<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>SOX 404 Compliance</title>
	<atom:link href="http://sox404.info/feed/" rel="self" type="application/rss+xml" />
	<link>http://sox404.info</link>
	<description>Sarbanes Oxley Sections 302 and 404</description>
	<pubDate>Tue, 02 Sep 2008 18:40:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>What is a &#8220;Key&#8221; Control?</title>
		<link>http://sox404.info/2008/08/12/what-is-a-key-control/</link>
		<comments>http://sox404.info/2008/08/12/what-is-a-key-control/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 14:13:33 +0000</pubDate>
		<dc:creator>ccoigne</dc:creator>
		
		<category><![CDATA[SOX 404 & 302]]></category>

		<category><![CDATA[SOX Testing]]></category>

		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[Key Control]]></category>

		<category><![CDATA[sox 404]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=21</guid>
		<description><![CDATA[It still surprises me that, after nearly 5 years of SOX history, many organizations I encounter still struggle with the question - &#8220;what is a key control?&#8221;.
Sarbanes Oxley requires the materially accurate reporting of financial results for publicly traded organizations.  Consequently, the easiest way to identify which controls are key is to ask yourself - &#8221;does this [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><h3>It still surprises me that, after nearly 5 years of SOX history, many organizations I encounter still struggle with the question - &#8220;what is a key control?&#8221;.</h3>
<p><strong>Sarbanes Oxley</strong> requires the materially accurate reporting of <strong>financial results </strong>for publicly traded organizations.  Consequently, the easiest way to identify which controls are key is to ask yourself - &#8221;does this control impact an account in the financial statements or a disclosure in the footnotes?&#8221;.  For many of the controls identified by my clients the answer is &#8220;no&#8221;.</p>
<p>As an example, let&#8217;s examine a control which obviously impacts the financial statements - the bank reconciliation.  When an individual performs the monthly bank reconciliation, they are utilizing an independent, third-party provided document to ensure the existence and accuracy (and probably completeness and cut-off) of transactions related to the Cash account.  There is little doubt that every organization executes this control and that it is essential to the accuracy of reported financial results.</p>
<p>As a counterpoint, let&#8217;s consider a control encountered time and again in the Human Resources or Payroll cycles of large organizations throughout the U.S - &#8220;Employee benefit requests and transactions are appropriately reviewed, approved, and validated to support&#8221;.  In my estimation, this is not a <strong>key control</strong> for <strong>SOX</strong> purposes.</p>
<p>Although many have argued the point with me, I submit the following:</p>
<ul>
<li>How material is any amount related to these types of transactions at any point in time, especially at a quarter end?</li>
<li>For balance sheet-related escrow/liability accounts, isn&#8217;t the periodic account reconciliation sufficient?</li>
<li>For income statement-related expense accounts (employer 401k, employer portion of health insurance, etc) any variance from actual would likely be identified during a fluctuation analysis - current to prior or current to budget or both.</li>
</ul>
<p>My point is this - what might be &#8220;key&#8221; to a process may not necessarily be key when looking at the financial balance being evaluated because multiple cycles/processes likely impact that balance and a control in another process may be sufficient for management to make assertions about that balance.  In short, <em><strong>sourcing</strong></em> the account/assertion intersection from the top-down to a sufficiently robust and precise control should enable management to avoid testing controls that may be important to a process, but less so for getting the reported balance materially correct.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/21/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/21/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=21&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/08/12/what-is-a-key-control/feed/</wfw:commentRss>
		</item>
		<item>
		<title>C&#8217;mon and Ask Some Questions/Leave Comments</title>
		<link>http://sox404.info/2008/08/09/cmon-and-ask-some-questionsleave-comments/</link>
		<comments>http://sox404.info/2008/08/09/cmon-and-ask-some-questionsleave-comments/#comments</comments>
		<pubDate>Sat, 09 Aug 2008 15:04:58 +0000</pubDate>
		<dc:creator>ccoigne</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://sox404.info/?p=30</guid>
		<description><![CDATA[We&#8217;re getting great traffic on this site, but the conversation is defintely one-sided.  Please leave some questions/comments and really make this site interactive!!
       ]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>We&#8217;re getting great traffic on this site, but the conversation is defintely one-sided.  Please leave some questions/comments and really make this site interactive!!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/30/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/30/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=30&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/08/09/cmon-and-ask-some-questionsleave-comments/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Splitting the &#8220;Assertion&#8221; hair; the key to avoiding &#8220;Over Optimization&#8221;</title>
		<link>http://sox404.info/2008/07/14/splitting-the-assertion-hair-the-key-to-avoiding-over-optimization/</link>
		<comments>http://sox404.info/2008/07/14/splitting-the-assertion-hair-the-key-to-avoiding-over-optimization/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 14:44:54 +0000</pubDate>
		<dc:creator>ccoigne</dc:creator>
		
		<category><![CDATA[SOX 404 & 302]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[assertions]]></category>

		<category><![CDATA[SOX Testing]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=12</guid>
		<description><![CDATA[AS5 gave public company management license to &#8220;optimize&#8221; their control environments.  The top-down, risk-based approach directed management to lift their gaze from the maze of process level controls and, instead, ensure that the controls they were testing actually mattered when it came to getting reported financial balances right.  The way to do that was to [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>AS5 gave public company management license to &#8220;optimize&#8221; their control environments.  The top-down, risk-based approach directed management to lift their gaze from the maze of process level controls and, instead, ensure that the controls they were testing actually mattered when it came to getting reported financial balances right.  The way to do that was to match relevant financial statement assertions to material balances for in-scope locations.  Most companies were already getting the materiality calculation right, but what about the assertions?  What are assertions, exactly, and how can a refinement of the assertion list aid management in avoiding &#8220;over-optimization&#8221; and exposing themselves to a potential restatement of financial results?</p>
<p>Financial assertions have always existed but they tended to be implicit in nature.  For instance, reported Cash balances implicitly <em>Existed</em> and were adequately <em>Safeguarded</em> and <em>Complete</em>.  Proper <em>Cut-Off</em> ensured that all transactions were reported in the proper period and management appropriately <em>Authorized</em> those transactions.  Management possessed <em>Rights</em> to the asset and, if pledged or otherwise restricted, that fact was fully <em>Disclosed</em>.</p>
<p>However, due to the myriad financial reporting scandals - Enron, Worldcom, Adelphia, Tyco, ad nauseum - that occurred during the early part of this decade, Congress enacted Sarbanes-Oxley (SOX) which, among other things, requires senior management (CEO and CFO) to <strong>explicitly</strong> assert to the reported balances.  As a result, Assertions have recently received much more attention.</p>
<p>In my experience, companies typically utilize five assertions: Existence/Occurrence, Completeness, Valuation/Allocation, Rights/Obligations, Presentation/Disclosure.  The Risk and Control Matrices I&#8217;ve encountered generally have an abudance of check marks - usually over-associating controls and assertions - leading me to conclude that a lack of understanding of the basic definitions exists.  I&#8217;ve found that splitting those five into a broader list of thirteen assertions generally leads to a better understanding of what management is attempting to achieve with each control:</p>
<p><strong>Existence/Occurrence</strong></p>
<ul>
<li>Existence - Balance Sheet focused - Assets, Liabilities and Ownership Interests (Equity) <strong>exist</strong> as of the statement date and balances have a <strong>real world counterpart</strong> (i.e. customers, suppliers, employees, banks, etc).</li>
<li>Safeguard Assets - Access to assets and critical documents that control their movement are suitably restricted to authorized personnel.  Often covered as part of Segregation of Duties review.</li>
<li>Occurrence - Income Statement focused - Transactions and events that have been recorded <strong>actually occurred</strong> and pertain to the entity.</li>
</ul>
<p><strong>Completeness</strong></p>
<ul>
<li>Completeness - <strong>All</strong> transactions and events that should have been recorded have been recorded.</li>
<li>Cut-Off - Transactions and events have been recorded in the <strong>proper period</strong>.</li>
</ul>
<p><strong>Valuation/Allocation</strong></p>
<ul>
<li>Valuation - Amounts based on <strong>estimates and judgements</strong>are in accordance with US GAAP</li>
<li>Allocation - Costs are allocated from the Balance Sheet to the Income Statement in the proper period (e.g. depreciation and amortization).</li>
<li>Accuracy - Amounts recorded are <strong>mathematically</strong> accurate.</li>
</ul>
<p><strong>Rights/Obligations</strong></p>
<ul>
<li>Rights - The entity holds the rights to the <strong>assets</strong>.</li>
<li>Authorization - Transactions are executed in accordance with management&#8217;s general and specific authority.</li>
<li>Obligations - <strong>Liabilities</strong> recorded are the obligation of the entity.</li>
</ul>
<p><strong>Presentation/Disclosure</strong></p>
<ul>
<li>Classification - financial statement focused - transactions and events have been recorded in the proper <strong>accounts</strong>.</li>
<li>Understanding - <strong>disclosure</strong> driven (generally footnotes) - financial information is appropriately described and understandable to users.</li>
</ul>
<p>While this may initially seem like an esoteric exercise, splitting the five into thirteen actually achieves two things:</p>
<ol>
<li><strong>Reduce</strong> the overall amount of <strong>time needed to test </strong>the control environment.  Risk focused testing means the nature of the testing (Inquiry/Observation, Examination, Reperformance) can vary for two different controls providing assurance over two different assertions.  For instance, Completeness becomes Completeness and Cutoff and, consequently two different assertion risk scores.  If we combine the two, then the testing must satisfy the riskiest of the two.</li>
<li><strong>Prevent over-reliance </strong>on a control.  An intersection of account/control/assertion on the Risk and Control Matrix could lead to incorrect conclusions regarding the assurance provided.  Once again utilizing Completeness as our example, it is possible that we would need two different controls to achieve assurance that <strong>all</strong> transactions have been recorded and that they have been recorded in the correct <strong>period</strong>.  If we do not adequately delineate between Completeness and Cut-Off, then we could inappropriately assume that a control mapped to the account/assertion intersection would enable management to explicity assert that the risk of misstatement has been mitigated.</li>
</ol>
<p>The first point is important and, I believe as a result of AS5, has been seized upon by management to reduce the time required to test key SOX controls and make the process more efficient.  <em>However, my concern is that the second point is often overlooked</em>.  In the rush to &#8220;optimize&#8221; their control environment, management may inadvertantly &#8220;over-optimize&#8221; or fail to identify and test a control that will enable them to certify that <em>all subsections</em> of a particular assertion have been covered and, consequently, <strong>expose the organization to the arguably greater risk for restatement of reported financial results</strong>.  Therefore, management should consider the evaluation of accounts at the greater granularity of thirteen assertions to obtain an &#8221;insurance policy&#8221; of sorts to reduce the risk of misstatement.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/12/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/12/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/12/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/12/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/12/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=12&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/07/14/splitting-the-assertion-hair-the-key-to-avoiding-over-optimization/feed/</wfw:commentRss>
		</item>
		<item>
		<title>External Auditor Reliance on Management Testing</title>
		<link>http://sox404.info/2008/07/08/external-auditor-reliance-on-management-testing/</link>
		<comments>http://sox404.info/2008/07/08/external-auditor-reliance-on-management-testing/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 14:01:04 +0000</pubDate>
		<dc:creator>ccoigne</dc:creator>
		
