Safeguarding assets has been an important objective of all organizations for centuries. In todayโs digital age however, what does safeguarding your assets really mean? Who is responsible for it? And how is โprotectionโ actually achieved? The COSO framework for enterprise risk management recognized the importance of safeguarding assets as an implicit component of effective internal […]
Internal Controls
Disclosure of Section 404 Weaknesses
Disclosure of Section 404 Weaknesses
Huge Progress in 404 Compliance
Corporate America has cut the number of internal control weaknesses it reports under Section 404 of the Sarbanes-Oxley Act by nearly 45 percent in the three years since SOX went into effect, a dramatic demonstration that companies are learning to tighten their financial reporting processes. Likewise, the number of adverse Section 404 opinions from external […]
Empowering CEOs in a Shifting Landscape
My last two columns dealt with the tug of war between boards of directors and shareholders and how boards are best comprised to effectively carry out their responsibilities. Central to these issues is the relationship with the chief executive officer; specifically, how to provide the kind of oversight that enables the CEO to run the […]
Auditing Computer Controls With AS5
Once upon a time, broad reviews of general computer controls were a cornerstone of IT audits. Now, Auditing Standard No. 5 may well close the book on that practice. Testing of operating systems, information security, and โchange managementโ in a companyโs IT environment has evolved rapidly since such audits became commonplace 15 years ago. AS5, […]
PCAOB AS5 Guidance for Small Companies
Audit regulators have published some preliminary guidance on how the new Auditing Standard No. 5 can be implemented in smaller, less complex companiesโthe ones that must begin evaluating their internal control over financial reporting at the end of this year. The Public Company Accounting Oversight Board has floated the document for a 60-day comment period. […]
The Right Approach for Your First 404 Audit
Large companies have had five years of hard-earned experience complying with Sarbanes-Oxley and its dreaded Section 404 provisions about internal controls over financial reporting. Now compliance looms for non-accelerated filers, and Iโd suggest leaning on that experience as much as you can. Based on my observations and experience (as the leader of SOX compliance for […]
Governance Divided by a Common Language
George Bernard Shaw had it right. When it comes to corporate executives and investors discussing corporate governance, we are, in the great Irish playwrightโs phrase: โdivided by a common language.โ Knowing which interpretation of that phrase is relevant in what situation can mean the difference between success and failure. It can even determine the future […]
Update on 409A, 404 Guidance, and Fraud
The Internal Revenue Service has extended the deadline to document compliance with its Section 409A rules on deferred compensation by a yearโand companies still have lots of compliance work to get done right now anyway. As Compliance Week has previously reported, the IRS extended the deadline for making final amendments to deferred compensation plans, but […]
Despite AS5, Liability Fears Still Loom Large
As public companies and audit firms prepare for a new approach to auditing internal controls over financial reporting, a certain trepidation hangs over the process. Regulators have called for a more relaxed audit, but how will the plaintiff lawyers react? The Securities and Exchange Commission and the Public Company Accounting Oversight Board codified their call […]


