Free Newsletters




   
CIO magazine chief information officer ERP IT strategy  research  analysis business technology e-business CRM customer relationship management e-business   enterprise resource management leadership
CIO.com
About
Search
Awards Programs
Subscribe
Magazine
Current
Previous
Print Links
Newsletters
CIO Store
CIO Conferences
CIO Executive Council
Blogs
News Alerts
CEO Reading
IT Strategy
Tech Linkletter
Tech Policy
Viewpoints
Experts
Alarmed
Analyst Corner
Beneath the Buzz
Consultant Briefing
Higher Learning
In the Know
Leading Questions
Weigh-In
Discussion Forums
Career
CIO Wanted
Counselor
IT Events Calendar
Movers & Shakers
Research & Polls
CIO Research Rpts
Quick Poll
Tech Poll
Reports & Guides
CIO Bookmark
Reading Room
Special Reports
Compliance
RITLAB
State of the CIO
Webcasts
White Papers
About Us
Advertise at CIO
Conference Info
Editorial Calendar
Editorial Staff
List Services
News Bureau
Reprints
Sales
Related Sites
CSO
CMO
Darwin
IDG Network
Feedback to CIO
© CXO Media Inc.
subscribe to CIO Magazine



Home > CIO Metrics
Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Regulatory Resource / Tactics

Compliance Can Improve Company Performance

By Melanie Warner

Government regulation, such as Sarbanes-Oxley and the Health Insurance Portability and Accountability Act (HIPAA), presents new and interesting challenges for the majority of America's corporations. The cost of failing to meet compliance requirements can be severe -- in the case of Sarbanes-Oxley, for example, it could even mean jail time for executives. Yet these regulations also offer something of a golden opportunity for CIOs to improve their IT systems in a way that will reward the entire company. Most CEOs and corporate executives view compliance purely as an additional cost to doing business. But there are also potential benefits to those who are willing to seize the opportunity.

It is true that regulation can cause significant problems for a company if compliance is not met.  That said, it is also true that CIOs can see these challenges as an opportunity to take ownership and propose innovative and strategic solutions that will not only address the compliance issue but also improve data management and integrity throughout the enterprise.

Take Sarbanes-Oxley, which every public company over $75 million in market cap must adhere to by November 15, 2004. Sections 404 and 302 of the law require that a company's executives maintain internal controls over financial reporting, that they make periodic assessments of those controls and that they personally testify to the accuracy of all quarterly and annual financial statements. To make these statements as accurate and easy as possible for internal and third-party groups to audit, companies must have a clear and traceable link between original data -- such as a sales order -- and the final numbers reported to the Securities & Exchange Commission.

This is fundamentally an IT problem. Finance executives oversee the organization and management of financial data, but it is software that does the essential job of shuttling this information amongst employees, customers, and suppliers. Using automated or integrated systems that create greater efficiency within this data chain will not only help satisfy compliance requirements, but also create a more efficient organization.

CIOs, however, must play an active role in not only deciding how "Sarbox" controls will be established and implemented, but also in educating other executives on how relevant IT can benefit the entire company. In many companies, this is not an easy undertaking. Too often, IT is left out of the decision-making process. A recent study by research company Hackett Group found that just 12 of 22 companies surveyed had IT representation on their Sarbox steering committees. And when Gartner surveyed 75 public companies last fall, just 63 percent said IT was involved in Sarbox planning.

Good IT investment can reduce the need for increasingly expensive audits, shorten the company's monthly close of the books, increase management transparency into financial accounting, and enable executives to respond faster to the demanding audit committees that are now a business reality. When it comes to taking ownership of compliance, educating top executives on these ancillary IT benefits is one of the most important jobs of the CIO.

The key to laying out an effective strategy to deal with Sarbox or any other government regulation lies in taking an ambitious high-level, enterprise-wide approach. It isn't enough to attempt to squeeze compliance requirements out of cobbled-together solutions. IT executives must shift their perspective from individual business units to the company's long-range needs and goals.

