Vous voulez voir cette page en français ? Cliquez ici.

Have one to sell? Sell yours here
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control [Hardcover]

Michael Ramos
5.0 out of 5 stars  See all reviews (1 customer review)

Available from these sellers.


Formats

Amazon Price New from Used from
Hardcover CDN $67.55  
Hardcover, Feb 27 2004 --  
There is a newer edition of this item:
How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control 5.0 out of 5 stars (1)
CDN$ 79.27
Usually ships in 3 to 5 weeks

Book Description

Feb 27 2004 0471653667 978-0471653660 1
This practical guide offers helpful guidance on how to go about to submitting to the SEC a company's annual assessment of the effectives of their internal control. Complete with practice aids-including forms, checklists, illustrations, diagrams, and tables-this comprehensive book provides a step-by-step approach for engagement performance and practical guidance on how an entity should test and evaluate its internal controls.

Product Details


Product Description

From the Inside Flap

Effective in 2004, as a result of Section 404 of the Sarbanes-Oxley Act of 2002, all public companies will be required for the first time to submit an annual assessment of the effectiveness of their internal control to the SEC. Additionally, each corporation’s independent auditors are required to audit and report on management’s internal control reports, just as they audit the company’s financial statements. How to Comply with Sarbanes-Oxley Section 404 provides a comprehensive, practical, and structured approach for the testing and evaluation of internal control required by Sarbanes-Oxley Section 404.

Drawing on original material by an expert in auditing and accounting, How to Comply with Sarbanes-Oxley Section 404 features a step-by-step process for evaluating a company’s internal control and proving these systems are effectively in place. This hands-on resource is packed with such practice aids as forms, checklists, illustrations, diagrams, and tables to assist anyone who participates in the planning or performance of an evaluation–including CFOs, internal auditors, and outside consultants.

Clearly and logically organized to make the material as accessible as possible, How to Comply with Sarbanes-Oxley Section 404 covers:

  • Management’s required assessment of the entity’s internal control
  • Considerations for outside consultants
  • Controls over information technology systems
  • Coordinating with independent auditors
  • Documenting your planning decisions
  • Hard-to-test entity-level control objectives
  • What auditors expect from management’s evaluation process
  • Documentation: what it is…and is not
  • Assessing the adequacy of existing documentation
  • Internal control reliability model
  • Evaluating the design and implementation of Sarbanes-Oxley automated compliance tools
  • An action plan for testing and evaluating entity-level controls
  • Operating effectiveness: test design considerations
  • Annual and quarterly reporting requirements
  • Expanded reporting on management’s responsibilities for internal control
  • Example disclosures of a material weakness
  • Example reports on management’s responsibilities for reporting and internal control

From the Back Cover

A step-by-step approach for planning and performing an assessment of internal controls In addition to financial results, companies must now analyze and evaluate the quality of the processes and controls used to report these results. How to Comply with Sarbanes-Oxley Section 404 provides a comprehensive, logically structured approach to help readers test and evaluate internal control in their companies. Designed specifically for Sarbanes-Oxley Section 404 compliance, How to Comply with Sarbanes-Oxley Section 404 features: A step-by-step approach to engagement performance Original material from a leading expert in auditing and accounting Practice aids, including forms, checklists, illustrations, diagrams, and tables In-depth explanations to help professionals understand how best to approach the internal control engagement Examples and action plans providing blueprints for implementing requirements of the Act

Inside This Book (Learn More)
Browse and search another edition of this book.
Explore More
Concordance
Browse Sample Pages
Front Cover | Copyright | Table of Contents | Excerpt | Index | Back Cover
Search inside this book:

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Reviews

4 star
0
3 star
0
2 star
0
1 star
0
5.0 out of 5 stars
5.0 out of 5 stars
Most helpful customer reviews
5.0 out of 5 stars Exceptional resource July 3 2004
Format:Hardcover
This book does not much dwell on the details of Sarbanes-Oxley - the reader is assumed to have an understanding of the salient details - but, instead lays out a comprehensive action plan for complying with Section 404.

The author begins with three chapters covering the overall goals and objectives, roles and responsibilities, assessment issues, and an excellent chapter about internal control criteria. Each of these chapters ends in appendices that support the compliance initiative.

Milestones, covered in Chapters 3 through 7, are clearly defined with respect to what it will take, key issues, and appendices that provide examples, guidelines, checklists and other material that support compliance. I was impressed by the straightforward approach, the complete and clear identification of all issues - and especially so regarding IT, developing documentation, and testing the controls - and the fact that the control objectives were carefully mapped to the COSO Framework.

If you want a realistic view of the scope and complexity of Section 404 compliance this book will provide it. If you are an IT professional I strongly recommend visiting Information Systems Audit and Control Association (ASIN B00006BW74), which makes available a free 84-page document titled "IT Control Objectives for Sarbanes-Oxley". For more general information, there is a commercial site that provides news and updates on Sarbanes-Oxley issues (ASIN B0000AM23N), as well as the Public Company Accounting Oversight Board (ASIN B00013Y80Y), which provides rule making information and a means to comment on proposed rules. You can reach these sites by pasting the ASIN numbers in the search box at the top of this page, selecting all products and clicking GO.

Was this review helpful to you?
Most Helpful Customer Reviews on Amazon.com (beta)
Amazon.com: 4.0 out of 5 stars  8 reviews
28 of 29 people found the following review helpful
5.0 out of 5 stars Exceptional resource July 2 2004
By Mike Tarrani - Published on Amazon.com
Format:Hardcover
This book does not much dwell on the details of Sarbanes-Oxley - the reader is assumed to have an understanding of the salient details - but, instead lays out a comprehensive action plan for complying with Section 404.

