Welcome!

Artificial Intelligence Authors: Zakia Bouachraoui, Liz McMillan, Yeshim Deniz, Elizabeth White, William Schmarzo

Related Topics: Artificial Intelligence

Artificial Intelligence: Article

SAP Business One & Sarbanes-Oxley Act

Information about how SAP Business One can be utilized in becoming compliant with Sarbanes-Oxley

SAP Business One on Ulitzer

The information below is excerpted from a Frequently Asked Questions document by SAP. The information below is designed to provide an overview of SAP Business One and the Sarbanes-Oxley Act. Companies running SAP Business One and needing to comply with the act will find information about how they can utilize the software to comply with requirements.

Sarbanes-Oxley Act - Background
On July 30, 2002, President Bush signed into law the U.S. Public Company Accounting Reform and Investor Protection Act of 2002, more commonly known as the Sarbanes-Oxley Act. The act, drafted by Sen. Paul Sarbanes and Rep. Michael Oxley, was created in response to a number of major corporate and accounting scandals involving a list of prominent companies including Enron and WorldCom. The act was designed to enforce corporate accountability and responsibility and granted the SEC increased regulatory control, lengthened the statute of limitations, and imposed greater criminal and compensatory punishment on executives and companies that do not comply.

The Sarbanes-Oxley Act contains over 1,000 sections, consolidated into 11 titles, and ranging from additional corporate board responsibilities to criminal penalties. A full detail of the act, including brief definitions, is over 60 pages long. Some of the act’s provisions went into effect immediately in 2002. Other provisions went into effect during the period of 2003 through 2004, and some of these provisions were later then extended until 2005 and 2006.

Who Must Comply with Sarbanes-Oxley?
A wide range of businesses including public and private companies in and outside the United States must observe Sarbanes-Oxley, including:

  • Publicly traded companies
  • Subsidiaries and divisions that are considered to be material to publicly held companies’ consolidated financial statements
  • Private companies that are issuers of public debt

Will SAP Business One Make a Company Compliant?
No software makes a company compliant with Sarbanes-Oxley, nor can a solution be guaranteed with respect to compliance on behalf of a company using that solution. If a company is responsible for complying with the act, then it is the company’s responsibility to secure the tools necessary to assist with compliance requirements. The role of software in supporting compliance with the act is to support management in implementing suitable processes, adequate controls, and to assist in the  documentation and auditing of those processes and controls. SAP Business One supports management’s efforts to implement, document, and audit appropriate processes and controls.

SAP Business One and Sarbanes-Oxley Compliance
Of the more than 1,000 sections of the Sarbanes-Oxley Act, there are three sections that are primarily concerned with management’s ability to state that adequate processes and controls are in place surrounding the preparation of financial statements. These three sections can be supported with business management solutions such as SAP Business One:

  • Section 302, Corporate responsibility for financial reports: requires CEO and CFO to certify annual or quarterly reports submitted to the SEC and face possible criminal penalties, including prison sentences
  • Section 404, Management assessment of internal controls: requires the preparation of reports certifying the presence and adequacy of internal controls over the financial reporting process
  • Section 409, Real-time issuer disclosures: requires real-time notification of material events to the public that may impact the financial results of the business

SAP Business One Design Features - Sarbanes-Oxley

SAP Business One - Integrated Approach
To the extent that a single software product allows a company to integrate the critical operations of the business, management can take a holistic view of its business processes and compliance issues. Information, whether used for management decisions, financial reporting, or record keeping, should come from a single source. SAP Business One is a single system that fully integrates financials, sales, purchasing, inventory, and manufacturing so that data flows seamlessly and a single database maintains data integrity.

SAP Business One - Alerts
SAP Business One allows users to develop an unlimited number of alerts to identify situations requiring management’s attention in a proactive fashion, as opposed to reacting after a crisis has arisen. Such alerts might include variances from budget, unusual quotations to customers, cash flow issues, or noncompliance to the company’s procedures. The built-in audit trail will  document the setting of these alerts, any changes to them, and compliance.

