Jeffrey T Hare, CPA CISA CIA's blog
Jeffrey Hare's blog on internal controls and security in an Oracle Applications environment.
SOX and Chamber of Commerce Survey
The timing on me finding a survey from the US Chamber of Commerce on my desk is impeccable with the financial crisis happening around us.  The survey was published Nov 07 and the question that I found interesting was:

"Looking ahead to Dec 08, to what extent do you expect compliance with SOX 404 will allow your company and your company's outside auditor to detect and prevent material fraud"



What is shocking to me is that 58.6% of respondents said "Very little at all" and only 36% said either "To a great extent" or "To a moderate extent."   Apparently, the majority of the people in the survey felt that documenting and testing internal controls would do very little to help prevent or detect fraud. 



I somewhat agree depending on how you define fraud - material fraud and sub-material fraud.  My latest white paper titled "Sub-Material Fraud: The Elephant in the Room" outlines why I believe that companies are no better off to detect sub-material fraud.  Request this white paper at www.oubpb.com.



However, in the context of this survey, I think the question related to material fraud because the context was SOX section 404.  The results are shocking since 58.6% believe that 404 hasn't done anything to prevent or detect fraud.  If you have a hunch why this might be please email me at jhare@erpseminars.com.



Now, in light of the current financial crisis, I see how people feel this way.  Greed on Wall Street has led to some of the most significant fraud ever perpetrated in the history of the world.  That type of fraud, apparently, is too difficult to detect, even for the most experienced audit firms.



I have released a schedule of the five books I plan on writing over the next year and a half.  If you are interested, check out: http://www.erpseminars.com/books.html



Regards,

Jeffrey T. Hare, CPA CISA CIA

Industry Analyst ∙ Author ∙ Consultant

Phone: 970-785-6455 Cell: 602-769-9049

Website: www.erpseminars.com

Blog: www.erpseminars.com/blog.html

Email: jhare@erpseminars.com

Oracle Users Best Practices Board (www.oubpb.com)



Please consider signing up for the various forums we host:  Oracle Internal Controls and Security; Oracle Apps Internal Controls Repository.



2008-10-02 23:42:33 GMT
Add to My Yahoo! RSS