The author begins with three chapters covering the overall goals and objectives, roles and responsibilities, assessment issues, and an excellent chapter about internal control criteria. Each of these chapters ends in appendices that support the compliance initiative.

Milestones, covered in Chapters 3 through 7, are clearly defined with respect to what it will take, key issues, and appendices that provide examples, guidelines, checklists and other material that support compliance. I was impressed by the straightforward approach, the complete and clear identification of all issues - and especially so regarding IT, developing documentation, and testing the controls - and the fact that the control objectives were carefully mapped to the COSO Framework.

If you want a realistic view of the scope and complexity of Section 404 compliance this book will provide it. If you are an IT professional I strongly recommend visiting Information Systems Audit and Control Association (ASIN B00006BW74), which makes available a free 84-page document titled "IT Control Objectives for Sarbanes-Oxley". For more general information, there is a commercial site that provides news and updates on Sarbanes-Oxley issues (ASIN B0000AM23N), as well as the Public Company Accounting Oversight Board (ASIN B00013Y80Y), which provides rule making information and a means to comment on proposed rules. You can reach these sites by pasting the ASIN numbers in the search box at the top of this page, selecting all products and clicking GO.

19 of 20 people found the following review helpful
3.0 out of 5 stars Relevance of Ramos' book for IT SOX professionals Oct 7 2004
By E. J. Hillard - Published on Amazon.com
Format:Hardcover|Amazon Verified Purchase
The fact that section 404 doesn't go beyond a high level statement about "internal controls" means that IT SOX audits are making it up as they go. There is a desparate need for more detailed, authoritative guidance in this area. Unfortunately, though Ramos' book makes a contribution to the general audit literature around Sarbanes-Oxley, it does not advance things for the IT professional. If you are this kind of person, I recommend not buying this book and instead continuing to rely on the resources available on the web, mostly downloadable for free, such as the IT Governance Institute's "IT Control Objectives for Sarbanes-Oxley".
16 of 18 people found the following review helpful
5.0 out of 5 stars A SOX Roadmap for the People Who Really Need It Sep 16 2004
By Christopher Byrne - Published on Amazon.com
Format:Hardcover
Let's face it. Most people think that auditors are lifeless, unemotional drones who move with a single minded efficiency in reviewing financial records, controls and other sundry items to ensure that the financial statements of a company are free of material misstatements and that they are accurate. In fact, Andersen auditors were often referred to as "Andersen Androids". But for most people in a corporation, that was fine because they had no real need to worry about or understand accounting and business control concepts. Put an auditing textbook in front of them and you could watch their eyes glaze over.

Section 404 of the Sarbanes-Oxley (SOX) Act changes all of that, especially for line of business managers and information technology professionals. Every day I talk to people who are faced with trying to understand SOX and implementing systems to support SOX requirements. There is often frustration in their voices or emails as they lack an effective roadmap. In How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Controls (290 pages, John Wiley and Sons, Inc, 2004. 290 Pages), Michael Ramos sets out to provide an understanding of how Section 404 of SOX came to be, what it requires, what is not required, and a roadmap for assuring compliance.

It is not an easy task to present a comprehensive guide to aid with Section 404 compliance, but Ramos delivers in this book in ways that many others have tried and failed. Ramos is a CPA and an auditor by training and background. He starts from the explaining the responsibilities of an information systems auditor and very basic concepts of business controls, which allows every reader of the book to start with a common framework. His writing leads a reader to integrate, weave and understand what controls are and how they fit into the compliance process. He writes it in a way that does not talk down to the reader, but engages them in a thoughtful conversation as a good teacher would in a classroom.

The book is intended to be a guidebook and a reference and its utility for this purpose will not disappoint. After laying the groundwork, Ramos leads the reader through every step of the audit processes associated with Section 404 compliance. He helps the reader understand what the auditor will be looking for and reviewing. He examines the role of automated compliance tools, including the pros and cons of their use. He helps the reader to understand the different types of controls, the different kinds of risk and what "materiality"means when reporting deficiencies. In fact, if there is one lesson to take from this book for non-auditors, materiality is not based on what YOU think is a deficiency that will impact your view and acceptability of a system, but the view of the users of a system and/or any information generated by the system.

Who should read this book? It should be read by ALL C-level officers of an organization so they understand the concepts and the processes. It should be read by all members of an organization's audit committee so they too have an understanding. It should also be read by information systems managers so they understand that they are not operating in a silo that is independent of the rest of an organization, but that they are a fully integrated part of an ecosystem designed to support business objectives and sound corporate governance. They also need to be able to communicate with their staff about the importance of sound controls. And last but not least, it should be read by and incorporated into the toolkit of every IS Auditor.

This is not a cheap book (US$65.00), but as the best, most comprehensive guide to Section 404 compliance out there, it is worth every penny. The implementation and evolution of tools and processes associated with Section 404 of the Sarbanes-Oxley Act will bring about technical business and cultural changes in the way business is managed so that sound corporate governance is in place. This book will more than help you manage the change effectively.

The Business Controls Caddy Scorecard: Double Eagle on a long Par 5.

Christopher Byrne

"The Business Controls Caddy"

http://www.controlscaddy.com/
Search Customer Reviews
Only search this product's reviews

Listmania!

Create a Listmania! list

Look for similar items by category


Feedback