Profitable Sarbanes-Oxley Compliance: Attain Improved Shareholder Value and Bottom-Line Results

Section 404 of the Sarbanes-Oxley Act brings new reality to management teams with the realization that they must assess the effectiveness of their internal controls. While there are a number of provisions of the legislation, Section 404 provided the most dramatic impact compared to other sections because of the extensive amount of change. Beyond the requirement for management to conduct self-assessment of internal controls were the new audit rules whereby external auditors provide an attestation of management's assessment. These revisions specify that internal control evaluation and monitoring are now components of the audit reports. These reports contain management's internal control report and the auditor's report on management's assessment in addition to the audit opinion on the financial statements. We will address the issues and challenges created by management self-assessments together with their audit implications.
These changes represent new territory for both management and auditors. The internal control gaps that have been exposed over the past few years led the Securities and Exchange Commission (SEC) and Public Company Accounting Oversight Board (PCAOB) to place heightened emphasis on both effective design of internal control and the operational effectiveness of the control system. When the regulations were issued, they did not provide guidance other than indicate that the COSO Framework was an acceptable, suitable, and recognizable framework. This left management teams and auditors with considerable room on to how to conduct the assessment and the attestation. Insight and guidance on the COSO frameworks have been provided. Now it is time to discuss...