New guidance for IT aspects of Sarbox
The strength of information technology systems when it comes to section 404 has a bitter bone of contention since Sarbanes-Oxley was enacted. Auditors, to the frustration of clients, have spent a lot of time trying to assess the strength of various controls, often relying on outdated guidance from the likes of COSO and COBIT. With AS5 released, the Institute of Internal Auditors (IIA) has released its anticipated guidance, which hopefully will put companies and auditors on the same page regarding IT. The guidance does not specify which systems are necessary across the board but rather offers aid for companies to determine which are necessary for its specific circumstances. This is in keeping with the recent reform measures. Some think it will give companies ammunition to confront their auditors, if the auditors are still taking the cover-your-butt approach.
For more:
- here's an article from CFO.com

