Search
Program Calendar
Browse By Day
Search Tips
Virtual Exhibit Hall
Personal Schedule
Sign In
Corporate governance places the ultimate responsibility for governance functions with the board of directors and executive management. The Sarbanes Oxley Act of 2002 reinforced and codified this view by placing clear legal responsibility and liability with executive management who must personally sign-off on the veracity of financial reports and on the effectiveness of internal controls. Cloud computing creates a governance paradox. By its very nature, cloud computing relies on a new shared governance mechanisms since it delegates some responsibility for IT computing resources to the cloud provider, thereby placing IT outside the direct control and direct monitoring of the firm. However, the client firm must still bear ultimate responsibility and liability for IT services and its related internal controls. Governance of cloud computing services relies on what is inherently a shared governance structure which must be carefully defined between the two contracting parties, the cloud client and cloud provider. It is not yet clear if most client firms have expanded and evolved their IT governance (ITG) structures to fully address the radically different nature of cloud computing.