SOX compliance in a new financial reporting system
Keeping an engineering firm compliant and confident through a financial reporting transformation
Keeping an engineering firm compliant and confident through a financial reporting transformation
Client
Jacobs Engineering Services
Sector
Engineering Services
Project
Oracle Cloud Security and Controls
A global engineering firm was undertaking a years-long Oracle Financial Systems transformation when it realized that there were gaps in the system鈥檚 compliance controls, especially around Sarbanes-Oxley (SOX). The firm asked 乐鱼(Leyu)体育官网 LLP to help identify and address the risks.
With a deep understanding of both Oracle and SOX, 乐鱼(Leyu)体育官网 configured the Oracle program to meet the client鈥檚 business needs. We assisted Jacobs Engineering in implementing business process controls across accounting, procurement, and other operations. We assessed the security access conflicts and helped the client strengthen segregation of duties across transactional access, master data access, and application settings. The completion of this project ensured Jacob鈥檚 Engineering could launch their new Oracle Cloud solution with confidence from a compliance perspective.
The implementation of the Oracle system inadvertently created compliance gaps with potential financial and reputational risks for the client. 乐鱼(Leyu)体育官网 identified multiple areas for improvement.
1
2
3
Billy Allen:
Jacobs is an engineering and consulting firm. We provide engineering solutions for companies across a lot of different markets.
I'm Chief Accounting Officer and Senior Vice President for Jacobs.
The company has been an Oracle shop for a number of years. Most recently, probably about two-thirds of the company is on an R12 on-prem platform. The rest of the company has been on a group of disparate systems, and we like the idea of Oracle Cloud being a really good solution for that group of companies and with their disparate systems to come together into one.
SOX challenges were pretty common. It was around getting good documentation and completeness of what our SOX control structures were that were in scope, that were associated with all of those disparate systems, and how to determine the bridge of how you were going to go from that portfolio of key controls in those old systems to the portfolio and what it would look like under this one common solution with Oracle Cloud.
It's about preparation at the very beginning, end to end, communicating with all the stakeholders, whether it be process owners, whether it be SteerCo members, executive management, members of the board, and the audit committee, helping them understand what the process is going to look like, not only the IT side, but also the business process side that's going to be affected by a conversion of this size.
Definitely get prepared. Communicate early. Learn the as is model of what you are converting from. Learn that backwards and forwards. It will enable the team to know what good is going to need to look like and be in a position to say, "Hey, we're ready on all fronts. The technology's working, the controls are working, the teams are trained. Everything is ready to go."
乐鱼(Leyu)体育官网 has been a partner for many years. There was a lot of familiarity with our policies and our procedures and our people, and that was really a winning combination that made the choice about who we would work with a pretty simple one, actually.
乐鱼(Leyu)体育官网, professional, first class, very communicative. And one of the best things about working with them on this project was their collaboration with our other external advisors who were also members of the Big Four, including our audit firm. And to this day, I talk to the team about how that made such a huge difference and was really a game changer for us to be able to cut over and convert to this first phase in the timeframe that we were able to do.
They brought the subject matter expertise into the conversations that helped us determine where we needed to look and also helped us build the tools that we want to use in the future that will help us get better at that really critical part of a conversion. They also knew what our requirements were going to be from an audit perspective.
I thought it said a lot about 乐鱼(Leyu)体育官网, that they saw the need to be collaborative and be nothing else except collaborative the entire time. When I think about capabilities and subject matter expertise on the system control side, definitely the experience speaks with the 乐鱼(Leyu)体育官网 team. Their organization, their approach to the project is very intuitive from the client perspective.
I like how 乐鱼(Leyu)体育官网 was able to assess the situation and immediately start to develop action plans that we needed to act upon. And you don't do that unless you have a lot of good experience and background. On the IT side and on the business process side, we couldn't have done it without 乐鱼(Leyu)体育官网, and we'd give them a very strong recommendation for other opportunities to do more of this work for other clients.
It鈥檚 recognizing compliance gaps and risks that can occur when implementing a new Cloud Financial system, having the commitment to address the potential gaps and risks proactively, and having confidence in the reliability and accuracy of the IT Systems in achieving compliance and meeting SOX reporting requirements.
Laeeq Ahmed
Managing Director, GRC Technology, 乐鱼(Leyu)体育官网 US
To ensure the new system was SOX compliant, 乐鱼(Leyu)体育官网 internal audit and Application Security and Controls professionals worked closely with the client to assess operations and reporting structures.
1
2
3
4
Today, due to 乐鱼(Leyu)体育官网 involvement, the company is confident in its compliance practices, including its SOX reporting.聽
1
2
3
We know Oracle and we know compliance
乐鱼(Leyu)体育官网 combines long history as an Oracle partner with unsurpassed SOX experience. We bring internal audit professionals and enterprise risk experts together with our Oracle application security and controls experts, who support the technical aspects of managing both risk and SOX requirements.
We work well with others
Our knowledge of business processes, compliance requirements and technology, coupled with our proven ease in collaborating with third parties to advance our client鈥檚 interests continue to make 乐鱼(Leyu)体育官网 a natural choice for configuring Oracle systems to meet the compliance needs of clients around the world.
We have built a record of outstanding performance
乐鱼(Leyu)体育官网 has a long history of helping companies implement transformations smoothly and efficiently. As a valued Oracle Alliance partner, we can harness the software鈥檚 power to help clients transform their front, middle and back office, empower users, all while protecting information and staying compliant with financial reporting requirements.聽