
How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control 3rd Edition
Author(s): Michael J. Ramos (Author)
- Publisher: Wiley
- Publication Date: 7 Feb. 2008
- Edition: 3rd
- Language: English
- Print length: 288 pages
- ISBN-10: 0470169303
- ISBN-13: 9780470169308
Book Description
Editorial Reviews
From the Inside Flap
How to Comply with Sarbanes-Oxley Section 404 Third Edition
Now fully revised and updated, the Third Edition of How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control is the perfect starting point for companies with no previous SOX experience to get up to speed quickly. Packed with practice aids including forms, checklists, illustrations, diagrams, and tables, the new edition leads auditing professionals through every step of the audit processes associated with Section 404 compliance.
Written by author and renowned auditing expert Michael Ramos, the Third Edition of this easy-to-follow and practical guide updates readers on a number of changes that have taken place since publication of the Second Edition. This indispensable guide includes:
-
Full incorporation of new interpreta-tions from SEC, PCAOB and COSO, with particular emphasis on SOX 404 as it relates to smaller public companies
-
Comprehensive, step-by-step approach for engagement performance with in-depth explanations and practice aids
-
Practical advice on making sound judgments about the internal control testing and evaluation process
-
Guidance on making the assessment of internal control more effective and less of a drain on already limited resources
-
Coverage of post-implementation best practices that enable companies to develop strategies and approaches for ongoing compliance
Sarbanes-Oxley is about process and requires more than just the reporting of results alone. How to Comply with Sarbanes-Oxley Section 404: Assessing the Effectiveness of Internal Control, Third Edition provides auditing professionals with everything necessary to apply these matters now so important to our financial reporting system.
From the Back Cover
Fully revised and updated
A step-by-step approach for planning and performing an assessment of internal controls
Thoroughly revised and updated, How to Comply with Sarbanes-Oxley Section 404, Third Edition brings practical clarity to a complex topic, providing a comprehensive, logically structured approach to effective testing and evaluation of internal controls within your company. Informative and clear, this refreshingly readable book demonstrates author Michael Ramos’s deep understanding of the technical 404 requirements and contains the most pertinent updates and important SEC and PCAOB releases.
The Third Edition helps CFOs, auditors, corporate managers, and consultants knowledgably interpret and conform to Sarbanes-Oxley Section 404 compliance and features:
-
Clear, jargon-free coverage of the Sarbanes-Oxley Act and how it affects you
-
Examples and action plans providing blueprints for implementing requirements of the Act
-
Easy-to-understand coverage of the requirements of SEC, PCAOB, and COSO guidance
-
Discussion of the requirements for assessing internal control effectiveness
-
A look at how the new guidance will reduce your costs
-
In-depth explanations to help professionals understand how best to approach the internal control engagement
-
Practice aids, including forms, checklists, illustrations, diagrams, and tables
This area of auditing and corporate governance will continue to evolve and bring about business and cultural change. How to Comply with Sarbanes-Oxley Section 404, Third Edition is your must-have, must-own guide to SOX 404 implementation and an effective tool and reference guide for every corporate manager.
About the Author
Michael J. Ramos, CPA, also author of Wiley GAAS, is a consultant who writes extensively on emerging auditing matters. He has written numerous successful pro-ducts, including non-authoritative practiceaids, implementation guides and authorita-tive AICPA audit and accounting guides. In addition to text-based products, he has also authored a variety of training programs, including computer-based multimedia training and audio and video scripts. Ramos has written in the areas of ethics, auditing, internal control, and fraud detection.
Excerpt. © Reprinted by permission. All rights reserved.
How to Comply with Sarbanes-Oxley Section 404
Assessing the Effectiveness of Internal ControlBy Michael J. Ramos
John Wiley & Sons
Copyright © 2008 Michael J. Ramos
All right reserved.
ISBN: 978-0-470-16930-8
Chapter One
The Evaluation Approach
CHAPTER SUMMARY
Overview of the SEC rules requiring management’s assessment of the effectiveness of the entity’s internal control over financial reporting
Description of a risk-based, top-down approach to the evaluation of an entity’s internal control and disclosure controls and procedures
Summary of the external auditor’s responsibilities and how management can work with its auditors to create an efficient internal control audit
MANAGEMENT’S EVALUATION OF INTERNAL CONTROL
The Sarbanes-Oxley Act of 2002 (SOX) made significant changes to many aspects of the financial reporting process. One of those changes is a requirement that management provide a report that contains an assessment of an entity’s internal control over financial reporting.
