An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein.

Slides:



Advertisements
Similar presentations
G L O B A L S E R V I C E / I N D U S T R Y A U D I T / T A X / A D V I S O R Y / L I N E O F B U S I N E S S SAS 112 Presentation California State University.
Advertisements

Control and Accounting Information Systems
IT Considerations in Integrated Audit By: Yusuf Musaji.
Internal Control.
Internal Control Chapter 7 covers two distinct, but related topics:
1 Sarbanes-Oxley Section 404 June 29,  SOX 404 Background 3  SOX 404 Goals 4  SOX 404 Requirements 5  SOX 404 Assertions 6  SOX 404 Compliance.
Office of the Secretary of Defense – Comptroller Financial Improvement and Audit Readiness Directorate Unclassified 17 September 2014 GAO Revised “Green.
SAS 112 – The Year After Presented by Chris Ray Partner - KPMG LLP KPMG LLP.
S11: Risk Based Audit Approach. Session Objectives  To define audit risks and establish the relationship between materiality and audit risk  To discuss.
Chapter 7 Control and AIS Copyright © 2012 Pearson Education, Inc. publishing as Prentice Hall 7-1.
Review of Introduction to Auditing
Standar Pekerjaan Lapangan: Pemahaman Memadai atas Pengendalian Intern Pertemuan 5.
Chapter 5 Risk Assessment: Internal Control Evaluation
SAS 112 Update Chapter 9 Presented by Chris Ray, Partner KPMG LLP KPMG LLP.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
18- 1 © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. Chapter 18 Integrated Audits of Internal Control (For Public Companies Under Sarbanes-Oxley.
Internal Control in a Financial Statement Audit
CHAPTER 2 FINANCIAL STATEMENT AUDITS AND AUDITORS’ RESPONSIBILITIES Fall 2007 u G enerally Accepted Auditing Standards u Assurance Provided by an Audit.
Section 404 Audits of Internal Control and Control Risk
UCSD Office of the Controller1 SAS112 Implementation UCSD Status Update.
Nature of an Integrated Audit
Sarbanes-Oxley Project Summary of COSO Framework Presented by Larry Dillehay & Scott Reitan Parkfield Group LLC.
Reports By David N. Ricchiute
Statement on Auditing Standards (SAS) 112 Communicating Internal Control Related Matters Identified in an Audit.
Internal Auditing and Outsourcing
Auditing Internal Control over Financial Reporting
D-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Module D Internal, Governmental, and Fraud Audits “I predict that audit.
5-1 McGraw-Hill/Irwin ©2005 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk “If everything.
Transitioning to the COSO 2013 Update.  Released on May 14, 2013  Designed to build upon the foundation of the 1992 Framework  Will supersede the 1992.
Auditing Internal Control over Financial Reporting
AICPA SAS 112 on Internal Controls: Implications and Impacts on State Agencies and Auditors Presented by Frank Crawford, CPA Crawford & Associates, P.C.
Chapter 07 Internal Control McGraw-Hill/IrwinCopyright © 2014 by The McGraw-Hill Companies, Inc. All rights reserved.
INTERNAL CONTROL OVER FINANCIAL REPORTING
Implementation Issues of Sarbanes-Oxley CASE Presentation September 23, 2004 By Denise Farnan.
Chapter Three IT Risks and Controls.
Chapter 5 Internal Control over Financial Reporting
Considering Internal Control
Introduction In 1992, the Committee Of Sponsoring Organizations of the Treadway Commission (COSO) published Internal Control-Integrated Framework (1992.
Internal Control in a Financial Statement Audit
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
1 Practical Implications of U.S. Requirements to Report on Internal Control Andrew D. Bailey, Jr. Deputy Chief Accountant: Professional Practice U.S. Securities.
NO FRAUD LEFT BEHIND The Effect of New Risk Assessment Auditing Standards on Schools Runyon Kersteen Ouellette.
1 The Impact of SAS 112 on Governmental Financial Statement Audits GAQC Member Conference Call January 4, 2007 Presented by Chuck Landes, CPA.
Learning Objectives LO5 Illustrate how business risk analysis is used to assess the risk of material misstatement at the financial statement level and.
1 Today’s Presentation Sarbanes Oxley and Financial Reporting An NSTAR Perspective.
5-1 McGraw-Hill/Irwin ©2007 by the McGraw-Hill Companies, Inc. All rights reserved. Chapter 5 Internal Control Evaluation: Assessing Control Risk.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
Copyright © 2013 by The McGraw-Hill Companies, Inc. All rights reserved.McGraw-Hill/Irwin.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 6-1 Chapter Six Internal Control in a Financial Statement Audit.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
A Guide for Management. Overview Benefits of entity-level controls Nature of entity-level controls Types of entity-level controls, control objectives,
McGraw-Hill/Irwin © The McGraw-Hill Companies 2010 Auditing Internal Control over Financial Reporting Chapter Seven.
BA 427 – Assurance and Attestation Services Lecture 7 Reporting on Internal Controls.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2006 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
©2012 Prentice Hall Business Publishing, Auditing 14/e, Arens/Elder/Beasley Section 404 Audits of Internal Control and Control Risk Chapter.
18-1 Copyright © 2016 McGraw-Hill Education. All rights reserved. No reproduction or distribution without the prior written consent of McGraw-Hill Education.
The Sarbanes-Oxley Act of Overview of the Sarbanes-Oxley Act of 2002 The Sarbanes-Oxley Act and the related SEC rule-making provide clarity and.
©©2012 Pearson Education, Auditing 14/e, Arens/Elder/Beasley Considering Internal Control Chapter 10.
Copyright © 2014 Pearson Education, Inc. Publishing as Prentice Hall. Chapter
Lecture 5 Control and AIS Copyright © 2012 Pearson Education 7-1.
Internal Control. McGraw-Hill/Irwin © 2004 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition A process...designed.
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
©2005 Prentice Hall Business Publishing, Auditing and Assurance Services 10/e, Arens/Elder/Beasley Internal Control and Control Risk Chapter 10.
Auditors’ Dilemma – reporting requirements on Internal Financial Controls under the Companies Act 2013 and Clause 49 of the Listing agreement V. Venkataramanan.
Internal Control Chapter 7. McGraw-Hill/Irwin © 2008 The McGraw-Hill Companies, Inc., All Rights Reserved. 7-2 Summary of Internal Control Definition.
Section 404 Audits of Internal Control and Control Risk
Internal Control Evaluation: Assessing Control Risk
Internal control objectives
Presentation transcript:

An Accountant’s Look at the Changing Horizons within SOX 404 Presented to Colorado Bar Association’s Securities Law Group Presented by Bill Evert Hein & Associates LLP September 21, 2006

Why should companies care about controls? Fraud Lost revenues SOX 404 compliance Personal liability

SOX 404 – Management Requirements Currently effective for accelerated filers ($75MM public float, etc.): Incorporate within the Company’s Form 10-K a report that: –Acknowledges responsibility for establishing/ maintaining adequate internal controls over financial reporting –Identifies framework used (COSO) –Assesses effectiveness at end of fiscal year –Confirms independent auditors issued attestation report on management’s assertion

Example Reporting Scenarios Situation Management’s Report Auditor’s Opinion on Management’s Assessment Effectiveness of ICOFR No material weakness identified. Internal control effective. Unqualified Material weakness identified by management and auditor. Internal control not effective. UnqualifiedAdverse

Example Reporting Scenarios Situation Management’s Report Company has one or more material weaknesses, but management’s assessment indicates internal control is effective. Issue adverse opinions on both management’s assessment and internal control. Management fails to fulfill its responsibilities regarding the internal control assessment. Communicate to management and the Audit Committee. Disclaim opinions. Consider possible additional auditor responsibilities.

Deficiencies – Conceptual Definitions Classification of Deficiency Likelihood of Misstatement Potential Magnitude of Misstatement Internal Control Deficiency RemoteORInconsequential Significant DeficiencyMore than remoteANDMore than inconsequential Material WeaknessMore than remoteANDMaterial A deficiency is considered a significant deficiency or material weakness if, either individually or in the aggregate, after considering compensating controls, the following criteria are met:

Current Events – Moving Targets New guidance: Remediation Standard (AS4) New SAS standard New COSO framework for small businesses (July 11, 2006) Coming soon: New SOX 404 guidance regarding non-accelerated filers and IPOs Guidance for companies implementing SOX 404 Revised AS2

Issues/Pitfalls Encountered Lack of: ― Lead time/resources/game plan ― Effective communication between auditor and client ― Motivation in second year Issues: ― Late start (prevents integrated audits and rising costs) ― Multiple operations/foreign subsidiaries ― Company’s GAAP and SEC expertise ― Consequences of adverse and disclaimer opinions ― Controls at outsourced service providers

Why is SOX 404 so difficult (and costly)? 1.Definition of significant deficiency “more than inconsequential”: A misstatement is inconsequential if a reasonable person would conclude, after considering the possibility of further undetected misstatements, that the misstatement, either individually or when aggregated with other misstatements, would clearly be immaterial to the financial statements. If a reasonable person could not reach such a conclusion regarding a particular misstatement, that misstatement is more than inconsequential. 1.Must have controls over all of the relevant assertions over all significant accounts and footnotes. 2.Materiality and deficiency evaluation. 3.Testing of attributes, not dollars - “What could go wrong; not what does.” 4.Adjustments the auditor finds.

Why should private companies adopt SOX? Better controls thereby: likelihood of fraud ― Decreasing the likelihood of fraud ― Increasing operational efficiency Exit strategy? SOX will eventually become the standard by which companies are judged New audit standards CHANGE IS GOOD YOU GO FIRST

Components of the Control Environment 1.Integrity and ethical values 2.Commitment to competence 3.Board of Directors and Audit Committee 4.Management’s philosophy and operating style 5.Organizational structure 6.Assignment of authority and responsibility 7.Human resources policies and practice

Why control environment is so important The following circumstances are at least a significant deficiency and a strong indicator of the existence of a material weakness per AS2. Restatement of previously issued financial statements. Auditor’s identification of a material misstatement in the current year audit that was not initially identified by the Company. Ineffective Audit Committee oversight. An ineffective internal audit or risk assessment function, if critical to reliability of Company’s financial reporting process. An ineffective regulatory compliance function in highly regulated companies if functions could have a material effect on the reliability of financial reporting. Identification of fraud of any magnitude on the part of senior management. Previously communicated significant deficiencies that remain uncorrected after a reasonable period of time. An ineffective control environment.

Oversight by the Audit Committee and Board Nature and frequency of meetings Consideration of fraud when reviewing: ― Accounting principles ― Non-routine transactions Evaluation of management’s assessment of fraud risk Discussion with auditor’s potential fraud areas

Risk Assessment Systematic process Consideration of potential fraud schemes: ― Types of fraud ― Fraud triangle Assessment of risk at all levels Evaluate likelihood and significance of risks Assessment of exposure Document oversight by Audit Committee