		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[SOX Testing]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=11</guid>
		<description><![CDATA[
In an effort to reduce overall SOX compliance costs, companies must find a way to reduce external audit fees by increasing the amount of reliance the auditors place on management&#8217;s testing of its control environment.  In a 2006 comment letter to the SEC/PCAOB, a group of controllers and CFOs made several recommendations including the following:
53% [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><div>
<p>In an effort to reduce overall SOX compliance costs, companies must find a way to reduce external audit fees by increasing the amount of reliance the auditors place on management&#8217;s testing of its control environment.  In a 2006 comment letter to the SEC/PCAOB, a group of controllers and CFOs made several recommendations including the following:</p>
<p>53% of companies (*see attribution below) indicate that auditor reliance on management testing is their primary discussion issue with their external auditors. We believe that auditors should have more flexibility to rely on management&#8217;s work, including process owners, for areas that are not considered to be at high risk. For example, automated transaction controls or controls over routine processes involve lower risk and can be tested by process owners. It is important that process owners are accountable for effective controls, but auditors believe that AS2 prevents them from relying on process owner assessments. This causes duplicate testing and is disruptive to operations.  Auditors should be allowed to rely on the quality of managements&#8217; overall compliance approach, including the presence of a robust compliance environment and entity- level controls, rather than focusing on individual assessor independence.      </p>
<p>We are therefore recommending that external auditors be required to rely on management&#8217;s work in testing (irrespective of entity performing the testing) for a mutually-agreed upon universe of low-risk controls.&#8221;</p>
<p>Submission of Comments to the SEC/PCAOB Roundtable, May 10 2006</p>
<p>- *Corporate Executive Board research; <a href="http://www.executiveboard.com/">http://www.executiveboard.com</a></p>
<p>AS5 addressed this concern by specifically directing auditors to rely more on the work of others.  However, more than 40% of the 257 companies, which participated in a September 2007 poll taken by the Institute of Internal Auditors, indicated their external auditors relied on less than 25% of the testing work performed by management.  Clearly, gains can be made - but what can be done to change the minds of auditors?  The first, and perhaps most important, step is for management to demonstrate an understanding of its environment via a robust assessment of the risks to accurate financial reporting.</p>
<p>Whether the assessment is the traditional &#8220;likelihood and impact&#8221; approach for each of the identified risks, or management chooses to utilize the risk factors identified by the PCAOB/SEC, or some other method entirely, the point of the exercise is to give external auditors a view into management&#8217;s evaluation of what could go wrong.  Ranking the relative risk of the resulting misstatements, and the controls that mitigate those risks, then provides a tool for framing the &#8220;reliance&#8221; discussion.  In year one, auditors may then be more comfortable relying on management&#8217;s testing of those controls that mitigate low level risks.  As time progresses and the risk discussion matures, management and auditors may achieve a balance of reperformance and reliance resulting in reduced cost of compliance. </p></div>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=11&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/07/08/external-auditor-reliance-on-management-testing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Analyzing the cost-benefit of Sarbanes-Oxley</title>
		<link>http://sox404.info/2008/05/14/analyzing-the-cost-benefit-of-sarbanes-oxley/</link>
		<comments>http://sox404.info/2008/05/14/analyzing-the-cost-benefit-of-sarbanes-oxley/#comments</comments>
		<pubDate>Wed, 14 May 2008 19:15:43 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
		