SAP Business One - Data Source Accessibility
SAP Business One allows users to trace journal entries to their originating business transaction, and the product’s unique relational database allows users to click on any item and drag it to a query for an instant report.

SAP Business One - Real-time Reporting
Reporting in SAP Business One is drawn on the live data residing in the product. There are built-in standard financial reports as well as the ability to create company-wide dashboards with the XL Reporter tool, which employs an easy-to-use Microsoft Excel interface.

SAP Business One - Tamper Resistant
SAP Business One provides authorizations that can be set to allow only authorized users to view or update forms, reports, and various functions within SAP Business One. To ensure that documents are posted in the correct period and no changes are made to the financial statements once they are reported, SAP Business One can be set up to allow posting to the current active period.

SAP Business One - Specific Features that Involve Compliance with Sarbanes-Oxley
The following are the aspects of SAP Business One that involve compliance with Sarbanes-Oxley.

Fully Integrated Solution
All functions within SAP Business One are fully integrated, allowing data to flow seamlessly throughout the system and be stored in a single database maintaining data integrity. All critical operations are tracked in SAP Business One including:

  • Financials
  • Sales & Purchasing
  • Customer Relationship Management
  • Light Manufacturing & Materials Resource Planning
  • Inventory Management
  • Reporting

Built-in Customization Tools
SAP Business One contains many built-in customization tools. User-defined fields and tables as well as formatted searches that provide custom logic to fields allow companies to customize the application to mirror their business processes. Information is stored in the SAP Business One database, thus eliminating the need for addon applications using separate databases.

Software Development Kit
For companies that require industry-specific functionality, SAP Business One provides a software development kit (SDK), which allows developers to build custom add-ons that integrate with SAP Business One. The SDK prevents writing directly to the core application tables so that system security, routines, and validations are preserved.

Is it possible to track approvals for material events?

Approval Procedures
To establish tighter control over significant events, such as purchases that exceed budget, approval requests can be sent to the appropriate managers, using SAP Business One approval procedures. Events vary from company to company, which is why SAP designed SAP Business One approval procedures to be completely customizable.

Can exceptions be highlighted?

Management Alerts
When exceptions occur that affect financial disclosures, such as significant write-offs, extraordinary deferrals, or exceptional financial variances, SAP Business One provides a powerful altering system that automatically and immediately sends notices to the appropriate executives.

Credit Limits for Business Partners
Each business partner can establish their own credit-limit thresholds that, when exceeded, can place the customer on hold.

Budgeting
Budget analysis can be performed on any financial account using the budgeting module, allowing actual versus budget comparisons to be highlighted.

How easy is it to find the source of data in financial reports?

Sub-ledgers with Drill Downs
Throughout SAP Business One there are many sub-ledgers and reports to assist companies when reconciling account balances. Each sub-ledger contains drill-down links to source transactions, allowing journal entries to be easily traced back to their originating transaction.

SAP Business One Drag&Relate Feature
Our patented Drag&Relate feature enables users to select a field of data with a single mouse click and then drag that field to virtually any menu item to get an instant report that displays the relationship among the items.

Unique Document Numbering
SAP Business One allows different types of transactions to have unique numbering, which allows companies to gain tighter control over sales and purchasing transactions.

Transferring Orders to Invoices
As purchase or sales orders are entered, a wizard can be used to transfer orders to invoices. As each invoice is created, a reference and link to.

Does the system provide real-time reporting?

Real-Time Posting
Sales and purchasing transactions are immediately posted to the general ledger in SAP Business One, which ensures no lag time from when a document is added to the system to when it is posted to the general ledger.

Built-In Financial Reporting
SAP Business One contains built-in standard financial reports for real-time reporting.

Advanced Financial Reporting with the XL Reporter Tool
The XL Reporter tool is an advanced financial reporting function that is fully integrated with SAP Business One and reports on live SAP Business One data, which eliminates the need to stage data. Reports can be organized into packages and scheduled for automatic distribution. Summary reports can be designed with drill-down links into detailed source information, giving managers easy and timely access to critical data.

