You are on page 1of 15

SOx 404 Checklist: Summary Page

SOx 404 Checklist: Do you have "Internal Control" of your Revenue?


The Sarbanes-Oxley Act requires proper internal controls and procedures to ensure correct financial reporting of public companies. To ensure
compliance the law specifically requires companies to:

a) Establish internal controls and procedures


b) Certify their completeness and quality
c) File an Internal Controls Report
d) Have an external auditor attest to the adequacy of your internal control system

One of the key reporting elements and the item, which was the leading cause for public restatements – REVENUE – is more under scrutiny than
ever. How are revenue related processes handled at your company? Can you be sure revenue is managed correctly throughout the entire revenue
cycle? What processes and checks and balances to you have in place to ensure proper revenue reporting?

Click on the button below to start the SOx 404 checklist challenge. You will be asked to answer a series of questions (multiple choice)
about your revenue related business processes. After you answer the questions, you can simply click on a button to calculate the score to
determine your level of preparation for this critical Sarbanes-Oxley milestone.

This document is provided by Softrax Corporation for education and informational purposes only and is not intended and should not be construed as legal advice. Your
organization may be subject to additional or different rules depending on state and local laws, court decisions, agency regulations and your organization's internal business
practices and structure.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx 404 Checklist: Questions Page

SOx 404 Checklist: Answer the following questions and see what you might be missing
This Sarbanes-Oxley Section 404 checklist is comprised of 15 questions (listed below) pertaining to your current revenue related business
practices. Each answer is weighted by a point system that is used to calculate a final score. The final score will let you gauge where your
company falls with regard to Section 404 preparation. Softrax has identified three possible categories based on level of preparedness. Use the
"Calculate" button at the bottom of this sheet to calculate and review your score.

What controls ensure that orders are recorded properly?

A Orders are keyed into an order entry system in the field by the sales staff.

B Orders are keyed into an order entry system in the field by the sales staff. Orders are then reviewed and recorded by
a member of the Finance / Accounting group.
C Orders entered by a member of the Finance / Accounting group are reviewed by management. A complete audit trail of all activity is maintained in
the order entry system.

What controls ensure that revenue is properly allocated to the components of the order (license fees, services, hardware, training,
maintenance, etc.)?

A Revenue is allocated by Accounting and entered into a spreadsheet.

B Spreadsheet entries are manually reviewed by management and compared to pricing based on established revenue recognition rules.

C Revenue is allocated automatically by an enterprise system based on established revenue recognition rules.

What controls ensure that the appropriate pricing is applied to each component of a contract in order to determine how revenue
should be allocated?

A Pricing is determined by Accounting at the time an order is entered into the enterprise system.

B Pricing is maintained in a spreadsheet. The spreadsheet calculates the amount to allocate to each component based on the pricing.

C The Order entry system provides price books. One price book contains the pricing to be used for revenue allocation. Revenue is reallocated
automatically based on the price book.

What controls ensure that invoices for non-delivered components of a contract are accounted for appropriately?

A Invoices are manually generated. Journal entries are entered into the system for the invoices.

B Invoices are generated by the system. Revenue is adjusted by Accounting based on information stored in a spreadsheet.

Revenue is scheduled automatically independent of billing terms by an enterprise system based on established
C revenue recognition rules.

What controls ensure that revenue is not recognized for delivered components of an order (e.g. license fees, hardware) until
distribution of CDs or activation keys has occurred?

A Shipping and accounting receive a duplicate report of orders to ship. Accounting Invoices from this report. Shipping contacts Accounting if an order
doesn’t ship.

B Shipping emails Accounting when the items are shipped. Accounting then creates a manual invoice.

C Shipping is integrated with the order entry and accounting system. Orders are released by accounting. Released orders are "ship confirmed" in the
system by shipping. System prevents invoice generation until shipment is confirmed.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx 404 Checklist: Questions Page

What controls ensure that unbilled revenue is being recorded properly?

A We don’t have unbilled revenue.