		<category><![CDATA[SOX 404 & 302]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[sox 404]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=10</guid>
		<description><![CDATA[A significant body of academic research and opinion exists regarding the costs and benefits of SOX, with significant differences in conclusions. This is due in part to the difficulty of isolating the impact of SOX from other variables affecting the stock market and corporate earnings.[5] Conclusions from several of these studies and related criticism are [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="font-size:10pt;font-family:Verdana;">A significant body of academic research and opinion exists regarding the costs and benefits of SOX, with significant differences in conclusions. This is due in part to the difficulty of isolating the impact of SOX from other variables affecting the stock market and corporate earnings.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-4#cite_note-4">[5]</a></sup> Conclusions from several of these studies and related criticism are summarized below:</span></p>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">FEI Survey: Finance Executives International (FEI) provides an annual survey on SOX Section 404 costs. For 200 companies with average revenues of $6.8 billion, the average compliance costs were $2.9 million, down 23% from 2005. Cost for decentralized companies (i.e., those with multiple segments or large divisions) were more than twice those of centralized companies. Auditor costs did not decline. When asked whether the benefits of compliance with Section 404 have exceeded their costs, 22 percent, on average, agreed, with 78 percent saying instead that the costs have exceeded the benefits. 34 percent agreed that compliance with Section 404 has helped prevent or detect fraud.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-5#cite_note-5">[6]</a></sup> </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">Butler/Ribstein: Their book proposed a comprehensive overhaul or repeal of SOX and a variety of other reforms. For example, they indicate that investors could diversify their stock investments, efficiently managing the risk of a few catastrophic corporate failures, whether due to fraud or competition. However, if each company is required to spend a significant amount of money and resources on SOX compliance, this cost is borne across all publicly traded companies and therefore cannot be diversified away by the investor.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-6#cite_note-6">[7]</a></sup> </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">Institute</span><span style="font-size:10pt;font-family:Verdana;"> of Internal Auditors</span><span style="font-size:10pt;font-family:Verdana;"> (IIA): The research paper indicates that corporations have improved their internal controls and that financial statements are perceived to be more reliable.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-7#cite_note-7">[8]</a></sup> </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">Skaife/Collins/Kinney/Lefond: This research paper indicates that borrowing costs are lower for companies that improved their internal control, by between 50 and 150 basis points (.5 to 1.5 percentage points).<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-8#cite_note-8">[9]</a></sup> </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">Zhang: This research paper estimated SOX compliance costs as high as $1.4 trillion, by measuring changes in market value around key SOX legislative &#8220;events.&#8221; This number is based on the assumption that SOX was the cause of related short-duration market value changes.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-9#cite_note-9">[10]</a></sup> However, the S&amp;P 500 index, a broad measure of U.S. stock value, increased 6% the day the law passed in Congress on July 24, 2002, and 1% the day after it was signed into law by President Bush on July 30. It then declined 7% in three trading days thereafter, regaining pre-signature levels by August 8.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-10#cite_note-10">[11]</a></sup> Measuring short-term fluctuations in market value is an acknowledged drawback in this study. One could have easily argued a $1.4 trillion benefit, using the 7% increase leading up to the day after signature, rather than the following 3-day decline. </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">Iliev: This research paper indicated that SOX 404 indeed led to conservative reported earnings, but also reduced &#8212; rightly or wrongly &#8212; stock valuations of small firms.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-11#cite_note-11">[12]</a></sup> Lower earnings often cause the share price to decrease. </span></li>
</ul>
<ul type="disc">
<li class="MsoNormal"><span style="font-size:10pt;font-family:Verdana;">The Lord &amp; Benoit Report: Do the Benefits Exceed the Cost? It included a population of nearly 2,500 companies, which represented ALL of the calendar year accelerated filers. Lord &amp; Benoit&#8217;s SOX research showed that companies with no material weaknesses in their internal controls, or companies who were able to identify and correct material weaknesses in a timely manner, experienced much greater increases in share prices than companies that did not.<sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-12#cite_note-12">[13]</a></sup> <sup><a href="http://en.wikipedia.org/wiki/Sarbanes-Oxley_Act#cite_note-13#cite_note-13">[14]</a></sup>, The report indicated that the benefits to a compliant company in share price (10% above Russell 3000 index) were greater than their SOX Section 404 costs. Lord &amp; Benoit, a SOX compliance company, issued the report on May 8, 2006. It was also published by the Wall Street Journal.</span></li>
</ul>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=10&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/05/14/analyzing-the-cost-benefit-of-sarbanes-oxley/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/ne224635-128.jpg" medium="image">
			<media:title type="html">ne224635</media:title>
		</media:content>
	</item>
		<item>
		<title>ERM: A Pragmatic Bottom-Up Approach (to Parallel the Top-Down)</title>
		<link>http://sox404.info/2008/04/28/erm-a-pragmatic-bottom-up-approach-to-parallel-the-top-down/</link>
		<comments>http://sox404.info/2008/04/28/erm-a-pragmatic-bottom-up-approach-to-parallel-the-top-down/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 15:56:51 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
		
		<category><![CDATA[ERM]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=9</guid>
		<description><![CDATA[Recent regulatory trends such as Basel II for fi nancial services and Sarbanes-Oxley (SOX) for publicly traded companieshave heightened the importance of better enterprise risk management (ERM). So have trends like globalization, integrated financial markets, the knowledge economy, and political uncertainty. Today, more than ever, how well you take and manage risks affects your cost [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Recent regulatory trends such as Basel II for fi nancial services and Sarbanes-Oxley (SOX) for publicly traded companieshave heightened the importance of better enterprise risk management (ERM). So have trends like globalization, integrated financial markets, the knowledge economy, and political uncertainty. Today, more than ever, how well you take and manage risks affects your cost of capital.</p>
<p>And yet, with the exception of industries such as banking and insurance, many companies fi nd the notion of ERM foreign and diffi cult to implement. The complexity of ERM at every level is daunting?</p>
<p>»How will you determine the universe of all your risks?<br />
»How will you perform an assessment to prioritize which ones are most important?<br />
»How will you design a system of controls that effectively mitigate the risk?<br />
»How will you make sure the controls are working or your risks are at acceptable levels?<br />
»How will you integrate all of this into the daily functioning of the business?</p>
<p>Change Is the Challenge</p>
<p>Anyone who has tried to initiate and gain adoption for an enterprise-wide program, such as Enterprise or Corporate Performance Management, knows that a key reason for failure is change. A fundamental challenge in implementing ERM is the ability to “sell” and “manage” the necessary change in behavior across the entire organization. Managing risk, like managing cost or revenue, cannot be done from the top alone— it must be “owned” by those closest to its occurrence, i.e. the process owners on the front line where managing risk must become just another part of their job. This paper lays out a pragmatic approach for addressing the challenge of change and establishing successful ERM through a series of bottom-up steps that build on existing functional capabilities. These should not be seen as replacing a top-down approach. They should be seen as acting in parallel, in an iterative, mutually re-adjusting and reenforcing manner.</p>
<p>SOX provides a great starting point for a bottom-up approach. When structured properly, the major investment for SOX compliance can now fi nally yield value far beyond an auditor’s attestation. The Internal Audit and IT departments can then integrate and build on this investment, each bringing longstanding experience for identifying and mitigating risk. Lastly, each Line of Business and its respective business functions also manage risk, which can be incorporated with the others together under one clear mapping. The five bottom-up steps below offer a simple, practical path that ensure that you get to this single viewpoint and that your ERM efforts are successful by leveraging existing strengths and gaining “ownership”<br />
from the frontline.</p>
<p>STEP 1<br />
Use Your 404 Documentation to Create a Common Map Section 404 of the Sarbanes-Oxley legislation created a single, consistent, and broad defi nition of the enterprise in contrast to existing fi nancial, operational, HR, or legal defi nitions. These defi nitions served a more narrow purpose and were therefore<br />
not as comprehensive nor were they usually consistent. Until SOX, there was no “Rosetta Stone” to provide a common, universally applicable map of the business, in terms of organizational entities, transaction processes, systems, people, risks, and their overall relationship to fi nancial accounts. A common map is the foundation for identifying risks in a consistent manner across the enterprise. It also ensures alignment across different regulatory environments, risk types, and process owners who may have to address them.</p>
<p>STEP 2<br />
Build on Your Top-Down, Bottom-Up Risk Assessment The new SEC guidelines and the PCAOB’s  Auditing Standard No. 5 have heightened the awareness for an integrated top-down and bottom-up risk assessment approach to SOX. The opportunity is to rationalize the number of key controls required and streamline their testing based on relative risk. Besides the effi ciency gains this yields in compliance itself, it creates a precedent for how to defi ne risks hierarchically and so be able to “cascade” and target your efforts where they are most valuable, i.e. where “top-level” assessments can be made based on consolidated views of risk and push “down” to lower levels of assessment, monitoring, and action.</p>
<p>STEP 3<br />
Extend and Integrate With Internal Audit Internal Audit is the next practical step in providing a foundation for an enterprisewide view of risks. Internal Auditors have built up a history of assessing operational, financial, and compliance risks across the enterprise for prioritizing and planning annual audits. These risks and audits share the same core elements of the map— companies, locations, and processes. Of course, the shared Audit Universe created by integrating SOX with IA will also result in greater resource effi ciencies and speed.</p>
<p>STEP 4<br />
Align With IT Governance Practices Sarbanes-Oxley requirements highlighted many existing good governance practices in IT, notably those represented by the COBIT framework. Beyond the general computer and application-level controls required for SOX, IT manages multiple risks on a daily basis, such as Business Continuity Planning, Disaster Recovery, and management of businesscritical projects to name a few, but these typically all can fi t into the structure in the same way as the SOX IT controls already have.</p>
<p>STEP 5<br />
Engage and Leverage Your Process Owners and LOBs The upfront disruption SOX had on process owners enlisted to create documentation, identify controls, provide self-assessments, and perform tests has largely been reduced. Initially overwhelmed in terms of both the time and learning curve required, many process owners are now far more aware of fi nancial misstatement risks within their areas. This “culture” of managing risk locally is a valuable asset, where new types of risks can be layered onto the same risk culture and framework. Finally, risk management is more than tracking and assessing threats. When risks are tracked against a common map of the business, it is easier to establish the relationship between business performance and risk, like fl ip sides of the same coin. How these risks are managed is critical to sustaining the goals in revenue growth, expense management, and longterm investment.</p>
<p>The Right Information Is Critical<br />
Underlying each of these steps is the need for a single, integrated view on enterprise- wide risks that is aligned with and supports each of the functional constituencies above. Furthermore, the nature of this information requires a fairly complex structure to effectively capture the fl exible hierarchies and many-to-many relationships it must convey, e.g. risks need to be dynamically categorized, assessed, and tracked by different “families” and “types” and associated to more than one location, process, activity, event, people, systems, and more. Such complexity is best addressed when the information source is based on business intelligence design, because if the information is in right, the job of slicing and dicing out what you need, when you need it, becomes a much more straightforward task that can be captured by your people and delivered into your culture in a much more expedient and powerful way.</p>
<p>Roland Mosimann, CEO and co-founder of Business Intelligence International is an industry pioneer in helping drive initiatives around risk and performance management that are anchored in business intelligence design. In 2004, he drove the launch of the Aline™ platform for on-demand Governance, Risk, and Compliance. He recently coauthored The Performance Manager: Proven Strategies for Turning Information into Higher Business Performance, itself a follow-up to his earlier book The Multidimensional Manager — 24 Ways to Impact Your Bottom Line in 90 Days with more than 400,000 copies printed that remain in use by organizations worldwide today.</p>
<p>About Business Intelligence International (BII): Business Intelligence International (BI International) is a global software and consulting company specializing in the development of Web-based business intelligence solutions to provide GRC +P functionality to companies of all sizes. Since 1996, BI International has provided robust, fl exible, and secure solutions to enable customers worldwide to cost-effectively manage their compliance, risk, and performance initiatives. Leveraging its Aline™ Software as a Service (SaaS) platform, BI International offers a suite of affordable yet powerful and easy-to-use tools that provide a single business intelligence-designed repository of information along with integrated analytics and standard reporting. This allows clients to gain real-time visibility to critical information to identify key issues and drive critical decision making. Visit <a href="http://www.aline4value.com">www.aline4value.com</a> for more information.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/9/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/9/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=9&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/04/28/erm-a-pragmatic-bottom-up-approach-to-parallel-the-top-down/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/ne224635-128.jpg" medium="image">
			<media:title type="html">ne224635</media:title>
		</media:content>
	</item>
		<item>
		<title>Evaluating Internal Control over Financial Reporting</title>
		<link>http://sox404.info/2008/04/28/evaluating-internal-control-over-financial-reporting/</link>
		<comments>http://sox404.info/2008/04/28/evaluating-internal-control-over-financial-reporting/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 14:46:05 +0000</pubDate>
		<dc:creator>ccoigne</dc:creator>
		
