Application-level IT Risk Assessment
ISACA Denver Chapter Meeting February 21, 2008
Kerry L. Shackelford KLS Consulting LLC
Outline
Why this topic? SEC interpretive guidance ABC’s implementation approach Design of the ITRA model Model walk-through / Q&A
Roundtable Feedback (04/13/05)
PCAOB & SEC Approve AS2 (03/09/04 & 06/17/04)
PCAOB Policy Statement (05/16/05)
KLS Consulting LLC
Why This Topic?
Corporate Outcry Begins
“The first-year implementation of new requirements for public companies’ internal control over financial reporting (ICFR) proved more burdensome and costly than expected, resulting in an outcry from corporate America.”
Integrate their audits Tailor audit plans to their client’s risks Use a top-down approach Use the work of others Communicate directly and timely with clients