1 Sarbanes-Oxley Section 404 June 29, 2005. 2  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance.

Slides:



Advertisements
Similar presentations
Sarbanes-Oxley Act of 2002 UAA – ACCT 316 – Fall 2003 Accounting Information Systems Dr. Fred Barbee.
Advertisements

Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Sarbanes-Oxley Act. 2 What Is It? Act passed by Congress in response to the recent and continuing corporate scandals. Signed into law July 30, Established.
Sarbanes-Oxley Compliance Process Automation
SOX and IT Audit Programs John R. Robles Thursday, May 31, Tel:
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
BA 427 – Assurance and Attestation Services
Chapter 5 Risk Assessment: Internal Control Evaluation
6-1 McGraw-Hill/Irwin ©2002 by The McGraw-Hill Companies, Inc. All rights reserved. Chapter 6 Internal Control Evaluation: Assessing Control Risk.
Internal Control Pertemuan 05 s.d 06 Matakuliah: F0712 / Lab Sistem Informasi Akuntansi Tahun: 2007.
Introduction to Financial Statements and Other Financial Reporting Topics COPYRIGHT ©2007 Thomson South-Western, a part of the Thomson Corporation. Thomson,
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Section 404 Audits of Internal Control and Control Risk
Chapter 4 IDENTIFYING RISKS AND CONTROLS IN BUSINESS PROCESSES.
The Integrity of Financial Reporting
Nature of an Integrated Audit
Chapter 2 The Financial Statement Auditing Environment McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
INTERNAL CONTROL OVER FINANCIAL REPORTING
® SOX Overview MTAC Meeting August 7, The Sarbanes-Oxley Act  Enacted in 2002 as a result of a series of large corporate financial scandals  Improves.
Chicagoland IASA Spring Conference
Auditing Internal Control over Financial Reporting
Fall 2003 Auditing Update for Auditing and Assurance Services: An Integrated Approach.
An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.
Fraud & Internal Control Frank M. Klaus, CPA. Fraud Definition  Fraud is the misappropriation of assets for the benefit of an individual.  “Willful.
The Sarbanes-Oxley Act of PricewaterhouseCoopers Introduction of Panel Members The Sarbanes-Oxley Act of 2002 What Companies Should Be Doing Now.
Auditing Internal Control over Financial Reporting
INTERNAL CONTROL OVER FINANCIAL REPORTING
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter Three IT Risks and Controls.
Chapter 5 Internal Control over Financial Reporting
Page 1 Internal Audit Outsourcing The Moss Adams Approach to Internal Audit Outsourcing Proposed SOX 404 Changes.
Considering Internal Control
Internal Control in a Financial Statement Audit
Chapter 2 The Financial Statement Auditing Environment McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
Copyright © 2015 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Scandals (in the public and private sector)  Enron  Worldcom  Livent  Nortel  HRDC  Sponsorship Scandal.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
1. IT AUDITS  IT audits: provide audit services where processes or data, or both, are embedded in technologies.  Subject to ethics, guidelines, and.
5-1 McGraw-Hill/Irwin ©2007 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk.
© The McGraw-Hill Companies, Inc., 2008 McGraw-Hill/Irwin Principles of Accounting (Accounting 1 for BBA - Undergraduate) SBS Victor Yerris, PhD
1 Sarbanes-Oxley Overview. 2 Sarbanes-Oxley Act Summary The Sarbanes-Oxley Act of 2002 §201Prohibited Non-Audit Services §202Audit Committee Pre-Approval.
CHAPTER 5 INTERNAL CONTROL OVER FINANCIAL REPORTING.
Casualty Loss Reserve Seminar General Session II September 9, 2003 Section 302/404 of Sarbanes-Oxley Act What Actuaries Need to Know Jan A. Lommele, FCAS,
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 2-1 Chapter Two The Financial Statement Auditing Environment.
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
BA 427 – Assurance and Attestation Services Lecture 7 Reporting on Internal Controls.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
©2008 Prentice Hall Business Publishing, Auditing 12/e, Arens/Beasley/Elder Section 404 Audits of Internal Control and Control Risk Chapter 10.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
Deck 5 Accounting Information Systems Romney and Steinbart Linda Batch February 2012.
The Sarbanes-Oxley Act of Overview of the Sarbanes-Oxley Act of 2002 The Sarbanes-Oxley Act and the related SEC rule-making provide clarity and.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Introduction Outline: Importance IT Governance
Chapter Two The CPA Profession
The Financial Statement Auditing Environment
The Financial Statement Auditing Environment
اطار الرقابة الداخلية و فقا للجنة دعم المنظمات COSO
Fraud & Internal Control
COSO Internal Control s Framework
Sarbanes-Oxley Act (404) An IT Viewpoint
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

