Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Sox Compliance Solution


Published on

SOX Compliance Solution

Sox Compliance Solution

  1. 1. Addressing Sarbanes-Oxley Challenges with the Microsoft Office System Gerald Walker Interactive America, Inc. [email_address]
  2. 2. Executive Summary <ul><li>Market Opportunity </li></ul><ul><ul><li>The Sarbanes-Oxley Act directly affects over 14,000 public companies </li></ul></ul><ul><ul><li>Additional opportunity with companies that do business with 14,000 public companies </li></ul></ul><ul><ul><li>A Microsoft Office System-based solution is appropriate for any organization with over 500 desktop computers </li></ul></ul><ul><li>Key Capabilities of the Microsoft Office System That Address Customers’ SOX Challenges </li></ul><ul><ul><li>Document and information management </li></ul></ul><ul><ul><li>Process automation </li></ul></ul><ul><ul><li>Communication and collaboration </li></ul></ul><ul><ul><li>Monitoring and reporting </li></ul></ul><ul><li>Partner Value Add </li></ul><ul><ul><li>System integrators: Integration with and enhancement of existing financial systems, installation, training, technical support, and project management. </li></ul></ul><ul><ul><li>Independent software vendors: Sox-specific add-ons and enhancements of existing financial and compliance systems. </li></ul></ul><ul><li>Call to Action </li></ul><ul><ul><li>Build solutions based on the Microsoft Office System </li></ul></ul><ul><ul><li>Leverage the Solution Showcase to increase exposure </li></ul></ul>The Solution Showcase for the Microsoft Office System highlights how leading organizations use the Microsoft Office System to solve important business problems .  
  3. 3. Agenda <ul><li>Solution Showcase Overview </li></ul><ul><li>Sarbanes-Oxley Background and Opportunity </li></ul><ul><li>Customer Challenges </li></ul><ul><li>Sample Solution </li></ul><ul><li>Partner Value-Add Opportunities </li></ul><ul><li>Using the Microsoft Office System </li></ul><ul><li>Partner References </li></ul><ul><li>Conclusions and Next Steps </li></ul>
  4. 4. Solution Showcase Overview <ul><li>The Solution Showcase for the Microsoft Office System highlights how leading organizations use the Microsoft Office System to solve important business problems </li></ul>Overall Objectives Increase customer value from existing Microsoft Office System investments Increase the viability of building a business using the Microsoft Office System Increase the relevance of the Microsoft Office System as a must-have component of solutions Strategies to Support the Objectives <ul><li>Generate customer demand for the Microsoft Office System by showing what is possible with Microsoft Office System solutions. </li></ul><ul><li>Help partners create solutions using the latest version of the Microsoft Office System, and feature these solutions in the Solution Showcase. </li></ul>Customer Partner Microsoft
  5. 5. Solution Showcase Partner Benefits Showcase your solutions Reach potential customers by having your solutions in the Solution Showcase on the Microsoft Web site. Highlight Microsoft Office System-based solutions and capabilities to the Microsoft sales force and Microsoft marketing teams. See illustrative examples of how to use the Microsoft Office System to solve customer business problems. Sell more effectively with Microsoft Office System solutions sales materials.
