George Gardiner
George Gardiner

Governance rules OK

Corporate governance rules will be top of firms' agendas in 2005

Written by George Gardiner

I was somewhat surprised to hear from a client that one of the biggest issues for his organisation in 2005 is compliance with Sarbanes-Oxley (SOX) corporate governance regulations. I had assumed the issues were fairly well understood and were being addressed. But it seems firms are struggling with the day-to-day problems of implementing SOX as an integral part of their processes.

Affected firms recognise the need to comply with SOX, Basel II finance rules and other corporate governance regulations, and now software vendors are launching products to help them.

Competition and variety in the software market is a good thing, but suppliers and potential customers need to be a bit more cautious. I'm not sure everyone understands what compliance is, particularly as it differs for each business. Compliance is not just a case of ticking a box.

Whatever measures are introduced, they have to satisfy an objective externally mandated set of requirements. In particular, you cannot have a compliance product that has weak security.

Compliance is about verification and authentication. Even software vendors who promote security and accountability as key features in their applications sometimes miss the mark.

Security and accountability have to apply from the system administrator down to the end-user and through all stages of the information lifecycle from the cradle to the grave. If the system administrator is not fully audited how can you ever prove that he or she hasn't altered the data? As an IT manager I would want the comfort of knowing that I am audited, otherwise the finger of blame will always be pointed at me.

Security and accountability also means that there have to be checks on the source and accuracy of the data. Both initially and throughout its life, data has to be secured in your systems, and it has to be securely archived. Encryption and access control is an absolute must.

In this minefield of legislation and regulations we find the Data Protection Act waiting to trap the unwary. Firms will have to take a pragmatic, sensible approach, ranking their compliance requirements by importance to the business and then dealing with them in order of priority. It is also possible that some firms will not be able to afford full compliance.

There are quite a few acquisitions taking place at the moment, as smaller firms are being taken over by larger ones. This raises another issue - the need to verify that the acquiring business gains ownership of the intellectual property rights it wants.

Unfortunately, nothing replaces a proper due diligence exercise. It is costly, but if you don't know what you are buying how can you value the business?

Every acquisition brings with it a complete can of worms. I am in the business of sorting these problems out, but I would prefer it if most of them were prevented or known about in the first place. I don't like surprises, particularly when they are costly. As tedious as it is, you simply have to conduct a proper due diligence process.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Sun will work with consultancy partners to help customers prepare for compliance legislation

Sun comes out for UK compliance

Partner programme aims to demystify UK regulations 23 Mar 2005

 

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

LaboratoryFeatures

Finding the right formula

Drug and food testing company Eclipse Scientific wanted to make its internal communications system easier to manage and more responsive to the needs of employees and customers. Nicola Brittain reports 16 Mar 2010

Videoconference on a laptopFeatures

Get ready to roll

Moving staff over to a unified communications platform can have a huge impact on their working practices. Rachel Fielding explains how IT leaders can ensure the transition goes smoothly 16 Mar 2010

Primary Navigation