<?xml version="1.0" encoding="utf-8"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><ttl>60</ttl><title>BLOG.SANDERSCONSULT.COM</title><link>http://blog.sandersconsult.com</link><lastBuildDate>Mon, 06 Sep 2010 10:19:08 GMT</lastBuildDate><pubDate>Mon, 06 Sep 2010 10:19:08 GMT</pubDate><language>en</language><copyright /><itunes:subtitle></itunes:subtitle><itunes:author /><itunes:summary /><description /><itunes:owner><itunes:name /><itunes:email>dsanders@sandersconsult.com</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Arts" /><item><title>A New Plan for Global Accounting Standards</title><link>http://blog.sandersconsult.com/2010/08/24/a-new-plan-for-global-accounting-standards.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;em&gt;&lt;span style="color: #c00000;"&gt;&lt;span style="font-size: 14px;"&gt;&lt;strong&gt;The FASB and IASB revised workplan for the convergence of standards&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;
&lt;/span&gt;&lt;/em&gt;&lt;br /&gt;
On June 24, 2010, the US Financial Accounting Standards Board ( FASB ) and International Accounting Standards Board (IASB ), in a letter and progress report to the G20 Leaders Summit, issued a revised work plan on the convergence efforts for a single set of global accounting standards.  They noted the previous emphasis that the G20 placed on the convergence timeline at the September 2009 Summit: “We call on our international accounting bodies to redouble their efforts to achieve a single set of high quality, global accounting standards within the context of their independent standard setting process, and complete their convergence project by June 2011.”   In their June 24, 2010 letter they note the importance of the effort, but cite the concern of stakeholders of “their ability to provide high quality input on the large number of major exposure drafts that were planned for publication in the second quarter of this year.”  Therefore they revised their plans, keeping the previous milestone goal of June 2011 for certain projects considered to be higher priority and extending the milestone targets for what are considered lesser priority projects by six months.&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Below summarizes the three main points of the modified plan and a table summarizing the modified milestone target dates for the convergence projects.&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;b&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-size: 14px;"&gt;&lt;span style="color: #c00000; font-size: 14px;"&gt;Modified strategy and work plan&lt;/span&gt;&lt;br /&gt;
&lt;/span&gt;&lt;br /&gt;
1.  Prioritized projects&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;br /&gt;
The Boards prioritized the major projects in the original Memorandum of Understanding (MoU) to provide more impact in the short term on those projects which were considered to bring about the most significant improvement and convergence of IFRS and US GAAP. &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;These projects include: financial instruments, revenue recognition, leases, the presentation of other comprehensive income, and fair value measurement.&lt;b&gt;&lt;span style="font-size: 13px;"&gt; &lt;br /&gt;
&lt;br /&gt;
2.  Phased publication of exposure drafts&lt;/span&gt;&lt;/b&gt; &lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 13px;"&gt;Stakeholders were concerned about the fast pace at which standards were going to be published and whether this would produce acceptable quality standards in such short time and whether stakeholders would have sufficient time to review the overwhelming number of exposure standards to provide quality feedback.  Therefore the Boards spaced out the publication of exposure drafts and related public round-table meetings to allow more time for stakeholders to provide comprehensive, quality feedback.  They also limited the number of significant or complex exposure drafts issued in any one quarter to four.  &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="font-size: 13px;"&gt;3.  Stakeholder input on effective dates and transition&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;The Boards will issue a separate document requesting stakeholder input about effective dates and transition methods.   The Boards recognized that there is a significant amount of change involved in implementing the converged standards and therefore will be consulting with stakeholders to establish reasonable effective dates and transition plans.&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;span style="font-size: 13px;"&gt;&lt;b&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="color: #c00000; font-size: 14px;"&gt;Milestone target dates for converged standards&lt;/span&gt; &lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;
&lt;table style="border: medium none; border-collapse: collapse;" border="1" cellspacing="0" cellpadding="0"&gt;
    &lt;tbody&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: #c0504d 3pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: white; border-right-color: #f0f0f0; border-left-color: #f0f0f0; padding-top: 0in;" valign="bottom"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Project&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: #c0504d 3pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: white; border-right-color: #f0f0f0; border-left-color: #f0f0f0; padding-top: 0in;" valign="bottom"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Exposure Draft&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: #c0504d 3pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: white; border-right-color: #f0f0f0; border-left-color: #f0f0f0; padding-top: 0in;" valign="bottom"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Comments due&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: #c0504d 3pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: white; border-right-color: #f0f0f0; border-left-color: #f0f0f0; padding-top: 0in;" valign="bottom"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Public Round-Table Meeting&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: #c0504d 3pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: white; border-right-color: #f0f0f0; border-left-color: #f0f0f0; padding-top: 0in;" valign="bottom"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Final Standard&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;“Priority” Projects from MoU&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="text-align: center; margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Financial Instruments&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;FASB 5/26/10&lt;/span&gt;&lt;/p&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;IASB Q3 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;9/30/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Presentation of Other Comprehensive Income&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;5/26/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;9/30/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Revenue Recognition&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;6/24/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;10/22/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Leases&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;8/17/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;12/15/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Fair Value Measurement&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;6/29/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;9/7/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;b&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Lesser priority projects&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Consolidations&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q3 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Derecognition&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;IASB Q3 2010*&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Balance sheet Netting of Derivatives and Other Financial Instruments&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Financial Instruments with Characteristics of Equity&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q3 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Financial Statement Presentation – main project&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;(Staff Draft 7/1/10)&lt;/span&gt;&lt;/p&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q3 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Presentation of Discontinued Operations&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q4 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Post-employment Benefits&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;IASB 4/29/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;9/6/10&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q1 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Insurance Contracts&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q3 2010&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: windowtext 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;Q2 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
        &lt;tr&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 100.65pt; padding-right: 5.4pt; background: #eeece1; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt;Emissions Trading Schemes&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: black 1pt solid; border-left: white 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 98.25pt; padding-right: 5.4pt; background: #a6a6a6; border-right-color: #f0f0f0; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;2&lt;sup&gt;nd&lt;/sup&gt; half 2011&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 84.15pt; padding-right: 5.4pt; background: #eeece1; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 70.15pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: white 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
            &lt;td style="border-bottom: black 1pt solid; padding-bottom: 0in; border-top-color: #f0f0f0; padding-left: 5.4pt; width: 89.6pt; padding-right: 5.4pt; background: #a6a6a6; border-left-color: #f0f0f0; border-right: black 1pt solid; padding-top: 0in;" valign="top"&gt;
            &lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="color: #000000; font-size: 13px;"&gt;2012&lt;/span&gt;&lt;/p&gt;
            &lt;/td&gt;
        &lt;/tr&gt;
    &lt;/tbody&gt;
&lt;/table&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 8pt;"&gt;Source: Quarter milestones compiled from the FASB/IASB June 24, 2010 Progress Report and updated with actual publish dates as of 8/20/10.  &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 8pt;"&gt; &lt;/span&gt;&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt;"&gt;&lt;span style="font-size: 8pt;"&gt;* IASB will finalize improved disclosure requirements similar to those in US GAAP.  Then in 2012 the FASB will conclude its post-implementation review of the application of its amended derecognition requirements. The board will make a decision about any further convergence efforts.&lt;/span&gt;&lt;/p&gt;
&lt;br /&gt;
&lt;a href="http://sandersconsult.com/uploads/A_New_Plan_for_Global_Accounting_Standards.pdf" target="_blank"&gt;Download or print article&lt;br /&gt;
&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;/b&gt;</description><category>Financial Reporting</category><comments>http://blog.sandersconsult.com/2010/08/24/a-new-plan-for-global-accounting-standards.aspx#Comments</comments><guid isPermaLink="false">47f760cb-ed94-4f89-a941-889cc27009c7</guid><pubDate>Tue, 24 Aug 2010 14:56:00 GMT</pubDate></item><item><title>Failures of Project Management - Why common practices still fall short</title><link>http://blog.sandersconsult.com/2010/06/14/failure-of-project-management--why-common-practices-still-fall-short.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;p&gt;Large scale corporate projects (system implementations and upgrades, consolidating operations or systems, new compliance or regulatory standards) run into preventable cost and time overruns far more frequently than they should.  They do this despite implementing mitigation plans around well known risks. Below are some of the common plans used to address the top failures and how some of these project management [PM] practices sometimes fall short.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;1. LACK OF PROJECT OVERSIGHT AND GUIDANCE&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;br /&gt;
