SOX 404-compliant ERP System Internal Control Framework - The Preliminary Outcome

نویسندگان

  • She-I Chang
  • Derek Jan
چکیده

After the enactment of the Sarbanes-Oxley Act (SOX), the importance of related issues, such as internal controls and information security, has greatly increased. In the first stage of this research, the grounded theory methodology is adopted to explore the necessary internal controls in Information Technology (IT) systems. The control criteria are mapped out in the Criteria for Establishment of Internal Control framework. In the second stage, a case study will conduct to verify the feasibility of the first established framework. This paper eventually offers a 12dimensional preliminary framework with a total of 37 control items to provide auditors with the capacity to perform effective audits by inspecting the essential internal control points in Enterprise Resource Planning (ERP) systems. Furthermore, it suggests that companies refer to this framework and consider the limitations of their own IT management in order to establish a robust IT management mechanism.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

SOX, compliance and power relationships: Tactics for the CIO

Chief Information Officers (CIOs) around the globe are being drawn into the implementation of Sarbanes Oxley (SOX) compliance. According to the Public Company Accounting Oversight Board (PCAOB) (www.pcaob-us.org) , 15,000 US companies, 1,200 non-US based companies and 1,423 accounting firms spread across 76 countries are affected by SOX. In particular, Section 404 (404), which deals with manage...

متن کامل

Title: Internal Control Framework of a Compliant Erp System Internal Control Framework of a Compliant Erp System

After the occurrence of numerous worldwide financial scandals, the importance of related issues such as internal control and information security has greatly increased. An internal control framework that can be applied within an enterprise resource planning (ERP) system is developed in this study. A literature review is first conducted to examine the necessary forms of internal control in infor...

متن کامل

Does SOX 404 Have Teeth? Consequences of the Failure to Report Existing Internal Control Weaknesses

We identify a sample of firms with restatements attributable to underlying control weaknesses, some which had previously reported these weaknesses as required by SOX 404 and some of which acknowledged them only after announcing the related restatement. We then examine whether various penalties that could serve as enforcement mechanisms for SOX 404 differ across these two groups. We find no evid...

متن کامل

The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity

The Sarbanes-Oxley Act (SOX) mandates management evaluation and independent audits of internal control effectiveness. The mandate is costly to firms but may yield benefits through lower information risk that translates into lower cost of equity. We use unaudited pre-SOX 404 disclosures and SOX 404 audit opinions to assess how changes in internal control quality affect firm risk and cost of equi...

متن کامل

Internal control framework for a compliant ERP system

After the occurrence of numerous worldwide financial scandals, the importance of related issues such as internal control and information security has greatly increased. This study develops an internal control framework that can be applied within an enterprise resource planning (ERP) system. A literature review is first conducted to examine the necessary forms of internal control in information ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010