Showing posts with label Sarbanes-Oxley. Show all posts
Showing posts with label Sarbanes-Oxley. Show all posts

Friday, August 19, 2011

In Business We Must "Jiggle the Gate" - Lessons From the Air and Water Show and the Home


Today, as the jets are flying over Chicago (and my office – how cool is that?) practicing their maneuvers for the annual Chicago Air and Water Show this weekend, I am reminded of two things:

1 – The importance of effective internal control systems

2 – The importance of monitoring those internal control systems


It doesn’t take an aerospace engineer to understand that while flying in tight formation a pilot must be constantly aware of his position relative to the other aircraft in the formation. One false move by any of the pilots would spell disaster for everyone. Fortunately they have computer systems in the cockpit that continuously calculate time, space, distance (i.e. internal control system) and a built in warning system alerting them when things are going wrong (i.e. monitoring). However, it is up to the pilot to react to these indicators to avoid disaster. It is pretty amazing to me that all of this works, considering they are flying at speeds over 500 mph and at a distance of 18 inches apart from each other. Heck, I find it difficult jogging next to someone who is only 18 inches away from me – I can almost guarantee we’d bump into each other – but not these pilots. Amazing!

Well, effective internal controls systems and monitoring the internal control systems is important in other places too. Parents of toddlers know all about internal control systems (gates around staircases, plastic covers over door knobs, protective covers over electric outlets…) and monitoring systems (you can’t leave a toddler alone, right? and when you do there is technology for to help - it is called a baby “monitor” after all!). How about pet owners? Do you think they know a little about internal control systems and monitoring? Absolutely.

My business is helping organizations evaluate their systems of internal controls and also the effectiveness of the internal control monitoring. It is as important in a corporation as it is in an airplane and as it is in the home. Can you think of an example of when there have been breakdowns in either the internal controls or the monitoring of those controls in business? You probably don’t have to think too hard. It has happened all too often and unfortunately it continues today. Sometimes it is a fundamental breakdown in internal control, sometimes it is someone circumventing internal control, and other times it is a failure to monitor the control. When done purposely or with malicious intent it is usually for a perceived short term gain (meeting quarterly earnings, making a bonus) at the expense of the long term.

The examples in the corporate world have been discussed and evaluated over and over and over. It cost many their jobs and many more their life savings. But business is not alone in this. If you happen to be a college sports fan, the recent examples of Ohio State (my alma mater) and this week the University of Miami (FL) are shining examples of failure to monitor internal controls systems, ignoring warning indicators, and/or circumventing internal controls systems… all for short term gain at the expense of long term success.

Why have internal controls and effective monitoring systems? Well, besides all the obvious reasons, it is simply the right thing to do. It is important to protect our pilots, protect our children, protect our pets, protect our investments, protect our reputations, and protect our chances at long-term success. However, it is not enough to simply design and implement a good system of internal control. You have to TEST it! Imagine installing a baby gate at the top of a staircase. When finished installing the natural instinct is to jiggle it to make sure it is stable, right? Who would install a baby gate and not test it? And, for good measure you would test it regularly. You could do a great job in creating the control (installing the gate), a great job in monitoring the control (checking regularly to make sure it is still there), but if you don’t test it (jiggle the gate) you could fail as a parent with catastrophic consequences.

When enacted in 2002, the Sarbanes-Oxley Act created the requirement for publicly traded companies to design, monitor, and test systems of internal controls. However, most private companies and private institutions are not held to such standards. While “it is the right thing to do” many private companies ignore the need for internal controls and many more fail to test. If you are reading this and work for a private organization (heck, any organization) think about how often your organization “jiggles the gate” when it comes to the financial reporting processes, information technology, security, privacy, policy and procedures, and operations. If you really think about it, you might not like the answer. A small investment each year to design controls, monitor controls, and “jiggle the gate” will go a long way to protect your opportunity for long-term success.

Effective systems of internal controls are critical to all of us in every walk of life. It is important in the cockpit, at home, in the classroom, and yes, in the workplace. So, do yourself a favor and go “jiggle the gate!”

For those of you in Chicago, I hope you enjoy the Air and Water Show this weekend!



This blog post was written by Steven Randall. Steve is a Managing Partner with Vonya Global, a premier provider of internal audit consulting services. If you would like more information about Vonya Global or if you have a questions for Steve, you may him through this blog, the company website, twitter, or his LinkedIn Profile.

Monday, September 27, 2010

IFRS Best Practice - Early Conversion

A change in accounting standards, shifting from GAAP to IFRS, is virtually inevitable in the U.S. The shift globally is well underway with 100 countries having switched from country specific accounting standards to IFRS. Based on the experience of these countries, adoption impacts all aspects of operations and will affect a company’s people, processes, information systems and internal controls. IFRS conversion is a significant endeavor; Vonya Global contends that an early start will make a significant difference reducing both effort and cost.

There are parallels between IFRS Conversion and the initial Sarbanes-Oxley Compliance initiatives and applying the lessons learned from Sarbanes-Oxley will significantly reduce the cost of conversion. The most important lesson is to prepare early and start early.

The changing requirements of Sarbanes-Oxley compliance in the first years after the legislation was initially passed gave most companies a false sense of security in pushing off the start date. Each company in this situation found significant resource shortages, an inefficient compliance process, and increased fees from professional services firms. Starting early could have made the compliance process far easier and would have spread the cost over multiple financial periods.

