTS SERVICE AUDITOR S REPORTS ARE GROWING IN IMPORTANCE,
AUDIT COMMITTEE CHARTER
AUDIT COMMITTEE CHARTER Purpose The Audit Committee ( Committee ) shall assist the Board of Directors (the Board ) in the oversight of (1) the integrity of the financial statements of the Company, (2)
Audit of the Test of Design of Entity-Level Controls
Audit of the Test of Design of Entity-Level Controls Canadian Grain Commission Audit & Evaluation Services Final Report March 2012 Canadian Grain Commission 0 Entity Level Controls 2011 Table of Contents
BOTTOMLINE TECHNOLOGIES (DE), INC. AUDIT COMMITTEE CHARTER
BOTTOMLINE TECHNOLOGIES (DE), INC. AUDIT COMMITTEE CHARTER A. Purpose The purpose of the Audit Committee is to assist the Board of Directors oversight of: the Company s accounting and financial reporting
Navigating the Standards for Information Technology Controls
Navigating the Standards for Information Technology Controls By Joseph B. O Donnell and Yigal Rechtman JULY 2005 - Pervasive use of computers, along with recent legislation such as the Sarbanes- Oxley
Saldanha Bay Municipality. Risk Management Strategy. Inclusive of, framework, procedures and methodology
Inclusive of, framework, procedures and methodology Contents 1 Introduction 1 1.1 Legislative Framework and best practice 1 1.2 Purpose of Enterprise Risk Management 2 1.3 Scope and Applicability 3 1.4
Asset Manager Guide to SAS 70. Issue Date: October 7, 2007. Asset
Asset Manager Guide to SAS 70 Issue Date: October 7, 2007 Asset Management Group A s s e t M a n a g e r G u i d e SAS 70 Table of Contents Executive Summary...3 Overview and Current Landscape...3 Service
High Value Audits: An Update on Information Technology Auditing. Robert B. Hirth Jr., Managing Director
High Value Audits: An Update on Information Technology Auditing Robert B. Hirth Jr., Managing Director The technology landscape and its impact on internal audit Technology is playing an ever-growing role
Assessing the Adequacy and Effectiveness of a Fund s Compliance Policies and Procedures. December 2005
Assessing the Adequacy and Effectiveness of a Fund s Compliance Policies and Procedures December 2005 Copyright 2005 Investment Company Institute. All rights reserved. Information may be abridged and therefore
B o a r d of Governors of the Federal Reserve System. Supplemental Policy Statement on the. Internal Audit Function and Its Outsourcing
B o a r d of Governors of the Federal Reserve System Supplemental Policy Statement on the Internal Audit Function and Its Outsourcing January 23, 2013 P U R P O S E This policy statement is being issued
Fraud and Role of Information Technology. September 2008
Fraud and Role of Information Technology September 2008 Agenda IT Value Proposition Slide 2 Prior Interpretations of Internal Control Structure Have Addressed Three Separate Parts Which Were Audited Somewhat
Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies
Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Sarbanes-Oxley Section 404 Implementation Practices of Leading Companies Dr. Robert A. Howell Distinguished Visiting Professor of
Guide to Public Company Auditing
Guide to Public Company Auditing The Center for Audit Quality (CAQ) prepared this Guide to Public Company Auditing to provide an introduction to and overview of the key processes, participants and issues
Regulatory Compliance Management (RCM) (formerly Legislative Compliance Management (LCM))
Guideline Subject: Category: (RCM) (formerly Legislative Compliance Management (LCM)) Sound Business & Financial Practices No: E-13 Date: November 2014 I. Purpose and Scope of the Guideline The purpose
February 2015. Sample audit committee charter
February 2015 Sample audit committee charter Sample audit committee charter This sample audit committee charter is based on observations of selected companies and the requirements of the SEC, the NYSE,
What Should IS Majors Know About Regulatory Compliance?
What Should IS Majors Know About Regulatory Compliance? Working Paper Series 08-12 August 2008 Craig A. VanLengen Professor of Computer Information Systems/Accounting Northern Arizona University The W.
