By Eric Brown and William Yarberry, Jr.
One problem with the implementation of SOX is that it tends to set a standard for compliance that may be inadequate. Meeting SOX standards does not imply that a firm or an IT department has the processes in place required to manage its business. Nor does it mean that an optimal level of control exists anymore than having a pulse signifies good health. SOX compliance is the minimum standard, not an optimum standard. Regardless of your firm’s current maturity level, you will need to demonstrate SOX compliance efficiently and honestly. This article describes the typical steps required to pass Section 404.