
MatchPoint Solutions can help companies implement Information Technology controls (or IT controls) to ensure that business objectives are met. These controls are a subset of an enterprise's internal control. We can help ensure that the IT general controls (ITGC) and IT application controls objectives meet the confidentiality, integrity, and reliability of data, and the overall management of the IT function of the business enterprise.
MatchPoint experts help organizations implement control over the Information Technology (IT) environment, computer operations, access to programs and data, program development and program changes. We use the COBIT Framework (Control Objectives for Information Technology) to define a variety of ITGC and application control objectives and recommend evaluation approaches. We then use the COBIT framework to assist with a Sarbanes-Oxley 404 IT Audit to ensure SOX compliance.
Our consultants can lead or be part of your internal team to implement a full life cycle of IT internal controls to comply with Sarbanes-Oxley regulatory requirements in the following ways:
- Remediate IT deficiencies and control deficiencies
- Design and implement IT internal controls that meet PCAOB/COBIT control objectives.
- Help create IT control audit objectives – COSO framework, PCAOB guidelines and COBIT control objectives and documentation, including the following areas:
- Access to Program and Data
- Program development
- Program change
- Computer operation
- End user computing
- Design, implement and evaluate Test of Design (TOD) and Test of Effectiveness (TOE) on key IT General and Application Controls.
- Create scripts to extract end user accounts to evaluate Segregation of Duties and User Access data issues at the system and application levels.
- Design compensating controls to remediate Segregation of Duties and User Access issues.
- Identify, test, evaluate and remediate effectiveness of company’s ERP application setup functions, including interfaces and custom programs.
- Provide pre- and post-audit in system implementation, including project management, data conversion, training and change management.
- Represent clients to host external IT audit team during the attestation period.
Our Business Transformation Services offer a wide range of solutions, please choose from the below options to get more information:
|