Sarbanes-Oxley 1
Sarbanes-Oxley Act of 2002
In 2002, legislation passed the Sarbanes-Oxley Act, also known as Sarbox or for this
paper SOX. Named after its sponsers, Senator Paul Sarbanes and Rep. Michael Oxley the SOX
Act set new standards for all public company boards, auditors, and lawyers in the United States.
The bill was ratified in response to multiple corporate and accounting scandals including Enron,
Tyco and WorldCom in an attempt to deter corruption. The bill improves financial disclosures
by requiring senior management to endorse the accuracy of the reported financial statements, and
mandating internal controls (Northeastern Illinois University, 2003).
Effects of SOX and the PCAOB
Prior to the SOX Act, public companies were reviewed by their peers. Companies would
select other companies to review their quality control process. While simple, this proved
ineffective as companies took advantage of the corporate relationships and were able to hide
corrupt acts such as embezzlement and reporting inflated revenues.
The SOX Act created the PCAOB (Public Company Accounting Oversight Board) to
ensure that public auditing companies were subject to the securities laws in an attempt to protect
investors. As a result, all public auditing firms are required to register with the PCAOB and are
subject to inspections by the PCAOB annually, if they audit more than 100 public companies in a
year, or once every three years if they audit fewer. The inspection makes certain the registered
company is compliant with rules and standards set forth by SOX (Addison-Hewitt Associates,
2003).
There are eleven sections contained in SOX covering areas from corporate board
responsibilities to the criminal penalties for altering documents, and how the SEC must approve
rules presented before the rules can be adopted. Where compliance in concerned, the most
Sarbanes-Oxley 2
important sections are often considered to be 302, 401, 404, 409 and 802 (Addison-Hewitt
Associates, 2003).
Section 302 states the Corporate Responsibility for Financial Reporting; this requires
officers of the company to review and sign their periodic reports stating they are presented fairly.
Section 302 also makes officers responsible for internal controls. Section 401 pertains to the
Disclosures in Periodic Reports requiring disclosure of all off-balance sheet items resulting in
transparent reporting. Section 404 requires management and external auditors to report on the
adequacy of their internal controls. The structure and procedure of internal controls for financial
reporting must be assessed. This is usually the most costly to a company and the hardest to
comply with as maintaining the internal controls can get very expensive. SOX section 404 also
encourages companies to centralize and automate their reporting systems. Section 409 pertains to
Real Time Issuer Disclosures. This requires any material changes to financial statements to be
disclosed to the public immediately (or as soon as can accurately be done). The report must be
given in such a way that is easy to understand and interpret. This prevents legal jargon from
‘hiding’ the truth. Section 802 covers criminal Penalties for Altering Documents. In an effort to
deter fraudulent activities, Section 802 can lay a 20-year prison sentence along with fines and
penalties for anyone altering, destroying or falsifying documents or assets. It also imposes a 10-
year sentence on accountants who intentionally “violates the requirements of audit or review
papers for a period of 5 years” (Addison-Hewitt Associates, 2003).
Auditing Standard Number 5
In attempt to help lessen the costs associated with Section 404, the PCAOB approved
Auditing Standard number 5 (AS5). AS5 allows for more flexibility and places additional
emphasis on auditor judgment. The restrictions that were in place in regards to what
Sarbanes-Oxley 3
information/work (that others, such as management, performed) the auditor can use, have been
lifted. Here is where the additional judgment comes into play. The auditor needs to determine if
the test of others were performed properly. This is usually done by re-performing a selection of
management’s tests (Sox Made Easy, 2010).
Another area of change allows auditors to receive “direct assistance” (Sox Made Easy,
2010) from third parties or internal sources. This can significantly lower costs as internal
employees will have a better idea of the processes already in place. An area this might come in
handy, is also pointed out in AS5, the Risk-focus of the standard. This implies that IT risk
assessment should not be a separate evaluation. If an auditor can identify where a misstatement
might occur within the application systems reduction of effort and cost will be inevitable (Sox
Made Easy, 2010).
Lastly, AS5 reduces the time an audit can take by being able to use “knowledge obtained
during past audits” (Sox Made Easy, 2010). Auditors can look at the previous years tests when
the controls were found to be effective (and have not changed) and tested to the auditors
approval (Sox Made Easy, 2010).
All these changes were made in an attempt to lessen the costs of implementing Section
404. The more aspects of AS5 a company puts into effect, the more money (and time) they can
potentially save.
Sarbanes-Oxley 4
References
Investopedia. (2010). Sarbanes-Oxley Act of 2002 - SOX. Retrieved from
[Link]
Addison-Hewitt Associates . (2003). A Guide To The Sarbanes-Oxley Act. Retrieved from
[Link]
Northeastern Illinois University. (2003). THE SARBANES-OXLEY ACT OF 2002: AN
OVERVIEW, ANALYSIS, AND CAVEATS. Retrieved from
[Link]
Sox Made Easy. (2010). Internal Control Compliance Made Easy. Retrieved from [Link]