		<category><![CDATA[ICFR]]></category>

		<category><![CDATA[SOX 404 & 302]]></category>

		<category><![CDATA[SOX Testing]]></category>

		<category><![CDATA[compliance]]></category>

		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[AS5]]></category>

		<category><![CDATA[assertions]]></category>

		<category><![CDATA[internal control]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=8</guid>
		<description><![CDATA[INTRODUCTION
Last year&#8217;s passage of Auditing Standard No. 5 (AS-5) seems to have been the Public Company Accounting Oversight Board&#8217;s (PCAOB) attempt to swing the Sarbanes Oxley regulatory pendulum back from the process oriented, control-centric, &#8220;kitchen sink&#8221; approach to one that allowed companies to make intelligent choices around properly mitigating their financial reporting risks via a [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>INTRODUCTION</p>
<p>Last year&#8217;s passage of Auditing Standard No. 5 (AS-5) seems to have been the Public Company Accounting Oversight Board&#8217;s (PCAOB) attempt to swing the Sarbanes Oxley regulatory pendulum back from the process oriented, control-centric, &#8220;kitchen sink&#8221; approach to one that allowed companies to make intelligent choices around properly mitigating their financial reporting risks via a top-down risk assessment. This in theory should have significantly lowered the amount of work to be done and the costs to be incurred. Furthermore, Auditing Standard 5 also encouraged auditors to rely on the work of others (i.e. documenting and testing key controls) when evaluating the system of internal control, which should have reduced the overall costs of SOX compliance even further.  Unfortunately, in practice, these savings have not been fully realized</p>
<p>In point of fact, external auditors often duplicate their clients&#8217; internally-generated work or perform testing of controls deemed non-key because of management&#8217;s inability to clearly and succinctly demonstrate how their own efforts addressed the organization&#8217;s financial reporting risks for the relevant assertions of significant accounts and disclosures.  If management is unable do so, then external auditors have no other choice than to exercise their own judgment in determining what work must be done to arrive at an opinion regarding the adequacy of internal control.  Their judgment would include selecting the controls required to achieve financial assertion coverage as well as the nature (inquiry/observation, examination, or re-performance), timing (reporting periods from which samples will be selected), and extent (sample sizes) of the tests to be performed on those controls.  In the current business environment, meeting professional obligations to third-party users of financial statements may impact an auditor&#8217;s testing decisions - better safe than sorry.</p>
<p>If an organization truly wants to benefit from AS 5, then it must adopt a systematic, objective approach to evaluating financial reporting and internal control risks and demonstrate management&#8217;s testing approach adequately addresses those risks.</p>
<p>CHALLENGES IMPACTING MANAGEMENT&#8217;S ABILITY TO EVAULUATE INTERNAL CONTROL OVER FINANCIAL REPORTING</p>
<p>Financial Statement Assertion Coverage</p>
<p>Financial statement assertions are nothing new - Sarbanes Oxley has merely changed them from implicit to overt declarations regarding the balances and disclosures reported by management.  Management must now be able to articulate which assertions should be made about a particular account and what assertions each control provides coverage for.  Inexperience with performing this task or unfamiliarity with the details or nuances of each control by the person performing the &#8220;Assertion Sourcing&#8221; task can result in four common problems:</p>
<p>1.Failure to document and evaluate all relevant assertions for each significant account.  As a result, it becomes difficult if not impossible to ascertain whether all controls necessary to adequately report on an account are in place.<br />
2.Redundant controls resulting in unnecessary testing due to the difficulty in evaluating the &#8220;many to many&#8221; relationships of risks, controls, and accounts. <br />
3.Associating to an assertion the wrong controls, i.e. ones that won&#8217;t help meet the assertion.  This situation can result from misunderstanding either the control or the assertion definition.</p>
<p>Claiming a control meets an assertion when it actually covers only a portion.  For instance, the Completeness assertion is really composed of both Completeness and Cutoff; that is, all transactions are recorded in the proper period.  A control like bank reconciliations allows management to assert proper cut-off, but not the completeness of the transactions, which should have been recorded in the General Ledger.<br />
A SUGGESTED METHODOLOGY TO OVERCOME THESE ISSUES</p>
<p>Control Sourcing - Ensuring Assertion Coverage While Optimizing Controls</p>
<p>To overcome these issues, a control-optimization effort can be designed to identify duplicative, overlapping, or non-financial key controls for elimination from testing, as well as any areas where additional controls are needed or testing needs to be enhanced.  However, while critical, the effort is not always simple.  Effective control-optimization requires the ability to evaluate the &#8220;many to many&#8221; relationships of risks, controls, and accounts and evaluate which control would best enable management to make assertions about significant accounts.  Control optimization also requires understanding which major classes of transactions in each cycle impact those accounts.  Since many organizations utilize spreadsheets to capture the risk and control data attributes/elements, they often find it difficult to evaluate the assertion coverage obtained, because there are too many unique dimensions for Excel to deal with.  Management should consider a true database structure to facilitate &#8220;Control Sourcing&#8221; to accounts and assertions in order to identify both duplication and control gaps via exposure by analysis.<br />
