|Long title||An Act To protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws, and for other purposes.|
|Nicknames||Sarbanes–Oxley, Sarbox, SOX|
|Enacted by||the 107th United States Congress|
|Public law||Pub.L. 107–204|
|Statutes at Large||116 Stat. 745|
|Acts amended||Securities Exchange Act of 1934, Securities Act of 1933, Employee Retirement Income Security Act of 1974, Investment Advisers Act of 1940, Title 18 of the United States Code, Title 28 of the United States Code|
|Titles amended||15, 18, 28, 29|
|Part of a series on|
The Sarbanes–Oxley Act of 2002 (Pub.L. 107–204 , 116 Stat. 745 , enacted July 30, 2002), also known as the "Public Company Accounting Reform and Investor Protection Act" (in the Senate) and "Corporate and Auditing Accountability, Responsibility, and Transparency Act" (in the House) and more commonly called Sarbanes–Oxley or SOX, is a United States federal law that set new or expanded requirements for all U.S. public company boards, management and public accounting firms. A number of provisions of the Act also apply to privately held companies, such as the willful destruction of evidence to impede a federal investigation.
The bill, which contains eleven sections, was enacted as a reaction to a number of major corporate and accounting scandals, including Enron and WorldCom. The sections of the bill cover responsibilities of a public corporation's board of directors, add criminal penalties for certain misconduct, and require the Securities and Exchange Commission to create regulations to define how public corporations are to comply with the law.[ citation needed ]
In 2002, Sarbanes-Oxley was named after bill sponsors U.S. Senator Paul Sarbanes (D-MD) and U.S. Representative Michael G. Oxley (R-OH). As a result of SOX, top management must individually certify the accuracy of financial information. In addition, penalties for fraudulent financial activity are much more severe. Also, SOX increased the oversight role of boards of directors and the independence of the outside auditors who review the accuracy of corporate financial statements.
The bill was enacted as a reaction to a number of major corporate and accounting scandals, including those affecting Enron, Tyco International, Adelphia, Peregrine Systems, and WorldCom. These scandals cost investors billions of dollars when the share prices of affected companies collapsed, and shook public confidence in the US securities markets.[ citation needed ]
The act contains eleven titles, or sections, ranging from additional corporate board responsibilities to criminal penalties, and requires the Securities and Exchange Commission (SEC) to implement rulings on requirements to comply with the law. Harvey Pitt, the 26th chairman of the SEC, led the SEC in the adoption of dozens of rules to implement the Sarbanes-Oxley Act. It created a new, quasi-public agency, the Public Company Accounting Oversight Board, or PCAOB, charged with overseeing, regulating, inspecting, and disciplining accounting firms in their roles as auditors of public companies. The act also covers issues such as auditor independence, corporate governance, internal control assessment, and enhanced financial disclosure. The nonprofit arm of Financial Executives International (FEI), Financial Executives Research Foundation (FERF), completed extensive research studies to help support the foundations of the act.[ citation needed ]
The act was approved in the House by a vote of 423 in favor, 3 opposed, and 8 abstaining and in the Senate with a vote of 99 in favor and 1 abstaining. President George W. Bush signed it into law, stating it included "the most far-reaching reforms of American business practices since the time of Franklin D. Roosevelt. The era of low standards and false profits is over; no boardroom in America is above or beyond the law."
[ citation needed ]
Debates continued as of 2007 over the perceived benefits and costs of SOX. Opponents of the bill have claimed it has reduced America's international competitive edge against foreign financial service providers because it has introduced an overly complex regulatory environment into US financial markets. A study commissioned by NYC Mayor Michael Bloomberg and US Sen. Chuck Schumer, (D-NY), cited this as one reason America's financial sector is losing market share to other financial centers worldwide.Proponents of the measure said that SOX has been a "godsend" for improving the confidence of fund managers and other investors with regard to the veracity of corporate financial statements.
The 10th anniversary of SOX coincided with the passing of the Jumpstart Our Business Startups (JOBS) Act, designed to give emerging companies an economic boost, and cutting back on a number of regulatory requirements.[ citation needed ]
A variety of complex factors created the conditions and culture in which a series of large corporate frauds occurred between 2000–2002. The spectacular, highly publicized frauds at Enron, WorldCom, and Tyco exposed significant problems with conflicts of interest and incentive compensation practices. The analysis of their complex and contentious root causes contributed to the passage of SOX in 2002.In a 2004 interview, Senator Paul Sarbanes stated:
The Senate Banking Committee undertook a series of hearings on the problems in the markets that had led to a loss of hundreds and hundreds of billions, indeed trillions of dollars in market value. The hearings set out to lay the foundation for legislation. We scheduled 10 hearings over a six-week period, during which we brought in some of the best people in the country to testify ... The hearings produced remarkable consensus on the nature of the problems: inadequate oversight of accountants, lack of auditor independence, weak corporate governance procedures, stock analysts' conflict of interests, inadequate disclosure provisions, and grossly inadequate funding of the Securities and Exchange Commission.