Assign a dedicated person from the organization to oversee the project and report to management.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;br /&gt;
&lt;/em&gt;The person assigned to oversee the project was simply available or lacking a defined role in the company and does not have experience in a disciplined project management approach.  Therefore, the project manager is little more than somebody to watch the vendors and raise questions and issues based on their gut instincts without good project plans to identify the real gaps.  Project dependencies, schedules, and risks end up not being managed effectively across vendors and resources of the project.&lt;/p&gt;
&lt;p&gt;Projects that will last months or years and involve multiple departments of a company need experienced project management with a defined project management methodology.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;2. INADEQUATE COMMUNICATION&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;br /&gt;
Written reports to communicate to the project sponsor(s) on the progress of the project&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Stakeholder representatives who have been designated to be involved in the project do not receive adequate explanation of project methodology, procedural processes (issue management, change control, training, etc.). Equally as important, these stakeholder representatives don’t always know when and how they will be involved. &lt;/li&gt;
    &lt;li&gt;Discussion of real issues and their root cause do not occur, since feedback is not solicited and the project team relies on the project management to tell them what to do real-time. &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Project management should ensure that the “process” of the project and everyone’s role in the project is clearly communicated both in writing and in meetings.  Issues should be looked for, discussed and understood when they occur. Proactively seeking out issues will save time and money by addressing them at the proper point. Pushing issues down the road can cause rework, missed objectives, and scrambling to make up time.&lt;br /&gt;
 &lt;br /&gt;
&lt;span style="color: #c00000;"&gt;&lt;strong&gt;3. USERS DO NOT RECEIVE ADEQUATE TRAINING AND MAY BE RESISTANT TO THE CHANGE(S)&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;br /&gt;
Assign a change management lead to coordinate training plans. Create a train the trainer program. Develop training manuals and presentations on how to use the new software.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;br /&gt;
&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Too much focus on the future state and not where the users come from. Failure to identify gaps from current to future state in the design and impact to the organization. &lt;/li&gt;
    &lt;li&gt;Lack of procedural-based training. Training focuses on how to perform a function, but ignores how that function may fit into a person’s job before and after the implementation.  For example, training may show how to create a purchase order in the system.  Without information about new purchasing policies and procedures such as who can approve a purchase and what types of purchases are allowed, the user may be lost after go-live.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Training programs need to be defined not only based on new system functionality, but also on the changes in the organizational structure, policies and procedures, and expectations. Defining the changes and addressing each of them creates a true change management program.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;4. LACK OF STAKEHOLDER MANAGEMENT COMMITMENT&lt;/strong&gt;&lt;/span&gt; &lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;br /&gt;
A project sponsor is identified from the executive team of the company to ensure the message is clear that the project is important and provide high level leadership.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Executive sponsor is not engaged in the project oversight. &lt;/li&gt;
    &lt;li&gt;Other senior management representing stakeholders are not involved/supportive.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While executive sponsorship is important, it is only effective if the sponsor takes an active part in overseeing the project. Sponsorship sometimes needs to include multiple disciplines of the company to effectively ensure buy-in and involvement of the necessary resources. &lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;5. LACK OF STAKEHOLDER INVOLVEMENT IN PROJECT&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans&lt;/em&gt;: &lt;br /&gt;
Project team representatives are defined from all stakeholder organizations.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Roles and authority are not made clear, resulting in an inability to make decisions and conclude on design. &lt;/li&gt;
    &lt;li&gt;Stakeholder organizations with a small impact from the project do not devote full-time resources and their involvement is not managed to ensure their input in sought for affected areas.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Project team roles and authority level must be defined. Processes and schedules should be segmented to identify affected departments and who must be involved.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;6. DESIGN FAILS TO ADDRESS BUSINESS REQUIREMENTS&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Requirements are defined prior to the beginning of the project in a project charter. &lt;/li&gt;
    &lt;li&gt;Project team includes users from the business.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Requirements are never clearly documented such that the project can have a clear definition of success. Project specifications are incomplete because they were documented in “powerpoint” fashion, i.e. so high-level as to only be project objectives and do not actually define business requirements at a level of detail for a design. This can also lead to a potentially long design timeline to sort through requirements and poor testing since the requirements to be tested are not clear.  &lt;/li&gt;
    &lt;li&gt;Too much consultant-led design causing a cookie-cutter design that doesn’t fit the business objectives. &lt;/li&gt;
    &lt;li&gt;Not enough project-experienced team leads. &lt;/li&gt;
    &lt;li&gt;Inherent requirements may not be addressed adequately without specific plans targeted at areas such as data quality, internal controls, and security.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Requirements must be documented in some form. While requirements can be defined and documented within the design phase of the project, this takes a structured approach and iterative confirmation by stakeholders.  The design process may be facilitated, but should not be taken over by consultants. Testing plans need business input on the various scenarios that may be encountered, not just generic test scripts of the base functionality.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;7. SCOPE CREEP&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans: &lt;br /&gt;
&lt;/em&gt;A statement of scope is defined in the project charter or business case based on the project objectives.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Definition of scope fails to identify dependent activities to achieve objectives such as report writing or data cleansing. &lt;/li&gt;
    &lt;li&gt;Scope simply addresses changing system functionality and does not address changing the company’s policies and procedures. &lt;/li&gt;
    &lt;li&gt;A change control process is not defined to decide and resolve potential scope changes.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Initial scope must address all activities to achieve goals, not just system functionality.  It must also include data changes, integration, policies, procedures, and internal controls.  Change control guidelines and escalation process must be defined and utilized.&lt;/p&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;8. PROJECT RISKS COME TO FRUITION&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Common plans:&lt;/em&gt; &lt;br /&gt;
A risk analysis is performed prior to the start of the project to identify risks to the project, prioritize the risks, and define how the risks will be addressed.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;PM Failures:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;Risks may not be re-analyzed during the project to determine whether the risk level is decreasing and whether risk mitigation plans are effective. &lt;/li&gt;
    &lt;li&gt;Risk mitigation plans are defined at too high of a level. For example: a mitigation plan for a project risk regarding project acceptance is defined as simply “training”.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;CONCLUSION&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;Project management is not just about having a project manager or documentation for a project.  Project management is a disciplined process.  Every project that lasts for more than a few months or involves multiple departments should have project management. This Project management needs to include: experienced project leadership, plans, defined processes for the key phases of the project, progress reporting, stakeholder communications and stakeholder involvement.  These are basic building blocks of project management.  The level of management and definition for processes will depend upon the size, requirements and complexity of the project.  Solid project management will result in reduced surprises, better ability to keep within time, budget and scope, and more stakeholders who will agree that the project was a success.&lt;br /&gt;
&lt;/p&gt;
&lt;a href="http://www.sandersconsult.com/uploads/Failures_of_Project_Management.pdf" target="_blank"&gt;Download or print article&lt;/a&gt; &lt;br /&gt;</description><category>Technology</category><category>Enterprise Risk Management</category><category>Project Management</category><comments>http://blog.sandersconsult.com/2010/06/14/failure-of-project-management--why-common-practices-still-fall-short.aspx#Comments</comments><guid isPermaLink="false">7e8f104f-0398-4f44-972f-d530be17404e</guid><pubDate>Tue, 15 Jun 2010 01:24:00 GMT</pubDate></item><item><title>Criteria for Enterprise GRC Software Selection</title><link>http://blog.sandersconsult.com/2010/04/12/criteria-for-enterprise-grc-software-selection.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;BR&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT color=#e60000&gt;&lt;EM&gt;&lt;FONT style="FONT-SIZE: 12px"&gt;&lt;STRONG&gt;Assessing the functionality of Enterprise GRC Software&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;BR&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Below provides a description of some of the c&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;ommon functionality found in Enterprise GRC Software, providing a list that can be useful for comparing products.&lt;/FONT&gt;&lt;/P&gt;&lt;BR&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; MARGIN: auto auto auto 18.9pt; WIDTH: 454.5pt; BORDER-COLLAPSE: collapse; BORDER-TOP: medium none; BORDER-RIGHT: medium none" class=MediumShading22 border=1 cellSpacing=0 cellPadding=0 width=606&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: windowtext 2.25pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: black; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; BORDER-TOP: windowtext 2.25pt solid; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT color=#ffffff&gt;Functionality&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: windowtext 2.25pt solid; PADDING-BOTTOM: 0in; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: black; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; BORDER-TOP: windowtext 2.25pt solid; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT color=#ffffff&gt;Description&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Data Relationships and hierarchy&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Ability to organize data elements such as accounts, processes, risks, and controls into the necessary relationships to match your use and maintain in an organized hierarchy.