Profitable Sarbanes-Oxley Compliance: Attain Improved Shareholder Value and Bottom-Line Results

Internal control is a process designed by, or under the supervision of, an entity's principal executive and financial officers. The Securities and Exchange Commission (SEC) rules went beyond COSO by placing responsibility for internal control squarely on the certifying officers. Section 404 requires management to assess the effectiveness of internal controls, which management has responsibility for designing and maintaining. Now, more than ever, management will need to understand processes and how to document them.
Management's assessment must evaluate not only the design of internal control over financial reporting, but also its operating effectiveness. This goes beyond the common level of thinking about Section 404 that a team of people can gather with clipboards and check off the list of key processes and then proclaim that the company is in compliance. Management and boards will now have to get in the trenches and understand the processes that allow the company to operate. Those who immerse themselves in the details will benefit from planning that will build processes and prevent poor performance. The rewards can extend beyond just compliance and provide a foundation for creating a strong competitive advantage through continuous business process improvement. Extending beyond understanding the evaluation and improvement of processes, we will examine the opportunities for building an infrastructure of business process management and business intelligence.
Documentation of controls cannot occur until controls relevant to financial reporting and disclosure have been identified. This step entails assessing the process risks and determining what could go wrong and...