Showing posts with label audit. Show all posts
Showing posts with label audit. Show all posts

Tuesday, July 12, 2011

Board Director and Audit Committee Member Independence

Audit Committee Member independence as it relates to SOX section 301 definitions and SEC Rule10A-3 (specifically the definitions of “affiliate” and “affiliated person”) proves to be an area clouded by many shades of gray. In short, a clear and explicit definition of an “affiliated person” or “affiliate” is not defined. Rather, what is provided is a safe harbor definition suggesting that an individual is not an “affiliated person” if that person:
  • is not an executive officer and,
  • does not own more than 10% of the company stock.
Although this specific definition applies to ownership of securities, determining if a Director is an “affiliated person” appears to require more than that initial look.

What the rules are as of now.
Under SEC Rule 10A-3, all issuers must be in compliance with SOX Section 301 in order to be listed on any securities exchange. Specifically, they require each member of the Audit Committee of the issuer must be independent. The requirements establish two criteria and allow for each exchange to make more strict rules of their own:
  • Audit committee members are barred from accepting any consulting, advisory or compensatory fee from the issuer or any subsidiary thereof, other than in the member’s capacity as a member of the board and any board committee.
  • An Audit Committee Member of an issuer that is not an investment company must not be an affiliated person (see definition of “affiliate” below) of the issuer or any subsidiary apart from the member’s capacity as a member of the board or any board committee.
To answer the question about an “affiliated person”, the definition of an affiliated person by the SEC is “a person that directly, or indirectly through one or more intermediaries, controls or is controlled by, or is under common control with, [the issuer]”. The SEC defines control as “the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a person, whether through ownership of voting securities, by contract or otherwise”. Finally, as part of the definitions by the SEC, they have provided a baseline determination for what may or may not be an affiliate by providing a safe harbor under which a person who is not an executive officer and is not a greater than 10% stockholder is not deemed to control the issuer, therefore not an “affiliated person”.

Based on many discussions and information, other than the safe harbor definition, clear or explicit requirements for who is defined as an “affiliate” are not provided. Rather, the determination of whether a person falls within the category of an “affiliate” requires a factual determination based on a consideration of all relevant facts and circumstances on a case by case basis by the Board. These facts and circumstances would look deeper into the relationship to determine if control or influence exists or whether interference with judgment may occur.

Given the impossibility of defining all the relationships with a company that may arise for Directors and Director candidates, we believe it is advisable that Boards retain discretion to decide independence on a case by case basis rather than use rigid standards.

However, if a company is looking to define or add more explicit language for the definition of an affiliated person, you can look beyond the SEC rules and Sarbanes Oxley to rules established by the national exchanges and other professional associations (e.g. NYSE, NASDAQ and NACD) where more strict independence requirements. These requirements although not explicitly defining “affiliate” look deeper into the relationships of the Board Directors and Audit Committee Members, including:
  • NYSE – “No material relationship.” Under the NYSE listings, no director qualifies as independent unless the board of directors affirmatively determines that the director has “no material relationship” with the listed company, either directly or as a partner, shareholder or officer of an organization that has a relationship with the company.
  • NASDAQ – “No interference with independent judgment.” The rules provide that an independent director is a person other than an officer or employee of the company or its subsidiaries or any other individual having a relationship that, in the opinion of the company’s board of directors, would interfere with the exercise of independent judgment in carrying out their responsibilities of a director.
  • NACD – “The strictest definition of the term is a director whose only connection to the company is the receipt of director fees.”
If an organization is looking to define independence in the strictest sense, then the NACD definition would fit best; however, based on our experience and knowledge, most Boards follow listing standards of the national exchange for which they belong. In addition to the exchange definitions, they also allow their Boards the discretion to make judgment on member independence on a case by case basis.


This post was contributed by Sargon Youmara, a Partner with Vonya Global. If you would like to contact or connect with Sargon directly you can find his profile on LinkedIn: http://www.linkedin.com/in/syoumara.

Friday, January 21, 2011

A Project for 2011... maybe for Internal Auditors: Reviewing Corporate Policies and Procedures


Are Policies and Procedures important? We certainly think so, unfortunately many companies have old, outdated Policy and Procedure manuals while some have none at all. As companies and internal audit departments are planning projects for 2011, consideration should be given to reviewing and updating the Corporate Policies and Procedures.

Policies and Procedures are a company’s way of documenting and communicating management’s vision into instructions for employees on how to handle issues as they arise and how employees should be executing their job responsibilities in a consistent manner.

