The regulatory mandate that audits of internal controls focus sharply on the risks of fraud or material misstatement has been heard loud and clear. Still, companies can expect some bumps along the road to achieving consistent implementation of that new attitude spelled out under Auditing Standard No. 5. Exactly how AS5 will be implemented by […]
Internal Controls
AS5 in Hand, More Companies to Act Alone
Will the number โ5โ signal greater self-reliance and less dependence on third parties for Sarbanes-Oxley compliance? That numberโsymbolic of both the fifth anniversary of Sarbanes-Oxley and the release of the Public Company Accounting Oversight Boardโs Auditing Standard No. 5โis certainly giving hope to companies that costs can be dropped and processes simplified through greater self-reliance […]
Small Filers Count Down to 404 Deadline
Ready or not, the Dec. 15 deadline for non-accelerated filers to start complying with Section 404 of the Sarbanes-Oxley Act is fast approachingโand this time, the odds that small companies can avoid compliance yet again are small. The Securities and Exchange Commission has issued its final changes to help companies meet their 404 compliance obligations, […]
AS5 Approved: No 404 Delay; More Guidance Coming
As Corporate America finally bids a not-so-fond farewell to the onerous standard known as Auditing Standard No. 2, companies and their auditors are already preparing for life under its replacement. As expected, the Securities and Exchange Commission last week unanimously approved a proposed new standard for auditors to report on the effectiveness of a companyโs […]
Setting Testing Levels For 404 Compliance
I was acting chief accountant at the Securities and Exchange Commission in May 2003 when the Commissionโs first set of rules implementing the provisions of Section 404 of the Sarbanes-Oxley Actโthe section that requires management and auditor reporting on internal controlsโwere passed. No other part of SOX has generated nearly as much controversy, anger, frustration, […]
Defense Giants Step Up IT Security Controls
The U.S. Army describes its Future Combat Systems program as a โcohesive system-of-systemsโ comprised of software, networks, and hardware (as in next-generation tanks) that will allow the future soldier โto see first, understand first, act first, and finish decisively.โ Not long after Boeing was named a lead system integrator on the program in 2004, the […]
AS5, โe-Communicationsโ Comments Sought
Bringing Corporate America one step closer to officially bidding farewell to Auditing Standard No. 2, the Securities and Exchange Commission has published for comment the Public Company Accounting Oversight Boardโs proposed Auditing Standard No. 5 and promises action on the rule no later than July 27. Comments on the proposed AS5, An Audit of Internal […]
Internal Audit Director Critiques AS No. 5
A triumph of hope over experience. Thatโs how one writer characterized the proposed Auditing Standard No. 5 in a recent comment letter to the Securities and Exchange Commission and the Public Company Accounting Oversight Board. Whatโs the hope? The most significant change in AS5 is often described as elimination of the external auditorโs report on […]
HIPAA Inspections Underscore IT Controls
Until now, the data security provisions of the Health Insurance Portability and Accountability Act received scant attention from regulators, particularly compared to enforcement activity for other federal information security mandates like the Sarbanes-Oxley Act or the Gramm-Leach-Bliley Act. That is beginning to change, as federal regulators complete their first HIPAA security audit and prepare to […]
Whereโs The 404 Guidance?
As Corporate America digests recent compliance changes to Section 404 of the Sarbanes-Oxley Act, lawmakers continue to push the Securities and Exchange Commission to allow smaller companies yet another extension for the deadline to comply with the nettlesome law. Regulators and other observers, however, are clear: Donโt bet on it. While the SEC has not […]