Securities and Exchange Commission (SEC) rule 13a-15 (f) defines internal control over financial reporting in this way:
The term internal control over financial reporting is defined as a process designed by, or under the supervision of, the issuer’s principal executive and principal financial officers, or persons performing similar functions, and effected by the issuer’s board of directors, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles and includes those policies and procedures that:
(1) Pertain to the maintenance of records that in reasonable detail accurately and fairly reflect the transactions and dispositions of the assets of the issuer;
(2) Provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with generally accepted accounting principles, and that receipts and expenditures of the issuer are being made only in accordance with authorizations of management and directors of the issuer; and
(3) Provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of the issuer’s assets that could have a material effect on the financial statements.
When considering the SEC’s definition, you should note these points:
The term “internal control” is a broad concept that extends to all areas of the management of an enterprise. The SEC definition narrows the scope of an entity’s consideration of internal control to the preparation of the financial statements-hence the use of the term “internal control over financial reporting.”
The SEC intends its definition to be consistent with the definition of internal controls that pertain to financial reporting objectives that was provided in the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Report. (See Chapter 2 of this book for a detailed discussion of the COSO Report).
This book, unless otherwise indicated, uses the term “internal control” to mean the same thing as “internal control over financial reporting,” as defined by the SEC rules.
Management files its internal control report together with the annual 10K. The internal control report must include:
(A) Management’s Annual Report on Internal Control Over Financial Reporting. Provide a report on the company’s internal control over financial reporting that contains:
(1) A statement of management’s responsibilities for establishing and maintaining adequate internal control over financial reporting;
(2) A statement identifying the framework used by management to evaluate the effectiveness of the company’s internal control over financial reporting;
(3) Management’s assessment of the effectiveness of the company’s internal control over financial reporting as of the end of the most recent fiscal year, including a statement as to whether or not internal control over financial reporting is effective. This discussion must include disclosure of any material weakness in the company’s internal control over financial reporting identified by management. Management is not permitted to conclude that the registrant’s internal control over financial reporting is effective if there are one or more material weaknesses in the company’s internal control over financial reporting; and
(4) A statement that the registered public accounting firm that audited the financial statements included in the annual report has issued an attestation report on management’s assessment of the registrant’s internal control over financial reporting.
(B) Attestation Report of the Registered Public Accounting Firm. Provide the registered public accounting firm’s attestation report on management’s assessment of the company’s internal control over financial reporting
(C) Changes in Internal Control Over Financial Reporting. Disclose any change in the company’s internal control over financial reporting that has materially affected, or is reasonably likely to materially affect the company’s internal control over financial reporting.
Overview of the Evaluation Process
Management must have a “reasonable basis” for its annual assessment. To provide this reasonable basis, management must perform an annual evaluation of internal control.
SEC Release Nos. 33-810 and 34-55928 provide important interpretative guidance for management regarding its evaluation of internal control. The SEC rules on evaluating internal control are objective driven and principles-based, and they start with a description of the overall objective of management’s evaluation. Having a clear understanding of the overall objective of your evaluation is vital if you want that process to be as effective and efficient as possible.
According to the SEC, the primary objective of management’s evaluation is to
Provide management with a reasonable basis for its annual assessment as to whether any material weaknesses in internal control exist as of the end of the fiscal year
The phrases in italics are of critical importance in planning and performing an evaluation of internal control.
Reasonable basis. A reasonable basis is “such level of detail and degree of assurance as would satisfy prudent officials in the conduct of their own affairs.” The notion of “reasonable” does not imply an unrealistic degree of precision or a single conclusion or evaluation approach. By setting a threshold of “reasonableness” to its guidance, the SEC acknowledges that management can and should exercise judgment in how it complies with its rules and that there is a full range of appropriate ways to evaluate internal control.
Material. An amount is material to the financial statements if it would change or influence the judgment of a financial statement user. Note that the SEC rules direct management to identify “material” weaknesses,” not all weaknesses or deficiencies in internal control. Having a clear understanding of what is and is not material will help you design a more efficient evaluation approach.
Even though the SEC has provided detailed interpretative guidance, ultimately this guidance not only allows for but actively encourages management to exercise its judgment in the design and execution of the procedures it performs to meet the overall objective for evaluating internal control.
Material Weakness
The SEC states that overall objective of the evaluation of internal control is to determine whether a material weakness exists as of the fiscal year-end. In order to meet this objective, it is critical you have a working definition of the term.
A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected in a timely basis.
A control deficiency exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis.
There is a reasonable possibility of an event when the likelihood of the event is more than remote.
With these definitions in hand, you have a sound basis for choosing the nature, timing and extent of procedures necessary to support your evaluation of internal control.
RISK-BASED JUDGMENTS
Underlying the SEC guidance is the idea that management’s assessment of risk is central to its process for evaluating internal control. Within this context, there are two types of risks. Although they are related to each other, it is important for you to distinguish between the two of them as you plan your evaluation process.
