“establish and maintain an optimal co-ordination, communication and liaison structure
between the IT function and … the corporate compliance group” (PO4.15). In addition, “the control
environment should be based on a culture that…encourages cross-divisional co-operation and teamwork …”
(PO6.1). Furthermore, it is important to “obtain independent assurance (internal or external) about the
conformance of IT with …the organization's policies, standards, and procedures …” (ME 4.7).