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Assessment&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Survey-based assessment, for example for the purpose of risk assessment or control self-assessment.&amp;nbsp; Automated data collection and reporting of results.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Risk management/monitoring&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Risk management involves identification of risks, the assessment of inherent risk impact and likelihood, identification of risk responses and management techniques, and the ongoing monitoring and re-evaluation of risk after risk responses have been implemented (residual risk). &lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Electronic Audit Workpapers&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Organizing and structuring audit workpapers by audit and folders, managing audit steps, tracking audit time, and keeping audit trail of persons who executed and reviewed steps.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Workflow&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Automated management of the sequence of events for executing work progress, tracking status and history of events.&amp;nbsp; Workflow should be customizable in the setup of the system to allow you to mimic your company’s work steps. &lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Document management &lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 0pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;(version control)&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Maintain electronic copies of documents, versions of each document change, and facilitating document check out/check in (assignment of document to a person and locking out others to provide change control).&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Policy management &lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Document management of policies, notification of policy changes, and maintaining their relationship to related controls.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Controls and Policy Libraries&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Pre-populated content from best practices developed by the vendor or regulatory content for control standards or general policies.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Test management&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Create test templates for testing procedures, manage multiple test runs or rounds of testing, and monitor status of tests.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Issue and remediation management&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Identify issue details, identify remediation activities, and manage the issue and remediation status (generally with workflow). Produce detail issue reports and high-level status reports.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Flexible Reporting&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Standard reports should be available for common types of reports.&amp;nbsp; Customizable query-based reporting should be available to produce reports with multiple data items linked by their relationship and their data elements. Commonly used queries can be saved as a report.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Dashboards/Metrics&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Ability to rollup metrics on status or specific data properties. Dashboards generally include graphical display of data in a chart or graph as well as table format reporting of metrics.&amp;nbsp; Metrics should allow drill-down to detail data.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Flexible customization&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Ability to add data elements for items (controls, risks, processes, etc.) of various types (text, numeric, user, reference to other items, picklist with valid values, date). &lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Role-based security&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Security allows restrictions based on role: auditor, process owner, tester, etc. and access may be restricted by workflow or by item.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Integrated regulatory/compliance content&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Some GRC products contain links or ability to pull in content from regulatory databases such as WestLaw and LexisNexis.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Data standardization&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Ability to standardize data across departments, locations or organizations and maintain consistency of the data regardless of where it occurs.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Automated controls&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Provides the implementation of automated controls in the form or edits and validations, warnings or role-based restrictions on the ability to perform functions or change certain data within an ERP application or other system.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Security assessment, design and provisioning&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM-COLOR: #f0f0f0; PADDING-BOTTOM: 0in; BACKGROUND-COLOR: transparent; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Provides the design of segregation of duties conflicts in security access and assessment of security for such conflicts. Analyze new access requests for conflicts to warn or prevent conflicts from being implemented in new provisions of access.&amp;nbsp; This is provided in EGRC systems that integrate with an ERP or other system.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="BORDER-BOTTOM: windowtext 2.25pt solid; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 157.5pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #595959; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;B&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt" color=#ffffff&gt;Continuous Controls Monitoring&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD style="BORDER-BOTTOM: windowtext 2.25pt solid; PADDING-BOTTOM: 0in; BORDER-TOP-COLOR: #f0f0f0; PADDING-LEFT: 5.4pt; WIDTH: 297pt; PADDING-RIGHT: 5.4pt; BACKGROUND: #d8d8d8; BORDER-RIGHT-COLOR: #f0f0f0; BORDER-LEFT-COLOR: #f0f0f0; PADDING-TOP: 0in" vAlign=top&gt;
&lt;P style="LINE-HEIGHT: 115%; MARGIN: 0in 0in 10pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Ability to tag certain business exceptions or events for automated real-time warning to user, email notifications or periodic reporting to management. This requires integration with another system.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;&lt;BR&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="FONT-SIZE: 14px; TEXT-DECORATION: underline" color=#e60000&gt;&lt;STRONG&gt;NON-FUNCTIONAL CONSIDERATIONS:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT size=+0&gt;&lt;FONT color=#000000&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Scalability &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Method of deployment and connectivity &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Ease of use &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Support &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Vendor background, stability, and reputation &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Product strategy and development &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Importing/Conversion of existing data &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Cost&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;&lt;/LI&gt;&lt;/UL&gt;&amp;nbsp;&lt;BR&gt;
&lt;UL&gt;&lt;/UL&gt;
&lt;UL&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 14px; TEXT-DECORATION: underline" color=#e60000&gt;QUESTIONS&amp;nbsp;FOR STARTING AN EVALUATION:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Who will be using the product and who are the primary stakeholders and their requirements? As Enterprise GRC products, these products have the potential to be used by auditors, compliance functions, risk management, business management, and IT. &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Have the potential uses been prioritized?&lt;/FONT&gt; 
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt" color=#000000&gt;What are the primary ways that you assess the status of GRC activities? &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt" color=#000000&gt;Are you selecting a product for processes that have been performed before?&amp;nbsp; If so, is the process itself one that you are happy with, but requires some enablement? What are the good and bad points of the process?&amp;nbsp; If not, have you defined the process and its requirements before selecting a software product? &lt;/FONT&gt;
&lt;LI&gt;&lt;FONT style="FONT-SIZE: 10pt"&gt;Is the current way that you organize GRC data acceptable or lacking?&amp;nbsp; If it is acceptable, how does the product handle your data classification and hierarchy?&amp;nbsp; If it is lacking, have you designed a data schema for which the product must accommodate? &lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT style="FONT-SIZE: 12pt; TEXT-DECORATION: underline" color=#e60000&gt;&lt;STRONG&gt;&lt;FONT style="FONT-SIZE: 14px" color=#e60000&gt;CAUTION&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&lt;FONT style="LINE-HEIGHT: 115%; FONT-SIZE: 10pt"&gt;Enterprise GRC software is a relatively new market. Consolidations of software vendors and their products have been occurring frequently over the past few years. Many Enterprise GRC products are presented as a suite which were formed from the integration of several products into modules of one suite. Beware of cobbled-together solutions that have not been proven out. &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://sandersconsult.com/uploads/Criteria_for_Enteprise_GRC_Software_Selection.pdf" target=_blank&gt;&lt;FONT style="FONT-SIZE: 12px"&gt;Download PDF and print article&lt;/FONT&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;&lt;FONT style="FONT-SIZE: 12px"&gt;Next GRC article: A Structured Approach to GRC Software Design&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description><category>Internal Controls</category><category>Sarbanes-Oxley</category><category>GRC Software</category><category>Enterprise Risk Management</category><category>Technology</category><comments>http://blog.sandersconsult.com/2010/04/12/criteria-for-enterprise-grc-software-selection.aspx#Comments</comments><guid isPermaLink="false">df256eb4-d844-4adc-9906-e8f6c4028341</guid><pubDate>Tue, 13 Apr 2010 02:32:00 GMT</pubDate></item><item><title>Roadmap to GRC Software</title><link>http://blog.sandersconsult.com/2010/03/23/roadmap-to-grc-software-2.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;p&gt;&lt;span style="font-size: 12px;"&gt;&lt;span style="color: #e60000; font-size: 12px;"&gt;&lt;em&gt;Understanding the terminology and types of GRC products&lt;/em&gt;&lt;/span&gt; &lt;br /&gt;&lt;/span&gt;&lt;br /&gt;‘Governance, Risk, and Compliance’ (GRC) emerged a few years ago as an umbrella term to describe the programs an organization would perform to manage these three areas entity-wide.  Companies do not necessarily integrate these activities and have various departments, policies and management activities to address them. The software market is similarly segmented.  Terminology used from one software company to another is inconsistent. The product markets often overlap. To confuse things further, analysis of specific products published by software research firms such as Gartner and Forrester is generally out-dated by the time it is published.   Since the introduction of the Sarbanes-Oxley Act (SOX), the market of GRC products has experienced rapid change.  New types of products and functionality have been developed for the management of SOX compliance.  Many of the software products originally referred to as “SOX software” developed into what is now “Enterprise GRC”. &lt;/p&gt;&lt;p&gt;Many companies decide they need software, understand one software vendor’s terminology in describing their product and then utilize the same definition in picking a short list of vendors to evaluate.  