The act of complying with Regulations, Standards and Frameworks is becoming essential business practice. The IDL Compliance Program identifies the compliance issues that are generating compulsory and compelling IT investment across a variety of industry sectors.

Please select a different Industry sector from the menu below:

Utilities Banking Retail Supply Chain Public Sector
Healthcare Pharmaceuticals Automotive Supply Chain Telco

Issue Brief New Policy Driver IT Investment Implications Compliance Timetable
Multilateral Instrument 52-111 - Reporting on Internal Control over Financial Reporting

Canadian Securities Administrators (CSA)
The proposed requirements are expected to continue the harmonization of Canadian regulatory reporting and certification rules with Sarbanes-Oxley. Under the proposed rules, reporting issuers on the Toronto Stock Exchange (TSX) will have to adhere to the following:- Management will be required to issue a report on the effectiveness of internal control over financial reporting- An external auditor will be required to issue an audit report on management's assessment. Document management systems
Email management systems
Content management Storage & Security solutions
Disaster recovery
Updates to accountancy systems and ERP systems
Processing power, server and network
Operational
Implementation of IT to reduce cost and risk of reporting.
Personal Information Protection and Electronic Documents Act (PIPEDA) Canada PIPEDA is described as an act to “promote the use of electronic commerce by protecting personal information that is collected”. In doing so, PIPEDA prohibits the use of personal data without the explicit permission of the individual involved. It places requirements on the collector of the information to identify the use for the data, obtain permission for collecting the data and to hold it securely. Beyond this it must be shown that the data that has been stored has only been used in the way in which it was intended. Individuals may also request to be shown what has been stored and the uses to which it has been put. Storage
Audit Trail
Backup
Disaster Recovery
Security
Database
Electronic signature technologies
Operational
Operating and IT solutions emerging.
CAN-SPAM Act of 2003 (Controlling the Assault of Non-Solicited Pornography and Marketing Act) US The Act provides controls on the way email is used for commercial purposes. It requires that unsolicited commercial emails are clearly labelled and offer the recipient the ability to opt out. It prohibits the use of deceptive subject lines and false headers. It also stipulates that emails are not sent to automatically generated addresses or addresses gained through underhand ways. Audit Trail
Email Systems
CRM Systems
Authentication Technologies
Operational
Operating and IT solutions emerging.
Sarbanes-Oxley Act (SOX) Act (part of 2002, Sarbanes-Oxley Act) which mandates that all auditing firms retain records relevant to audits and reviews also has significant implications on companies’ IT resources. Document Retention Systems
Email Management Systems
Content Management Storage Solutions
Operational
SOX 404 deadline for non-accelerated filers and foreign private issuers in 2007 opening IT solutions for automated reporting including US owned off-shore corporations.
58-201 Effective Governance and Proposed Multilateral Instrument This law and attendant instrument are in the final discussion stages in Canada. Based on the Toronto Stock Exchange’s (TSX) existing rules for corporate governance, these are expected to be passed for national (Canadian) policy. At the same time the TSX is expected to repeal its own laws to adopt 58-201. Document retention systems
Email management systems
Content management storage solutions
Operational
Fully operational and demand for IT solutions still expected to reduce cost and risks.
Corporate Information Security Accountability Bill Currently a draft bill that calls for US publicly listed firms to adhere to minimum IT security standards that would be set by the Securities and Exchange Commission (SEC). Proposes an annual audit with results to be submitted with annual reports and SoX submissions. Affects a wide range of security products to help companies comply with ‘industry standard’ security practices. Also requires tools to assist with gap analysis, scooping, audit. Potential
Draft bill.
California Database Breach Act. State Bill SB 1386 Applies to all individuals and organizations wishing to do business in California. This bill is designed to protect consumers from identity theft. It builds on existing privacy laws and mandates notice of breach of security or any other exposure. IT security applications and services
Customer data handling
Operational
Fully operational and demand for IT solutions still expected to reduce cost and risk.
Privacy Act The purpose of this Act is to extend the present laws of Canada that protect the privacy of individuals with respect to personal information about themselves held by a government institution and that provide individuals with a right of access to that information. Storage
Security
Data Management
Data Consolidation
Database
Data Mining
Disaster Recovery
Document Management
Operational
In operation and is continually being updated.
Do-Not–Call Registry The Federal Trade Commission (FTC) has amended the Telemarketing Sales Rule (TSR) to give consumers a choice about whether they want to receive most telemarketing calls. It will be illegal for most telemarketers or sellers to call a number listed on the registry. Similar standards and laws in UK, Direct Marketing Association ‘Preferred Services’. Data Storage
CRM
Operational
Adapting contact and call centre IT systems.
RFID Supply Chain Radio Frequency Identification (RFID) code tags attached to products to provide greater efficiency in tracking and identification. Data storage
Database solutions
Integration with ERPSCM for greater supply chain visibility and fast decision-making.
Operational
RFID mandated by [a] leading retailers (Walmart, K-Mart, Tesco, M&S etc) [b] US Department of Defence to defence contractors, and [c] FDA for pharmaceuticals for fraud detection & clinical trials.
GCI (Global Commerce Initiative) Headed by over 40 major international companies, the GCI has built a set of standards in the retail/manufacturing industries, to promote global supply chain efficiency and enhance consumer value. Electronic Data Interchange
XML
SCM
ECMS
Operational
Implementation taking place and integrated IT solutions for supply chain emerging.
UCC net Uniform Code Council standard for product identification designed to improve supply chain efficiency by storing all product information in its GLOBAL registry. Supply Chain Technology
Database solutions
Internet solutions
Hardware (scanners)
Operational
Standard being rapidly adopted particularly by large retailers.
ISO 20000
IT Service Management Standard
ISO 20000 comprises two parts: ISO 20000-1 is the 'Specification for Service Management, and ISO 20000-2 is the 'Code of practice for Service Management'.

Together, these form a top-down framework to define the features of service management processes that are essential for the delivery of high quality services.

ISO 20,0000 allows IT organizations to formally certify their IT services, using ITIL [Information Technology Infrastructure Library] global best practice for IT service delivery.
Security Management
Storage Management
Business Application Management
Server, Network & Device Management
Operational
Rapidly adopted as the international standard for IT Service Management based upon ITIL based upon substantial TCO reduction as business case.
ISO 27001 Information Security Standard ISO 27001 is the formal standard against which organizations may seek independent certification of their Information Security Management Systems to reduce businesses’ information security vulnerability. ERP solutions
IT Security Applications and services
Operational
Rapidly being adopted worldwide as the standard for business’ information security.
IAS (International Accounting Standards) International standards on accounting and the regulation of financial result calculation. Designed to improve transparency and represent a step towards a common global accounting standard. Enterprise integration systems
Data gathering systems.
Operational
The legislation will require significant investment in appropriate systems to facilitate internal reporting and data gathering.
Bar-code modification Works in conjunction with UCCNet and requires all 12-digit bar codes to be updated to 13 or 14-digits inline with international standards. SCM solutions Operational
Adapting supply chain solutions.
Enhancing Services Through the Innovative Use of Information and Technology This enshrines Canada’s e-Government initiatives taking a 10-year strategic vision of the steps and initiatives needed to deliver access to government services. Communications
Internet Services and Technologies
Security and user identification
Storage
Document Management
Data Consolidation
Operational
Steady demand for integrated IT solutions.
Copyright © 2010 Industry Direct Limited. All Rights Reserved.