abednarz
Executive Editor

Happy birthday, SOX

News
Jul 31, 20064 mins

July 30 marks the four-year anniversary of the signing of the Sarbanes-Oxley Act.

Since its passage, SOX has raised the ire of public companies forced to comply with its provisions. In particular, detractors have railed against Section 404 of the legislation, which requires companies to validate the effectiveness of internal controls put in place to protect financial reporting processes.

The biggest complaint has been the cost of compliance. Analysts estimate companies accumulate $1 million in SOX expenses for every $1 billion in revenue.

But lately things are looking up, industry watchers say.

Companies today are in a better position to comply with SOX, says John Hagerty, a vice president at AMR Research. The Securities and Exchange Commission (SEC) and the Public Company Accounting Oversight Board (PCAOB) have begun to issue more clear implementation guidance. As part of that effort, the SEC and PCAOB are advocating a risk-based approach to compliance that encourages companies to focus on areas that present the greatest risk to financial reporting accuracy.

“This has caused organizations to go back and rethink what they had done in previous years, especially the early compliers,” Hagerty says. “2006 has been a year of streamlining for a lot of companies. The number of things that they look at is getting smaller and smaller; they’re getting more focused; and they’re putting more attention on the areas that are really at most risk.”

Recent research from Ernst & Young (PDF) confirms that as public companies accumulate SOX experience, the time and resources companies devote to the compliance effort is dropping in many cases.

Among 255 companies surveyed, 81% said they spent less time on Section 404-related activities in their second year of compliance. Nearly half (46%) trimmed internal hours by 10% to 25%; another 30% decreased hours by 25% to 50%; and 5% slashed the time spent by more than 50%.

Many respondents also were able to refine their testing approach and narrow the scope of controls identified for testing in the second year of compliance. Roughly 47% decreased the number of controls tested by 10% to 25%; another 11% cut controls tested by 25% to 50%; and 4% cut more than 50% of controls tested in year two.

Ongoing challenges

Kathleen Barret sees the benefit of compliance experience — though she’s not expecting overnight relief.

Barret is a consulting manager at BMO Financial Group in Toronto, where she heads up the financial institution’s requirements management/business analysis center of competency. BMO has been compliant with Section 404 since early 2006. Now the challenge is maintaining compliance. While there are fewer staff focused solely on SOX compliance, there are more employees who need to think about how their business decisions might impact BMO’s compliance status, Barret says.

“People need to get used to thinking that way,” she says. “Over the next few years it’s going to be a little bit tricky. Then after a while it will become business as usual.”

Looking back, one of the most difficult parts of achieving 404 compliance was that it diverted resources from other business efforts, Barrett says. “The timeline, the investment of resources — and the fact that those resources were pulled off other potentially very valuable projects — is hard on any organization,” she says.

But the experience of reviewing business processes and bolstering internal controls was important to do, she says. “It’s good from that perspective. I think it’s important to force organizations to do that. If you don’t, they won’t do it and then there’s the potential for problems like we’ve seen before.”

BMO Financial isn’t alone in zeroing in on the positive impact SOX has had on corporate practices.

“A lot of people have said it’s really forced them to pay attention to how the company performs certain activities,” Hagerty says. In the process, companies often have identified duplicative ways of doing the same task and found places to standardize. “There are two types of streamlining that have gone on — streamlining of the things that need to be included in a compliance regime, and a streamlining of the business activity itself,” he says.

Looking ahead, the biggest beneficiaries of early compliers’ experience might be the foreign registrants, who have to begin complying with Section 404 this year, and the small cap companies that have to being complying in 2007, Hagerty says.

“Because the guidance is more clear, and because the auditors are much more succinct regarding what they’re looking for, it’s going to be an easier time for those who are going through their first phase of compliance in the next 18 months.”

abednarz

Ann Bednarz is the executive editor of Network World. Ann is a longtime IT journalist and has spent 26 years writing and editing for Network World, where she has worked as a news reporter, managed product testing and reviews, and developed features and how-to articles for an audience of network professionals and data center managers. Over the last two years, she has conceived and edited award-winning content for Network World that includes 2025 Jesse H. Neal Award finalists, 2025 Azbee Award regional winners and national finalists, and 2024 Eddie & Ozzie Award finalists.

Ann holds a bachelor’s degree in architecture and spent the early part of her journalism career writing about architectural design and construction. In her free time, she keeps those skills alive through DIY projects.

More from this author