This can both eliminate viable possibilities, as well as include vendors that don’t meet the basic functional requirements simply due to inconsistent use of terminology. The first step in any software evaluation is to understand your current and potential future needs and their priority.   The primary functionalities should then be the basis of identifying products, not a label for the software products.  This could produce a list of multiple point solutions as well as Enterprise GRC suites.  Only then can you begin to assess the fit of the products themselves.&lt;/p&gt;&lt;p&gt;Below outlines some of the terminology and how the product categories may overlap.&lt;/p&gt;&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;&lt;img alt="" style="border: 0px solid; float: right;" src="http://images.quickblogcast.com/5/6/6/3/8/194446-183665/Figure1_RoadmaptoGRCMar242010.jpg?a=20" /&gt;ENTERPRISE GRC SOFTWARE&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;When publishers refer to GRC software, they are usually referring to what the analysts now call “Enterprise GRC” software.  Enterprise GRC technology supports the oversight and management of all three of the primary activities: a company’s governance functions, enterprise risk management, and compliance processes.  Functionality of this type of software includes the ability to capture data relationships between items such as processes and controls, document controls and policy libraries, perform risk assessment, and monitor control activities and testing.  &lt;/p&gt;&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;POINT SOLUTIONS&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;A point solution may address one or more of the three (governance, risk management or compliance) or may address a specific departmental focus such as financial, operational or information technology.  Point solutions can also include products to actively provide compliance (for instance security controls) as opposed to manage a compliance process or documentation of compliance.  Whereas Enterprise GRC products are generally designed to manage the overall GRC process, point solutions often address a specific industry, regulation or product-specific need (for example security specific to the company’s ERP system).  &lt;/p&gt;&lt;p&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;CATEGORIZATION OF SOLUTIONS&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The below figure depicts the possible overlap or hierarchy of how products may be categorized.  Enterprise GRC, shown at the top of this hierarchy, can be used to manage all the GRC processes for the second tier. The point solutions under each of the second tier generally operate more specific GRC activities.  Recently, Enterprise GRC “Suites” have started to include activity-specific GRC point solutions.  &lt;/p&gt;&lt;p&gt;Even though this shows common groupings, some products may still fall into various categories.&lt;/p&gt;&lt;p&gt;&lt;img alt="" style="border: 0px solid; width: 650px; height: 533px;" src="http://images.quickblogcast.com/5/6/6/3/8/194446-183665/Figure2_RoadmaptoGRCMar242010.jpg?a=64" /&gt;&lt;/p&gt;&lt;p &gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;SUMMARY&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Don’t attempt to create a short list of software for a selection process based on their label. &lt;/li&gt;    &lt;li&gt;Define your requirements.&lt;/li&gt;    &lt;li&gt;Then identify the software with the primary functionalities to meet requirements.&lt;/li&gt;&lt;/ul&gt;&lt;span style="color: #c00000;"&gt;&lt;strong&gt;DEFINITIONS&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;Financial compliance&lt;/strong&gt;&lt;br /&gt;The management and control of financial processes and the compliance to specific financial standards and regulations (Sarbanes-Oxley Act, SEC, IRS).  &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;SOX - &lt;/strong&gt;Many of the current Enterprise GRC products began as software for the management of the Sarbanes-Oxley Act compliance process and were originally called “SOX software”.  &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Tax compliance - &lt;/strong&gt;Software to prepare tax returns for federal, state or local taxes.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;XBRL - &lt;/strong&gt;XBRL Software provides the tagging of data into the XBRL format for electronic standardized data capture and submission of financial statements to the SEC.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;IT GRC Management&lt;/strong&gt; &lt;br /&gt;Various point solutions exist within this realm, including security and identity management, configuration management, business continuity, IT asset management, IT policy management, and general IT risk management.  Many of the Enterprise GRC products can also be used for general IT governance, risk management, compliance and policy management.    &lt;br /&gt;&lt;strong&gt;&lt;ul&gt;    &lt;li&gt;Security  - Security products may include infrastructure security management such as intrusion detection, intrusion prevention systems (IDS or IPS) or firewall management or business application security such as segregation of duties and access provisioning.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Segregation of duties (SOD) and Access provisioning&lt;/strong&gt; - Software providing analysis of security roles and their assignment or “provisioning” to users where potential conflicts are identified which may be considered a conflicting set of duties which would allow inappropriate access.  Some SOD software is only detective in nature, analyzing existing access, and others are preventive in nature, analyzing a potential access provisioning to prevent granting access against corporate policy.  SOD and access provisioning software may be embedded in continuous controls monitoring software.&lt;/li&gt;&lt;/ul&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Audit&lt;/strong&gt; &lt;br /&gt;Audit products are designed for the documentation of audits, assessment or monitoring of controls, and analytical auditing. &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;Electronic workpapers&lt;/strong&gt; -“Electronic workpapers”, as they are generally called, have existed before the advent of Sarbanes-Oxley when many of the GRC software vendors emerged. They include functionality for workflow and document management for the purpose of maintaining internal audit workpapers.   &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Continuous Controls Monitoring (CCM)&lt;/strong&gt; - CCM allows you to monitor business exceptions to company policies or potential fraud indicators by identifying triggers.  These may report information on dashboards, reports or produce email notifications.  This type of software may be used by auditors or by management as part of its normal operations.  &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Data analysis and auditing&lt;/strong&gt; - This type of software is used primarily by auditors but may also be used by business analysts. It is used for the programmatic examination of data for the purpose of identifying potential audit anomalies or fraud, sampling, or continuous controls monitoring.   This process is often referred to as “CAATs” or Computer-Assisted Audit Techniques or Computer-Aided Audit Techniques.  These tools provide identification and combination of data files from various sources. Some data analysis software vendors refer to their products as continuous controls monitoring software.  &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; &lt;strong&gt;Other Point solutions&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;Privacy&lt;/strong&gt; - Privacy products may provide security functionality (overlapping into the IT GRC area) and manage the classification of data to manage privacy or disclosure requirements and regulations. &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Legal GRC&lt;/strong&gt; - Legal GRC products deal with litigation management, records retention and records management, contract management and compliance, and other legal risks and compliance issues.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Human Resources&lt;/strong&gt; - Management of HR policies, compensation practices, hiring and termination practices, employee satisfaction, and training and employee development systems.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Health, Safety and Environmental&lt;/strong&gt; - Software that tracks health programs, track safety programs, incidents and reporting, or maintain environmental controls. &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Insurance&lt;/strong&gt; - Insurance software products manage claims as well as policies.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Quality&lt;/strong&gt; - Quality management products are often found in operations management for statistical quality control monitoring.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Vendor management&lt;/strong&gt; - Vendor management products assist in managing vendor policies, credit checking, or general identity verification.&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Regulatory compliance&lt;/strong&gt; - Software specific to particular regulations (such as HIPAA, PCI, etc.).  For example, some security monitoring software will claim that you can maintain PCI compliance with its use.  &lt;/li&gt;&lt;/ul&gt;&lt;p&gt; Next article: Evaluating Enterprise GRC Software&lt;/p&gt;</description><category>Internal Controls</category><category>Sarbanes-Oxley</category><category>GRC Software</category><category>Enterprise Risk Management</category><category>Technology</category><comments>http://blog.sandersconsult.com/2010/03/23/roadmap-to-grc-software-2.aspx#Comments</comments><guid isPermaLink="false">a9f4ce01-0e8c-4c03-bedc-21b1fed3636b</guid><pubDate>Wed, 24 Mar 2010 02:03:27 GMT</pubDate></item><item><title>IFRS - Waiting on the SEC? What does it matter right now to US public companies?</title><link>http://blog.sandersconsult.com/2010/01/27/ifrs--waiting-on-the-sec-what-does-it-matter-right-now-to-us-public-companies.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;P&gt;Many companies are waiting on the SEC’s timeline for a US GAAP to IFRS adoption to get up to speed on International Financial Reporting Standards and take steps to assess IFRS impact.&amp;nbsp; What about the impact of IFRS now?&amp;nbsp; What impact you say?&amp;nbsp; If the SEC hasn’t mandated it for US issuers, then it’s a non-issue right?&amp;nbsp; Not necessarily.&amp;nbsp; The impact now for a US issuer which operates internationally is from other countries adopting IFRS.&amp;nbsp; The potential magnitude of this impact seems to have gotten shuffled under the rug.&lt;/P&gt;
&lt;P&gt;The impact to a US issuer operating internationally can be broken down into four components:&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Changes in the local country accounting and systems&lt;BR&gt;2.&amp;nbsp;Maintenance of two or more sets of accounting books (yes, I said MORE)&lt;BR&gt;3.&amp;nbsp;Changes in the US consolidation&lt;BR&gt;4.&amp;nbsp;New risk to internal control over financial reporting (Sarbanes-Oxley implications)&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;1.&amp;nbsp;CHANGES IN THE LOCAL COUNTRY ACCOUNTING AND SYSTEMS&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;Local statutory reporting requirements vary by country, the type of legal entity, and operating circumstances. Your specific circumstances will determine whether your company must adopt IFRS locally when the country announces a transition to IFRS.&amp;nbsp; As such, the best way to know your company requirements for reporting is to contact the local regulatory authorities. &lt;/P&gt;
&lt;P&gt;As a local entity adopts IFRS, decisions must be made on how items will be accounted for under IFRS on the local books.&amp;nbsp; These changes to accounting result in the following changes and considerations: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Accounting policies and procedures – Policies and procedures will need to be updated to reflect IFRS policies and procedures. 
