Advertisement
  • Networking
  • Storage
  • Security
  • Mobility and Wireless
  • Applications
  • OS and Servers
  • Mid-sized Business
  • Green IT
  • IBM Infoclipz

Home | News | Insight | How-tos | Case studies | Interviews | Briefings | Reviews | Blog

Software Applications Insight

July 14, 08

Touchpaper questions IT readiness for EuroSOX

Guidance offered to Europe's version of Sarbanes-Oxley.

By Tom Jowitt, Techworld

Asset management company Touchpaper has released a white paper examining the impact on European companies of the EU's version of the Sarbanes-Oxley act.

Advertisement

The Statutory Audit and the Company Reporting Directives are commonly referred to as EuroSOX. These two European directives were issued by the European Union Council of Ministers, and aim to engender more transparency and public confidence in the operations of companies operating within the EU.

The Statutory Audit Directive aims to strengthen the standards and public accountability of the audit profession. The Company Reporting Directive meanwhile aims to enhance confidence in financial statements and annual reports from European companies.

The two EU Directives are required to incorporated into the national laws of EU member states this summer. States are expected to comply with the Statutory Audit Directive by 29 June, and the Company Reporting Directive by 5 September.

"Directives are not directly applicable (i.e. directly binding on individuals and companies etc) but EU member states must implement them into their national law by the stated deadlines," explained the UK department for Business, Enterprise and Regulatory Reform (BERR).

One of the most notable aspects of these Directives is the requirement that any new business created through either merger or acquisition should be able to produce consolidated accounts within a month of joining forces.

Earlier this year, the Information Security Forum (ISF) warned that the introduction of EuroSOX could be chaotic, as each state will have to interpret and translate the collection of directives that make up EuroSOX, leading to subtle divergences of law between different states.

But Touchpaper, which has recently been acquired by Avocent, is encouraging IT directors to view EuroSOX as an opportunity rather than a headache, with IT departments using the Directives to driver better IT governance. Its white paper aims to help companies understand the practical implications of the Directives, particularly from an IT service management perspective.

Touchpaper warns IT directors that while there is no technology-based 'magic bullet' solution for compliance with the Directives, the IT department nevertheless has a vital role to play in improving the general state of corporate governance in Europe.

"IT directors should be informed, so when the financial director asks them, they know a bit about it," said Marina Stedman, director at Touchpaper and the author of the white paper. "There wasn't enough information about EuroSOX, so we wanted to know more, hence the white paper. The paper offers short term actions IT directors can start thinking about."

"European directives are much less onerous than Sarbanes-Oxley," Stedman told Techworld. "They really just highlight best practises. You should be having trained auditors, should understand areas of high risk, fraud prevention etc."

And the IT Director shouldn't worry over possible conflict between EuroSOX and the Sarbanes-Oxley Act. UK and European companies only need to worry about the Sarbanes Oxley Act (which is a piece of US legislation) if they operate in the United States. UK and European companies will need to operate under the EuroSOX directives however.

"Good companies will use the European directives to put their houses in order and implement best practises," Stedman added. "We would tell IT directors that they need to understand its basic principles. Understand what processes they have in place, who is accessing corporate information, how it is transmitted etc. If someone asked who has access to this information, would they know?"

"IT also needs to report on it," said Stedman. "For auditing and company reporting purposes, IT needs to record access controls, compliance etc," she said.

That said Stedman does not see technology as the answer, but she believes it can help put processes in place. "Obviously EuroSOX can’t stop some things, so that is why we advise people to be wary of people claiming to have the answers in their software applications," she said. Stedman also cautions against EuroSOX specific solutions.

"Due to the complex nature of the Directives, the wide range of activities included, the number of member states involved and the long timetable for implementation, it will not be possible to buy a technology solution that delivers full compliance with all of their requirements. Beware of any vendor that professes to do this," she warns.

Jump to page : [ 1 ] [ 2 ]

close

Email this article to a friend or colleague:




PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

close
  • This article is now being printed.
close

What are your views on this subject? Use the form below to post a comment on this article up to 1000 characters.


Characters remaining:

close

Click below to add 'Touchpaper questions IT readiness for EuroSOX' to your blog.



If you do not have a ComputerworldUK Account and would like to use this feature, please Register.

If you are a registered, logged-in user, this will post the title and first paragraph of this story to your blog to share with your readers.

What is this?

<<newer article | back to index | older article>>



Advertisement
Advertisement

WHITE PAPERS

Techworld topic pages