Current Campaign


Latest Archives

  1. August 23, 2010 Getting Serious about Risk Monitoring Posted in: Daily News with: 0 comments

  2. August 17, 2010 Y211? And other Risks . . . Posted in: Daily News with: 0 comments

  3. August 10, 2010 Video Spills on Government Fraud Posted in: Daily News with: 0 comments

  4. August 5, 2010 Re-Inventing the Internal Auditor? Posted in: Daily News with: 0 comments

  5. August 3, 2010 The Guidance Gauntlet Posted in: Daily News with: 0 comments

  6. July 30, 2010 Stopping the Spreadsheet Scourge Posted in: Daily News with: 1 comment

  7. July 21, 2010 Robbing Risk Management to Pay Receivables Posted in: Daily News with: 0 comments

  8. July 15, 2010 Trailblazing Uncle Sam Posted in: Daily News with: 0 comments

  9. July 13, 2010 CCM Momentum Posted in: Daily News with: 0 comments

  10. July 8, 2010 Introducing Approva One On Demand Posted in: Daily News with: 0 comments

Recent Articles

Study Shows Progress In Internal Controls Effectiveness

Posted on December 11th, 2007 by admin »Permalink

Compliance Week (subscription required) recently released a study on the effectiveness of internal controls implemented in the wake of Sarbanes-Oxley. Financial Week covers it here, but the gist is that there is clear progress being made three years into the internal controls requirements that SOX has mandated.

The highlights? Large filers last year disclosed only a third of the number of the material weaknesses in internal controls that they reported three years ago. Restatements are also down, as are late filings and corporate litigation. And more weakness disclosures are being filed quarterly than annually, which the CW folks point to as a positive sign that companies are uncovering and disclosing problems more quickly.

This is indeed a step in the right direction, and something for corporate America to be proud of. It’s gratifying to see tangible results on the vast amounts of time and money that have gone to attaining and maintaining SOX compliance. But it’s also a reminder of how much farther we have to go to truly get our money’s worth out of GRC investments.

Focusing on compliance issues like general computing and user-access controls is necessary and useful for compliance efforts, but it is in improving the efficiency and effectiveness of these controls where companies will see actual business improvement. When controls themselves become more efficient and effective, they can begin to provide meaningful intelligence about the business and where processes can be improved, with benefits including reduced time and expenses involving external audits, reduced fraud and mistakes, and decreased time required to test and monitor controls.

Governance, risk and compliance (GRC) is still a relatively new concept, and most companies are still on the cusp of realizing its true potential. When we discuss with our clients the “vision” of GRC, they understand what we are saying, and the value that such an approach holds. But they aren’t yet addressing GRC on a day-to-day basis. Many have invested in boosting the efficiency of compliance systems, but we have yet to see widespread dedication to making controls more effective – and an even smaller number are actively trying to realize the link between compliance systems improvement and improved business processes.

Time will tell how the GRC market ultimately evolves – whether it can grow to encompass all the markets it entails and bring together functions from board-level dashboards for enterprise risk management to IT regulatory compliance testing tools, and whether there exists or could feasibly exist a single comprehensive GRC solution. But the vision is there, and the rewards are real. Here’s to all of us being part of the dialogue.

- Dana Hamerschlag, Senior Director, Product Marketing

Bookmark and Share

4 Responses

Leave a Reply