Marchetti Book Chapter 7: Ongoing Compliance Overview
Origin and Impact of the Sarbanes-Oxley Act
The Sarbanes-Oxley Act of 2002 (SOX) was enacted following several high-profile cases of corporate fraud and accounting improprieties to improve financial transparency and ethical standards.
It is considered the most significant legislation for the accounting profession since the Securities Act of 1933 and 1934.
The act consists of 11 titles outlining compliance requirements for public companies and their relationships with external auditors.
Non-compliance carries significant criminal penalties and fines for corporate executives.
Management Responsibility and Accountability
Executive management is explicitly responsible for maintaining internal controls over financial reporting.
The Chief Executive Officer and Chief Financial Officer (CFO) must certify the accuracy of financial reports filed with the Securities and Exchange Commission (SEC).
Section 302 requires executive financial statement certification, while Section 404 mandates internal controls over financial reporting.
Process owners are directly accountable for the effectiveness of internal controls; their roles must be clearly defined to ensure systems are followed after external consultants leave.
Strategic Value and Integration
Initial compliance often focused on short-term minimum requirements, but long-term value is generated by integrating compliance with Business Performance Management (BPM) and Enterprise Risk Management (ERM).
Organizations should use a risk-based, top-down approach to identify events that may impact business operations.
Finance departments should transition into a consultative role by removing non-value-added processes identified in Section 404 documentation.
Technology and automation, such as Enterprise Resource Planning (ERP) systems and web-based distribution applications, should be leveraged to eliminate manual workarounds and spreadsheets.
Moving Beyond Initial Compliance
Ongoing monitoring is critical to avoid the risk of noncompliance beyond year one; compliance is a continuous process, not a one-time event.
Section 302 requires quarterly evaluations and reporting of changes in internal controls that could materially affect financial statements.
Section 409 (Real Time Issuer Disclosures) requires disclosure of material changes in financial condition.
A sustainable program requires an efficient infrastructure for repeatable activities, including documentation reviews, testing, and remediation.
Principles for Ongoing Compliance Strategy
Tone at the Top: Senior executives must project a positive commitment to reliable reporting to ensure compliance is not perceived as a burden by employees.
Compliance Education: Continuous training is vital for employees to understand their individual roles in meeting SOX requirements.
Monitoring: Implementing internal control self-assessments and utilizing software with monitoring capabilities helps ensure timely remediation.
Process Change Procedures: Formal procedures ensure timely quarterly disclosures and maintain confidence in the control environment.
Remediation and Operational Efficiency
Remediation efforts should be categorized into Control Improvements, SOX Compliance and Financial Reporting Improvements, and Productivity Improvements.
High-impact improvements address material issues within 90 days.
Medium-impact improvements focus on material issues and typically take between 3 to 6 months to implement.
Ongoing compliance costs currently range from 50% to 70% of initial compliance costs.
To manage costs, many companies are moving toward centralization or shared services models to achieve economies of scale, despite the high social and technical costs of such changes.