Several companies in the healthcare sector have already started using HIPAA requirements as an impetus to bring a greater degree of automation and security into their enterprises. Insurance company Humana in Louisville has started encrypting all patient information it sends outside the organization. When thinking about how to meet HIPAA's Security Rule, which will start being enforced on April 21, 2005, Humana's IT team envisioned the issue as broadly as possible, thinking about how technology could protect the company from all possible security breaches.

Government regulation invariably dictates what companies must do, but leaves it up to them to figure out how. For the CIO to play a role in constructing smart solutions, it is critical to persuade other stakeholders within the company that IT is an integral part of compliance and that the intelligent investment in it will pay enormous dividends for the enterprise as a whole.

Melanie Warner writes for The New York Times.

CIO Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Sectors
Law
Tactics
Related Content
Fast Fact

"12 of 22 companies surveyed had IT representation on their Sarbanes-Oxley steering committees."

--Hackett Group






Advertisers



Free Newsletters
Sponsor Content
 Domains
Compliance CIO Partner Domain for I.T. Productivity
The domain for everything you need to assess, measure and improve
IT Productivity within your organization, Whitepapers, Books, Research, Benchmarking tools and lots more.
 Webcasts
Compliance Failure is not an option: Why online compliance and security can’t wait.
Compliance BI Standardization: Attend our virtual conference for real advice.
Compliance Getting Smart about Offshoring: How Visual Simulation Gets It Right the First Time
Compliance Turning Best Practices to Best Projects
Compliance Securing Enterprise Data In An Unsecured World
Compliance A New Game—The Fast Emerging World of IP Convergence
Compliance All CIO Webcasts
 White Papers
Compliance Organizations Shift Focus to Information Management
Compliance Tera-Scale Data Warehouse Appliances Overcome the Technology Bottleneck
Compliance Knowing the Risk
Compliance Why Asset Management and Discovery are Core Contributors to Effective Business Service Management
Compliance Start your ERP upgrade with a distinctive master data advantage
Compliance Putting your Spend Data Warehouse on steroids
Compliance All CIO White Papers

IDG ENTERPRISE NETWORK

NetApp launches expanded NAS line - Infoworld Staff
IBM, BEA lay out new Java specs - Infoworld Staff
  »More  

Phishing scams rocket
Wi-Fi switches: breakthrough year, future fear
  »More  

Users get going on SP2 rollouts
Shark Tank: Just one more thing to remodel
  »More  

SPONSORED LINKS:
Align IT with business goals. Introducing PlanView Enterprise.
A data warehouse 10-50x faster at ½ the cost. Learn more!
How do you compare with 565 IT organizations?
For real advice on BI Standardization attend the Virtual Conference on Feb 22
Manage IT Change. Manage the Business. Free white paper.
Ten Principles for Knowledge Management Success" - Get the free white paper from ServiceWare
Audit the Data or Else: Un-audited data increases business risk Grid
See Qualcomm, EPL, and Deutsche Post on the Oracle Grid
Preventing Client/Vendor Mismatch: click here to learn more

Free Newsletters

Dated: March 01, 2005
http://www.cio.com/blog_view.html?ID=221


About CIO.com | Welcome | Privacy Policy | Terms of Service | Linking to us

CIO.COM complies with the ASME Guidelines with IDG extensions for new media.

CIO magazine chief information officer ERP strategy IT research analysis business technology management e-business knowledge management intranet CRM cio.com CRM customer relationship management e-business ERP enterprise resource management leadership management measuring IT value outsourcing supply chain

© 1994 - 2005 CXO Media Inc.

An International Data Group (IDG) Company



 HOME  CURRENT ISSUE  ARCHIVE   About CIO :: Advertise :: Subscribe :: Conferences 

Reprints, IDG Network, Privacy Policy

THE IDG NETWORK
CSO :: CMO :: Darwin :: Computerworld :: Network World :: Infoworld :: PC World :: Bio-IT World
IT Careers:: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp



Problems/complaints/compliments about this site can be sent to deiben@cio.com.