Misstatement risk is the risk that the financial statements could be misstated, irrespective of the entity’s internal controls. For example, consider a high-technology manufacturing company. The nature of its business means that the company is vulnerable to rapid advances in technology, which could make its products obsolete. This obsolescence must be reflected in the company’s financial statements (in the way inventory is valued). Because of the materiality of inventory to its financial statements and due to the high degree of judgment in making an estimate of the value of high-tech inventory in a constantly changing business environment, you might consider misstatement risk related to inventory to be high.
Risk of control failure is the risk that a failure in the design or operation of a control could lead to a material misstatement of the financial statements.
The risk of control failure is a function of misstatement risk and the likelihood of a control failure. If this combination of factors is high, then the risk of control failure increases. If this combination of factors is low, then the risk of control failure decreases.
For example, consider the high-tech manufacturing company, as discussed. The circumstances of the company’s business lead to a relatively high misstatement risk. But what about the risk of control failure?
Assume that the company conducts an annual physical count of this inventory to determine the quantity of items on hand. This control procedure is critical if the company is to accurately report the valuation of its year-end inventory and its cost of sales throughout the year. Obtaining a proper count by inventory item is critical not only for determining the gross amount of the inventory balances, but also for identifying the amount of inventory that may be subject to obsolescence. Put another way, if this control procedure were to fail (i.e., the company did not get an accurate inventory count), there would be a high risk that the failure could lead to a material misstatement.
Suppose that the nature of the inventory required a high degree of specialized knowledge to determine precisely what the item was (i.e., all processing chips look the same to the untrained eye). Further, the company had a 100% turnover of personnel assigned to conduct the inventory count. Given these circumstances, the likelihood of a control failure (i.e., an inaccurate inventory count) would be relatively high.
In this situation, the combination of a high misstatement risk and a high likelihood of control failure results in a high overall risk of control failure.
As the combination of misstatement risk and likelihood of control failure decreases, however, so does control risk.
For example, suppose that the high-tech manufacturer changes its policy for reimbursing employees for their cell phone usage. The company raises the amount it will reimburse employees from $50 per month to $75 per month. The sales manager knows from past experience that most salespeople will fail to read the e-mail announcing the change in policy, and as a result, it will take months before the new policy is universally endorsed. Once the salespeople realize that the reimbursement has been raised, they will be reimbursed retroactively. That is, as of a given point in time, the company technically has a liability to all its salespeople who have not yet figured out the new policy.
Thus, there is a risk that the company’s accrued liabilities may be understated. But how significant is this risk to the financial statements as a whole? Most likely, the total amount of this liability is inconsequential to the company’s financial position.
Because misstatement risk is low, the risk of control failure also should be small. Remember that by definition, the risk of control failure is the risk that a failure of the control could lead to a “material” misstatement. In this case, even if there was no control over reimbursing employees for cell phone usage, the company could not materially misstate its financial statements. The risks related to control failure are nonexistent.
Given this combination of high likelihood but extremely small significance, there is probably a low overall risk that a material misstatement of the financial statements would occur as a result of this circumstance. With such a low risk, you probably would not include controls related to capturing unpaid cell phone reimbursements within the scope of your internal control evaluation.
Why Understanding Risk Is Important
The proper design and efficient performance of an evaluation of internal control depends greatly on management’s assessment of risk. The fundamental principle is that you should focus your attention where the risk is the highest, where there is a relatively high likelihood that a significant misstatement of the financial statements could result. The nature and extent of the procedures you perform to document and test controls should be commensurate with the risk that a failure of those controls could result in a material misstatement of the financial statements. The opposite also is true: You do not need to spend a great deal of time on those areas where risk is the lowest.
Management’s decisions should be driven by an evaluation of the risk in three areas:
1. Identifying controls to include in the assessment. A control where there is a low risk that its failure could lead to a material misstatement is scoped out of the evaluation; that is, it is not included in the documentation, testing, or evaluation of controls.
2. Evaluating the operating effectiveness of the controls. The procedures management uses to obtain evidence about the operating effectiveness of controls should be based on an assessment of risk. For those controls where the risk of material misstatement is highest, the procedures performed should produce highly reliable evidence about operating effectiveness; if the controls have a lower risk, then the evidence does not have to be as reliable.
3. Documenting the evidence related to testing of the controls. When the risk associated with a control is relatively high, the documentation of the tests performed should be extensive. The converse also is true-if the risk is low, then the documentation need not be as extensive.
Exhibit 1.1 illustrates how risk-based judgments affect each of these three decisions.
Later chapters of this book will provide more guidance on how to make risk-based judgments in each of these areas.
(Continues…)
Excerpted from How to Comply with Sarbanes-Oxley Section 404by Michael J. Ramos Copyright © 2008 by Michael J. Ramos. Excerpted by permission.
All rights reserved. No part of this excerpt may be reproduced or reprinted without permission in writing from the publisher.
Excerpts are provided by Dial-A-Book Inc. solely for the personal use of visitors to this web site.
Wow! eBook

