Add Your Voice to the Compliance Team Maine

Thousands of large public companies were able to comply with Sarbanes-Oxley requirements in their annual reports recently thanks to the efforts of their information technology teams. But while IT is acknowledged as playing a crucial role in regulatory compliance, CIOs often find themselves without a seat at the table because ownership of the data originated in another department.

Local Companies

Cloudhawk Management Consultants
(207) 767-4500
71 Myrtle Ave
South Portland, ME
Bancroft & Company
(207) 772-6317
15 Monument Sq
Portland, ME
American Landmark Companies Inc
(207) 548-7250
11 E Main St
Searsport, ME
Nasson Heritage Center
(207) 324-0888
9 Bradeen St
Springvale, ME
Eastern Maine Development Corp
(207) 942-6389
1 Cumberland Pl Ste 300
Bangor, ME
MacMillan Associates Inc
(207) 443-5800
Phippsburg, ME
Keirstead & Fox PA
(207) 883-9501
7 Oak Hill Plz
Scarborough, ME
Public Consulting Group Inc
(207) 621-2300
77 Sewall St Ste 6
Augusta, ME
Stillwater Consulting Group Inc the
(207) 771-2090
500 Forest Ave Ste 11
Portland, ME
Dresser & Associates Inc
(207) 885-0809
243 US Route 1
Scarborough, ME


Add Your Voice to the Compliance Team



By Elizabeth Wasserman

Thousands of large public companies were able to comply with Sarbanes-Oxley requirements in their annual reports recently thanks to the efforts of their information technology teams. But while IT is acknowledged as playing a crucial role in regulatory compliance, CIOs often find themselves without a seat at the table because ownership of the data originated in another department.

The paradox is that CIOs are tasked every day with knowing the information infrastructure underlying the business -- information that is vital for others in the organization in charge of compliance. IT tools can help company officials share and verify crucial data between internal and external auditors, finance managers, and business units before it ends up in financial reports. Such tools can also be deployed to automate what were once manual processes. For these reasons, the CIO is in the best position to improve compliance procedures throughout the organization.

As companies struggled to meet Sarbanes-Oxley deadlines in the last few years, they sometimes failed to realize the value of the CIO. A study released last year by the Hackett Group, an Atlanta-based business advisory firm, found that fewer than half of the CIOs interviewed were involved in the steering committees for Sarbanes-Oxley compliance.

"It was a wake-up call," said Beth Hayes, a research fellow at the Hackett Group. She said that some companies have since determined that IT participation is critical to successful Sarbanes-Oxley compliance and have brought CIOs into the fold -- but not all. The law requires not only that a company's financial reports be accurate, but that proper controls are in place so that the CEO and CFO know if the financials are inaccurate. As the CIO has responsibility for the management, operation, and acquisition of the IT systems that are at the core of a company's operations and financial management, it's only fitting that this official be part of the compliance team.

"It seems obvious that the CIO ought to be represented," said Ann Senn, global leader for CIO advisory services for Deloitte Consulting. "We have done a lot of work with compliance teams, and I can't tell you how often we have found that compliance teams -- a number of which are focused on financial controls -- deal with IT as one of the elements they have to go through and not as a core vocal member of the compliance steering team."

CIO representation is important in part because compliance teams often make decisions about priorities for future process improvements. A compliance team could make decisions that alter the IT operation's priorities, such as maintaining a secure and available information environment; or its ability to meet business goals. As a result, uninformed decisions could end up making compliance with regulatory mandates even more difficult. In other words, CIOs may lose control over the very thing it is their responsibility to maintain: IT.

"If you're not there, you are in a position of taking orders," said Senn. "You take orders and you do the best. But if you're taking orders, you're not making decisions. You're in the position of fulfilling the orders."

To prevent that scenario from occurring, CIOs need a game plan for proving themselves to other executives.

  • Be Proactive  Understand how IT can help the company meet compliance deadlines in a less painful and time-consuming fashion next time around. Outline your plan in a memo or request to make a presentation to the compliance team.