Written Policies communicate:
  • Company Rules in simple language
  • Delegation of Authority
  • Enforcement and consequences if not followed
  • Impartial administration of company-wide Policy
  • Evidence for Governance, if legally approved and followed

Procedures communicate:
  • Clear guideline on how to implement a policy
  • Establish boundaries for employees

While Policies are general in nature, Procedures provide the details as to what to do, often with examples and forms. Sometimes procedures include emergency steps.

By creating a Policy and Procedure Manual, the company provides a source for all employees to turn for guidance on standard matters and have management focus on exception handling and not need to waste time on day-to-day operations.

Successful Policy and Procedure Manuals require reviews and updates as laws and company environments change. Their dynamic nature requires work but overall it eliminates the redundant need for repeated instructions through time consuming meetings, memos or other correspondence.

Policies and Procedures should be assigned to a position within the company, for example the Finance Manual should be “owned” by the highest Finance position within the company, such as the CFO, and the Employee Handbook by the highest HR position such as the HR Director, etc. Policies should cover the key activities which need to be customized for each organization.

The objective is to create easy to understand policies and procedures that provide clear guidelines for everyone to follow.

Need a hand? We would be glad to help, just give us a call.

Monday, November 8, 2010

Data Analytics: Providing Greater Internal Audit Depth During A Turbulent Economy

Data Analysis through Computer Assisted Audit Techniques (CAATs) is an efficient way to test transactions, providing 100% assurance on the effectiveness of Internal Controls. Using basic tools such as Microsoft Excel and Access, advanced tools such as ACL or IDEA, or the tools embedded in ERP applications has been a best practice for years but has often been viewed as a luxury, not a necessity. This year, during this economy, using CAATs has become absolutely critical.

Obviously budget pressures have gone through the roof, resulting in massive global layoffs. Reductions in work force, especially to the accounting department, create enormous pressure on the employees who remain. Requiring employees to take on more responsibility often increases the likelihood of errors and misstatements. Added pressures like salary freezes combined with less oversight can tempt an otherwise honest employee to cut corners or commit fraud. The risk of financial misstatement doesn’t get any higher.

A critical way to respond to these challenges is to increase (or initiate) the use of data analytics. This approach evaluates and monitors data from every transaction processed by a company to identify anomalies. Applying data analytics to review transactions in accounts payable, advertising, freight, health benefits, construction, and other areas can yield hundreds of thousands or more in savings and recoveries. When this process is done by management instead of internal audit, errors are identified sooner and with more precision.

CAATs have been around for more than 20 years and those experienced in using CAATs have had experience ranging from good to fabulous. Unfortunately CAATs have typically been used only by Internal Audit Departments and only on selected audit projects. The inconsistent usages of CAATs make it difficult to maintain the knowledge and experience to make CAATs a regular and sustainable part of the audit process.

With the status of the economy, CAATs have become an essential part of effective Corporate Governance. The first step is gaining the basic knowledge to make CAATs part of the oversight process. The second step is sharing the knowledge throughout the Internal Audit department and management ranks. The third step is imbedding the process into the fabric of the organization to make it sustainable and continuous. Getting more oversight with less effort is possible today by simply leveraging CAATs, a technology most companies already employ.

To learn more about how to make CAATs a routine part of the audit process, please contact Vonya Global for a free consultation. Leveraging readily available software tools in combination with proprietary methodologies, our team of data analysis experts focus data analytics at common problem areas to help our clients recover overpayments and develop a sustainable approach to continuous auditing.

ACL is a registered trademark of ACL Corporation and IDEA is a registered trademark of Caseware IDEA.



This article was contributed by Joe Oringel and Kim Jones of Visual Risk IQ, a thought leader in Continuous Auditing and Monitoring. For more information on Visual Risk IQ, please visit their web site at www.visualriskiq.com.

Monday, November 1, 2010

Data Analytics: Identifying and Responding to Business Risks Efficiently

Every time a company processes a transaction there is risk. Be it accidental errors such as duplicate entry, incorrect posting, and transposing numbers or intentional misconduct, all might be difficult to spot. As technology has advanced, so has the speed and volume of transaction processing. More is done in less time, which potentially increases the likelihood of error.

What can be done to prevent or mitigate these risks? Internal Controls. When designed properly, Internal Controls can detect a risk once it happens, or better yet, prevent a risk from happening in the first place.


