ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Office applications Toolkit

Accounting rules: you must keep e-mails

John Iosub

Published: 21 Mar 2003 11:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Over the years, I've noticed that many small to midsize companies do not save e-mail communication properly. They are typically concerned with being able to restore a failed system and don't pay any attention to retention. However, in the light of new regulations, such as the US Sarbanes-Oxley Act , your company could be at fault for knowingly replacing old backups and not saving them for possible future investigations.

The Act will have an effect outside the US, because your company and its partners may well be doing business in the US, or with US companies. The Act applies to companies that wish to remain listed in the US. Even if Sarbanes-Oxley does not affect your company, it seems likely that similar laws will eventually appear in Europe. Frits Bolkestein, the European commissioner for internal markets and taxation, has called for equivalent European legislation.

To help you make sense of this act, I will discuss how Sarbanes-Oxley and similar legislation will affect IT managers.

Sarbanes-Oxley overview

The Sarbanes-Oxley Act on corporate responsibility for financial reporting was passed in the US in 2002, in response to the WorldCom and Enron debacles, to protect investors. It is intended to improve the accuracy and reliability of corporate disclosures. The Act amends mail and wire fraud infractions with harsher punishments and imposes fines and prison sentences of up to 20 years for anyone who knowingly alters or destroys a record or document with the intent to obstruct an investigation. Due to the availability of reliable technology, most responsible companies have already regulated themselves, and the Act merely sets the tone for proper corporate conduct.

Most provisions of the Act focus on financial records. Section 302 requires certification of financial statements by both the CEO and the CFO. This means that all future financial reporting must be thoroughly verified by management with more acuity than ever before. No doubt the IT department supporting financial systems will also have to ensure the accuracy of these records.

The implications of the act are clearly not meant to stop with financial records, however. For example, during an investigation, discovery requests can be submitted to IT departments. In addition, such requests could require access to all e-mail communication.

E-mail messages as business records

Although trivialised by mixed personal and business content, e-mails are, in fact, corporate documents and should be preserved. The courts will treat e-mail messages and attachments as business records that must be retained to achieve regulatory compliance. Most large companies have a policy on e-mail communication retention. But is this common practice? The answer may come from a PricewaterhouseCoopers survey titled "Digital Discovery and its Importance on the Practice of Litigation." Surprisingly, respondents stated that their clients rarely act upon notice of litigation to stop automatic overwriting processes. In another section of the survey, almost 50 percent of the respondents said that e-mails are the most requested electronic data.

The scenario is common: A company gets a new Microsoft Exchange server, and the users are happy with the Outlook calendar and Internet e-mail capabilities. Messages go in and out, but there is no archival process. Backups are sent to tape, which are rotated weekly and overwritten. However, according to Sarbanes-Oxley, if your network administrator is instructed to overwrite the tapes, then your company knowingly allows potential evidence to be destroyed. Depending on your business risks, this scenario could become a malpractice time bomb. In addition, a simple backup of the Information Store with all the mailboxes in your Exchange server will not give you all the e-mails going in or out. So you are at risk when users delete messages, especially if they are engaged in some kind of misconduct.

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
96 out of 153 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Security/Quality Analyst-00055189

Quality Act as the primary point of contact to ensure that Accenture provides the client with the Sarbanes Oxley support it requires to get sign-off. ...

Warwick - Problem Manager-00049422

Service Management process Achieve Key Performance Indicators (KPIs) targets set by the Delivery Centre Participate in client and/or Accenture ...

Quality Lead - Unilever - Level C-00055185

The Quality and Process Improvement programme (QPI), Sarbanes Oxley (SOX) Compliance and Security are highly visible subject matter on this ...

Featured Talkback

Why do so many (virtually all) software packages think that they are so important that they have to be started automatically every time the computer boots? What is the largest number of "speed access", "update check", "camera download" and whatever other background programs you have ever seen running? Of those, how many did you really need?

By: J.A. Watson

Read full story:
Annoying software: a rogues' gallery

Vista Upgrade Blog

XP survival, from one horses mouth, an...

Hi everyone....for those that need more information on XP survival, I have pasted this open letter from Bill Veghte, senior vice president of microsoft, found on microsoft .com. Hope... More

2 comments

A $40 CONSUMER-class router has create...

Believe it or not I don't work in IT, haven't for 7 years. Yes I work with Microsoft's Windows XP Embedded and as a result I have to know a lot about the OS, the kernal, Win API calls... More

Post a comment

Sick Puppy Redo

I generally follow a dispassionate investigative process when trying to discern what happened when a project goes bad. Although its a low priority item, it gets done simply because... More

Post a comment