“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.

Slides:



Advertisements
Similar presentations
Organizational Governance
Advertisements

Chapter 10 Accounting Information Systems and Internal Controls
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Agency Risk Management and Internal Control Standards Presentation to the Board of Visitors November 14, 2014.
Risk Management and Internal Controls ASSAL 20 November 2014 Annick Teubner Chair, IAIS Governance Working Group.
It’s Time to Talk About Risk and Control
Introduction to Enterprise Risk Management (ERM)
BNSF Ethics and Compliance Program Roger Nober Executive Vice President Law and Secretary July 13, 2011.
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
CBIZ Risk & Advisory Services, LLC 1 Quality Assessments Lessons Learned/Best Practices Thomas A. Johnson, CIA November 13, 2007.
AUDIT COMMITTEE FORUM TM ACF Roundtable IT Governance – what does it mean to you as an audit committee member July 2010 The AUDIT COMMITTEE FORUM TM is.
18 years of experience in compliance, risk management, strategic planning, consulting and audit in the financial services industry. Leadership role and.
Sarbanes-Oxley Compliance Process Automation
Seminar in Accounting & Society SOX – Section 404 April 23, 2008.
6/2/20151 Enterprise Risk & Assurance Management in Zurich North America Brian Selby MA (Audit), FIIA, QiCA, MBCS, CISA.
Operational risk management Margaret Guerquin, FSA, FCIA Canadian Institute of Actuaries 2006 General Meeting Chicago Confidential © 2006 Swiss Re All.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
PwC Role of Internal Audit in Corporate Governance September 2010 Tumin Gültekin, Partner.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Building a Compliance Risk Monitoring Program HCCA Compliance Institute New OrleansApril 19, 2005 Lois Dehls Cornell, Esq. Assistant Vice President, Deputy.
PAINTING THE FULL PICTURE
1 Business Continuity and Compliance Working Together Kristy Justice, AVP WaMu Card Services 08/19/2008.
INTERNAL CONTROL OVER FINANCIAL REPORTING
BRIEFING TO THE PORTFOLIO COMMITTEE ON THE DPSA’S RISK MANAGEMENT STRATEGY PRESENTATION TO THE PORTFOLIO COMMITTEE 12 MAY
Information Technology Audit
© Copyright 2012 Pearson Education. All Rights Reserved. Chapter 10 Fraud & Internal Control ACCOUNTING INFORMATION SYSTEMS The Crossroads of Accounting.
CORPORATE GOVERNANCE Regulatory expectations and current good practice Charles Cattell The Cattellyst Consultancy.
Colorado Springs Utilities Environmental Services Functional Assessment Presentation for the American Public Power Association’s 2001 Engineering & Operations.
“ Heightened Expectations” for Corporate Governance AIBA 2 nd Annual Compliance Seminar June 14, 2012 Lester Miller, Senior International Advisor International.
Enterprise Risk Management (ERM) ABN AMRO Business Unit North America (BU NA) Overview for ERM Committee April 11, 2007.
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter 5 Internal Control over Financial Reporting
CDS Operational Risk Management - October 28, 2005 Existing Methodologies for Operational Risk Mitigation - CDS’s ERM Program ACSDA Seminar - October 26.
Monitoring Internal Control Systems Johann Rieser Senior Auditor, Ministry of Finance, Vienna.
Internal Control in a Financial Statement Audit
Enterprise Risk Management Expectations Outpacing Capabilities and The Audit Committee’s Role July 30, 2013 Presented by: Suzette E. Ramsden (B.Sc., CISA,
F INANCIAL S ERVICES Institute of International Bankers Enterprise Risk Management October 29, 2007.
Copyright© 2006 Hewitt Associates Presenter - Ken Vijayakumar source – Hewitt Associate Mergers and Acquisitions in Asia Pacific (Module-19) The Human.
Role of the Board of Directors
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
1. 2 Today’s Presentation The City of Baltimore Water and Wastewater Systems Challenges facing the City The Strategic Planning Initiative So Where Are.
© 2003 DelCreo, Inc. All rights reserved. | U.S. Toll-free 866.DELCREO | International 001/ |
Roadmap For An Effective Compliance And Ethics Program The Top Ten Things the Board Must Know [Name of Presenter] [Title] [Date]
Bank Audit. Internal Audit Internal audit is an independent, objective assurance activity and can give valuable insight in providing assurance that major.
1 Sarbanes-Oxley Overview. 2 Sarbanes-Oxley Act Summary The Sarbanes-Oxley Act of 2002 §201Prohibited Non-Audit Services §202Audit Committee Pre-Approval.
Balance Between Audit/Compliance and Risk Management- Best Practices FIRMA 21 st National Training Conference Julia Fredricks, U.S. Chief Compliance Officer.
1 The Auditor’s Role in Governance: Emulate, Evaluate, Educate Lori Cox, CIA, CGAP IIA Tucson Chapter President Director – Internal Audit, Pima Community.
RISK MANAGEMENT : JOURNEY OR DESTINATION ?. What is Risk? “ Any uncertain event that could significantly enhance or impede a Company’s ability to achieve.
Where Do We Go From Here: Risk Management after the Financial Meltdown Kevin McCabe Wells Fargo Audit Services EVP & Chief Auditor FIRMA 24 th National.
Page 1 Fundamental elements of internal control. 2 Reputation promise/mission The Auditor-General has a constitutional mandate and, as the Supreme Audit.
An Update of COSO’s Internal Control–Integrated Framework
Internal Control Systems
S3: Understanding the Business. Session objective To explain why understanding of the business of the entity is important for the auditor To explain why.
Kathy Corbiere Service Delivery and Performance Commission
Company: Cincinnati Insurance Company Position: IT Governance Risk & Compliance Service Manager Location: Fairfield, OH About the Company : The Cincinnati.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
1 Overview of PCAOB Auditing Standard No. 5 An Audit of Internal Control Over Financial Reporting that is Integrated with an Audit of Financial Statements.
Corporate Governance Week 10 BUSN9229D Saib Dianati.
1 Internal Audit’s Role in Enterprise Risk Management March 22, 2016 Chris Kalafatis, Manager, Risk Advisory Services.
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Shared Services and Third Party Assurance: Panel May 19, 2016.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
JMFIP Financial Management Conference
Roadmap For An Effective Compliance And Ethics Program
Internal control objectives
PLANNING THE INTERNAL AUDIT (8 - 10%)
COSO Internal Control s Framework
An overview of Internal Controls Structure & Mechanism
Presentation transcript:

“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association of Regulatory Utility Commissioners Committee on Water February 2008

2 American Water  Founded in 1886  Largest investor-owned water and wastewater utility in the United States  Serves approximately 16.2 million people  Operations in 32 states and Ontario, Canada  Approximately 7,000 employees

3 Agenda SOX Benefits to Companies Continuing Evolution of SOX Initial SOX Compliance Experience An Evolving Best Practice Beyond SOX – Enterprise Risk Management Controls Rationalization Top Down Risk-Based Approach

4 Benefit of SOX Compliance According to a survey entitled “Oversight Systems Financial Executive Report” conducted with 222 Corporate finance leaders: –74 percent said their company benefited from SOX –79 percent reported “significantly stronger” or “somewhat stronger” internal controls as a result of SOX –46 percent said SOX compliance benefits the company by ensuring accountability –75 percent said they would vote to keep Section 404 if they were members of Congress

5 Benefits of SOX Compliance Positive influence on maintaining investor confidence (and long-term share price) through increased transparency and fewer surprises –Investors are requiring successful risk management –Rating agencies are increasingly focused on qualitative factors around risk management More timely and reliable financial reporting Improved overall control culture Better business risk information for Audit Committees and Management Enhancement of processes and the underlying control structure to drive operational effectiveness and cost efficiencies Improved Corporate Governance Process Back to the basics: strengthening foundational controls that had received less attention prior to SOX Alignment of IT with the business Elimination of outdated, redundant and ineffective processes and controls Easier employee on-boarding process

6 SOX Benefits to Customers and Regulators Enhances capital attraction at appropriate rates –Avoids a risk penalty Transparency –Enhances regulatory and public confidence More pro-active Board of Directors Oversight Greater financial accountability Attracts and improves quality of employees

7 Initial 404 Compliance Experience Most companies faced various challenges around their initial SOX compliance exercise: –Reliance to heavily on manual controls and under utilized IT potential –Lack of a risk-based approach and performed repetitive, manual tasks –Had disparate IT systems, making access to data very difficult –Identified a very high number of key controls Detect and manual controls were, in many instances, prevalent –Staffing issues Lack of sufficient resources Employees who lacked clear roles, responsibilities and goals Sarbanes Oxley was key to companies rethinking many of these issues

8 An Evolving Best Practice e f f i c i e n c y c o s t Top-Down Risk Assessment & Scoping Risk Based Testing & Evaluation Optimization & Standardization of Controls Leveraging Monitoring Controls Controls Automation & Continuous Controls Monitoring Risk Convergence- Consistent Risk & Control Framework Coverage of Fraud Risk & Controls Process & Controls Improvement strategic operations financial compliance i n v e s t m e n t v a l u e Making the Business Better: Leverage 404 efforts to invest in a comprehensive control environment, drive efficiency and create value to the company

9 Beyond SOX: Enterprise Risk Management Evolution of Enterprise Risk Coverage as a “Best Practice” –Coordinated approach to address strategic, financial, operational and compliance risks (leverage the SOX compliance documentation to extend risk assessment beyond financial reporting) –Enhanced risk assessment process, which fully considers the business strategy, business drivers and initiatives –Enhanced change management processes across the company –Entity-level controls are leveraged Risk Management as a Competency –Embedded in the organization, its management processes and functions –SOX compliance seen as an evolving process, not a project –Achieved through a framework of activities to improve the management of an organization’s constantly evolving risk profile

10 Controls Rationalization Rationalization: Removing controls that are not significant or are unnecessarily redundant Optimization: Selecting controls that are more efficient to test than other controls which mitigate the same risk (e.g., automated vs. manual controls), leveraging strong entity-level controls to reduce the need to rely solely on transaction-level controls Improvement: Modifying, re-designing or re-engineering a process and underlying control structure to drive operational efficiency and effectiveness Objective: To create value and promote efficiency

11 Top Down Risk-Based Approach Financial Statement Risk Assessment Company-Level Controls High Risk Accounts, Processes, and Locations Pervasive Coverage Materiality All Other Accounts and Locations -Top-down approach begins by identifying, understanding, and evaluating the design of company- level (entity level) controls. Entity-level controls include: -Controls within the control environment, such as tone at the top, organizational structure, commitment to competence, human resources policies and procedures; -Management’s risk assessment process; -Control to monitor other controls; and -The period-end financial reporting process. PCAOB – FAQ 38

12 In Closing Benefits of SOX (beyond compliance) –Capital attraction –Improved processes and controls –Stakeholder confidence –Enhanced governance and culture –More engaged and informed audit committees and Board of Directors –Enhanced Customer Service Continuing Evolution of SOX –New SEC Management Guidance and PCAOB Auditing Standards –The ability to leverage SOX efforts for Enterprise Risk Management and increased rigor over non-financial processes Q&A