ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Compliance Toolkit

Sarbanes-Oxley: What IT managers need to know

Staff

Published: 18 Jan 2005 11:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Testing control effectiveness
In general, testing controls boils down to three steps: First, inventory the control activities. Second, write test plans to evaluate the effectiveness of each control activity. Third, relate each activity to an "underlying assertion" in the financial statements.

Once you have an inventory of control activities, you can begin writing your tests of effectiveness. These tests determine whether the control is operating as intended and whether the person performing the control is properly qualified and authorised to do so.

The next step is to classify each control activity by relating it to the underlying financial statement assertions: Existence or Occurrence; Completeness; Valuation or Allocation; Rights and Obligations; and Presentation and Disclosure. Then you'll want to indicate whether your control is manual or automated, and indicate if the control is preventative or detective.

If you're starting to get bogged down by the audit jargon, you can read up on how to apply these terms by going to www.auditnet.org/sbc.htm and downloading the two-volume publication called Standards for Business Controls.

Next, you have to write the test steps, which are also known as audit procedures. Audit procedures consist of a combination of inquiry, observation, and detailed testing through either examination or re-performance. For ideas on how to test your controls, try reviewing existing audit programs. One source of free audit programs is www.auditnet.org.

To ensure coverage on the test of effectiveness, the PricewaterhouseCoopers approach uses four information processing objectives: Completeness, Accuracy, Validity and Restricted Access (CAVR). The CAVR approach gives you a standardised means to measure each control activity. You should select the information processing objective(s) which best relates to your control activity. Ideally, each element of CAVR should be addressed in some combination of control activities for each objective.

If you'll just have faith and follow along with what your project manager asks, your piece of the "control effectiveness" mosaic will eventually fit into place.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with Konica

Did you find this article useful?
230 out of 464 people found this useful


Full Talkback thread

0 comments

Loading Video Player ....

Featured Talkback

In association with Intel
There will be further activation issues to watch out for as Microsoft plans to offer a similar service to independent software vendors whereby they can "control" licensing through activation and other measures similar to the Software Protection Platform.

By: DefenceIT

Read full story:
Microsoft outage down to 'human error'

Sentry Posts Blog

Virtual Teams: Small Business Innovati...

Virtual Teams: Small Business Innovation Author: Eric Everson, Founder – MyMobiSafe.com As the founder of MyMobiSafe.com, I’ve found that because of our presence in the industry... More

Post a comment

Mobile Security and Innovation: An Ope...

Mobile Security and Innovation: An Open Case Author: Eric Everson, Founder MyMobiSafe.com The times are changing in the mobile industry as “big wireless” in the US Markets are calling... More

Post a comment

Government launches new e-crime unit

Ok, so this is outside of my main area of focus of sustainable and green tech but I do track some security issues too. I was at a meeting last week with Microsoft's security advisor... More

Post a comment