&lt;LI&gt;Accounting system – The local accounting system needs to reflect changes relevant to international accounting standards, including potentially a new ledger, new calculation methods, new general ledger accounts, and new reports. 
&lt;LI&gt;Internal controls – Changes to policies and procedures at the local country level will likely impact the internal controls performed and documented relevant to the company’s Sarbanes-Oxley assessment. 
&lt;LI&gt;Processes to submit financial data to US Corporate – If the local country submits a standard reporting package to the US corporate office, is that reporting package going to change? Is the local accounting staff responsible for transforming the IFRS books to US GAAP?&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;2.&amp;nbsp;MAINTENANCE OF TWO OR MORE SETS OF ACCOUNTING BOOKS&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;As a US public company with an international entity adopting IFRS, at the local country level there will be a set of books for IFRS reporting, and for US consolidation there will need to be a US GAAP version of the books.&amp;nbsp; Why do I mention potentially more?&amp;nbsp; During the year before IFRS is required, a company which reports comparative financial statements will likely be compiling financial data under both the current local statutory requirements and the IFRS requirements.&amp;nbsp; Also, depending upon the specific country requirements, the company could be required to report under a different set of standards to other entities, such as taxing authorities or banks.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;3.&amp;nbsp;CHANGES IN THE US CONSOLIDATION&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;As the local country accounting changes, the reporting package sent to corporate or system interfaces to the US corporate reporting system may change, unless the transformation from IFRS to US GAAP is to take place in the local country.&amp;nbsp; In either case, the accounting staff responsible for the conversion from IFRS to US GAAP needs training on IFRS and new procedures on this conversion.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;4.&amp;nbsp;NEW RISK TO INTERNAL CONTROL OVER FINANCIAL REPORTING&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;All of the above present new risks to internal control over financial reporting (ICFR) and a new consideration in management’s and their auditor’s Sarbanes-Oxley assessment.&amp;nbsp; New and updated control procedures should be considered for the changes to processes, systems, and ensuring the adequacy of skills and knowledge of IFRS and the new related procedures.&lt;/P&gt;
&lt;P&gt;While the US GAAP transition to IFRS may be the largest potential IFRS impact to US companies, the impact of other countries’ transition should not be ignored or minimized.&amp;nbsp; Companies that do not take the necessary steps to manage the change and its related risk may be sorry when their auditor finds errors in the US consolidated financial statements.&lt;BR&gt;&lt;BR&gt;&lt;A href="http://sandersconsult.com/uploads/IFRS_-_What_does_it_matter_right_now_for_US_public_companies.pdf" target=_blank&gt;Download or print article&lt;BR&gt;&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;</description><category>Internal Controls</category><category>Sarbanes-Oxley</category><category>Financial Reporting</category><comments>http://blog.sandersconsult.com/2010/01/27/ifrs--waiting-on-the-sec-what-does-it-matter-right-now-to-us-public-companies.aspx#Comments</comments><guid isPermaLink="false">cb14623d-2290-46e1-bea7-59e3d8aecd18</guid><pubDate>Wed, 27 Jan 2010 21:41:00 GMT</pubDate></item><item><title>The risk of Enterprise Risk Management</title><link>http://blog.sandersconsult.com/2010/01/04/the-risk-of-enterprise-risk-management.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;P&gt;The SEC gave final approval to a rule requiring disclosure of certain governance practices, including the Board’s role in a company’s risk oversight effective February 28, 2010.&amp;nbsp; Other entities recently focusing on the topic of Enterprise Risk Management (ERM) include COSO, the AICPA, and Standard &amp;amp; Poor’s credit rating agency. The main targets of concern are the Board and Audit Committee role and ensuring that Board’s are addressing risk. The SEC rules provide vague requirements on how a Board or company should be addressing risk and simply require that the Board’s role in risk oversight be described. For the Chief Financial Officer or Chief Audit Executive raising awareness to the Board and Audit Committee, the challenges that exist include little SEC or authoritative guidance on what risk management should include, very few benchmarks of companies implementing ERM, and potential litigation or public perception challenges around disclosure.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;In this article, I’ve laid out how we got here, the guidance that exists, and questions that need to be addressed as a company moves toward a plan for addressing the new disclosure rules and implementing ERM.&lt;BR&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;IMG src="http://images.quickblogcast.com/5/6/6/3/8/194446-183665/Figure___ERM_Jan_5_2010_2.jpg?a=84"&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;ERM BACKGROUND&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;The practice of risk management has been around a long time but its first real public appearance began after the Enron and WorldCom scandals in the early 2000s, which led to the development of the Sarbanes-Oxley (SOX) Act of 2002. Although entity-wide controls such as risk assessment, monitoring, and communication were part of the overall risk framework, the focus of SOX was on financial reporting risk. This was followed by the New York Stock Exchange governance rules requiring Audit Committees to discuss risk management policies and practices.&amp;nbsp; The concept referred to as “Enterprise Risk Management” was coined by the Committee of Sponsoring Organizations of the Treadway Commission when they published “Enterprise Risk Management – Integrated Framework” in 2004.&amp;nbsp; The COSO ERM framework defined risk broader than financial risk. This document defined ERM as a "…process, effected by an entity's board of directors, management, and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives."&amp;nbsp; The COSO ERM Framework has eight Components and four objectives categories. It is an expansion of the COSO Internal Control-Integrated Framework published in 1992 and amended in 1994. The eight components are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Internal Environment 
&lt;LI&gt;Objective Setting 
&lt;LI&gt;Event Identification 
&lt;LI&gt;Risk Assessment 
&lt;LI&gt;Risk Response 
&lt;LI&gt;Control Activities 
&lt;LI&gt;Information and Communication 
&lt;LI&gt;Monitoring &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;The four objectives categories are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Strategic - high-level goals, aligned with and supporting the organization's mission 
&lt;LI&gt;Operations - effective and efficient use of resources 
&lt;LI&gt;Reporting - reliability of operational and financial reporting 
&lt;LI&gt;Compliance - compliance with applicable laws and regulations &lt;/LI&gt;&lt;/UL&gt;&lt;SPAN style="COLOR: #cc0000"&gt;
&lt;P&gt;&lt;STRONG&gt;RECENT FOCUS&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/SPAN&gt;ERM has begun to receive more focus lately by Boards and regulators due to recent changes in our environment, including the recent banking financial crisis and recession of 2008/2009.&amp;nbsp; Recent activity includes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The SEC proposed in July 2009 and finalized in December 2009 a ruling requiring Boards to disclose their role in the company’s risk management process in proxy and information statements, annual reports and registration statements. 
&lt;LI&gt;The AICPA Audit Committee Effectiveness Center published an article on effective Enterprise Risk Management in September 2009. 
&lt;LI&gt;COSO released a thought paper, Effective Enterprise Risk Oversight: The Role of the Board of Directors in August 2009. 
&lt;LI&gt;Standard &amp;amp; Poors (S&amp;amp;P), the credit rating and equity research company announced its plans to include a series of questions about risk management in its company evaluation process. This started with financial companies in 2007. The results of this inquiry is one of the many factors considered in debt rating, which has a corresponding impact on the interest rates lenders charge companies for loans or bonds.&amp;nbsp; On May 7, 2008, S&amp;amp;P also announced that it would begin including an ERM assessment in its ratings for non-financial companies starting in 2009. &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;THE CHALLENGES OF ERM DISCLOSURE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;The SEC approved rules relating to board leadership structure and the board's role in risk oversight require disclosure about:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A company's board leadership structure, including whether the company has combined or separated the chief executive officer and chairman position, and why the company believes its structure is the most appropriate for the company at the time of the filing. 
&lt;LI&gt;In certain circumstances, whether and why a company has a lead independent director and the specific role of such director. 
&lt;LI&gt;The extent of the board's role in the risk oversight of the company.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Questions that companies must now answer for themselves in disclosing this information include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What is effective risk oversight? – While articles and whitepapers have been written by the AICPA and COSO, no &lt;SPAN style="TEXT-DECORATION: underline"&gt;authoritative/regulatory&lt;/SPAN&gt; rules exist on what would be considered effective risk oversight or enterprise risk management practices.&amp;nbsp; 
&lt;LI&gt;Does disclosure of the board’s role in risk oversight present new bases for potential lawsuits by shareholders when the company has unfavorable results or surprises? 
&lt;LI&gt;How favorable or unfavorable is the public perception of delegation of risk oversight by the board to a risk committee or the audit committee? 
&lt;LI&gt;To what extent does the lack of a formal enterprise risk management program play in public perception?&amp;nbsp; Many companies have been so focused on Sarbanes-Oxley over the past few years that a broader view of risk has been somewhat obscured.&amp;nbsp; While risks are identified in Item 1A and the management discussion and analysis section of a company’s 10-K, and companies inherently address some risks in their operations, many companies do not have formal programs to ensure they address these risks. 
