Mind map sources: Brink's Modern Internal Auditing (7th edition) Roberth Moeller

Sarbanes-Oxley and Beyond
1 Key Sox element: Overview of the legislation
1.1 Public Company Accounting Oversigh Board
1.1.1 PCAOB Administration and Public Accounting Firm Registration Establish auditing standards Conduct inspections of registered public accounting firms Conduct investigation and disciplinary procedures Registration of the public accounting firms that perform audits of corporation Perform other standard and quality functions as the board determines Enforce SOx compliance
1.1.2 Inspections, Investigation, and Disciplinary Procedures
1.1.3 Auditing , Quality Control, and Independence Standards Audit workpapers retention Concurring partner approval Scope of internal control testing Evaluation of internal control structure and procedures Audit quality control standards
1.1.4 Accounting Standards
1.2 Auditor Independece
1.2.1 Limitation on external auditor services Financial Information Systems design and implementation Bookkeeping and financial statement service Management and human resource function Other prohibited service
1.2.2 Audit committee preaproval of services
1.2.3 External audit partner rotation
1.2.4 External auditor reports to audit committees
1.2.5 Conflicts of interest and mandatory rotations of external audit firms
1.3 Corporate Resposibility
1.3.1 Audit committee governance rules
1.3.2 Section 302: Corporate responsibility for financial report
1.3.3 Improper influance over the conduct of audit
1.3.4 Forfeitures, bars and penalties Forfeiture of improper bonuses Bars to officer or director service Pension fund blackout periods Attorney proffesional responsibility Fair fund for investors
1.4 Enhance Financial Disclosures
1.4.1 Expanded conflict of interest provisions and disclosure
1.4.2 Management assessment of internal control: section 404
1.4.3 Financial officer code of ethic
1.4.4 Required disclosures
1.5 Analyst Conflicts of Interest
1.6 Fraud Accountability and White-Collar Crime
1.7 Corporate Fraud Accountability
2 Section 404 internal accounting control reviews
2.1 Section 404 Internal Controls Assessment Today
2.2 Launching the Section 404 Comliance Review
2.2.1 Identifying Key Processes
2.2.2 Internal Audit Role Consultant Reviewer and tester Help but not get involve with reviews
2.2.3 Organizing the Project Organize the Section 404 compliance project approach Develop a project plan Select key process for review Document selected process transaction flow Assess selected process risk Assess control effectiveness through appropriate test procedures Review compliance results with key stakeholders Complete the report on the effectiveness of the internal control structure
3 SOx's Auditing Standard No. 5 (AS 5) risk-based approaches
3.1 Focus internal control audit on the most important matters
3.2 Eliminate procedures that are unnecessary to achieve their intended benefit
3.3 Make the audit clearly scalable to fit the size and the complexity of any enterprise
3.4 Simplify the text of the standard