B We don’t recognize unbilled revenue because there is no way to track it.

C We keep spreadsheets of unbilled revenue and periodically review, recognize and match against billing activities.

D We have a enterprise system that separates billing schedules from revenue schedules, which allows us to recognize revenue independently from
billing activity.

What controls ensure that invoices for complex terms (e.g. milestones) are generated based on the stated terms of the contract?

A Complex billing terms are maintained in a spreadsheet. Invoices are created manually based on this information.

B Invoices are manually compared to the terms of the original contract for accuracy. Once confirmed, the invoice is re-keyed into the accounting
enterprise system.

C Complex terms are set up in the enterprise system at the time of order entry. Invoices are generated automatically based on these terms. Invoices
tied to an event are not released until the completion of the event is confirmed.

What controls ensure that deferred revenues are recognized based on established revenue recognition guidelines?

A All deferred revenues are entered into the General Ledger. G/L accounts are amortized in total.

B Deferred revenues are scheduled in a spreadsheet. The spreadsheet provides the amount to be recognized monthly. The amount to be recognized
is manually posted to the G/L.

C Deferred revenues are scheduled automatically by the accounting enterprise system at the time an order is entered. Schedules are created for
each deferred item individually. Revenue is then recognized automatically based on these schedules.

What controls ensure that revenues recognized under a percent complete method or based on specific milestones are not
recognized prematurely?

A Contracts are manually reviewed and journal entries are posted based on the review.

B Complex spreadsheets are maintained to help calculate the amount to be recognized monthly. Spreadsheets are manually updated. Journal entries
are booked to recognize revenue based on the information in the spreadsheet.

C Deferred revenues are scheduled automatically by the accounting enterprise system at the time an order is entered. Schedules are created for
each deferred item individually. Revenues tied to milestones are placed on hold until the milestone is met. Revenues under a percent complete
method are updated and recognized directly in the enterprise system. General ledger entries are generated by the system based on the amounts
contained in the revenue schedules.

What controls ensure that payments received are posted to the appropriate invoices?

A Invoices are re-keyed into a spreadsheet. Paid invoices are removed from the spreadsheet. A separate spreadsheet is maintained for paid invoices.

B Invoices are manually reentered into an accounts receivable system. Payments are recorded against these invoices.

C Accounts receivable is integrated with the order entry (OE) system. All Invoices created in OE are included in a customers A/R. When payments
are received, the system provides a list of all open invoices. Partial payments, write-offs and credits can all be applied directly within the system.

What controls ensure that amounts reported in the G/L reconcile with the various supporting systems (Order Entry, A/R, etc)?

A All journal entries are manually entered into the system based on the amounts contained in the supporting systems. Adjustments are booked when
discrepancies are found.

B Entries are made to the accounting system manually. All accounts are reconciled by accounting monthly.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx 404 Checklist: Questions Page

C All systems including A/R, A/P, Order entry and deferred revenues are integrated with the G/L. Subsidiary ledgers are maintained directly in the
system. Manual entries are not permitted to the G/L accounts impacted by these systems. A complete audit trail is maintained by the system for all
activity impacting the G/L.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx 404 Checklist: Questions Page

What controls ensure that components of a contract that renew automatically (e.g. maintenance) are appropriately recorded and
renewed in the correct period?

A Renewable components of a contract are entered into a spreadsheet by Accounting. At the time of renewal, an invoice is created manually and
entered into the A/R system.

B Renewals are maintained in a spreadsheet, manually created invoices are reviewed by management for errors.

C Renewable components are managed within the enterprise system and are set up automatically at the time of order entry. The system stores the
start and end dates for the period, and provides a routine to select renewals for processing based on expiration dates.

What controls ensure that adjustments to renewable components of a contract are properly recorded and reflected in a customer’s
invoice?

A Invoices are manually generated based on the information stored in the renewal spreadsheet. Adjustments are then booked to the customer’s A/R
account after invoicing.

B Statements are generated offline based on information stored in the renewal spreadsheet. Customers are given 30 days to notify
company of any changes. After 30 days, the information is reentered into the A/R system and invoices are generated.

