PDA

View Full Version : Anyone been through a Sarbanes Oxley Audit yet?


MacroGuru
12-07-2004, 04:54 PM
Just checking to see if anyone has been involved in one, and if so, were the active in it.

I am the one getting stuck as the leadman for the database dev team.

I just want to know, if you have, did it hurt much?

Balldog
12-07-2004, 05:02 PM
Yeah, I have and it kind of sucked.

Just a lot of work.

gottimd
12-07-2004, 05:11 PM
Yeah, I have and it kind of sucked.

Just a lot of work.


Me too, and I have the same feelings towards it.

MacroGuru
12-07-2004, 05:40 PM
I am already having that feeling, in the last two weeks, I have printed out close to 1000 pages of documentation, and typed up the bulk of them.

Right now, our SDLC is under the gun, and it is killing me.

moriarty
12-07-2004, 09:34 PM
If you've ever gone through an ISO 9000 type certification, it's even worse.

Basically, no one really understands the requirements so you just have to document the crap out of everything. You'll likely have a bunch of 20 year old auditors poke around and ask stupid questions like "why didn't you get a vendor quote" uh, because we have contracted pricing with the vendor - and then spend weeks trying to justify the obvious.

Grrr...

Best thing you can do is actually read the Sarbannes requirements and push back intelligently on some of the the paper requests.

Philliesfan980
12-07-2004, 09:36 PM
If you've ever gone through an ISO 9000 type certification, it's even worse.

Basically, no one really understands the requirements so you just have to document the crap out of everything. You'll likely have a bunch of 20 year old auditors poke around and ask stupid questions like "why didn't you get a vendor quote" uh, because we have contracted pricing with the vendor - and then spend weeks trying to justify the obvious.

Grrr...

Best thing you can do is actually read the Sarbannes requirements and push back intelligently on some of the the paper requests.


I'm one of those stupid 20 some year old auditors :mad:

moriarty
12-07-2004, 09:42 PM
I'm one of those stupid 20 some year old auditors :mad:

You may be a 20 year old auditor ... but you'll have to determine if you're one of the stupid ones.

Well at least w/ Sarbannes Oxley you have some job security for the next several years. :D

Buzzbee
12-07-2004, 09:58 PM
This is interesting. The company I work for is a software company. They developed internal software to help them with their SOX compliance. At some point it dawned on them that there might be a pretty good demand for it, and they are in the business of selling software, so they've modified it and I believe are having moderate success selling it.

Alan T
12-07-2004, 10:00 PM
I currently have spent the last 2 months getting ready and going through this. Basically it seems like no one knows what the requirements are, and the requirements change daily. Its like trying to hit a moving target without knowing what the target even is. Each day some new stupid curveball comes out of nowhere to ruin my day thanks to this...

scc27
12-07-2004, 10:14 PM
This is just another way for the accounting/auditing firms to screw more money from corporations. Their consulting revenue was starting to decrease so what better way for them to add revenue. They don't know what they want so they ask for everything and then charge about 100 - 200 dollars an hours to go through all of the documentation. Just another reason why US companies cannot complete very well globally.

finkenst
12-07-2004, 10:39 PM
likewise here...

change tickets. trouble tickets. database backups. financially significant applications. key controls.

blah blah blah

Draft Dodger
12-07-2004, 10:57 PM
I feel like such an idiot reading this thread

finkenst
12-07-2004, 11:08 PM
I feel like such an idiot reading this thread
no need to feel like an idiot.

SOx has killed my enjoyment of my job.

Tekneek
12-08-2004, 12:15 AM
At some point it dawned on them that there might be a pretty good demand for it, and they are in the business of selling software, so they've modified it and I believe are having moderate success selling it.

No doubt my employer has bought this, especially if it takes a truck full of money to get the license.

Anthony
12-08-2004, 12:16 AM
i fucked sarbanes oxley in the ass. 2 times.

Tekneek
12-08-2004, 12:18 AM
This is just another way for the accounting/auditing firms to screw more money from corporations.

We have plenty of those folks hanging around. Some of them sit in a little room, not far from my cube, spending all day typing on their laptops and writing things on the whiteboard...with pretty motivational posters on the other wall. So far they have managed to push through some re-orgs, as well as extra hoops for all of us to jump through. When you ask why your job just got more difficult, all anyone says is, "SOX compliance", with a shrug of their shoulders. Nobody seems to know the details, and take the word of these consultants as if it is the gospel. If these folks are wrong, we're going to be in a real mess.

Anthony
12-08-2004, 12:20 AM
just piss on their faces.

MacroGuru
12-08-2004, 12:30 AM
Damn.....

It's good to know that several of you out there have experienced the pain I am going through.

The consultants ran through a test of the SDLC tonight, and it passed, with only 3 small remediations suggested by them.

The major factor comes tomorrow when we get the test of our controls of balancing from our order system to the general ledger. This is one that I think, we will be brutally slaughtered on, and it will force me to snap at work...and go off on a rampage....

Anthony
12-08-2004, 12:34 AM
myh penis is SOX compliance. word to yo momma.

finkenst
12-08-2004, 12:59 AM
We have plenty of those folks hanging around. Some of them sit in a little room, not far from my cube, spending all day typing on their laptops and writing things on the whiteboard...with pretty motivational posters on the other wall. So far they have managed to push through some re-orgs, as well as extra hoops for all of us to jump through. When you ask why your job just got more difficult, all anyone says is, "SOX compliance", with a shrug of their shoulders. Nobody seems to know the details, and take the word of these consultants as if it is the gospel. If these folks are wrong, we're going to be in a real mess.
whoa, do we work for the same company?

Franklinnoble
12-08-2004, 11:34 AM
myh penis is SOX compliance. word to yo momma.


whoa, do we work for the same company?

gottimd
12-08-2004, 11:35 AM
Anyone ever been in a Turkish Prison?

rkmsuf
12-08-2004, 11:35 AM
i fucked sarbanes oxley in the ass. 2 times.

I couldn't stop laughing when I got to this one.

John Galt
12-08-2004, 11:37 AM
I didn't realize HA posted in this thread as well. More comic gold!!! How can you top:

"i fucked sarbanes oxley in the ass. 2 times."

edit: rkmsuf beat me too it. I'm still chuckling in my office reading it.

gottimd
12-08-2004, 11:42 AM
He posted in a ton of threads I think.

Franklinnoble
12-08-2004, 11:44 AM
I didn't realize HA posted in this thread as well. More comic gold!!! How can you top:

"i fucked sarbanes oxley in the ass. 2 times."

edit: rksmuf beat me too it. I'm still chuckling in my office reading it.

http://sarbanes.senate.gov/images/pics/ready/bwphoto2.jpg
Sarbanes

http://oxley.house.gov/images/oxley_index_poxley.jpg
Oxley

Way to go, HA.