Friday, March 26, 2010

BI Vendors and Compliance

BI vendors already have the infrastructure to deal with data quality issues, and to monitor those issues over time. Many have also taken regulatory requirements into account to enhance their functionality by adding actual modules or features designed to meet the ongoing reporting requirements of SOX. For example, vendors such as SAS, Applix, and Business Objects integrate SOX compliance functionality into their BI suites.

SAS ensures compliance with SOX by providing the capabilities to assess and validate financial statements with sophisticated reporting and analytics, and to create an audit process with a searchable repository for financial documents, processes and controls. Financial processes are tightly controlled, and reporting cycles are greatly reduced (compared to organizations able to run month-end reports only), due to the structures already in place for cleansing, consolidating, and assessing data. Also, SAS Financial Intelligence allows users to consolidate data from disparate sources more quickly and accurately; track, analyze and report on risks and material changes; and monitor the effectiveness of compliance and governance initiatives.

Applix TM1 has built-in automated logging of all data changes at the user level to provide ongoing audit trails, with the ability to selectively reverse any of the entries. Workflow is also automated to ensure proper review of reports prior to release. TM1 also has the ability to build ad hoc reports, accurately communicating business changes. Additionally, TM1's real time dashboards help management interact with and manage the financial and accounting business components, in an ongoing way.

The finance intelligence analytics of Business Objects give users the ability to view every area of an organizations' financial data, whether from a summary level or a detailed level. For specific SOX audit and control analyses, Business Objects has implemented a Sarbanes-Oxley Analytic Solution, enabling organizations to gain immediate insight into internal controls, policies, and procedures. Additionally, by integrating Crystal Reports into its software suite, organizations are able to perform in-depth analyses of their financial reporting.

Other BI vendors, such as Cognos and Hyperion, have teamed up with consulting firms to provide SOX-specific modules, and to take into account systems requirements as well as business requirements to meet the additional needs of their clients.

Cognos, along with Business Intelligence International (BII), a Cognos Silver Partner, has developed SOX-specific modules to provide clients with the ability to integrate SOX compliancy in the use of their software. These include the SOX scorecard and status reporting module, the SOX work product reporting module, and the SOX analytics module. Along with these modules, Cognos includes data migration activities for loading data from Excel spreadsheets into consolidated databases and prepackaged reports using Cognos Metrics Manager, PowerPlay, and ReportNet. The BII-Cognos solution also has embedded automated testing of reporting audit trails and detection of controls monitoring.

Hyperion has joined with leading business consulting and systems integration firms, including Accenture, Cap Gemini, BearingPoint, Deloitte, and IBM, to help clients meet the financial reporting and auditing requirements of SOX compliancy. Taking into account the essential systems requirements needed to meet SOX compliancy, along with the critical business requirements that can be identified by partnering with a consulting firm, Hyperion has developed an enhanced solution for meeting the needs of its clients. Some of the features provided by BearingPoint-Hyperion are the tracking and visibility of data with corresponding audit trails; event detection and error checking; real-time monitoring of financials; participation by business unit controllers in the certification process; and delegated certification capabilities. Also, performance controls are used to enhance decision making, through a CFO dashboard. System processes are enabled by the sophisticated use of workflow, process management, and the independence of auditing roles and responsibilities.

Other BI and business performance management (BPM) vendors also provide similar functionality to the vendors mentioned above; however, not all BPM vendors have embedded data integration functions, which are essential for ensuring compliance. Without accurate data, the reporting and structures put in place to meet compliance may not be met. Obviously, each organization has different needs when considering a BI or BPM solution. However, when an organization considering SOX compliance evaluates these solutions, data integration and data quality functionality and controls must be taken into account.

No comments:

Post a Comment