cancel
Showing results for 
Search instead for 
Did you mean: 
Subscribe

Hi All,

I am looking for the detailed activities that are involved in GRC Internal and External Audit ( SOX Audit ).

Any links or info. will be great.

Thanks in advance.

Rgds,

Raj.

0 Likes
View Entire Topic
Former Member
0 Likes

Hello Raj,

Majorly, the audit is to check how you have configured your GRC implementation for your organization. Broadly, to name a few, it will cover areas like:

1. The configuration that you have done and the mapping of your company processes in the same.

2. Checking up that you have taken care of all the SODs and the fuctions are defined in such a way that there are no conflicts within a process in your organization.

3. Looking up for proper controls for Mitigation.

4. User Acess provisioning.

5. Risk mitigation and Alert monitoring should be properly defined and logs should show proper execution for the alerts.

Each of these and other such tasks can be drilled bown to any level as desired by the audit, to check the health and stability of your implementation against frauds and SOD violations.

Regards,

Hersh.

Former Member
0 Likes

Hi Hersh,

Thanks for the reply.

The list of the things you mentioned are the features of the GRC tools.

I am looking for the complete audit checklist kind of information, if it is available( weblink ).

Thanks,

Raj.