You are here: silicon.com > Management > Law & Policy

Law & Policy

'SOX rocks!' Techies love legislation

...or one does at least...

Tags: sox, compliance, sarbanes-oxley

By Andrew Donoghue

Published: 28 January 2005 08:50 GMT

Complying with regulations such as the Sarbanes-Oxley Act may have diverted money away from revenue-generating IT projects but it has forced business to get their technical houses in order, according to a senior IT manager at investment bank Dresdner Kleinwort Wasserstein.

Speaking on Thursday at the financial technology show FinExpo, Stephen Ashton, director of Global IT business management at the bank, said Sarbanes-Oxley was a knee-jerk reaction to corporate scandal that was costing companies "a fortune" to comply with.

"Around 10 to 15 per cent of our total headcount is working on compliance and regulation and that is quite a big cost," he explained.

He also warned that although European companies may consider Sarbanes-Oxley as a US-only issue, a similar scandal on this side of the Atlantic would undoubtedly see regulators in Brussels follow the American lead.

Sarbanes-Oxley was signed off in 2002 and is designed to prevent financial malpractice and accounting scandals such as the Enron debacle. Overall spending on complying with the Sarbanes-Oxley Act was estimated to be around $5.5bn last year, according to a recent survey by AMR Research.

However, despite the costs involved, Aston said that overall compliance was good for IT departments as it forced companies to reorganise disparate systems that in many firms had grown into random silos that did not communicate effectively.

"I think it is a great thing not just for IT but for business generally. From an IT perspective I think it’s a doubly great thing, obviously it helps us straighten things out but it is also helping us generate new value," he said.

From a systems management perspective, Ashton said, complying with Sarbanes-Oxley has forced the company to catalogue its existing IT systems and investigate exactly how those systems are being used currently.

He described how in many companies IT systems are akin to a "monster" that has no respect for time and space. Complying with regulations means taming this monster in order for companies to be able to provide the kind of transparency required by the legislation.

"We have just completed a data centre review. The thing that came out of it was that we have tonnes of information but very little knowledge. There is a lot of partial and inaccurate data in our systems," said Ashton.

The bank is working with business-intelligence provider Tideway Systems, which has an application that allows a company to build an accurate map of all the disparate elements that make up its IT infrastructure.

Richard Muirhead, founder and chief executive of Tideway, said: "You need to be in a position to be able to map all of the components in infrastructure – starting with network layer and moving up into applications including financial reporting apps that Sarbanes-Oxley is so concentrated on."

Muirhead said this kind of analysis is "not easy stuff to achieve and is nigh on impossible manually", which is where Tideway's tools come into play by automating the procedure as much as possible.

Andrew Donoghue writes for ZDNet UK.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Quality Lead - Unilever - Level C-00055185

The Quality and Process Improvement programme (QPI), Sarbanes Oxley (SOX) Compliance and Security are highly visible subject matter on this ...

Security/Quality Analyst-00055189

Quality Act as the primary point of contact to ensure that Accenture provides the client with the Sarbanes Oxley support it requires to get sign-off. ...

Business Analyst / Finance Systems Analyst

The role on offer is an initial 6 month contract, with possibility for extension, working across multiple projects and Sarbanes Oxley initiatives. If ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: