Marchetti Book Chapter 8: Ongoing Compliance Challenges
Challenges in Section Compliance
Achieving Section compliance has proven more challenging and costly than initially anticipated for most organizations.
Accelerated filers experienced significant resource strain in year one, with burdens continuing through year three and beyond.
Nonaccelerated filers often lack the required evidence for certification and have not conducted appropriate levels of control testing.
A majority of compliance time is spent on remediation rather than developing long-term efficiency or infrastructure.
Compliance costs have risen due to increased audit fees and a higher volume of material weakness disclosures and restatements.
The Framework for Compliance Optimization
The Sarbanes-Oxley Act (SOX) created an "inverted pyramid" effect where organizations focused heavily on transaction-level testing while often disregarding risk assessment.
Companies should adopt a top-down risk view encompassing governance, risk management, and compliance.
A commitment to the "tone at the top" is critical, where senior leadership fosters a culture of integrity and sets expectations for ethical behavior.
Optimized programs improve control effectiveness and realize cost savings by defining clear roles, responsibilities, and ongoing processes.
Adherence to governance policies must be monitored continuously and embedded throughout the organizational culture.
Common Deficiencies and Remediation Focus
Financial Close: This remains a high-risk activity due to its complexity and short timeframe; organizations should seek to automate and strengthen reporting processes.
Information Technology Controls: Many organizations lack sufficient documentation for general IT controls, including backup, recovery, and program change control.
Postmerger Integration: Merging systems, people, and technology creates a high risk for control gaps and weaknesses.
Outsourced Functions: Organizations must obtain a Statement of Auditing Standards type II letter to understand a vendor's control environment and ensure overall reporting accuracy.
Remediation Strategies: Companies should prioritize entity-level controls, evaluate specific fraud risks, and automate manual controls to reduce annual testing volume.
Executing the Ongoing Compliance Plan and Reporting
Initial SOX compliance plans should be refined to remove one-time pilot efforts and include current risk assessments conducted through interviews and questionnaires.
Specific work plans must define compliance owners, task sequences, expected durations, and reporting hierarchies.
Section requires CEOs and CFOs to certify quarterly and annual financial reports.
Section mandates an annual internal control report stating management's responsibility and assessment, plus an external auditor attestation for accelerated filers.
Compliance plans are not "one-size-fits-all" and must be customized based on organizational complexity, culture, and technology sophistication.
Integrating compliance with Business Performance Management (BPM) and Enterprise Risk Management (ERM) can reduce costs by as much as .
Evolving Roles of Internal Audit and the Audit Committee
Internal Audit: Should rebalance activities from strictly compliance support to traditional auditing, including operational and strategic risk assessment.
Auditing Standard No. : This pronouncement from May allows external auditors to rely on internal audit testing if it is independent of management testing, potentially reducing audit fees.
Audit Committee: Members are increasingly accountable and must spend more time preparation for interactions with management and auditors.
Committee Best Practices: Support the "tone at the top," monitor gap remediation progress, and ensure management has a formal, tested business continuity plan.
Strategic Oversight: The audit committee should support cost-effective initiatives, as ongoing compliance is estimated to consume between and of the cost of initial compliance.