  6. 6. SOX in the Context of Compliance COMPLIANCE Sarbanes-Oxley Fiscal accountability for all public companies Basel II Capital assessment and reporting standards for global banking U.S. PATRIOT Act Customer documentation requirements in order to “know your customer ” DoD 5015.2 and UK PRO Federal standards of records management Health Insurance Portability Accountability Act (HIPAA) NASD 3110 Written policies and procedures for review of correspondence with the public All records related to securities transactions to be maintained for 3 years Gramm-Leach Bliley Act (GLBA) Privacy of financial information Right to carry insurance between jobs; privacy of patient information SEC Rules 17a-3 & 17a-4
  7. 7. Sarbanes-Oxley Act of 2002 <ul><li>The Most Sweeping Corporate Reform Legislation since the 1930’s </li></ul><ul><li>Amends certain provisions of Securities and Exchange Act of 1934 </li></ul><ul><li>Aims to Restore Investor Confidence </li></ul><ul><li>Effects: </li></ul><ul><ul><li>Corporate Governance Regulations </li></ul></ul><ul><ul><li>Corporate Compliance Activities </li></ul></ul><ul><ul><li>All US firms above 75M. </li></ul></ul><ul><ul><li>All Non US Firms with SEC Registration </li></ul></ul>
  8. 8. Sarbanes in Brief <ul><li>Requires Corporations to Document the Financial Statement Close Processes and Controls </li></ul><ul><li>Requires Audit Testing of Controls and Validation of the Environment </li></ul><ul><li>Provides Government Regulators (Prosecutors) More Power and Additional Tools to Punish Corporate Malfeasance </li></ul><ul><li>Prescribes additional penalties for wrongdoing </li></ul><ul><li>Establishes a New Watchdog over the Public Accounting Profession </li></ul><ul><ul><li>– Public Company Oversight Accounting Board (PCOAB) –Power to Sanction Accounting Firms </li></ul></ul>
  9. 9. The Sarbanes-Oxley Act of 2002 <ul><li>SOX affects public companies listed on United States stock exchanges, including foreign companies </li></ul><ul><li>SOX mandates fiscal accountability </li></ul><ul><li>A complex undertaking: </li></ul><ul><ul><li>11 new compliance titles </li></ul></ul><ul><ul><li>90+ individual legal sections </li></ul></ul><ul><ul><li>Over 1,000 subsequent filings, interpretations, and petitions since 7/02 </li></ul></ul>Section 302 requires executives to personally certify the validity of financial statements Section 404 requires complete documentation of internal controls and procedures for financial reporting, as well as auditor attestation
  10. 10. Sarbanes-Oxley: Market Opportunity <ul><li>Fortune 100 companies each spend $5–$7 million on compliance </li></ul><ul><li>Directly affects over 14,000 United States-listed companies </li></ul><ul><li>Future growth opportunity </li></ul><ul><ul><li>Private and foreign companies wanting to do business with public companies in the United States </li></ul></ul><ul><ul><li>Sarbanes-Oxley Act compliance viewed as competitive necessity </li></ul></ul><ul><li>Market dynamics </li></ul><ul><ul><li>Technology spending related to SOX compliance was estimated at over $1 billion in 2004. </li></ul></ul><ul><ul><li>26 percent of IT and business executives say that government compliance mandates will continue to be the focus of IT spending in 2005. </li></ul></ul>Sources: AMR Research Report, “2004 Sarbanes-Oxley Spending and Project Planning Trends,” February 2004 AMR Research Report, “Bare Minimum Versus Improved Business: Spend Compliance Money Well,” December 2004 Global Sox Expenditure (In Billions)
  11. 11. <ul><li>Over 14,000 public and non-public companies are actively working to reduce risk and comply with the Sarbanes-Oxley Act </li></ul><ul><li>Legal actions, accounting reviews, and manual control documentation steps have been taken by many </li></ul><ul><li>AMR estimates $6.2B in SOX spending in 2005 </li></ul><ul><li>Typical Fortune 500 company will spend additional $3M+ annually </li></ul><ul><li>Companies balancing the normal competitive pressures with new pressures </li></ul><ul><li>Most are now realizing the scope of work and effort required to comply is greater than anticipated </li></ul>Urgency of Sarbanes-Oxley Deadlines are approaching
  12. 12. Consequences of Compliance <ul><li>Legally mandated changes in corporate governance, auditing, and business practices </li></ul>A New Way of Doing Business Accelerated discovery, validation, and disclosure of financial information High risks of non-compliance Limited resources, time, and budgets available for compliance initiatives
  13. 13. Does this Sound Familiar? “… documents are lost in e-mail.” “… how can I monitor status across the company?” “ If we had better visibility of our processes….” “… no time to learn new software.” “ We need one integrated system…” “ Is our financial data secure?”
  14. 14. Sox Business Problem <ul><li>Meeting requirements of SOX Sections 302/404 </li></ul><ul><li>Scheduling and automating the workflow of compliance initiatives </li></ul><ul><li>Managing exposure to business risk </li></ul><ul><li>Demonstrating financial transparency and good corporate governance </li></ul><ul><li>Building a corporate governance infrastructure that is cost-effective, easy to deploy, and easy to use </li></ul>Proactively manage disclosure and control processes for your organization
  15. 15. Microsoft Supports Compliance <ul><li>Address immediate Sarbanes-Oxley 404 and 302 compliance challenges </li></ul><ul><ul><li>Complete compliance platform delivered and customized by Microsoft partners </li></ul></ul><ul><li>Utilize existing technology investments </li></ul><ul><ul><li>Optimize your existing Microsoft environment </li></ul></ul><ul><ul><li>Familiar to users throughout your organization </li></ul></ul><ul><li>Begin building a long-term corporate governance vision </li></ul><ul><ul><li>Microsoft is dedicated to corporate governance company-wide </li></ul></ul>Why choose Microsoft for your Sarbanes-Oxley compliance needs?
  16. 16. Microsoft Office System Addresses the Key Sarbanes-Oxley Challenges Business Challenges <ul><li>Extensive documentation effort required for 404 compliance </li></ul><ul><li>Need for pro-active monitoring of controls </li></ul><ul><li>Limited experience in controls management </li></ul><ul><li>Protect investments for evolving compliance needs </li></ul><ul><li>Implement rapidly at low cost </li></ul><ul><li>Easy to learn and integrate with existing productivity tools </li></ul>Microsoft Office System Benefits <ul><li>Provide document management and workflow tools for compliance solution </li></ul><ul><li>Configure to utilize any of the Big4 methodologies </li></ul><ul><li>Extend platform to deploy broader compliance offerings </li></ul><ul><li>Address immediate Sarbanes-Oxley challenges through rapid deployment </li></ul><ul><li>Leverage existing investments into familiar Microsoft technologies </li></ul><ul><li>Reliable and rapid implementation for mission critical business solution </li></ul><ul><li>Lower Total Costs of Ownership for compliance solution </li></ul><ul><li>High-quality documentation and controls </li></ul>
  17. 17. Protect Investments by Establishing a Compliance Infrastructure Partner-Enabled solutions using Enhanced SOX Compliance Extensive Compliance Infrastructure Business Intelligence Document Lifecycle Management Document Rights Management Workflow Management Records Management E-Mail Compliance Archiving Business Analytics Collaboration and Information Management
  18. 18. What is the Sarbanes Oxley Accelerator? <ul><li>Single, shared workspace for 404/302 documentation and workflow </li></ul><ul><ul><li>Configurable by customers or their audit firm </li></ul></ul><ul><ul><li>Built on Windows SharePoint Services & InfoPath </li></ul></ul><ul><li>What it’s not? </li></ul><ul><ul><li>Intelligent system that discovers deficiencies with internal controls </li></ul></ul><ul><ul><li>Self-service guidance tool that advises on how to complete the 404 process </li></ul></ul>
  19. 19. Offering Capabilities <ul><li>Facilitates Sarbanes-Oxley 404 and 302 compliance </li></ul><ul><ul><li>Includes auditor and deployment partner content and functionality </li></ul></ul><ul><li>Supports long-term corporate governance vision </li></ul><ul><ul><li>Broad partner ecosystem to support customer specific needs </li></ul></ul><ul><ul><li>Company wide interest in compliance: </li></ul></ul><ul><ul><ul><li>Office System, Windows, MBS, XBRL </li></ul></ul></ul><ul><li>Utilize existing Microsoft environment </li></ul><ul><ul><li>Optimize customer investments in Microsoft technology </li></ul></ul><ul><ul><li>Applications are familiar to users of Office System </li></ul></ul><ul><ul><li>Solution Accelerator requires limited training </li></ul></ul>