Achieving Business Imperatives through IT Governance and Risk
IBM Global Technology Services Achieving Business Imperatives through IT Governance and Risk Peter Stremus Internet Security Systems, an IBM Company Introduction : Compliance Value Over the past 15 years
Communicating Internal Control Related Matters Identified in an Audit
Communicating Internal Control 1843 AU Section 325 Communicating Internal Control Related Matters Identified in an Audit (Supersedes SAS No. 112.) Source: SAS No. 115. Effective for audits of financial
Audit of the Policy on Internal Control Implementation
Audit of the Policy on Internal Control Implementation Natural Sciences and Engineering Research Council of Canada Social Sciences and Humanities Research Council of Canada February 18, 2013 1 TABLE OF
Sarbanes-Oxley 404. Sarbanes-Oxley Background. SOX 404 Internal Controls. Goals of Sarbanes-Oxley
Sarbanes-Oxley Background Sarbanes-Oxley 404 Internal Controls in Financial Reporting: Implications for Actuaries Legislation passed July 30, 2002 Applies to GAAP financial statements filed with SEC Effective
Charter of the Audit Committee of the Board of Directors of Woodward, Inc.
AUDIT COMMITTEE CHARTER Charter of the Audit Committee of the Board of Directors of Woodward, Inc. Purpose The Audit Committee (the Committee ) is appointed by the Board of Directors to oversee the accounting
Transmittal Letter... 1. Objectives and Scope... 2. Approach... 3-7. Financial System... 8. Permitting Application... 9
Internal Audit Committee of Information Technology Risk Assessment Public Report Prepared By: Internal Auditors of Brevard County September 30, 2009 Table of Contents Transmittal Letter... 1 Objectives
STANDING ADVISORY GROUP MEETING INITIATIVES TO IMPROVE AUDIT QUALITY ROOT CAUSE ANALYSIS, AUDIT QUALITY INDICATORS, AND QUALITY CONTROL STANDARDS
1666 K Street, NW Washington, DC 20006 Telephone: (202) 207-9100 Facsimile: (202) 862-8430 www.pcaobus.org STANDING ADVISORY GROUP MEETING INITIATIVES TO IMPROVE AUDIT QUALITY ROOT CAUSE ANALYSIS, AUDIT
PwC Advisory Internal Audit. PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley*
PwC Advisory Internal Audit PricewaterhouseCoopers State of the internal audit profession study: internal audit post Sarbanes-Oxley* Table of Contents Overview 02 As demands on internal audit escalate,
Audit Committee Charter Altria Group, Inc. In the furtherance of this purpose, the Committee shall have the following authority and responsibilities:
Audit Committee Charter Altria Group, Inc. Membership The Audit Committee (the Committee ) of the Board of Directors (the Board ) of Altria Group, Inc. (the Company ) shall consist of at least three directors
Risk Management Advisory Services, LLC Capital markets audit and control
Risk Management Advisory Services, LLC Capital markets audit and control November 14, 2003 Office of the Secretary Public Company Accounting Oversight Board 1666 K Street, N.W. Washington, D.C., 20006-2803
COSO Enterprise Risk Management. Establishing Effective Governance, Risk, and Compliance (GRC) Processes. 2nd Edition. Wiley Corporate F&A
Brochure More information from http://www.researchandmarkets.com/reports/2220031/ COSO Enterprise Risk Management. Establishing Effective Governance, Risk, and Compliance (GRC) Processes. 2nd Edition.
The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies
The Upside of Risk: Enterprise Risk Management and Public Real Estate Companies James Barkley, Simon Property Group, Inc. and David E. Weiss, DDR Corp. Introduction: As lawyers, particularly real estate
Guidance Note: Corporate Governance - Board of Directors. March 2015. Ce document est aussi disponible en français.