&lt;LI&gt;Will companies that disclose a greater level of detail about their risk management practices be better or worse off in the market? 
&lt;LI&gt;If your company doesn’t have an ERM program, what will you do to implement a program in the coming months? And will you disclose this in absence of an existing program?&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;A href="http://sandersconsult.com/uploads/The_risk_of_ERM.pdf" target=_blank&gt;Download or print this article (pdf)&lt;/A&gt;&lt;/P&gt;</description><category>Internal Controls</category><category>Sarbanes-Oxley</category><category>Enterprise Risk Management</category><comments>http://blog.sandersconsult.com/2010/01/04/the-risk-of-enterprise-risk-management.aspx#Comments</comments><guid isPermaLink="false">8f66cc30-acd7-4e16-ad8a-f8832db32a58</guid><pubDate>Mon, 04 Jan 2010 15:11:00 GMT</pubDate></item><item><title>The Business Case for a New ERP System: When is it time?</title><link>http://blog.sandersconsult.com/2009/12/02/the-business-case-for-a-new-erp-system-when-is-it-time.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;P&gt;An Enterprise Resource Planning (ERP) system is a big investment and one that can provide huge benefits to a company.&amp;nbsp; The worries around making such an investment involve fears of growing project timelines, over-budget project costs, and consultants taking huge amounts of time from your staff away from their normal duties.&amp;nbsp; On the other hand, the benefits of ERP can produce better productivity, reduced operating and administrative costs, better reporting to manage the business, and better internal control.&amp;nbsp; So when do you take that step? How do you know if you need a new ERP system?&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Many of the benefits of an ERP system come from the ability to integrate and standardize processes and functions into one system that were decentralized or disparate systems.&amp;nbsp; This article outlines the major signs or symptoms that it might be time to consider implementing a new ERP system or consolidating into a single ERP and the associated benefits. &lt;BR&gt;&lt;BR&gt;
&lt;TABLE border=2 cellSpacing=1 cellPadding=1 bgColor=#e0e0e0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD bgColor=#ffffff vAlign=top align=left&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Symptom&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD bgColor=#ffffff&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Benefit of an integrated ERP&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#a9a9a9&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Fast growth&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;Rapid growth may provide obstacles to your ability to provide the appropriate system capability.&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Scalable&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;A robust ERP solution provides scalability for additional volume of operations, users, new locations or entities.&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Inefficiency due to redundant processes and systems&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;If your company has grown through acquisition, acquiring companies with different systems or expanded into new regions and each new entity or product line has implemented their own systems, you may have inefficiency challenges.&amp;nbsp; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;Various disparate systems often mean:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Processes vary which can cause excess time and cost in monitoring and consolidating activities. 
&lt;LI&gt;Data transfers between systems are required, in turn requiring reconciliation and potentially large amounts of data manipulation.&amp;nbsp;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;Standardized Processes&lt;/STRONG&gt; &lt;BR&gt;&lt;FONT size=2&gt;A single integrated ERP system facilitates the execution of standard processes.&lt;/FONT&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;BR&gt;Reduced data transfer and manipulation&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR&gt;A single integrated system reduces or eliminates data transfer, manipulation and the associated risks. &lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Over-reliance on error-prone spreadsheets and manual processes&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;Key processes are performed in spreadsheets, such as financial consolidation or fixed asset tracking and depreciation. Key management reports are produced in spreadsheets.&amp;nbsp; If adequate systems are not in place, you may be spending a great deal of time manipulating data outside your system and often correcting errors.&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Efficient and accurate automated processes&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;Calculations and functions of an ERP are tested in implementation and can be relied upon going forward without the repeated review of a spreadsheet process.&amp;nbsp; Time spent on spreadsheet creation and review to perform functions that are standard functionality of a an ERP can be redirected to more high-impact analysis.&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Inadequate reporting capability&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;The company is lacking in its ability to forecast or plan or even report the right information timely.&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Improved reporting&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;ERP Systems support more robust planning, budgeting, and analytics to support financial analysis and control. &lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;Meeting reporting deadlines is difficult&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR&gt;Reporting is not available timely due to the need to gather data from multiple systems. Reconciling information is challenging due to multiple sources of data.&lt;BR&gt;&lt;BR&gt;When a company has multiple general ledger systems, it often means there are multiple closing processes for each set of books, transfer of data, adjustments and reconciliation.&amp;nbsp; Many companies spend a great deal of timing consolidating and making adjustments in a spreadsheet.&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;Reduced time on consolidation and period-end closing&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR&gt;The processes for period-end closing, consolidation, review and reporting are often a simpler and less time-consuming process in a centralized reporting system.&amp;nbsp; An ERP system utilizing a consolidation and reporting engine can enable a simpler, shorter closing process.&amp;nbsp; This may allow a company to either reduce headcount or re-focus accounting personnel on more strategic activities or better accounting controls such as account reconciliation. &lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;A single system holding all the data leads to timely reporting and no need to reconcile various data sources.&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;International requirements &lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR&gt;Many accounting systems are only designed for one set of accounting books and other countries generally have local statutory requirements different than the US.&amp;nbsp; &lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;Foreign currency translation may be performed inconsistently across the company with multiple systems. Exchange rates stored in separate systems may be sourced from different places and inconsistently applied.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;Companies that have multiple general ledger systems for multi-location entities are familiar with the need to have very manually intensive intercompany processes, with difficulties reconciling at period-end.&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Multi- entity accounting books&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;A true ERP system allows you to maintain multiple sets of books for multiple entities.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Consistent application of foreign currency translation&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;A single ERP system would eliminate having various exchange rates and translations in various systems. Many systems do not handle multiple currencies.&amp;nbsp; For a company with international entities, an ERP system which handled foreign currency translation is key to ensuring accurate financial statements. &lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;Balancing inter-company transactions&lt;/STRONG&gt;&lt;BR&gt;&lt;/FONT&gt;Utilizing a single ERP system, inter-company transactions would automatically facilitate both entity’s posting. &lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;High compliance costs&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;A company with various locations, systems, and processes may have inconsistent internal controls, difficulties in monitoring controls, and excessive compliance costs due to the lack of standardization.&amp;nbsp; Highly manual processes take more time to monitor and test for compliance than automated ones.&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Reduced compliance costs&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR&gt;A consistent system across locations and processes would allow better standardization of processes, controls and compliance testing.&amp;nbsp; Some internal controls that may be decentralized could become centralized, reducing the cost of performing and monitoring the control. &lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Repeated internal control deficiencies&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;Highly manual processes have more potential for error and may require more controls for redundancy and level of comfort. &lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;Some applications have inadequate security functionality to enforce proper password controls or segregation of duties. &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;Companies that have multiple systems may find it extremely tedious and difficult to manage and monitor appropriate segregation of duties.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;Physical security to servers housing key applications may be weak at regional locations.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;The ability to verify that unauthorized changes have not been made to systems can be extremely difficult or impossible within some systems without additional products.&amp;nbsp; &lt;BR&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Automated Process Controls&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;Centralized integrated processing allows for more potential to automate controls for reconciliation and monitoring and fewer redundant controls.&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Security&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR&gt;A good ERP solution can have consistent robust security that can be managed and monitored centrally across the company.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;A centralized ERP system can be maintained in one central data center making physical security easier to manage and maintain.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=2&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;Change control&lt;/STRONG&gt;&lt;BR&gt;&lt;/FONT&gt;Many good ERP systems have a change control management system that keep an audit trail and allow reporting to verify when, where, and by whom changes to the system were made.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;High IT costs&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;Distributed systems with various support models are both costly and ineffective for consistent internal controls.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#a9a9a9 vAlign=top align=left&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;&lt;FONT size=3&gt;Centralized infrastructure and support&lt;/FONT&gt;&lt;BR&gt;&lt;/STRONG&gt;A centrally-managed ERP allows for lower IT costs by maintaining one system instead of several in terms of less hardware and software, fewer support processes for user administration and helpdesk, patch management, backups, and monitoring. Other benefits may include lower user training cost and increased intercompany mobility.&lt;BR&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR&gt;One or more of the above symptoms might drive your decision to investigate an ERP solution.&amp;nbsp; However, a careful, experienced assessment might determine that existing systems can be modified and/or processes modified to achieve your objectives with a moderate investment. Your best course of action over the next few years may be to maintain your current system(s).&amp;nbsp; If you aren’t sure what the cause of your issues is or where your constraints are, then you need to start with a process and system assessment and determine this first.&amp;nbsp; The above symptoms are, at the least, signs that process improvements should be made to improve efficiency and control.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #cc0000"&gt;&lt;STRONG&gt;&lt;FONT size=2&gt;6 KEY QUESTIONS IN THE ENHANCE-OR-REPLACE DECISION&lt;BR&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR&gt;A new system is never about the latest technology but rather understanding and meeting your business goals.&amp;nbsp; As you try to decide whether to enhance or upgrade current system(s) or replace one or more systems, some key questions to keep in mind:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What are the current and future business goals you are trying to meet?&amp;nbsp; 
&lt;LI&gt;Do you have multiple disparate systems and processes which cause confusion, inefficiency, onerous data manipulation and increased potential for errors? 