Similarly, early IFRS conversion will streamline the process and spread the cost out over multiple financial periods. IFRS implementation has enterprise wide application – with implications beyond finance and financial reporting – reaching and affecting all parts of the business. It requires modification of processes and systems to support the new accounting and reporting requirements. Companies should begin embarking on their initiatives to achieve timely convergence with IFRS, taking a slower and methodical approach. Some of the advantages to early conversion to IFRS include:

- Simplified reporting
- Reduced operating costs
- Greater transparency
- Comparability for investors
- Improved access to capital

Eventually, GAAP will go away, and IFRS will be the lone standard. This is a historic event. It is accelerating. And it is inevitable. Those who embrace this early will be rewarded.

Tuesday, May 4, 2010

Vonya Global is Lowering the Cost of a SAS 70 Assessment

Statement on Auditing Standards Number 70 (SAS 70) issued by the AICPA requires service organizations to obtain an external opinion assessing internal controls. Issued in 1993, the SAS 70 is not a new requirement but it has increased in relative importance since the enactment of the Sarbanes-Oxley Act of 2002 (SOX, Sarbox), Gramm-Leach-Bliley Act (GLBA), and other new regulatory requirements. Any service organization holding third party data must provide assurance that the data is protected. The certification process can be quite costly for all service organizations, and disproportionally so for smaller companies.

Vonya Global has a history of working with companies on SAS 70 readiness. The work completed by Vonya Global helps companies streamline their internal processes and controls making it easier for the certifying agent to complete the assessment. The easier it is to certify, the lower the cost of certification. As the SAS 70 is an annual requirement, the cost savings are realized each year.

For a limited time, Vonya Global is offering its SAS 70 readiness services at a discounted price. For more information please contact a representative of the firm.

Tuesday, March 16, 2010

Responding to Fraud Risk: the CAE’s Role


Background: The Association of Certified Fraud Examiners (ACFE) conducts a bi-annual study on fraud investigations, the results of which get summarized in the ACFE Report to the Nation. The most recent report was issued in 2008 and revealed the following:
- U.S. organizations lose 7% of their annual revenues to fraud
- There is approximately $994 billion in fraud losses each year
- Fraud schemes typically last for at least 2 years before they are caught
- Corruption was the #1 scheme at 27% of all reported fraud cases
- False Billing was the #2 scheme at 24% of all reported fraud cases
- Frauds are most likely to be uncovered by a “tip” rather than any other method, including audit
- Roughly 38% of Frauds happened at small companies (>100 employees)
- Roughly 42% of Frauds happened at large companies (1,000+ employees)
- Roughly 39% of Frauds happened at Private Companies
- Roughly 28% of Frauds happened at Public Companies

What these statistics prove is while fraud may not happen at every company; no company is immune to fraud risk. As an inherent risk to business, fraud should be included in Enterprise Risk Management (ERM). Methods for managing and controlling the risk of fraud should include strategies for fraud prevention, fraud detection, and fraud deterrence.

The Chief Audit Executive (CAE) must be involved in the organizational anti-Fraud strategy. As with other business risks the CAE should be assessing Fraud Risk and evaluating the effectiveness of the anti-Fraud strategies. Here is a sample list of strategies:

Fraud Prevention
- Anti-Fraud Tone at the Top
- Strong Corporate Governance and Internal Control Environment
- Policies and Procedures to reflect mindset and actions
- Hire ethical employees (Background checks, signed forms, etc.)
- Code of Conduct – signed by every employee
- Conflict of Interest Statement (employees and business partners)

Fraud Detection
- Establish a Hotline
- Fraud Risk Assessment
- Fraud Penetration Study based on Schemes and Concealment Strategies
- Incorporate Fraud in every phase of an audit (SAS 99)
- Create/utilize a Red Flags Database
- Implement effective SOX Fraud Controls
- Data mine instead of sample testing
- Create a Toolkit including a resource roster of experts (Fraud expert, Investigator, Data mining, etc.)
- Continuously Monitor Transactions for possible Fraud

Fraud Deterrence
- Create an Internal Audit department
- Publicize Ethics Hotline
- Publicize Internal Fraud Cases and Punishment
- Publicize Continuous Monitoring Program


Vonya Global and the ACFE are not affiliated. Information in the opening paragraph is sourced from the ACFE 2008 Report to the Nation, which can be downloaded at the ACFE website.


Wednesday, November 4, 2009

House Financial Services Committee passes Garrett-Adler amendment

The anticipated roll-call vote on the Garret-Adler amendment happened today... passing by a 37-32 vote. The amendment would exempt Small Caps from SOX 404 compliance. There is a long way to go before this bill becomes law, but it is said that the White House supports the bill.

Is this amendment a good thing? You can start a discussion here or follow the one going on now on LinkedIn.

Wednesday, October 7, 2009

Small Caps Get Another SOX Reprieve

The SEC announced on Friday, October 2, 2009 that the SOX deadline for Small Caps is pushed to June 2010. The effort by the regulatory body to make the compliance process easier for the Small public companies makes one wonder if the compliance requirement will ever stick. If so, Vonya Global has a proprietary methodology geared to help Small Caps and IPO's (newly listed public companies). SOX OnPOINT(TM) is a top-down risk based approach which streamlines the compliance effort and is consistent with the PCAOB Audit Standard Number 5.

http://www.vonyaglobal.com/sarbanes-oxley-sox-sarbox.html

The full release from the SEC can be found at: http://www.sec.gov/news/press/2009/2009-213.htm