  • Demonstrate IT's Role  Establish usage rules and audit trails for every information system feeding financial data into reports. Actions speak louder than words. Impress the CFO and CEO with a track record of running IT as a business and being customer-service oriented.


  • Designate an IT Controller  Create a new position on your own staff for an IT Controller, the point person on compliance, risk management, vendor management, and security. This person will ensure that IT is not a risk factor in compliance and show other C-level executives that you take compliance seriously, according to the Hackett Group's Hayes. 


  • Court Your CFO and CEO  Your proven track record has earned their respect. You understand the issues. Now it's time to make your case for inclusion at the table to the executives who feel they have the most at stake. Show that you understand the concerns of the CFO and CEO, who face potential criminal penalties and fines if they sign false financial statements. Meet with them personally to outline your plan for how to make compliance easier from this moment forward.

If the CIO isn't a member of the compliance team, Senn said, he or she ought to at least have a "good counselor" who can make sure IT's voice is represented in discussions and report information from the meetings. That counselor can hold any position in the company, but it needs to be someone who can be frank about discussions and who knows something about the IT infrastructure and how technology can help.

Once the CIO wins a place on the compliance team, successful results could go a long way to winning more representation for IT at the executive committee level. And maybe even win the CIO a seat at that table.

Elizabeth Wasserman has written about technology and business for Inc., CIO Insight, and the San Jose Mercury News. She is a freelance writer based in Fairfax, Virginia.

Featured National Company

NRG Global

213-383-6745
3807 Wilshire Blvd.
Los Angeles, CA
http://www.nrgglobal.com

NRG Global provides availability monitoring and performance management products and
services.

Use our products to monitor and manage your IT resources, including: servers, operating
systems, databases, applications, files, CPU's, memory, disks, and more.

Our flagship product is CleverEye. CleverEye is availability monitoring, alerting and reporting software. Automatically measure response time and trigger alerts when thresholds are broken. Easy to install, agent-less, and Web based, supports multiple concurrent users. Four powerful modules to monitor from different perspectives: network layer, application layer, SNMP and operating system. Monitor servers, websites, databases, applications, CPUs, memory, disk, FTP, DNS, LDAP and more.

We also provide consulting expertise to integrate our solutions.


Related Articles
- Making Compliance Part of the "IT DNA" Maine
For today's enterprises, meeting the requirements of a variety of technical standards, IT governance frameworks, and laws related to security and administration have become a significant challenge. And as numerous industry experts have observed, the pressure to demonstrate compliance with such mandates will likely increase in 2007.
- Sarbanes-Oxley Compliance: Round Two Maine
- Sarbanes-Oxley: Where Do You Stand? Maine
- NERC CIP: Don't Be a Compliance "Laggard" Maine
- IT Compliance Maine
- Oil and Gas: Stepping Up to Security Compliance Maine
- Manage Collaboration With Alexsys Team 2 Maine
- Managing IT Security Compliance Maine
- Sustainable IT Compliance Maine
- Critical Challenges for Corporate Compliance Maine
Related Articles
- Oil and Gas: Stepping Up to Security Compliance Maine
Ask any IT professional, and the word "compliance" is likely to mean a number of different things. But the intent of multiple regulations, industry standards and best-practice frameworks across industries today is unambiguous: The emerging compliance paradigm seeks to ensure the security, availability and integrity of business information.
- Sustainable IT Compliance Maine
- IT Compliance Maine
- Sarbanes-Oxley: Where Do You Stand? Maine
- Manage Collaboration With Alexsys Team 2 Maine
- Sarbanes-Oxley Compliance: Round Two Maine
- Critical Challenges for Corporate Compliance Maine
- Making Compliance Part of the "IT DNA" Maine
- Managing IT Security Compliance Maine
- NERC CIP: Don't Be a Compliance "Laggard" Maine
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Software
Business Services Fashion Internet Technology
Career Financial Services Legal Telecommunications
Cars Franchise Miscellaneous Trade Shows
Computer Hardware Health Nightlife Travel
Construction Holidays Online Database Weddings
Education Home Appliances Real Estate Resources World History
Entertainment Home Electronics