This presentation discusses: who is responsible for compliance?; what level of involvement should IT have in compliance?; applying control frameworks [COBIT (Control Objectives for Information and related Technology) and COSO (Committee of Sponsoring Organizations of the Treadway Commission)]; and lessons learnt from SOX (the Sarbanes-Oxley Act of 2002).