C All renewal information including the current start and end dates and the correct pricing to renew at, is stored directly in the enterprise system. The
system generates a proforma statement based on the information in the system. Adjustments can be made to the pro forma. Invoices are
generated based on the information contained in the proforma.

What controls prevent unauthorized changes to transactions in the system?

A None

B Manual Notes describing changes.

C Complete audit trail of all transaction including date and user ID

D Complete Audit trail combined with security controls preventing unauthorized users from modifying or creating transactions

What controls ensure that changes to deferred revenue schedules are properly reflected in the G/L?

A Manual Notes

B Spreadsheet gets updated for future reference.

C Manual adjustment in G/L.

D Change is made in enterprise system, which automatically makes appropriate updates to the integrated G/L.

Back to Home Page


Calculate my SOx 404 checklist
score

This document is provided by Softrax Corporation for education and informational purposes only and is not intended and should not be construed as legal advice. Your
organization may be subject to additional or different rules depending on state and local laws, court decisions, agency regulations and your organization's internal business
practices and structure.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx 404 Checklist: Results Page

SOx 404 Checklist: How did your "Internal Controls" measure up?

Compliance Alert Level SOx 404 Compliance Assessment

Your score was from 0 - 30 points: Most of your processes are manual and in spreadsheets. There is considerable
Red compliance risk because of the lack of appropriate internal controls and the risks of human error inherent in manual
processing.

Your score was between 30 - 60 points: You have some control mechanisms in place, but are still relying in to many
Yellow areas on manual processes. This may lead to errors and indicates weaknesses in your internal controls. Additionally it
indicates a high cost of doing business because of considerable operational inefficiencies.

Your score was 60 points or higher: Congratulations! It appears that you have implemented numerous automatic
Green internal controls and at the same time are operating very efficiently.

Back to Checklist Reset the SOx 404


Back to Home Page
checklist
The foregoing test should help you to begin examining your own internal processes. It is not intended to be comprehensive but rather to suggest to you
certain areas where your internal controls may be vulnerable. A more comprehensive evaluation can be conducted with the assistance of your financial,
legal and business advisors.

This document is provided by Softrax Corporation for education and informational purposes only and is not intended and should not be construed as legal advice. Your
organization may be subject to additional or different rules depending on state and local laws, court decisions, agency regulations and your organization's internal
business practices and structure.

© 2003 Softrax Corporation. All Rights Reserved. 406535066.xls


SOx Checklist Formulas

1 What controls ensure that orders are recorded properly?

0 Orders are keyed into an order entry system in the field by the sales staff.
0 Orders entered by a member of the finance / accounting group are reviewed by management. A compl
0 Orders are reviewed and recorded by a member of the finance / accounting group.

2 What controls ensure that revenue is properly allocated to the components of the order (license fees, services, hardwa

0 Revenue is allocated by accounting and entered into a spreadsheet.


0 Spreadsheet entries are manually reviewed by management and compared to pricing based on establ
0 Revenue is allocated automatically by an enterprise system based on established revenue recognition

3 What controls ensure that the appropriate pricing is applied to each component of a contract in order to determine how

0 Pricing is determined by accounting at the time an order is entered into the enterprise system.
0 Pricing is maintained in a spreadsheet. The spreadsheet calculates the amount to allocate to each com
0 The Order entry system provides price books. One price book contains the pricing to be used for reven

4 What controls ensure that invoices for non delivered components of a contract are accounted for appropriately?

0 Invoices are manually generated. Journal entries are entered into the system for the invoices.
0 Invoices are generated by the system. Revenue is adjusted by accounting based on information stored
0 Revenue is scheduled automatically independent of billing terms by an enterprise system.

5 What controls ensure that revenue is not recognized for delivered components of an order (e.g. license fees, hardware)

0 Shipping and accounting receive a duplicate report of orders to ship. Accounting Invoices from this rep
0 Shipping emails accounting when the items are shipped. Accounting then creates a manual invoice.
0 Shipping is integrated with the order entry and accounting system. Orders are released by accounting.