1 Sarbanes-Oxley Section 404 June 29, 2005

2  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance 7  COSO – Internal Controls 8  COSO – Internal Controls Framework 9  Why Do You Really Care About SOX 404?10  Things You Can Do11 Table of Contents

3 SOX 404 Background Due to the scandals in corporate financial reporting, Congress enacted in 2002, the Sarbanes Oxley Act (“SOX”). The Security Exchange Commission oversees the compliance by publicly traded companies to the Act. The Public Companies Accounting Oversight Board (“PCAOB”) drives the compliance. SOX Section 404 rules require each annual report to contain an internal control report which shall state the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting, and contain an assessment of the effectiveness of the internal control structure and procedures of the issuer for financial reporting. Filing due dates: Fiscal years ended on or after November 15, 2004 for accelerated filers (ie., market capitalization in excess of $75mm) Fiscal years ended on or after July 15, 2006 for non-accelerated filers.

4 SOX 404 Goals  no material weaknesses that must be reported at the registrant level by either management or the by external auditor;  no significant deficiencies that must be reported at the registrant level by either management or the external auditor to the Audit Committee of the Board of Directors; and  no material misstatements of the company’s financial statements The goals of a SOX 404 program are to ensure that enterprise internal controls are of such quality that there will be:

5 SOX 404 Requirements  Client management must:  Document and test the internal controls over financial reporting  Issue an annual assertion on the effectiveness of internal control over financial reporting  External Auditors must:  Determine nature, timing, and extent of testing  Review work performed by management  Perform some independent tests of controls  Attest and report on: Management’s 404 assertion process Design and effectiveness of internal controls

6 In order to make the assertion, the client must:  Document and evaluate the design of controls  Evaluate the operating effectiveness of significant controls  Identify significant deficiencies or material weaknesses  Document the results of the evaluation  Communicate findings (e.g., significant deficiencies and material weaknesses) to the independent auditor Note: Absence of sufficient evidence to support the Company’s assessment may constitute a significant deficiency that results in a report qualification by the external auditors. SOX 404 Overview - Assertions

7 SOX 404 Compliance

8  COSO provides the PCAOB’s accepted basis for establishing internal control systems and determining their effectiveness.  Stands for “Committee of Sponsoring Organizations”  Originally formed in 1985 to sponsor the National Commission on Fraudulent Financial Reporting (aka “The Treadway Commission”)  The sponsoring organizations include:  American Institute of Certified Public Accountants (AICPA)  The Institute of Internal Auditors (IIA)  Financial Executives International (FEI)  Institute of Management Accountants (IMA)  American Accounting Association (AAA)  Published two documents and one pending  1992 – Internal Controls – Integrated Framework  Mid 90’s – Internal Control on Derivative Issues  Early 2004 – Enterprise Risk Management Framework COSO – Internal Controls

9 The control conscience of an organization. The “tone at the top” The evaluation of internal and external factors that impact an organization’s performance The policies and procedures that help ensure that actions identified to manage risk are executed and timely The process which ensures that relevant information is identified and communicated in a timely manner The process to determine whether internal control is adequately designed, executed, effective and adaptive COSO - Internal Control Framework Components Objectives

10 Non-profit (country clubs) and non-publicly traded (hotels) companies are not required to comply with SOX 404 requirements. Reasons to care: Why Do You Really Care About SOX 404? Board members, who are responsible for the establishment and maintenance of good corporate governance –ALL Financing sources (banks and investors) want assurance that the financial statements are not misrepresented – ALL Owners want assurance that the financial statements are not misrepresented – Hotels Risk of membership loss due to fraudulent practices disclosed to the public – Country Clubs If acquired by a publicly traded company, SOX 404 compliance is required - Hotels

11 Things You Can Do Steps to take to enhance your internal controls: Establishment of an audit committee to provide financial reporting and internal control expertise, along with oversight on such matters Establish a “Whistle-Blower” policy to provide the means and safeguards to those who identify fraudulent practices Assess the risk associated with the processes that make-up your organization (ie., sales/revenue, cash, accounts receivable, fixed assets, accounts payable, payroll, etc.) For high risk areas and processes ask yourself, “What Could Go Wrong” and address the answers to the question (ie., segregation of duties) Reference List: