Sarbanes Oxley

TheGuy

Expert Member
Joined
Sep 14, 2009
Messages
2,971
Hi

Does anyone know of a company that does Sarbanes Oxley IT Auditing?

Thanks
 

crazy_cat

Well-Known Member
Joined
Aug 21, 2007
Messages
326
audit firms, the big four, kpmg, pwc, e&y, and d&t - im sure there are smaller local firms as well such as sizwe nsaluba etc.

also, if you asking about sox, your probably part of a multi-national...

more importantly, what are you after from the audit. sox is about controls and considering that you asking the question i would ask who are your current auditors are (internal and external) it should form some part of the annual audit plan
 

TheGuy

Expert Member
Joined
Sep 14, 2009
Messages
2,971
Thanks Crazy Cat

I'm currently the IT manager and handle all the SOX controls. Just looking for an external company that specializes in this.
 

crazy_cat

Well-Known Member
Joined
Aug 21, 2007
Messages
326
if you want, pm with your details and i can try to get you in touch with someone from a big four firm who can assist.
 

Vleis12

Well-Known Member
Joined
Nov 13, 2008
Messages
129
Ask for Linda Voges at PwC Jhb on (011) 797-4000. She is a partner in their IT auditing department and has a lot of SOX experience, ex. ABSA.
 

Obelix

Senior Member
Joined
Sep 28, 2003
Messages
961
I use KPMG for my internal "self-audits" and D&T for the external audits. Both of them know SOX, but youre going to have to setup a playbook that covers the controls for your company. SOX is the most detailed audits i know of. You have to setup the controls that apply to you and then have the auditors check those controls.....

Also, SOX is so much more than just IT contorls. Its handles all business processes too....
 

Sting

Ghost in the Machine
Joined
Mar 4, 2009
Messages
27,435
Rather de-list from the NYSE than implement SAOX!!! It's going to drive your whole company crazy!!!
 

TheGuy

Expert Member
Joined
Sep 14, 2009
Messages
2,971
Thanks guys I will contact the above people. Unfortunately our company is part of a global group
 

Sting

Ghost in the Machine
Joined
Mar 4, 2009
Messages
27,435
Thanks guys I will contact the above people. Unfortunately our company is part of a global group

Then good luck for when you also have to apply with the King II requirements !!!!

SAOX is not just a few employees complying on processes... a significant sample of employees must comply that they are following all the processes 100%. So to start with you need to have every single operation in company draw up and archive their processes. Then you have to document the controls and risks in each process. Then you do quarterly compliances... I could carry on but I'm thankful we no longer have to do it!
 
Top