Hi All,
I am looking for the detailed activities that are involved in GRC Internal and External Audit ( SOX Audit ).
Any links or info. will be great.
Thanks in advance.
Rgds,
Raj.
Help others by sharing your knowledge.
AnswerRequest clarification before answering.
Hello Raj,
Majorly, the audit is to check how you have configured your GRC implementation for your organization. Broadly, to name a few, it will cover areas like:
1. The configuration that you have done and the mapping of your company processes in the same.
2. Checking up that you have taken care of all the SODs and the fuctions are defined in such a way that there are no conflicts within a process in your organization.
3. Looking up for proper controls for Mitigation.
4. User Acess provisioning.
5. Risk mitigation and Alert monitoring should be properly defined and logs should show proper execution for the alerts.
Each of these and other such tasks can be drilled bown to any level as desired by the audit, to check the health and stability of your implementation against frauds and SOD violations.
Regards,
Hersh.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.