Landmark Study Reveals SOX Compliance Issues

COSO 1992 Control Framework and Management Reporting on Internal Control: Survey and Analysis of Implementation Practices, a landmark research study by the Institute of Management Accountants (IMA), reveals two key cost drivers for public companies complying with Sarbanes Oxley (SOX) Section 404.

“IMA’s study is the first comprehensive study of its kind that goes beyond estimating the cost of compliance. This study helps to identify the real drivers of cost and provides actionable insights for policy makers, regulators and professionals associations,” Paul Sharman, president and chief executive officer (CEO) of the IMA, said in a prepared statement announcing the results. “We have hypothesized for some time that current controls frameworks are inadequate, as they do not allow management practitioners to conduct cost-effective, risk-based assessments covering internal controls over financial reporting, fraud risk, general IT controls, and other areas.”

The study, conducted by professor Parveen P. Gupta of Lehigh University, assessed the views of nearly 400 experienced chief financial officers (CFOs), controllers, internal auditors, and SOX compliance specialists at publicly traded companies. The two key factors identified were a lack of practical management implementation guidance and the incomplete nature of the Committee of Sponsoring Organizations (COSO) 1992 framework in assessing the effectiveness of internal controls over financial reporting (ICoFR). Other key findings include:

  • Approximately two-thirds of those responding attributed the two key factors as major cost drivers.

  • More than half of respondents acknowledged that they did not use COSO 1992 to assess IT control effectiveness, in spite of indicating their control assessment was done in accordance with COSO 1992. Almost 52 percent of respondents used COBIT for the critical aspect of their ICoFR assessment.

  • More smaller companies, 45 percent compared to 35 percent of larger companies, are using a “bottom-up” approach to internal controls rather than a “risk-based” point-of-view, suggesting a skills gap in applying robust risk assessment methods.

  • Only 38 percent of respondents did not believe that the COSO 1992 controls framework was guiding their internal control assessments, while 62 percent primarily rely on Accounting Standard 2 (AS2), which has become the de facto assessment standard for company management.

  • Fifty-seven percent of respondents did not believe that the COSO 1992 framework alone was sufficient guidance for determining the effectiveness of internal controls, strongly suggesting that practical assessment methodologies linked to the framework are necessary to assert to the Securities and Exchange Commission (SEC) that an organization has an effective system of internal controls.

“These results suggest that our hypotheses have been proven to a reasonable degree. Now it is time to develop the long awaited assessment guidance so desperately needed by American businesses to cost-effectively comply with SOX while protecting shareholder interests,” Sharman added.

The study was designed to determine the extent to which companies are using COSO’s 1992 internal controls framework and identify the factors which inhibit a successful and cost-effective SOX compliance outcome, including high-cost compliance activities, definition and use of “risk based” models, application of risk assessments (fraud, plausible, and inherent risk), integrated audits, IT controls assessments, skills gap issues and other practical areas. The study, COSO 1992 Control Framework and Management Reporting on Internal control: Survey and Analysis of Implementation Practices, includes an Executive Summary that is available free of charge. The full study is available for purchase from IMA at www.imanet.org.

You may like these other stories...

Accountants who specialize in forensic and valuation services point to electronic data analysis, or big data, as the most pressing issue they’ll face in the coming months, according to results of a new survey released...
Renaissance avoided more than $6 billion tax, report saysThe Senate Permanent Subcommittee on Investigations said on Monday that a Renaissance Technologies LLC hedge fund’s investors probably avoided more than $6...
Your 15-year-old may be tech-savvy enough to debug your computer, back-up data on your mobile devices, and help you stream episodes of Game of Thrones, but chances are you can’t expect them to display the same level of...

Upcoming CPE Webinars

Jul 23
We can’t deny a great divide exists between the expectations and workplace needs of Baby Boomers and Millennials. To create thriving organizational performance, we need to shift the way in which we groom future leaders.
Jul 24
In this presentation Excel expert David Ringstrom, CPA revisits the Excel feature you should be using, but probably aren't. The Table feature offers the ability to both boost the integrity of your spreadsheets, but reduce maintenance as well.
Jul 31
In this session Excel expert David Ringstrom helps beginners get up to speed in Microsoft Excel. However, even experienced Excel users will learn some new tricks, particularly when David discusses under-utilized aspects of Excel.
Aug 5
This webcast will focus on accounting and disclosure policies for various types of consolidations and business combinations.