Under the COSO Internal Control-Integrated Framework, internal control is broadly defined as a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories: a) Effectiveness and efficiency of operations; b) Reliability of financial reporting; and c) Compliance with laws and regulations.*

An example of an internal control is the three way match between a Purchase Order, a receipt of the goods and the related invoice. The control is that the match ensures that the invoice has the authorized price from the Purchase Order and that the quantity agrees to what has been received.

Designing an effective system of Internal Controls is just the beginning. Once designed, it is important to test the Internal Controls to make sure they are operating effectively. The traditional method for testing would investigate a sample size of roughly 25 invoices. If there are exceptions, the sample size will be increased. If there are no exceptions in the first 25, the Internal Controls were deemed effective. Without automation, this is the typical way to test the transactions and make assumptions on the entire population by extrapolation since there are too many transactions to manually test each one.

But what if there were errors, just not represented within the sample? Using CAATTs is the answer.

Computer Assisted Audit Tools and Techniques (CAATTs), is the practice of using software such as Excel or Access, or specialized Audit software such as ACL or IDEA, or ERP specific tools built into SAP or Oracle to automate or simplify the audit process. CAATTs are an efficient way to test all transactions, providing 100% assurance on the effectiveness of Internal Controls.*

What are the benefits?
  • Large amount of data can be examined efficiently
  • Timely identification of business risks and exceptions
  • Business days are not interrupted with information requests to pull paper samples
  • Once established, running the tests is simple and very cost-effective
What are the drawbacks?
  • Setup time requires IT resource knowledge and availability
  • Knowledge of the software to create the tests accurately
  • Different system applications at different locations requires different tests to be created
To learn more about using CAATTS to identify and respond to business risks more efficiently visit www.vonyaglobal.com or contact Vonya Global for a free consultation.

* Excerpts taken from www.wikipedia.com

Wednesday, October 20, 2010

Internal Auditors – Playing a Strategic Role

"We believe Internal Auditors can play a more strategic role; whether they do in their specific organization is up to the Audit Committee, Executive Management, and the Internal Audit Department. We have released a report that will provide a starting point for a conversation between the three groups." - Vonya Global

Vonya Global's 2010 Executive Study on the Strategic Role of Internal AuditVonya Global announced today that the Final Report on the Strategic Role of Internal Audit has been released. In compiling information for the study, Vonya Global surveyed a cross-section of Executives and Internal Auditors from both public and private organizations in a variety of industries to evaluate their opinions regarding the strategic role of Internal Audit. The study set out to determine whether it is Internal Audit’s role to evaluate strategic risks and if Internal Audit is equipped to do so effectively. The primary goal was to provide a benchmark for Internal Auditors and Executives on the strategic role of Internal Audit.

The 2010 study is a follow up to a similar study conducted in 2008 and was designed to compare opinions in 4 areas:
1. Vision, Goals, and Objectives of Internal Audit
2. Mission and Value Relative to Strategic Risks
3. Process, Skills, Time, and Budget
4. Compliance Requirements

In 2008 it was revealed that a gap exists between Executive Management and Internal Auditors on the function of Internal Audit. The 2010 study set out to explore whether this gap still exists or if it has been closed. In addition, the new study provides a more detailed comparison between Executive Management and Internal Auditors.

While the 2010 Report on the Strategic Role of Internal Audit reveals that many gaps still exist between Executives and Internal Auditors, there are encouraging findings as well. One assumption going into the study was that Internal Audit plays a critical role in a company’s ability to meet its strategic objectives and there appears to be general agreement between Executives and Internal Auditors in many categories. The report provides details and quotes from the participants, such as:

"We make understanding the strategic direction and goals a priority in our risk assessment process so that we can link our audit plan to the strategies and goals of the company.”

"Internal Audit is at the table for senior management discussions, for input on operational challenges and control risks, for the implementation of new systems and replacement of outdated processes, and for risk management.”

“The only risks that management should fear are the ones that they do not know about - it is Audit's job to provide that information.”

The full report can be downloaded by following the link on the Vonya Global home page.

Wednesday, November 4, 2009

House Financial Services Committee passes Garrett-Adler amendment

The anticipated roll-call vote on the Garret-Adler amendment happened today... passing by a 37-32 vote. The amendment would exempt Small Caps from SOX 404 compliance. There is a long way to go before this bill becomes law, but it is said that the White House supports the bill.

Is this amendment a good thing? You can start a discussion here or follow the one going on now on LinkedIn.