2 ms·
Very little in SOX scope is going to detect transactions outside of the company such as these. SOX is primarily about having effective mechanisms to assure that
by grantc 5y ago
Very little in SOX scope is going to detect transactions outside of the company such as these. SOX is primarily about having effective mechanisms to assure that the financial information you report is accurate and complete, and then those mechanisms are inspected internally and audited externally. SOX is about what happens inside a company and with a companies resources -- you might have different means of preventing an employee from exfiltrating the company's money, and those are SOX-scoped.
Being able to detect whether a given employee has taken a bribe from a vendor might trip over SOX-relevant things incidentally but not directly. For example, you might need to certify that every employee has taken anti-bribery training every year, and that's your preventative mechanism so at least employees know what is permissible and what the consequences are.