SOX compliance query to show user rights

What query does anyone run against a SQL 2000 or 2005 database to show all users rights at the system level and the database level ? I guess what I am asking is I need to show the auditors what userids exist that have access to a specific database that could have system level like 'sa' rights and the like AND what rights specific to the database like 'data reader' ?