Risk-Based Testing</p>
<p>Many organizations currently utilize a &#8220;one size fits all&#8221; approach to control testing.  Control frequency determines sample sizes and the nature of the tests tends to skew towards examination and re-performance.  Internal audit or independent management testers obtain evidence of the control and</p>
<p>Management should consider utilizing an approach which considers the combined effect of Financial Reporting risk (FR) (think Materiality and Impact) and Internal Control risk (IC) (think Likelihood), enabling them to assess the relative significance of controls and potential impact of control failures on Internal Control over Financial Reporting (ICFR) by calculating a numeric score based on objective risk criteria relevant to account balances, assertions, process and controls in a highly defined manner.  No longer would all controls be equal.  Instead, those whose failure could result in a more significant misstatement of the results of operations and required disclosures would receive more robust, objective and timely scrutiny. </p>
<p>The firm of AC Lordi Consulting has developed such a testing methodology and then taken it one step further. It leverages the information gained during the risk assessment, by                                                                                                                                                                                             recommending the nature (inquiry/observation, examination, re-performance), extent (sample sizes) and timing (period from which samples are drawn) for a test based  on the ICFR  score obtained for the related control. </p>
<p>For instance, an automated application control, in a well-controlled ERP environment, ensuring the summary of data compiled in the Accounts Receivable sub-ledger is completely and accurately recorded in the General Ledger is much less risky than the activities of an individual summarizing a list of invoices and then data-entering them to the General Ledger via a manual journal entry.  Failure of either control would result in relatively the same financial reporting risk, but the process and control risk of the latter would be significantly higher, So the second control would receive a higher ICFR score based on the Process and controls IC risk contribution This higher score would portend a more severe approach to testing, likely resulting in a larger sample size, performed more often and much closer to the end of the reporting period.</p>
<p>Additionally, this methodology permits an organization to both spread the work more evenly over the year by testing the controls with lower (less risky) ICFR scores earlier in earlier quarters while ensuring management tests controls with higher ICFR scores closer to end of the reporting year and the testing is assigned to the more objective and independent Internal Audit function.</p>
<p>Instead of the usual two-phased approach to testing where the bulk of the testing is performed perhaps nine months into the year, with the remainder done shortly after year-end, and all controls have samples drawn from each of the two periods, management can schedule the tests to occur during less demanding timeframes and Internal Audit can integrate its testing with existing audit responsibilities.</p>
<p>CONCLUSION</p>
<p>Management should take a proactive position in helping frame the conversation regarding testing with the external auditors by providing sufficient documentation of a &#8220;top-down, risk-based&#8221; evaluation of the risks to providing timely and adequate financial results and disclosures to third-parties.  Their approach should clearly show how the evaluation focused efforts on riskier activities and should aid management in achieving their desired goal of reducing compliance costs by clearly demonstrating to the external auditors familiarity with what could go wrong.  Such an approach should also provide senior management and the Board of Directors with greater assurance that their duties have been properly discharged.<br />
Management&#8217;s ability to evaluate its control environment is highly dependent on its ability to properly structure its risk assessment in a way that allows deep visibility into the nature of the framework. Knowing what controls can be omitted and what tests can be simplified amounts to understanding the importance associated to a control and the gaps that exist in meeting the assertions. But with the right methodology, data structures and reporting toolsets, this exercise becomes straightforward and highly cost-effective.</p>
<p>Copyright April 2008 Christopher D Coigne and John Dorsam</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/8/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/8/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=8&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/04/28/evaluating-internal-control-over-financial-reporting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SOX 404 Compliance</title>
		<link>http://sox404.info/2008/04/28/sox-404-compliance/</link>
		<comments>http://sox404.info/2008/04/28/sox-404-compliance/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 14:19:08 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
		
