Marchetti Book Chapter 7: Ongoing Compliance Overview

Origin and Impact of the Sarbanes-Oxley Act

  • The Sarbanes-Oxley Act of 2002 (SOX) was enacted following several high-profile cases of corporate fraud and accounting improprieties to improve financial transparency and ethical standards.

  • It is considered the most significant legislation for the accounting profession since the Securities Act of 1933 and 1934.

  • The act consists of 11 titles outlining compliance requirements for public companies and their relationships with external auditors.

  • Non-compliance carries significant criminal penalties and fines for corporate executives.

Management Responsibility and Accountability

  • Executive management is explicitly responsible for maintaining internal controls over financial reporting.

  • The Chief Executive Officer and Chief Financial Officer (CFO) must certify the accuracy of financial reports filed with the Securities and Exchange Commission (SEC).

  • Section 302 requires executive financial statement certification, while Section 404 mandates internal controls over financial reporting.

  • Process owners are directly accountable for the effectiveness of internal controls; their roles must be clearly defined to ensure systems are followed after external consultants leave.

Strategic Value and Integration

  • Initial compliance often focused on short-term minimum requirements, but long-term value is generated by integrating compliance with Business Performance Management (BPM) and Enterprise Risk Management (ERM).

  • Organizations should use a risk-based, top-down approach to identify events that may impact business operations.

  • Finance departments should transition into a consultative role by removing non-value-added processes identified in Section 404 documentation.

  • Technology and automation, such as Enterprise Resource Planning (ERP) systems and web-based distribution applications, should be leveraged to eliminate manual workarounds and spreadsheets.

Moving Beyond Initial Compliance

  • Ongoing monitoring is critical to avoid the risk of noncompliance beyond year one; compliance is a continuous process, not a one-time event.

  • Section 302 requires quarterly evaluations and reporting of changes in internal controls that could materially affect financial statements.

  • Section 409 (Real Time Issuer Disclosures) requires disclosure of material changes in financial condition.

  • A sustainable program requires an efficient infrastructure for repeatable activities, including documentation reviews, testing, and remediation.

Principles for Ongoing Compliance Strategy

  • Tone at the Top: Senior executives must project a positive commitment to reliable reporting to ensure compliance is not perceived as a burden by employees.

  • Compliance Education: Continuous training is vital for employees to understand their individual roles in meeting SOX requirements.

  • Monitoring: Implementing internal control self-assessments and utilizing software with monitoring capabilities helps ensure timely remediation.

  • Process Change Procedures: Formal procedures ensure timely quarterly disclosures and maintain confidence in the control environment.

Remediation and Operational Efficiency

  • Remediation efforts should be categorized into Control Improvements, SOX Compliance and Financial Reporting Improvements, and Productivity Improvements.

  • High-impact improvements address material issues within 90 days.

  • Medium-impact improvements focus on material issues and typically take between 3 to 6 months to implement.

  • Ongoing compliance costs currently range from 50% to 70% of initial compliance costs.

  • To manage costs, many companies are moving toward centralization or shared services models to achieve economies of scale, despite the high social and technical costs of such changes.