  20. 20. Microsoft Office System – Platform for Sarbanes-Oxley Solutions <ul><ul><li>Addresses information management and collaboration, not just data collection and storage </li></ul></ul><ul><ul><li>Enables enhanced visibility and reporting capabilities over corporate processes, risks, and internal controls </li></ul></ul><ul><ul><li>Meets immediate Sarbanes-Oxley solution needs, and is adaptable to evolving requirements </li></ul></ul>Document & Information Management Process Automation & Workflow Communication & Collaboration Monitoring & Reporting
  21. 21. <ul><li>Store reference materials in a knowledge repository </li></ul><ul><li>Track document changes with built-in audit trail features </li></ul><ul><li>Streamline your work with reusable templates and forms </li></ul><ul><li>Easily store, access, and manage compliance data in XML </li></ul>Document & Information Management The Microsoft Office System can facilitate management process, risk, control, and test documents
  22. 22. Control Document for Capturing Workflow and Metadata Site administrator can add properties and property values as necessary to meet new compliance needs Signoff process stores the user’s logon ID, a time stamp, and any optional notes from the signer Numbered sections are workflow steps Roll-back option is captured as a part of the audit history for the document Example Solution Value to Businesses <ul><li>Maintain a reliable audit trail with secure sign-off and time-stamp functionality </li></ul><ul><li>Adapt to changing compliance requirements by making it easy for the system administrator to add or modify properties </li></ul><ul><li>Streamline processes by documenting workflow steps and assigning tasks </li></ul>
  23. 23. <ul><li>Electronically approve documents </li></ul><ul><li>Define roles, and manage system access </li></ul><ul><li>Prompt users for action with e-mail alerts </li></ul><ul><li>Easily edit workflow assignments as employees shift roles </li></ul><ul><li>Customize workflow steps per document type </li></ul><ul><li>Dynamically add users and tasks to workflow </li></ul>Process Automation & Workflow The Microsoft Office System enables automated processes to enhance information routing and organizational efficiency
  24. 24. Control Environment for Document Management Familiar tree structure simplifies navigation Personalized tree view is populated for current user by using SharePoint Products and Technologies and user credentials View document properties without opening documents Single item can show up multiple times (for example, for multiple risks) without creating multiple copies of the record Example Solution Value to Businesses <ul><li>Minimize training costs with the use of simple navigation and familiar tools and user interfaces </li></ul><ul><li>Reduce risk and improve efficiency by eliminating the need to create and store duplicate items </li></ul><ul><li>Maintain security by showing only the items to which an individual user has access </li></ul>
  25. 25. <ul><li>Personalize content and layout of information in team Web portals </li></ul><ul><li>“ My Documents” filter of internal controls documentation </li></ul><ul><li>Monitor document status </li></ul><ul><li>Ensure users have the most current information </li></ul><ul><li>Allow audits of data and processes through controlled access </li></ul>Communication & Collaboration The Microsoft Office System can empower individuals to collaborate and share information across teams
  26. 26. Central Portal to Access Sarbanes-Oxley Controls Example Solution One-click access to internal control environment Secure user access to systems and controls Easy to customize with branding, Web Parts, document libraries, issues lists, etc. Shows overall project status at a glance Value to Businesses <ul><li>Simplify processes with a central information portal and launch point for all actions within the solution </li></ul><ul><li>Keep control environment secure, accessible only to appropriate users with a login ID </li></ul><ul><li>Manage risk with real-time view of status for all Sarbanes-Oxley projects </li></ul>