		<category><![CDATA[SOX 404 & 302]]></category>

		<category><![CDATA[sarbanes oxley]]></category>

		<category><![CDATA[sox 404]]></category>

		<guid isPermaLink="false">http://sox404.wordpress.com/?p=4</guid>
		<description><![CDATA[While completing their first SOX attestation, one of the world’s largest biopharmaceutical outsourcing organizations with operations throughout 43 countries in 56 locations and approximately 6,200 employees, knew that building and maintaining a Sarbanes-Oxley compliance program presented challenges &#8212; unearthing and solving the issues that stood in the way of compliance and managing the myriad of [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong><span style="font-weight:normal;font-size:9pt;font-family:Arial;">While completing their first SOX attestation</span></strong><strong><span style="font-size:9pt;font-family:Arial;">,</span></strong><span style="font-size:9pt;font-family:Arial;"> one of the world’s largest biopharmaceutical outsourcing organizations with operations throughout 43 countries in 56 locations and approximately 6,200 employees, knew that building and maintaining a Sarbanes-Oxley compliance program presented challenges &#8212; unearthing and solving the issues that stood in the way of compliance and managing the myriad of spreadsheets and documents that are needed for the task.</span></p>
<p><span style="font-size:9pt;font-family:Arial;">In 2005, the Company completed its first year of SOX primarily by performing the tasks in shared services centers in the United States, the United Kingdom and Germany. The Company identified <span style="text-decoration:underline;">over 1,000</span> key business controls; remediate and re-tested several hundred key controls and implemented a document control process; tracked remediation; and then tested and re-tested its program.</span></p>
<div><span style="font-size:9pt;font-family:Arial;">The company passed the first year of SOX compliance, <em><span style="text-decoration:underline;">but at what cost</span></em> ? Approximately 25,000 internal and external labor hours were needed, and several million dollars were invested.<span style="font-size:9pt;font-family:Arial;">The Company knew it needed to find a better way.</span></span></div>
<div><span style="font-size:9pt;font-family:Arial;"><span style="font-size:9pt;font-family:Arial;"> </span></span></div>
<p><span style="font-size:9pt;font-family:Arial;"><span style="font-size:9pt;font-family:Arial;"> </p>
<p></span></span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sox404.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sox404.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sox404.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sox404.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sox404.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sox404.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sox404.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sox404.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sox404.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sox404.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sox404.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sox404.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sox404.info&blog=3597981&post=4&subd=sox404&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sox404.info/2008/04/28/sox-404-compliance/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/ne224635-128.jpg" medium="image">
			<media:title type="html">ne224635</media:title>
		</media:content>
	</item>
	</channel>
</rss>