6 What controls ensure that unbilled revenue is being recorded properly?

0 We don’t have unbilled revenue.


0 We don’t recognize unbilled revenue because there is no way to track it.
0 We keep spreadsheets of unbilled revenue and periodically review, recognize and match against billing
0 We have a enterprise system that separates billing schedules from revenue schedules, which allows u

7 What controls ensure that invoices for complex terms (e.g. milestones) are generated based on the stated terms of the

0 Complex billing terms are maintained in a spreadsheet. Invoices are created manually based on this in
0 Invoices are manually compared to the terms of the original contract for accuracy. Once confirmed, the
0 Complex terms are set up in the enterprise system at the time of order entry. Invoices are generated a

8 What controls ensure that deferred revenues are recognized based on established revenue recognition guidelines?

0 All deferred revenues are entered into the G/L. G/L accounts are amortized in total.
0 Deferred revenues are scheduled in a spreadsheet. The spreadsheet provides the amount to be recog
0 Deferred revenues are scheduled automatically by the accounting enterprise system at the time an ord

9 What controls ensure that revenues recognized under a percent complete method or based on specific milestones are

0 Contracts are manually reviewed and journal entries are posted based on the review.
0 Complex spreadsheets are maintained to help calculate the amount to be recognized monthly. Spread
0 Deferred revenues are scheduled automatically by the accounting enterprise system at the time an ord

10 What controls ensure that payments received are posted to the appropriate invoices?

0 Invoices are re-keyed into a spreadsheet. Paid invoices are removed from the spreadsheet. A separate
0 Invoices are manually reentered into an accounts receivable system. Payments are recorded against t
0 Accounts receivable is integrated with the order entry system. All Invoices created in OE are included i

11 What controls ensure that amounts reported in the G/L reconcile with the various supporting systems (Order Entry, A/R

0 All journal entries are manually entered into the system based on the amounts contained in the suppor
0 Entries are made to the accounting system manually. All accounts are reconciled by accounting month
0 All systems including A/R, A/P, Order entry and deferred revenues are integrated with the G/L. Subsidi

12 What controls ensure that components of a contract that renew automatically (e.g. maintenance) are appropriately reco

0 Renewable components of a contract are entered into a spreadsheet by accounting. At the time of ren
0 Renewals are maintained in a spreadsheet, manually created invoices are reviewed by management f
0 Renewable components are managed within the enterprise system and are set up automatically at the

13 What controls ensure that adjustments to renewable components of a contract are properly recorded and reflected in a

0 Invoices are manually generated based on the information stored in the renewal spreadsheet. Adjustm
0 Statements are generated offline based on information stored in the renewal spreadsheet. Customers
0 All renewal information including the current start and end dates and the correct pricing to renew at, is

14 What controls prevent unauthorized changes to transactions in the system?

0 None
0 Manual Notes describing changes.
0 Complete audit trail of all transaction including date and user ID
0 Complete Audit trail combined with security controls preventing unauthorized users from modifying or c

15 What controls ensure that changes to deferred revenue schedules are properly reflected in the G/L?

0 Manual Notes
0 Spreadsheet gets updated for future reference.
0 Manual adjustment in G/L.
0 Change is made in enterprise system, which automatically makes appropriate updates to the integrate

Questions Points Selection


Q1 0 2 3 0
Q2 1 3 5 0
Q3 1 3 5 0
Q4 1 3 5 0
Q5 1 3 5 0
Q6 0 1 2 5 0
Q7 1 3 5 0
Q8 1 3 5 0
Q9 1 3 5 0
Q10 1 3 5 0
Q11 0 3 5 0
Q12 1 3 5 0
Q13 1 2 5 0
Q14 0 1 2 5 0
Q15 0 1 1 5 0

Total Points 0
SOx Results

Compliance Red Alert - see table below.


