Marchetti Book Chapter 8: Ongoing Compliance Challenges

Challenges in Section 404404 Compliance

  • Achieving Section 404404 compliance has proven more challenging and costly than initially anticipated for most organizations.

  • Accelerated filers experienced significant resource strain in year one, with burdens continuing through year three and beyond.

  • Nonaccelerated filers often lack the required evidence for certification and have not conducted appropriate levels of control testing.

  • A majority of compliance time is spent on remediation rather than developing long-term efficiency or infrastructure.

  • Compliance costs have risen due to increased audit fees and a higher volume of material weakness disclosures and restatements.

The Framework for Compliance Optimization

  • The Sarbanes-Oxley Act (SOX) created an "inverted pyramid" effect where organizations focused heavily on transaction-level testing while often disregarding risk assessment.

  • Companies should adopt a top-down risk view encompassing governance, risk management, and compliance.

  • A commitment to the "tone at the top" is critical, where senior leadership fosters a culture of integrity and sets expectations for ethical behavior.

  • Optimized programs improve control effectiveness and realize cost savings by defining clear roles, responsibilities, and ongoing processes.

  • Adherence to governance policies must be monitored continuously and embedded throughout the organizational culture.

Common Deficiencies and Remediation Focus

  • Financial Close: This remains a high-risk activity due to its complexity and short timeframe; organizations should seek to automate and strengthen reporting processes.

  • Information Technology Controls: Many organizations lack sufficient documentation for general IT controls, including backup, recovery, and program change control.

  • Postmerger Integration: Merging systems, people, and technology creates a high risk for control gaps and weaknesses.

  • Outsourced Functions: Organizations must obtain a Statement of Auditing Standards 7070 type II letter to understand a vendor's control environment and ensure overall reporting accuracy.

  • Remediation Strategies: Companies should prioritize entity-level controls, evaluate specific fraud risks, and automate manual controls to reduce annual testing volume.

Executing the Ongoing Compliance Plan and Reporting

  • Initial SOX compliance plans should be refined to remove one-time pilot efforts and include current risk assessments conducted through interviews and questionnaires.

  • Specific work plans must define compliance owners, task sequences, expected durations, and reporting hierarchies.

  • Section 302302 requires CEOs and CFOs to certify quarterly and annual financial reports.

  • Section 404404 mandates an annual internal control report stating management's responsibility and assessment, plus an external auditor attestation for accelerated filers.

  • Compliance plans are not "one-size-fits-all" and must be customized based on organizational complexity, culture, and technology sophistication.

  • Integrating compliance with Business Performance Management (BPM) and Enterprise Risk Management (ERM) can reduce costs by as much as 50%50\%.

Evolving Roles of Internal Audit and the Audit Committee

  • Internal Audit: Should rebalance activities from strictly compliance support to traditional auditing, including operational and strategic risk assessment.

  • Auditing Standard No. 22: This pronouncement from May 20052005 allows external auditors to rely on internal audit testing if it is independent of management testing, potentially reducing audit fees.

  • Audit Committee: Members are increasingly accountable and must spend more time preparation for interactions with management and auditors.

  • Committee Best Practices: Support the "tone at the top," monitor gap remediation progress, and ensure management has a formal, tested business continuity plan.

  • Strategic Oversight: The audit committee should support cost-effective initiatives, as ongoing compliance is estimated to consume between 40%40\% and 70%70\% of the cost of initial compliance.