When it comes to Sarbanes-Oxley, one of the hardest parts of compliance is getting started. Flooring manufacturer Congoleum knew what Section 404 of the legislation required – that it develop and be able to validate the adequateness of controls put in place to protect its financial reporting systems and processes. But to do so meant first documenting its in-house systems and processes.
Congoleum’s existing documentation wasn’t up to par, says Ron Duchesneau, information systems director at the Mercerville, N.J., company. “A lot of the documents either weren’t in place or they were obsolete. Our whole set of policies and standards – and even some operating procedures – had to be developed pretty much from scratch.”
That’s no easy feat. “We spent the first six to eight months of the SOX project figuring out how we were going to do this,” Duchesneau recalls. After a couple of false starts, Duchesneau realized the company needed a solid base for its documentation efforts so that it could work from there to address any gaps in its system and process controls.
“Since we didn’t have a lot of our policies, procedures and standards documented, we needed to come up with a basic framework that we could use to get started,” Duchesneau says. For this key foundation, Congoleum is using the Command Center platform from Scalable Software.
Scalable’s Command Center software is designed to identify gaps between a company’s current operations and SOX requirements. It includes an auditable, centralized repository for policies and controls, as well as vast libraries and templates to help users get started. Reporting and incident management features help companies evaluate risk and respond to audit inquiries.
Command Center’s library of policies and standards helped jumpstart Congoleum’s implementation. “Once we adopted a framework for developing policies, standards and procedures, we made really good progress,” Duchesneau says. “The documentation process really started to fall into place.”
With the documentation hurdle surmounted, Congoleum could turn its attention to implementing any necessary SOX controls the system flagged. “We still have a lot more work to do, but as far as the documentation and general infrastructure of our processes, it’s pretty much done,” Duchesneau says.
For its next phase of SOX compliance, Congoleum invested in tools to help automate some of the ongoing monitoring requirements. For example, it’s using software from Bsafe Information Systems to analyze security logs from its IBM AS/400 systems – something IT staff used to do manually in the past, Duchesneau says. It’s also using TurnOver change management software from SoftLanding Systems to monitor and log changes to application programs.
Using automated tools for these tasks not only saves IT time, but also provides a much more audit-friendly trail. “If you’re able to show that this information is coming from a system like TurnOver or Bsafe, then you’re given a whole lot more latitude as far as the amount of auditing that you need to do to prove that a particular control works,” Duchesneau says.
Next up, Duchesneau hopes to find ways to further streamline the auditing process. With the documentation complete and controls in place, the challenge of SOX will be maintaining compliance – and validating compliance through regular audits. “What concerns us is the effort to maintain the control processes and perform the audits that SOX 404 seemingly suggests we need to do,” Duchesneau says. “That’s going to take a lot of time.”
Fortunately, Congoleum is right where it wants to be in terms of SOX compliance – ahead of the deadlines. Based on its size and fiscal calendar, Congoleum is due to begin complying with Section 404 when its fiscal year ends in December of next year. But the company plans to be compliant by mid-2006, “so that if there are any little bumps along the way, we’ll be able to handle them,” Duchesneau says. “That’s why we’ve been pressing forward to get our processes in place and get to the point where we can do internal audits by July.”
Looking back on what Congoleum has accomplished since launching its SOX efforts in earnest last February, Duchesneau says there are good and bad results. On the downside, SOX has consumed a lot of IT focus. “It’s definitely eating into other IT projects. We’ve had to scale back on some projects until our executive group is satisfied that we’re compliant,” Duchesneau says.
On the plus side, the company is better off for all its work formalizing its processes and procedures, Duchesneau says. “A lot of the documents that we’ve produced over the last six months are documents that we’re glad to have, and we’re glad we went through the process.”
See also:
Qualcomm shares two years of SOX experience
Blue Rhino tackles SOX with tools on hand
The SOX tax