&lt;LI&gt;Are you managing by spreadsheets for major processes and finding inconsistency and spending an inordinate amount of time on reconciliation? 
&lt;LI&gt;What type of growth strategy does the company have? (acquisition, new products/services, new regions or countries? 
&lt;LI&gt;What new regulatory requirements might be imposed on the company over the next few years due to either potential changes in regulations or your growth plans? For example: new accounting standards, potential IPO and related Sarbanes-Oxley and SEC requirements, new locations subject to different regulations, international operations (Foreign Corrupt Practices Act, reporting under local country statutory requirements or transition to International Financial Reporting Standards).&amp;nbsp; 
&lt;LI&gt;Which requirements are constrained by current systems and can the systems or processes be modified to meet those requirements? If so, at what cost/benefit?&amp;nbsp; &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;A href="http://www.sandersconsult.com/uploads/ERP_The_Business_Case_for_ERP.pdf" target=_blank&gt;Download or print article&lt;/A&gt;&lt;/P&gt;</description><category>Technology</category><category>Process Improvement</category><comments>http://blog.sandersconsult.com/2009/12/02/the-business-case-for-a-new-erp-system-when-is-it-time.aspx#Comments</comments><guid isPermaLink="false">922ce3ca-12da-4d05-8e49-4f170da58f6b</guid><pubDate>Wed, 02 Dec 2009 15:59:00 GMT</pubDate></item><item><title>IT General Controls - Is it really important to financial reporting?</title><link>http://blog.sandersconsult.com/2009/08/19/it-general-controls-for-sox--is-it-really-important-to-financial-reporting.aspx?ref=rss</link><dc:creator>Denise Sanders</dc:creator><description>&lt;P&gt;&lt;A href="http://sandersconsult.com/uploads/IT_General_Controls.pdf" target=_blank&gt;Download or print article&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We are coming into the fall season when IT auditors schedule their annual IT walkthrough and assessment. Many IT Directors and Chief Accounting Officers responsible for the results of their company’s Sarbanes-Oxley (SOX) internal control assessment dread this timeframe because they often still have the same philosophical and practical disagreements each year over IT general controls (ITGC).&amp;nbsp; These include: what areas should be in scope for assessment, how much should be tested, what is considered adequate controls for an objective, or even the basic premise of why it’s relevant to SOX and the evaluation of internal controls over financial reporting (ICFR).&amp;nbsp; What are the common areas of disagreement between IT auditors and management when it comes to IT general controls? And, what is really important?&amp;nbsp; &lt;/P&gt;
&lt;P&gt;To tackle the question of what’s important, we must first have a common understanding of 1) what is an IT General Control (ITGC) and how does it fit into an overall control framework, 2) the authoritative guidance, 3) the control frameworks that provide guidance on ITGC, and last, but not least, reflect on the importance to the specific organization or 4) the company’s facts and circumstances.&amp;nbsp; We can then apply this framework to some commonly disputed items.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;1.&amp;nbsp;DEFINING IT GENERAL CONTROLS&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;IT general controls can best be defined by contrast to IT application controls.&amp;nbsp; Application controls are those that are implemented within a software application and directly affect or control the processing of a transaction or event, often referred to as transaction processing controls.&amp;nbsp; IT general controls, in contrast, do not directly relate to processing transactions but support the IT environment. Some IT general controls have a more direct connection to the process controls, and others are more indirect.&amp;nbsp; To this extent, ITGC are very similar in nature to entity-level controls.&lt;/P&gt;
&lt;P&gt;ITGC controls are focused on four areas:&lt;BR&gt;&amp;#8226;&amp;nbsp;Computer Operations&lt;BR&gt;&amp;#8226;&amp;nbsp;Program Changes&lt;BR&gt;&amp;#8226;&amp;nbsp;Information Security or access to programs and data&lt;BR&gt;&amp;#8226;&amp;nbsp;Systems Development and Implementation&lt;/P&gt;
&lt;P&gt;These four areas are outlined in the &lt;EM&gt;COSO Internal Control: Integrated Framework &lt;/EM&gt;as well as the &lt;EM&gt;Control Objectives for Information and related Technology (COBIT)&lt;/EM&gt; framework.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;2.&amp;nbsp;AUTHORITATIVE GUIDANCE FOR PUBLIC ISSUERS&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;EM&gt;SEC Release 33-8810&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The SEC guidance on management’s internal control assessment provides the best basis for establishing that IT general controls must be considered in a SOX assessment.&lt;/P&gt;
&lt;P&gt;It states &lt;EM&gt;“Controls that management identifies as addressing financial reporting risks may be automated, dependent upon IT functionality, or a combination of both manual and automated procedures.&amp;nbsp; In these situations, management’s evaluation process generally considers the design and operation of the automated or IT dependent application controls and the relevant IT general controls over the applications providing the IT functionality.&amp;nbsp; While IT general controls alone ordinarily do not adequately address financial reporting risks, the proper and consistent operation of automated controls or IT functionality often depends upon effective IT general controls.” &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Important in this narrative is the reference to automated controls or those dependent upon IT functionality.&amp;nbsp; A company may not have identified any key automated controls to the financial reporting process and therefore, believe that IT general controls are not relevant to the SOX process.&amp;nbsp; However, when referring to controls dependent upon IT functionality, the SEC specifically gives examples such as balanced postings.&amp;nbsp; This would suggest, as seems reasonable, that a company is dependent upon IT functionality where it is using a general ledger application or any other financially-relevant information system that compiles, balances, or reports financial information for the interim or annual financial statements.&amp;nbsp; Therefore the IT general controls that support the operation and management of changes in these environments are relevant to the evaluation of ICFR.&lt;/P&gt;
&lt;P&gt;The SEC further explains that the identification of risks and controls within IT should be an integral part of management’s top-down, risk-based approach.&amp;nbsp; They go on to explain that &lt;EM&gt;“aspects of IT general controls that may be relevant to the evaluation of ICFR will vary depending upon a company’s facts and circumstances”&lt;/EM&gt;, an area we will address as item number four below.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;PCAOB Audit Standard No. 5&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Public Company Accounting Oversight Board’s Audit Standard No. 5&lt;/EM&gt; (“The Standard”) which replaced Audit Standard No. 2 to focus more on a risk-based approach does not directly give guidance on how much IT general controls should be considered.&amp;nbsp; It states that an important factor in considering the risk of a control is the extent to which it relies upon &lt;EM&gt;“the effectiveness of other controls (e.g., the control environment or information technology general controls)”&lt;/EM&gt;.&amp;nbsp; The Standard also discusses the need to test ITGC controls when application controls are relied upon to ensure the effective operation of the application controls.&lt;/P&gt;
&lt;P&gt;One of the most impactful pieces of information in the Standard regarding the importance of IT general controls does not actually even mention the specific term “IT general controls”.&amp;nbsp; It is the guidance on the evaluation of deficiencies. The Standard states that the severity of a deficiency is dependent upon two things: &lt;EM&gt;“1) Whether there is a reasonable possibility that the company's controls will fail to prevent or detect a misstatement of an account balance or disclosure; and 2) The magnitude of the potential misstatement resulting from the deficiency or deficiencies.”&lt;/EM&gt;&amp;nbsp; In applying this standard, many IT auditors conclude that one ITGC deficiency by itself generally would not warrant an evaluation as a significant deficiency or material weakness since ITGC controls do not directly relate to the achievement of a financial statement assertion. However, if an ITGC issue contributes to the deficiency of a key application control, (for example, ineffective testing of program changes to an application resulting in inaccurate system calculations of an account balance), then the ITGC deficiency is generally considered to be as severe as the application deficiency. The aggregation of multiple ITGC deficiencies however, can trigger an auditor to conclude that they are important enough to call to the attention of those responsible for oversight of financial reporting, i.e. the Chief Financial Officer and Audit Committee, and therefore a significant deficiency. The step from significant deficiency to material weakness is largely judgmental.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;3.&amp;nbsp;THE CONTROL FRAMEWORKS&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;EM&gt;COSO&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Committee of Sponsoring Organizations of the Treadway Commission’s Integrated Framework for Internal Control (COSO)&lt;/EM&gt; is the most commonly used control framework when evaluating the Sarbanes-Oxley Section 404 assessment of ICFR.&amp;nbsp; COSO defines internal control and five components of internal control: control environment, risk assessment, control activities, information and communication, and monitoring.&amp;nbsp; IT general controls may be contained in any of these five components.&amp;nbsp; COSO provides a definition of IT general controls and the key areas considered in ITGC but does not give detail guidance on designing or implementing IT controls.