  27. 27. <ul><li>Monitor executive dashboards to assess project status and control effectiveness </li></ul><ul><li>Validate risk assessments and planned responses </li></ul><ul><li>Capture and drive issues to resolution </li></ul><ul><li>Build advanced reports using SQL Reporting Services </li></ul><ul><li>Export and link data to Microsoft Excel </li></ul><ul><li>Print summary or detailed reports with compliance results and company readiness </li></ul>Monitoring & Reporting The Microsoft Office System can facilitate project status review across the organization from a single access point
  28. 28. Standard or Customized Reporting Views One-click access to multiple views Open and review documents directly from a report module Create custom views to map to needs of the business Real-time view of document status Example Solution Value to Businesses <ul><li>Monitor progress in different parts of the business by defining multiple views </li></ul><ul><li>Assure timely reporting by tracking project documentation in real time </li></ul><ul><li>Enable deeper analysis by exporting data to Excel </li></ul>
  29. 29. High-Level Solution Architecture Windows XP Web Components InfoPath 2003 Windows Server 2003 SharePoint Products and Technologies Document Libraries Web Services Web Part Infrastructure Custom Event Handlers and User Interface Code ASP.NET SQL Server 2000 Configuration Content Client Server <ul><li>Modular User Interface </li></ul><ul><li>Extensibility </li></ul><ul><li>Web Services </li></ul><ul><li>Core Operating System </li></ul><ul><li>Web Server </li></ul><ul><li>Document Libraries </li></ul><ul><li>Task Pane </li></ul><ul><li>Lists </li></ul><ul><li>Web Services </li></ul><ul><li>Document Management </li></ul><ul><li>Site Directory </li></ul><ul><li>Search </li></ul><ul><li>Alerts </li></ul><ul><li>Storage </li></ul><ul><li>Notification </li></ul><ul><li>Full-text Search </li></ul>
  30. 30. Partner Opportunities <ul><li>Solution Integrator opportunities: </li></ul><ul><ul><li>Integration with and enhancement of existing financial systems; installation, training, technical support, and project management </li></ul></ul><ul><li>Independent Software Vendor opportunities: </li></ul><ul><ul><li>Sox-specific extensions to existing financial and compliance systems, analytics, workflow automation, ERP control integration, archiving, and security </li></ul></ul><ul><li>Audit Firms/Risk Advisors: </li></ul><ul><ul><li>Guidance and consulting on compliance issues </li></ul></ul>Partners have the opportunity to build on Microsoft Office System functionality to develop Sarbanes-Oxley solutions
  31. 31. Microsoft Partners -- Building Compliance Solutions on the Microsoft Office System <ul><li>Domain and industry expertise </li></ul><ul><li>Planning, design, deployment, setup, and configuration </li></ul><ul><li>Training and ongoing support </li></ul><ul><li>Customization and extended functionality </li></ul><ul><li>Microsoft’s extensive partner ecosystem includes: </li></ul><ul><ul><li>Risk Advisors such as KPMG, PWC, Deloitte and Ernst & Young have rich content libraries that offer guidance on compliance </li></ul></ul><ul><ul><li>Solutions Integrators (SIs) provide technical support, including development, integration, and enhancement </li></ul></ul><ul><ul><li>Independent Software Vendors (ISVs) deliver value-add functionality to complement Microsoft Office System solutions </li></ul></ul>
  32. 32. Conclusion Microsoft Office System provides a solution platform that facilitates control documentation, workflow, communication, and reporting across business units <ul><li>Address immediate Sarbanes-Oxley 404 and 302 compliance challenges </li></ul><ul><ul><li>Microsoft partners deliver a complete compliance platform </li></ul></ul><ul><li>Utilize existing technology investments </li></ul><ul><ul><li>Optimize your existing Microsoft environment </li></ul></ul><ul><ul><li>Familiar to users throughout your organization </li></ul></ul><ul><li>Begin building a long-term corporate governance vision </li></ul><ul><ul><li>Microsoft is dedicated to corporate governance company-wide </li></ul></ul>
  33. 33. <ul><li>Get more information </li></ul><ul><li> </li></ul>Next Steps Use the Microsoft Office System to develop Sarbanes-Oxley solutions
  34. 34. © 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.