No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Fight SOX Complacency To Reduce Your Risk of Restatement

by Mark Alexander
May 8, 2014
in Risk
Fight SOX Complacency To Reduce Your Risk of Restatement

A growing number of public companies with complacent SOX programs are facing restatement and penalties from improper disclosures, improper revenue recognition and improper expense recognition. A fear of non-compliance with SOX and COSO 2013 has increased the risk that companies will adopt narrowly focused programs that attempt to mitigate the immediate regulatory compliance risks while failing to address the true intent of these regulations. It is a classic case of complying with the “letter of the law” and not its intent. The solution is for internal audit to lead through risk management assurance.

SOX compliance is now a routine process for most companies. How can we then explain the rapidly growing number of restatements and recognition complaints when companies certify they are in compliance?

I agree with Norman Marks, who believes that “complacency and denial” is being perpetuated by routine and checklist-like reviews.  Norman recently wrote about his favorite role that internal audit (IA) plays in an organization.  He describes that role as a fighter against “complacency and denial” that can be perpetuated by routine and checklist-like COSO [and SOX] reviews where it easy to utter “we have completed our quarterly review of the top risks and believe they are effectively managed.” He compares this delusional form of risk management to an “ostrich sticking his head in the sand while the battle rages around him and saying I looked up an hour ago.” Read Norman’s Blog on CAE Risk Intelligence.

It is easy to see how things have arrived at this point. Organizations needed help to rapidly design a SOX blueprint. Management was called upon to make prompt business unit risk determinations which have since been retired to a state of inertia. External auditors and IA, much like engineers, assisted organizations in turning the complex problem of SOX compliance into a quarterly routine of redundancy. During the honorable quest to bring swift order to regulatory chaos, a key to the assurance process suffered from neglect…risk management.

The result of this complacency and neglect is an increased risk of restatement. In October 2013, the PCAOB’s Staff Audit Practice Alert No. 11: Considerations For Audits Of Internal Control Over Financial Reporting  stated that “… it appeared to the inspections staff that firms did not sufficiently understand the likely sources of potential misstatements related to significant accounts or disclosures as part of selecting controls to test.” To comply with COSO 2013, AS5 and SOX, the PCAOB (and the SEC) continue to expect and require that companies and their auditors follow a top-down risk approach.

“The high rate and severity of inspection deficiencies in critical aspects of the audit, and at some of the world’s largest companies, is a wake-up call to firms and regulators alike. More must be done to improve the reliability of audit work performed globally on behalf of investors,” said Lewis Ferguson of the Public Company Accounting Oversight Board, the body that polices auditors in the United States.
– Reuters’ “Audits around the world are riddled with problems – survey” April 10, 2014

What can companies do and how can IA help?

Inspection deficiencies in public company audits found at the six largest accounting firms should be viewed as a wake-up call to the C-Suite and as an opportunity for IA to play a more active and vigilant role. While management is ultimately responsible for determining risks, risk levels and risk management practices, IA should be the organization’s risk champion by providing risk management assurance.

To combat complacency, organizations should have a documented and comprehensive:

  1. Integrated governance, risk management and compliance (GRC) plan (promotes a holistic view of risks and combats against silos)
  2. Organizational risk assessment (formalizes the organization’s risk, risk levels and risk tolerance)
  3. Enterprise risk management (ERM) program (protects the organization from risk pitfalls)
  4. COSO 2013 readiness plan (safeguards against “checklist” compliance; promotes a top-down risk approach)
  5. Critical business activity contract review (i.e., sales and procurement contracts) (ensures that information is not missing from the general ledger and financials) [SOX testing and certification is limited to what exists in the general ledger.]
  6. Fraud risk assessment and anti-fraud program (assists in identifying fraud risks (i.e., FCPA, UKBA, cybersecurity violations, etc.)

Are these efforts robust and vigilant in your organization?
Can you quantify the risk of restatement to your organization?

The last word: complacency by the Board, management and auditors is a real threat to organizations. The CEO/CFO must certify that internal controls are adequate via SOX, but regular SOX testing is not enough to address the risks and controls of the organization. SOX is a compliance framework that should neither drive the company’s business nor its assurance activities. To combat complacency and help reduce the risk of restatement, IA must use risk management assurance (beyond SOX matrices) as part of a dynamic monitoring initiative to provide proper assurance to the Board. The Institute of Internal Auditors believes so strongly in this principle that it recently launched the CRMA (Certification in Risk Management Assurance).


Previous Post

5 Risks That Should Be On the Internal Audit Radar – Now!

Next Post

Stop Getting Ripped Off: The Financial and Reputational Case for a Deeply Embedded Ethical Culture

Mark Alexander

Mark Alexander

Mark Alexander headshot 5-8-14 - CopyMark J. Alexander is an executive consultant, internationally recognized subject matter expert, speaker and trainer on audit, compliance, fraud, risk management and corporate governance. He has 20 years of experience working on critical engagements for over 30 different Fortune 500 and Global 2000 organizations.  He has also held the position of Chief Audit Executive with several organizations and is actively involved with the internal audit community, serving as a member of the IIA Chicago NW Metro Chapter’s Board of Governors. Mr. Alexander holds a BA in Organizational Behavior, BA in Business, MS in Management, Masters in Corporate Governance, MBA in Accounting and is currently completing a Doctorate in Accounting. He is also a member of over 20 professional associations and holds certifications in audit, controls, compliance, risk management, and information systems. Mr. Alexander can be reached at markjalexander@aol.com  

Related Posts

GFT Canada Update

GFT Expands AI Compliance Suite for Canadian Credit Unions

by Corporate Compliance Insights
May 8, 2025

Digital transformation company GFT has expanded its compliance suite to help Canadian credit unions combat payment scams and identity theft...

AxiomGRC Launch

Business Resilience Platform Axiom GRC Enters Global Market

by Corporate Compliance Insights
May 8, 2025

A business resilience platform called Axiom GRC has launched in the UK, backed by £500 million private equity investment from...

MyCOI Launch

myCOI Launches AI-Powered Insurance Compliance Platform

by Corporate Compliance Insights
May 8, 2025

Insuretech provider myCOI has launched illumend, an AI-powered platform designed to manage third-party insurance compliance and certificate of insurance processing....

Beachhead Documentation Launch

Beachhead Solutions Launches Compliance Documentation Tool

by Corporate Compliance Insights
May 8, 2025

Data security provider Beachhead Solutions has launched ComplianceEZ, a new compliance documentation tool built into its BeachheadSecure platform. The tool,...

Next Post
Stop Getting Ripped Off: The Financial and Reputational Case for a Deeply Embedded Ethical Culture

Stop Getting Ripped Off: The Financial and Reputational Case for a Deeply Embedded Ethical Culture

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights