Sarbanes-Oxley 'good for IT'

Summary: Compliance legislation is a good motivator for IT departments to get systems in order, says one senior IT manager who has up to 15 percent of his staff working on the issue

Complying with regulations such as Sarbanes-Oxley may have diverted money away from revenue-generating IT projects but it has forced business to get their technical houses in order, according to a senior IT manager at investment bank Dresdner Kleinwort Wasserstein.

Speaking on Thursday at the financial technology show FinExpo, Stephen Ashton, director of Global IT business management at the bank said Sarbanes-Oxley was a knee-jerk reaction to corporate scandal that was costing companies "a fortune" to comply with.

"Around ten to fifteen percent of our total headcount is working on compliance and regulation and that is quite a big cost," he explained.

He also warned that although European companies may consider Sarbanes-Oxley as a US-only issue, a similar scandal on this side of the Atlantic would undoubtedly see regulators in Brussels follow the American lead.

Sarbanes-Oxley was signed off in 2002 and is designed to prevent financial malpractice and accounting scandals such as the Enron debacle. Overall spending on complying with the Sarbanes-Oxley Act was estimated to be around $5.5bn last year, according to a recent survey by AMR Research.

However, despite the costs involved, Aston said that overall compliance was good for IT departments as it forced companies to re-organise disparate systems that in many firms had grown into random silos that did not communicate effectively.

"I think it is a great thing not just for IT but for business generally. From an IT perspective I think it’s a doubly great thing, obviously it helps us straighten things out but it is also helping us generate new value," he said.

From a systems management perspective, Ashton said, complying with Sarbanes-Oxley has forced the company to catalogue its existing IT systems and investigate exactly how those systems are being used currently.

He described how in many companies IT systems are akin to a "monster" that has no respect for time and space. Complying with regulations means taming this monster in order for companies to be able to provide the kind of transparency required by the legislation.

"We have just completed a data centre review. The thing that came out of it was that we have tonnes of information but very little knowledge. There is a lot of partial and inaccurate data in our systems," said Ashton.

The bank is working with business-intelligence provider Tideway Systems which has an application that allows a company to build an accurate map of all the disparate elements that make up its IT infrastructure.

"You need to be in a position to be able to map all of the components in infrastructure – starting with network layer and moving up into applications including financial reporting apps that Sarbanes-Oxley is so concentrated on," said Richard Muirhead, founder and chief executive of Tideway.

Muirhead said this kind of analysis is "not easy stuff to achieve and is nigh on impossible manually," which is where Tideway's tools come into play by automating the procedure as much as possible.

Topic: Networking

Andrew Donoghue

About Andrew Donoghue

"If I'd written all the truth I knew for the past ten years, about 600 people - including me - would be rotting in prison cells from Rio to Seattle today. Absolute truth is a very rare and dangerous commodity in the context of professional journalism."

Hunter S. Thompson

Andrew Donoghue is a freelance technology and business journalist with over ten years on leading titles such as Computing, SC Magazine, BusinessGreen and ZDNet.co.uk.

Specialising in sustainable IT and technology in the developing world, he has reported and volunteered on African aid projects, as well as working with charitable organisations such as the UN Foundation and Computer Aid.

adonoghue.wordpress.com/

www.greenwashIT.co.uk

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

2 comments
Log in or register to join the discussion
  • What a load of crap. I'm at a fortune 500 company and SOX continues to make IT the whipping boy of the organization. The Project Office has acquired new powers in meddling and the result is worsening internal customer service. I'm in the engineering division and we can't change a wrong date on a record without signoff from business stakeholders, etc. The result is not positive.

    My bottomline - anytime the government is the driver, you can be sure the results will not be good. If companies needed to clearn their own house, that's a separate issue.
    anonymous
  • Sarbanes Oxley is nothing but pure bullshit..
    What are small companies to do that have small IT staffs (that are already overworked)?
    What used to take 30 seconds (like resetting a disabled userid), now takes an act of congress and days to get done, just so an end user can sign on to a system and do their job.
    So I guess it's a better interest to investors knowing that a company's employee can't work for 3 days because IT couldn't let them in the system without all the appropriate approval... Wake up you Morons!!! (I guess you will when China becomes the new world leader... maybe then you'll see what idiots you all were)..
    anonymous