How did COVID-19 change work environments and potentially affect SOX costs?
The pandemic forced many organizations to make some or all the following significant operational changes:
- Switch to a remote work environment
- Reassess audit fees
- Reduce staff assigned to operating controls
- Decrease support for external auditors
- Furlough employees or reduce work schedules
These changes have ramifications for a control environment, and companies had to adjust accordingly.
For example, when an employee who is a control activity owner is furloughed, laid off, or put on a reduced work schedule, companies must reassign the responsibility and decide how to maintain proper segregation of duties. And, given the economic impact of the pandemic, companies had to navigate these challenges while keeping their SOX costs as low as possible.
What common mistakes can an organization make in its internal control environment?
Many companies inadvertently complicate their control environments unnecessarily, which can result in errors and delays and unmitigated risks to reliable financial reporting.
Companies often compromise the efficiency of their control environment when they:
- Maintain different financial reporting processes across business units and geographies
- Expand the number of applications impacting financial reporting
- Allow the number of key control activities and operators to grow
- Postpone their annual risk assessments
- Postpone annual SOX training
- Overlook the importance of attracting and retaining the necessary finance and accounting staff to design and operate SOX controls
- Delay integrating acquired companies into their control environment
Increase in financial reporting applications
One of the more common mistakes is expanding the number of applications impacting financial reporting.
For example, if your primary general ledger application doesn’t provide great reporting, you could introduce new technology.
That could include data visualization tools and reports as part of your internal controls evaluation, as they produce information the company can use. This typically requires more effort and can lead to errors.
How can an organization avoid mistakes in its internal control environment?
To avoid common internal control mistakes:
- Understand how to use source information in financial reporting controls
- Limit these controls to systems and applications where you use source information in financial reporting
- Reduce financial reporting system complexity
These opportunities could create possibilities to reduce overhead expenditure.
How does an organization take a top-down approach to internal controls compliance?
There are four key steps to keep in mind for a top-down approach to internal controls compliance:
- Reevaluate your organization’s current controls
- Reexamine and refresh your risk assessment strategies
- Compare your control strategies to the external auditor’s report
- Integrate your audits
Reevaluate current controls
Controls can directly influence the work and effort by audit firms; reevaluating the current controls and implementing a top-down approach can help cut down the length of your audit process. Less time means less impact on your organization and potentially less money.
The more detailed and precise you are when describing and documenting your entity-level controls, the greater the opportunity to minimize cost and impact.
For many reasons, audit firms have a natural tendency for testing more process-level controls in lieu of testing entity-level controls; either the audit team is unable to assess the entity-level controls, or they don’t understand how the entity-level controls operate at a level of precision necessary to prevent and detect material weaknesses.
This is critical when an organization seeks to reduce the number of process level controls, especially when entity-level controls can provide a needed-level of precision over financial assertions.
Process-level controls operate where most of the company activity occurs — such as a division, plant, or revenue cost center — while entity-level controls happen at higher levels in the organization.
Specifically, process level controls directly relate to a specific business cycle impacting financial reporting while entity-level controls focus on reviews that may cover one or more business units.
Reexamine and refresh risk assessment
Reexamine your company’s risk assessment to reduce the number of control activities necessary to mitigate risks to material misstatements. Identify entity-level controls that address relevant risks operating at an appropriate level of precision.
Document the design factors of your entity-level controls so your external auditor can understand and use them.
How can your organization optimize evidence to support assertions?
Your company can optimize evidence of your controls and support the assertions of your audit and help cut costs in the following ways:
- Use control self-assessments
- Remediate significant deficiencies and material weaknesses
- Consolidate controls
Use control self-assessments
Consider using control self-assessments for all SOX controls that your external auditor chooses to test independently.
Control self-assessments can be an efficient, cost-effective way to provide reassurance to your executives without hiring a third party to test your controls.
If you have a third-party test controls to support your 404(a) assertion and your external auditor ignores this work, discuss next steps. Consider whether the cost of a third-party is worth the expense if the external auditor isn’t going to rely on this work.
Use this understanding to increase your external auditor’s reliance on your organization’s work while they test high-risk areas independently. This could provide leverage to negotiate your audit fee.
Remediating significant deficiencies and material weaknesses may enable the auditor to rely on controls for the financial statement audit and simultaneously reduce the number of items selected for testing.
This reduces the audit firm’s overall sample sizes and minimizes the time your company spends responding to audit requests.
If your company receives a list of deficiencies that haven’t been assessed as significant deficiencies or material weakness, your external auditor may be testing too much.
In this case, remove deficient control activities from the SOX population if the ineffective control didn’t result in a significant deficiency or material weakness by itself or in the aggregate.
Remember your auditor doesn’t have to test controls that don’t prevent or detect a material weakness by themselves or in the aggregate. Therefore, if the control fails and it’s evaluated as a deficiency, you could have an opportunity to remove the control and point to another control — especially if the evaluation of the deficiency leads to other mitigating controls.