310 likes | 632 Views
SOX Project Handoff. [Enter Business Unit Name]. Admin and Ground Rules. Facilities Prizes Silence Mobile phones All contributions welcome. Why are You Here?. Mandatory Project team is leaving Time for the business to receive its SOX. Business Unit Ongoing Work Effort.
E N D
SOX Project Handoff [Enter Business Unit Name]
Admin and Ground Rules • Facilities • Prizes • Silence Mobile phones • All contributions welcome SOX Project Handoff - OPSS C12.ppt
Why are You Here? • Mandatory • Project team is leaving • Time for the business to receive its SOX SOX Project Handoff - OPSS C12.ppt
Business Unit Ongoing Work Effort BU must: Generate, Maintain & Control Evidence User Level of Effort Understanding the project team’s existing body of knowledge Updates and revisions to existing controls Update and/or create and test the documentation set Last Qtr 2005\ First Qtr 2006 Periodic Reviews Triggered Reviews as needed Continuous Improvement SOX Project Handoff - OPSS C12.ppt
Objectives • Define Key SOX terms • Identify stages of the SOX cycle of events • Describe how SOX impacts me and my team • What am I responsible for? • Identify the pieces of SOX documentation and distinguish between documentation and evidence SOX Project Handoff - OPSS C12.ppt
Language of SOX • Risks and Controls • Segregation of Duties (SOD) • AoO • PCAOB SOX Project Handoff - OPSS C12.ppt
Tell me what you do What does SOX Compliance Mean? Show me how do it Proveit to me SOX Project Handoff - OPSS C12.ppt
Narrative • Process Flow • Procedures Documentation – the Tell Me stage • What does SOX Documentation include? Tell me SOX Project Handoff - OPSS C12.ppt
Show me Evidence – the Show Me stage • What is evidence? • Why is it important? • What do we do with it? SOX Project Handoff - OPSS C12.ppt
Testing – the Prove It stage • Self-Testing • Management Assessment • Internal/External Audit Proveit SOX Project Handoff - OPSS C12.ppt
The SOX Register – Part 1 • What is the Register? • Processes & Sub-Processes • Controls • Significant • Organizational • Non-SOX • What is the most current, correct source of information about my group’s controls? SOX Project Handoff - OPSS C12.ppt
The SOX Register – Part 2 • Actual Control Descriptions (ACDs) • Objectives • Guidelines • The 5 Ws SOX Project Handoff - OPSS C12.ppt
Actual Control Description (ACD) Example Control Objective: “To ensure that appropriate provision is made for all bad debts” • “If needed the Claims Review Panel / Delegated authority asks confirmations/opinions from outside lawyers/experts. xxx calculates the provision needed based on GFAP/GFIM”. • “On a quarterly basis, provisions are calculated by the xxx after receiving inputs from the various focal points. If needed lawyer's /expert letter is obtained to assess the provision. <function> reviews if provisions are in compliance with GFAP/GFIM and approves total provision by signing <provision overview>”. Not Clear Clear and Meets the 5W’s and an H criteria SOX Project Handoff - OPSS C12.ppt
Annually & at change Annually Evaluate Self Test Internal Audit External Audit The SOX Cycle Each change Document Daily Generate & Maintain Evidence SOX Project Handoff - OPSS C12.ppt
Control Executors (everyone) Sox Documentation LEAD Control Owners Document and Test Process Owners Overall Sign Off Generate Evidence Review and Sign Off Register Roles & Responsibilities SOX Project Handoff - OPSS C12.ppt
How Will I Learn to Document & Test? • Follow the Methodology • Provides guidance for creating documentation • Owned by the Central Methodology Team • Changes frequently to accommodate new guidance from SEC and other governance groups • Location: https://sww-knowledge.shell.com/knowhow/livelink.exe?func=ll&objId=32271315&objAction=browse&sort=name • Take the Documentation and Self-Testing training online (SOX404 Website) SOX Project Handoff - OPSS C12.ppt
Who Can I Ask Questions of? • Teammates/Managers/Project Team • Embedding/Transition Team • Email Central Team QA SOX Project Handoff - OPSS C12.ppt
SOX Audits • Once your documentation and testing are complete, auditing begins • What are the phases of audit in SOX? • What is the audit process? • Who talks with the auditors? SOX Project Handoff - OPSS C12.ppt
Attest Assess Document SOX is Built on Your Daily Work • Auditors can’t attest • Managers can’t assess …Without documentation and evidence Evidence SOX Project Handoff - OPSS C12.ppt
Summary SOX Project Handoff - OPSS C12.ppt
Review Objectives • Define Key SOX terms • Identify stages of the SOX cycle of events • Describe how SOX impacts me and my team • What am I responsible for? • Identify the pieces of SOX documentation and distinguish between documentation and evidence SOX Project Handoff - OPSS C12.ppt
Next Steps • Attend the Maintain SOX Evidence training • Build shortcuts to the documentation and evidence repositories • Get ready for specialized training as needed for your role • Make sure you know what you need to know I went to Project Handoff, and all I got was this lousy binder SOX Project Handoff - OPSS C12.ppt