Compliance Yellow Alert - see table below.
Your company is SOx 404 compliant - congratulations!
are reviewed by management. A complete audit trail of all activity is maintained in the order entry system.
accounting group.

rder (license fees, services, hardware, training, maintenance, etc.)?

d compared to pricing based on established revenue recognition rules.


ed on established revenue recognition rules.

a contract in order to determine how revenue should be allocated?

ed into the enterprise system.


tes the amount to allocate to each component based on the pricing.
ontains the pricing to be used for revenue allocation. Revenue is reallocated automatically based on the price book.

accounted for appropriately?

o the system for the invoices.


ccounting based on information stored in a spreadsheet.
s by an enterprise system.

n order (e.g. license fees, hardware) until distribution of CDs or activation keys has occurred?

ship. Accounting Invoices from this report. Shipping contacts accounting if an order doesn’t ship.
nting then creates a manual invoice.
m. Orders are released by accounting. Released orders are ship confirmed in the system by shipping. System prevents invoice generation until shipment is

ew, recognize and match against billing activities.


om revenue schedules, which allows us to recognize revenue independently from billing activity.

ed based on the stated terms of the contract?

are created manually based on this information.


ract for accuracy. Once confirmed, the invoice is re-keyed into the accounting enterprise system.
order entry. Invoices are generated automatically based on these terms. Invoices tied to an event are not released until the completion of the event is conf

evenue recognition guidelines?

e amortized in total.
sheet provides the amount to be recognized monthly. The amount to be recognized is manually posted to the G/L.
ng enterprise system at the time an order is entered. Schedules are created for each deferred item individually. Revenue is then recognized automatically ba

or based on specific milestones are not recognized prematurely?

based on the review.


ount to be recognized monthly. Spreadsheets are manually updated. Journal entries are booked to recognize revenue based on the information in the sprea
ng enterprise system at the time an order is entered. Schedules are created for each deferred item individually. Revenues tied to milestones are placed on h

oved from the spreadsheet. A separate spreadsheet is maintained for paid invoices.
tem. Payments are recorded against these invoices.
l Invoices created in OE are included in a customers A/R. When payments are received, the system provides a list of all open invoices. Partial payments, w

upporting systems (Order Entry, A/R, etc)?

n the amounts contained in the supporting systems. Adjustments are booked when discrepancies are found.
ts are reconciled by accounting monthly.
es are integrated with the G/L. Subsidiary ledgers are maintained directly in the system. Manual entries are not permitted to the G/L accounts impacted by t

maintenance) are appropriately recorded and renewed in the correct period?

sheet by accounting. At the time of renewal, an invoice is created manually and entered into the A/R system.
voices are reviewed by management for errors.
em and are set up automatically at the time of order entry. The system stores the start and end dates for the period, and provides a routine to select renewa

properly recorded and reflected in a customer’s invoice?

d in the renewal spreadsheet. Adjustments are then booked to the customer’s A/R account after invoicing.
the renewal spreadsheet. Customers are given 30 days to notify company of any changes. After 30 days, the information is reentered into the A/R system a
and the correct pricing to renew at, is stored directly in the enterprise system. The system generates a proforma statement based on the information in the

unauthorized users from modifying or creating transactions

ected in the G/L?

es appropriate updates to the integrated G/L.


generation until shipment is confirmed.

mpletion of the event is confirmed.


n recognized automatically based on these schedules.

the information in the spreadsheet.


o milestones are placed on hold until the milestone is met. Revenues under a percent complete method are updated and recognized directly in the enterpris

nvoices. Partial payments, write-offs and credits can all be applied directly within the system.

G/L accounts impacted by these systems. A complete audit trail is maintained by the system for all activity impacting the G/L.

es a routine to select renewals for processing based on expiration dates.

entered into the A/R system and invoices are generated.


sed on the information in the system. Adjustments can be made to the pro forma. Invoices are generated based on the information contained in the proform
nized directly in the enterprise system. General ledger entries are generated by the system based on the amounts contained in the revenue schedules.

on contained in the proforma.


the revenue schedules.

You might also like