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;COBIT&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Control Objectives for Information and related Technology (COBIT)&lt;/EM&gt; published by the IT Governance Institute (ITGI) is widely used by IT auditors and management to supplement the COSO framework since it goes beyond defining the key areas of ITGC by outlining specific guidance on the application of a control framework for designing and implementing IT controls. It defines commonly accepted control objectives for technology and gives examples of controls to meet the control objectives.&amp;nbsp; &lt;EM&gt;The IT Control Objectives for Sarbanes-Oxley, 2nd Edition&lt;/EM&gt; (“SOX COBIT”) published by the ITGI applies the COBIT framework to Sarbanes-Oxley and&amp;nbsp;provides additional IT guidance on areas of greater importance to internal control over financial reporting.&amp;nbsp; This includes an approach to risk assessment for the information technology environment and guidance on the priority of controls. It is interesting to note that this publication places a greater priority on risk assessment and the risk-based approach than the first edition, although it was published prior to the PCAOB’s Audit Standard No. 5 which emphasized risk-based approach. The references to PCAOB in SOX COBIT refer to Audit Standard No. 2, which is now superceded.&amp;nbsp; The SOX COBIT document provides good guidance on points to consider, example controls and tests for controls.&amp;nbsp; The use of this document however, sometimes gets warped when the points to consider for entity-level IT controls and example activity-level controls get used as a “checklist” rather than as guidance, and little thought is given to understanding the company’s circumstances and the overall achievement of control objectives.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;4.&amp;nbsp;THE COMPANY’S FACTS AND CIRCUMSTANCES&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;In applying the above guidance and frameworks, it is important to also take the company’s specific circumstances into consideration.&amp;nbsp; Avoiding a “checklist” audit is as simple as two considerations:&lt;/P&gt;&lt;STRONG&gt;&lt;EM&gt;
&lt;OL&gt;
&lt;LI&gt;Achievement of relevant control objectives&lt;BR&gt;&lt;/EM&gt;&lt;/STRONG&gt;In most cases, a variety of different controls can be utilized to achieve the same control objective. Sometimes it is desirable to utilize multiple controls to achieve a control objective to achieve greater assurance. However, utilizing all the possible controls or all of the illustrative controls listed in the SOX COBIT is not necessary to provide reasonable assurance of control over financial reporting.&lt;STRONG&gt;&lt;EM&gt; 
&lt;LI&gt;Risk (or applicability) to the company&lt;BR&gt;&lt;/EM&gt;&lt;/STRONG&gt;An auditor who is not following a top-down risk-based approach to the assessment of company controls may request information on controls or control objectives that are not even relevant to the company, such as controls around a System Development Lifecycle methodology, when the company has no software development activities and utilizes only “off-the-shelf” applications. The controls relevant to assess for SOX not only need to be applicable, but the level of control and the nature and extent of testing should be consistent with the system’s or area’s risk and the specific control risk.&amp;nbsp; The use of a good risk assessment for IT will right-size the number of controls identified as key to SOX and the nature and extent of testing to what is reasonable and appropriate to the company. A good IT risk assessment is not independent of the overall SOX risk assessment, but follows it from the identification of existing risk to financial statement accounts to relevant process to the IT applications and systems that support those processes.&lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;COMMON AREAS OF DISAGREEMENT&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;&lt;EM&gt;Network vulnerability&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When assessing controls to ensure system security, many auditors following COBIT will insist that a network vulnerability assessment or attack and penetration test should occur every year. An auditor following the SOX COBIT model will point to an illustrative control that states: “Appropriate controls, including firewalls, intrusion detection and vulnerability assessments exist and are used to prevent unauthorized access via public networks.”&lt;BR&gt;However, this control is only illustrative and by no means mandatory.&amp;nbsp; Furthermore, the SOX COBIT document identifies some controls as “most relevant” to SOX, however threat and vulnerability assessments are not among them.&amp;nbsp; Companies with an elevated threat level, such as Fortune 100 companies or companies that are well-known in the media, and could be considered a target from outside hackers may need to have continuous vulnerability monitoring with specialized network monitoring software (intrusion detection systems or intrusion prevention systems) as well as periodic attack and penetration studies, along with strict firewall rules and related configuration policies.&amp;nbsp; However, a middle-market company with little external threat based on name-recognition or confidentiality of information in its possession may have adequate security even if its network is secured only by good firewall rules and basic firewall monitoring.&amp;nbsp; The level of control should be commiserate with the company and the IT risk assessment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Segregation of duties&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A common assessment of segregation of duties by an IT auditor includes obtaining security data from the company’s ERP system, and then comparing it to best practice cases, outlining which duties should not be performed by any one single person. One such best practice, for example, mandates that “A person who creates accounts payable invoices in the system should not also be able to produce check runs to pay the invoices”.&amp;nbsp; While this addresses the valid concern that a person could create an invoice to their own benefit and then create a check to pay that invoice, there are a number of conceivable mitigating controls that may be in place to prevent such an occurrence.&amp;nbsp; A strict conflict match based on two activities considered to be inappropriately segregated according to best case scenarios, however, does not consider mitigating controls or the remaining risk level.&amp;nbsp; In the above example, an Accounts Payable clerk who can create both invoices and checks may be prevented from defrauding the company by not having the authorization to&amp;nbsp; create invoices for vendors that have not been approved by a another party, or sign any of the checks they have created themselves. Checks may be reconciled by another person. These would be considerations in the assessment of segregation of duties that may fully mitigate or reduce the conflict to a point where the risk of the scenario is very low.&amp;nbsp; A structured approach to documenting segregation of duties conflicts, related controls, and mitigating controls will reduce the amount of discussion with auditors and helps avoid the time-consuming assessment of segregation of duties.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Backup and recovery&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;From the beginning of SOX assessments, auditors have agreed that a full-scale disaster recovery plan was outside the scope of SOX.&amp;nbsp; Continued debate occurs, however, as to what relevance to internal control over financial reporting there is to taking data backups of systems. Also debated is whether testing the recovery of those backups is something that should occur periodically and to what extent.&amp;nbsp; The inclusion of controls over data backups is closely tied to our definition of ITGC and the authoritative guidance on what types of ITGC are considered relevant in an assessment of ICFR. ITGC support the IT environment and their inclusion is based on the extent to which process or application controls are dependent upon IT.&amp;nbsp; Data backups sustain the continuity of the IT environment which supports the financially-relevant applications. At a small company where most journal entries are made at month-end and a whole new set of financial statements could be re-created very quickly, data backups are not as significant.&amp;nbsp; And while backups are relevant to most companies, the absence of reliable backup procedures or controls may not pose a high risk and may not lead to a significant deficiency.&amp;nbsp; The necessity of testing the ability to recover data from backup is often debated.&amp;nbsp; The fact is that you can’t rely on a backup being usable unless you can prove it.&amp;nbsp; The level of backup control should be based on 1) ability to ensure that the right data is in fact there, and 2) data can be recovered.&amp;nbsp; Some auditors insist that a full recovery test be performed.&amp;nbsp; If one separates verification of data and ability to recover into two parts then you find that full recovery testing may not be necessary. The question of what proves it can be recovered will depend upon the software and data format. &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #c03333"&gt;CONCLUSION&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;ITGC is a necessary part of the IT controls supporting financially-relevant applications.&amp;nbsp; Auditors may go overboard on what controls are necessary, the level of significance of certain controls and on certain tests due to a checklist approach to auditing ITGC.&amp;nbsp;&amp;nbsp; A structured IT risk assessment supported by documentation of the environment, including relationships to related process controls can reduce the amount of discussion and therefore time spent by auditors.&lt;BR&gt;&lt;BR&gt;&lt;A href="http://sandersconsult.com/uploads/IT_General_Controls.pdf" target=_blank&gt;Download or print article&lt;/A&gt;&lt;/P&gt;</description><category>Technology</category><category>Sarbanes-Oxley</category><category>Internal Controls</category><comments>http://blog.sandersconsult.com/2009/08/19/it-general-controls-for-sox--is-it-really-important-to-financial-reporting.aspx#Comments</comments><guid isPermaLink="false">0d60569b-b4c3-41fa-b4c7-c18220a427f3</guid><pubDate>Thu, 20 Aug 2009 02:58:00 GMT</pubDate></item></channel></rss>