Guidance Note: Corporate Governance - Board of Directors March 2015 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance
CVS HEALTH CORPORATION A Delaware corporation (the Company ) Audit Committee Charter Amended as of September 24, 2014
CVS HEALTH CORPORATION A Delaware corporation (the Company ) Audit Committee Charter Amended as of September 24, 2014 Purpose The Audit Committee (the Committee ) is created by the Board of Directors of
Vendor Risk Management Financial Organizations
Webinar Series Vendor Risk Management Financial Organizations Bob Justus Chief Security Officer Allgress Randy Potts Managing Consultant FishNet Security Bob Justus Chief Security Officer, Allgress Current
BAKER HUGHES INCORPORATED. CHARTER OF THE AUDIT/ETHICS COMMITTEE OF THE BOARD OF DIRECTORS (as amended and restated October 24, 2012)
BAKER HUGHES INCORPORATED CHARTER OF THE AUDIT/ETHICS COMMITTEE OF THE BOARD OF DIRECTORS (as amended and restated October 24, 2012) The Board of Directors of Baker Hughes Incorporated (the Company ) has
Developing Effective Internal Controls Using the COSO Model
Developing Effective Internal Controls Using the COSO Model Office of State Controller Internal Controls in a COSO Environment Seminar Raleigh, North Carolina March 2007 Mark S. Beasley Director, ERM Initiative
Enterprise risk management: A pragmatic, four-phase implementation plan
Enterprise risk management: A pragmatic, four-phase implementation plan Prepared by: John Brackett, Managing Director, Risk Advisory Services, RSM McGladrey, Inc. 704.442.3820, [email protected]
FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE
FIRST CITIZENS BANCSHARES, INC. FIRST-CITIZENS BANK & TRUST COMPANY CHARTER OF THE JOINT AUDIT COMMITTEE As amended, restated, and approved by the Boards of Directors on July 28, 2015 This Charter sets
Implementing Internal Controls over Executive Compensation Creating a Sustainable Compensation Control Environment
NASPP Implementing Internal Controls over Executive Compensation Creating a Sustainable Compensation Control Environment Michael S. Kesner, Principal Sustainable Compensation Control Environment Tone At
Establishing a Quality Assurance and Improvement Program
Chapter 2 Establishing a Quality Assurance and Improvement Program O v e rv i e w IIA Practice Guide, Quality Assurance and Improvement Program, states that Quality should be built in to, and not on to,
Policy 10.105: Enterprise Risk Management Policy
Name: Responsibility: Complements: Enterprise Risk Management Framework Coordinator, Enterprise Risk Management Policy 10.105: Enterprise Risk Management Policy Date: November 2006 Revision Date(s): January
CFE 2. Enterprise Risk Management. Study Guide - Supplemental Background Material
P a g e 1 CFE 2 Enterprise Risk Management Study Guide - Supplemental Background Material The passing score for this test is 74% Reference Guides: Enterprise Risk Management Best Practices: From Assessment
Outsourcing & Regulatory Compliance Risks
Outsourcing & Regulatory Compliance Risks By Matthew Sullivan Today s marketplace dictates that Financial Services Institutions (FSIs) consider using offshore IT services to remain competitive. However,
SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT
SECTION B DEFINITION, PURPOSE, INDEPENDENCE AND NATURE OF WORK OF INTERNAL AUDIT Through CGIAR Financial Guideline No 3 Auditing Guidelines Manual the CGIAR has adopted the IIA Definition of internal auditing
Sarbanes-Oxley Section 404 Compliance: A Guiding Framework using igrafx SOX Accelerator
Sarbanes-Oxley Section 404 Compliance: A Guiding Framework using igrafx SOX Accelerator 2007 Corel Corporation. All Rights Reserved. Table of Contents Introduction...P - 1 Using igrafx for SOX Compliance...P
RISK BASED AUDITING: A VALUE ADD PROPOSITION. Participant Guide
RISK BASED AUDITING: A VALUE ADD PROPOSITION Participant Guide About This Course About This Course Adding Value for Risk-based Auditing Seminar Description In this seminar, we will focus on: The foundation
Governance SPICE. ISO/IEC 15504 for Internal Financial Controls and IT Management. By János Ivanyos, Memolux Ltd. (H)
Governance SPICE ISO/IEC 15504 for Internal Financial Controls and IT Management By János Ivanyos, Memolux Ltd. (H) 1. Evaluating Internal Controls against Governance Frameworks Corporate Governance is
How Perforce Can Help with Sarbanes-Oxley Compliance
How Perforce Can Help with Sarbanes-Oxley Compliance C. Thomas Tyler Chief Technology Officer, The Go To Group, Inc. In collaboration with Perforce Software Perforce and Sarbanes-Oxley The Sarbanes-Oxley
Oceaneering International, Inc. Audit Committee Charter
Oceaneering International, Inc. Audit Committee Charter Purpose The Audit Committee of the Board of Directors (the Committee ) is appointed by the Board of Directors (the Board ) to assist the Board in
AMPLIFY SNACK BRANDS, INC. AUDIT COMMITTEE CHARTER. Adopted June 25, 2015
AMPLIFY SNACK BRANDS, INC. AUDIT COMMITTEE CHARTER Adopted June 25, 2015 I. General Statement of Purpose The purposes of the Audit Committee of the Board of Directors (the Audit Committee ) of Amplify
