Thursday, August 02, 2007
Driving the cost out of regulatory compliance
Brad Ames explains how HP is gaining efficiency and reducing compliance costs while still maintaining its risk management standards.
The practice of dispatching internal auditors throughout the organization seems strangely inefficient to Brad Ames, HP’s Director of IT Auditing – especially given the substantial post-SOX costs involved in traditional risk assessment methods. Here, he explains to Business Management how HP is gaining efficiency and reducing compliance costs while still maintaining its risk management standards.
BM. Let’s start with the obvious question first – do we really need more products and services in IT for Sarbanes Oxley compliance? Why can’t IT executives approach this as they have with other reporting requirements – a yearly fire drill that can be done manually?
See full Article.