2011
DOI: 10.1016/j.cose.2011.03.005
|View full text |Cite
|
Sign up to set email alerts
|

Compliance by design – Bridging the chasm between auditors and IT architects

Abstract: System and process auditors assure -from an information processing perspective -the correctness and integrity of the data that is aggregated in a company's financial statements. To do so, they assess whether a company's business processes and information systems process financial data correctly. The audit process is a complex endeavor that in practice has to rely on simplifying assumptions. These simplifying assumptions mainly result from the need to restrict the audit scope and to focus it on the major risks.… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

1
18
0

Year Published

2013
2013
2021
2021

Publication Types

Select...
4
2
1

Relationship

2
5

Authors

Journals

citations
Cited by 29 publications
(21 citation statements)
references
References 10 publications
1
18
0
Order By: Relevance
“…Data-oriented methods are well suited to identify Information Holder endpoints, but sometimes go too far. 18 The counter position is taken by a post in M. Nygard's blog 19 for a responsibility-based strategy for avoiding pure Information Holder Resources, which he refers to as "entity service anti-pattern": He recommends to always evolve away from this pattern 20 (because it creates high semantic and operational coupling) and rather "focus on behavior instead of data" (which we describe as Processing Resource and "divide services by life cycle in a business process" (which we see as one of several service identification strategies). In our opinion, this advice goes too far as well: Information Holder Resources do have their place, but any usage should be a conscious decision motivated and justified by the business and integration scenario at hand -because of the impact on coupling that Nygard describes.…”
Section: Resolution Of Forcesmentioning
confidence: 99%
“…Data-oriented methods are well suited to identify Information Holder endpoints, but sometimes go too far. 18 The counter position is taken by a post in M. Nygard's blog 19 for a responsibility-based strategy for avoiding pure Information Holder Resources, which he refers to as "entity service anti-pattern": He recommends to always evolve away from this pattern 20 (because it creates high semantic and operational coupling) and rather "focus on behavior instead of data" (which we describe as Processing Resource and "divide services by life cycle in a business process" (which we see as one of several service identification strategies). In our opinion, this advice goes too far as well: Information Holder Resources do have their place, but any usage should be a conscious decision motivated and justified by the business and integration scenario at hand -because of the impact on coupling that Nygard describes.…”
Section: Resolution Of Forcesmentioning
confidence: 99%
“…Compliance is a well-known research subject in IS. The literature addresses topics such as the compliance of business processes and services [14][15][16], requirements engineering and conceptual modeling [17,18], auditing IS compliance [19,20], and the alignment between law and IT compliance [21]. However, the majority of studies focus on the perspective of modeling and checking compliance [10], lacking the human behavior in that regulatory space and the guidance to allow cooperation between different experts, not specific to a technology or IT architecture.…”
Section: Is Design and Compliancementioning
confidence: 99%
“…There are similarities between the development methods of the IS and of specific systems that define the ORS, for instance, the ISO 9001 management system [27]. As stated by [2,20,21], both the IS and regulatory compliance should be achieved by an holistic design.…”
Section: Is Design and Compliancementioning
confidence: 99%
“…Audits commonly validate the adequacy and effectiveness of internal controls (Carlin and Gallegos, 2007;Julisch et al, 2011). Currently, auditors performing audits at service providers largely rely on manual approaches to information procurement.…”
Section: Introductionmentioning
confidence: 99%