‎2007 May 31 7:26 AM
Hi all,
I have got a requirement To create a report that fulfills the SOX requirement for visibility to VAT Record changes .Can you please tell me the what is SOX in context of VAT .
Thanks in Advance,
Rashmi.
‎2007 May 31 7:36 AM
‎2007 May 31 7:36 AM
‎2007 Dec 07 10:57 AM
As you now know SOX is a (Regulatory) Act.
The most important section that is of direct relevance is Sec 404: Assessment of Internal Controls.
This section requires that all the internal controls that relate to capturing and processing information are adequate to ensure accurate representation of business operations.
Internal Controls is a system of checks and balances. Think of it as a logical framework that will prevent incorrect processing of transaction and fraudulent activities.
Your role: (I am assuming you are an FI consultant) You need to take care of things like:
1) Proper authorization to accounting guys to post transactions, for example if invoice amount is > lets say $5000, it would require manager approval.
2) Posting periods are properly maintained, accounting clerks are not allowed for postings in pervious periods, if it is a must then it should require manager approval. If posting to previous periods is allowed without restrictions it can result in fraudulent activities.
3) Mater Data changes should always be approved/tracked by a higher authority, as some one may include a fake vendor, obtain fictitious services for the company and issue REAL checks that will be encashed by the "bad guy" who made changes to the master data.
4) Proper authorizations exits while determining discounts and bad debts.
These are just a few examples. You can think of hundreds of other issues that would compromise your company's ability to initiate, record and processes information accurately and effectively.
You may want to have a meeting with your accounting department/head in charting down controls. Once you have a list of controls, you can then confirue SAP FI-CO and other integration points appropriately.
You may also need to interact with SAP Security consultants if you have them in your team.
Configuring controls for SOX is not a one time activity. Changes in the business processes, organizaitonal changes, new business lines/products/services, all demand continuous fine tuning and monitoring.