Does the system prevent tampering?

Authorizations
SAP Business One provides granular authorizations that can allow only authorized users to view or update forms, reports, and various functions within SAP Business One. An authorized owner can be assigned to each order and invoice in SAP Business One as they are saved to the system. Document ownership rules can be assigned to teams, departments, managers, and peers, so that only authorized members can view team information.

Posting to One Open Period
To ensure that documents are posted in the correct period and no changes are made to the financial statements once they are reported, SAP Business One provides the ability to lock non-current periods, which prevents postings to periods that have been reported on and closed.

More Stories By Brad Windecker

As the President and CEO of Orchestra Software, I lead a talented team of bright people with the unified mission of helping growing industries run better. Orchestra builds industry vertical ERP software that is highly specific to the needs of the industries we serve. This strategy has enabled Orchestra to double or triple in size and revenue every year.

IoT & Smart Cities Stories
LogRocket helps product teams develop better experiences for users by recording videos of user sessions with logs and network data. It identifies UX problems and reveals the root cause of every bug. LogRocket presents impactful errors on a website, and how to reproduce it. With LogRocket, users can replay problems.
Data Theorem is a leading provider of modern application security. Its core mission is to analyze and secure any modern application anytime, anywhere. The Data Theorem Analyzer Engine continuously scans APIs and mobile applications in search of security flaws and data privacy gaps. Data Theorem products help organizations build safer applications that maximize data security and brand protection. The company has detected more than 300 million application eavesdropping incidents and currently secu...
Rafay enables developers to automate the distribution, operations, cross-region scaling and lifecycle management of containerized microservices across public and private clouds, and service provider networks. Rafay's platform is built around foundational elements that together deliver an optimal abstraction layer across disparate infrastructure, making it easy for developers to scale and operate applications across any number of locations or regions. Consumed as a service, Rafay's platform elimi...
The Internet of Things is clearly many things: data collection and analytics, wearables, Smart Grids and Smart Cities, the Industrial Internet, and more. Cool platforms like Arduino, Raspberry Pi, Intel's Galileo and Edison, and a diverse world of sensors are making the IoT a great toy box for developers in all these areas. In this Power Panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists discussed what things are the most important, which will have the most profound e...
In today's enterprise, digital transformation represents organizational change even more so than technology change, as customer preferences and behavior drive end-to-end transformation across lines of business as well as IT. To capitalize on the ubiquitous disruption driving this transformation, companies must be able to innovate at an increasingly rapid pace.
Growth hacking is common for startups to make unheard-of progress in building their business. Career Hacks can help Geek Girls and those who support them (yes, that's you too, Dad!) to excel in this typically male-dominated world. Get ready to learn the facts: Is there a bias against women in the tech / developer communities? Why are women 50% of the workforce, but hold only 24% of the STEM or IT positions? Some beginnings of what to do about it! In her Day 2 Keynote at 17th Cloud Expo, Sandy Ca...
New competitors, disruptive technologies, and growing expectations are pushing every business to both adopt and deliver new digital services. This ‘Digital Transformation’ demands rapid delivery and continuous iteration of new competitive services via multiple channels, which in turn demands new service delivery techniques – including DevOps. In this power panel at @DevOpsSummit 20th Cloud Expo, moderated by DevOps Conference Co-Chair Andi Mann, panelists examined how DevOps helps to meet the de...
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
In his keynote at 18th Cloud Expo, Andrew Keys, Co-Founder of ConsenSys Enterprise, will provide an overview of the evolution of the Internet and the Database and the future of their combination – the Blockchain. Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life ...
While the focus and objectives of IoT initiatives are many and diverse, they all share a few common attributes, and one of those is the network. Commonly, that network includes the Internet, over which there isn't any real control for performance and availability. Or is there? The current state of the art for Big Data analytics, as applied to network telemetry, offers new opportunities for improving and assuring operational integrity. In his session at @ThingsExpo, Jim Frey, Vice President of S...