Shortly after Sarbanes-Oxley (SOX) first appeared in 2002, "compliance" applications started hitting the market in a big way. Companies from established players like Oracle and Documentum to start-ups looking for a piece of the action began marketing applications designed to take your company from the non-compliance darkness into the light of compliant, quarterly SOX reporting.
The problem is none of these "solutions" is a complete solution in and of itself. Most are starting points that run the gamut from simple, spreadsheet-style reporting tools to applications that integrate into your ERP system and automatically pull out, record, document, and track all events material to SOX compliance, including, in some cases, elusive threads like email and phone conversations.
But that is at the high-end of the game. Oracle, for example, provides these capabilities, says Seamus Moran, Oracle's director of financial application development, as well as a compliance roadmap based on the COSO (Committee of Sponsoring Organizations of the Treadway Commission) enterprise risk management framework to help you get started. It's easier to use, however, if you're an Oracle shop. Otherwise, expect the need for a lot of custom API work or manual data entry before things run smoothly.
Some compliance apps have gaps in their coverage too large to ignore. For example, Gartner Analyst Rich Mogull says his company no longer recommends Microsoft's offering in the compliance game because Microsoft failed to make Gartner aware of some important security vulnerabilities in the document-handling schema. Specifically, changes could be made to documents without any trace of who made the alterations — a critical no-no from a SOX point of view.
Although security seems to be a recurring problem with Microsoft products, shortcomings invariably are going to be found in most offerings. So, depending on a piece of software to bring your enterprise into total SOX compliance is simply not going to work.