The House passed Rep. Oxley's bill (H.R. 3763) on April 24, 2002, by a vote of 334 to 90. The House then referred the "Corporate and Auditing Accountability, Responsibility, and Transparency Act" or "CAARTA" to the Senate Banking Committee with the support of President George W. Bush and the SEC. At the time, however, the Chairman of that Committee, Senator Paul Sarbanes (D-MD), was preparing his own proposal, Senate Bill 2673.
Senator Sarbanes's bill passed the Senate Banking Committee on June 18, 2002, by a vote of 17 to 4. On June 25, 2002, WorldCom revealed it had overstated its earnings by more than $3.8 billion during the past five quarters (15 months), primarily by improperly accounting for its operating costs. Senator Sarbanes introduced Senate Bill 2673 to the full Senate that same day, and it passed 97–0 less than three weeks later on July 15, 2002.
The House and the Senate formed a Conference Committee to reconcile the differences between Sen. Sarbanes's bill (S. 2673) and Rep. Oxley's bill (H.R. 3763). The conference committee relied heavily on S. 2673 and "most changes made by the conference committee strengthened the prescriptions of S. 2673 or added new prescriptions."
The Committee approved the final conference bill on July 24, 2002, and gave it the name "the Sarbanes–Oxley Act of 2002". The next day, both houses of Congress voted on it without change, producing an overwhelming margin of victory: 423 to 3 in the House;and 99 to 0 in the Senate.
On July 30, 2002, President George W. Bush signed it into law, stating it included "the most far-reaching reforms of American business practices since the time of Franklin D. Roosevelt".
A significant body of academic research and opinion exists regarding the costs and benefits of SOX, with significant differences in conclusions.This is due in part to the difficulty of isolating the impact of SOX from other variables affecting the stock market and corporate earnings. Section 404 of the act, which requires management and the external auditor to report on the adequacy of a company's internal control on financial reporting, is often singled out for analysis.
According to a 2019 study in the Journal of Law and Economics, "We find a large decline in the average voting premium of US dual-class firms targeted by major SOX provisions that enhance boards’ independence, improve internal controls, and increase litigation risks. The targeted firms also improve the efficiency of investment, cash management, and chief executive officers’ compensation relative to firms not targeted by SOX. Overall, the evidence suggests that SOX is effective in curbing the private benefits of control."
Some have asserted that Sarbanes–Oxley legislation has helped displace business from New York to London, where the Financial Conduct Authority regulates the financial sector with a lighter touch. In the UK, the non-statutory Combined Code of Corporate Governance plays a somewhat similar role to SOX. See Howell E. Jackson & Mark J. Roe, "Public Enforcement of Securities Laws: Preliminary Evidence" (Working Paper January 16, 2007). London based Alternative Investment Market claims that its spectacular growth in listings almost entirely coincided with the Sarbanes Oxley legislation. In December 2006, Michael Bloomberg, New York's mayor, and Chuck Schumer, U.S. senator from New York, expressed their concern.
The Sarbanes–Oxley Act's effect on non-U.S. companies cross-listed in the U.S. is different on firms from developed and well regulated countries than on firms from less developed countries according to Kate Litvak.Companies from badly regulated countries see benefits that are higher than the costs from better credit ratings by complying to regulations in a highly regulated country (USA), but companies from developed countries only incur the costs, since transparency is adequate in their home countries as well. On the other hand, the benefit of better credit rating also comes with listing on other stock exchanges such as the London Stock Exchange.
Piotroski and Srinivasan (2008) examine a comprehensive sample of international companies that list onto U.S. and U.K. stock exchanges before and after the enactment of the Act in 2002. Using a sample of all listing events onto U.S. and U.K. exchanges from 1995–2006, they find that the listing preferences of large foreign firms choosing between U.S. exchanges and the LSE's Main Market did not change following SOX. In contrast, they find that the likelihood of a U.S. listing among small foreign firms choosing between the Nasdaq and LSE's Alternative Investment Market decreased following SOX. The negative effect among small firms is consistent with these companies being less able to absorb the incremental costs associated with SOX compliance. The screening of smaller firms with weaker governance attributes from U.S. exchanges is consistent with the heightened governance costs imposed by the Act increasing the bonding-related benefits of a U.S. listing.
Under Sarbanes–Oxley, two separate sections came into effect—one civil and the other criminal. 15 U.S.C. § 7241 (Section 302) (civil provision); 18 U.S.C. § 1350 (Section 906) (criminal provision).
Section 302 of the Act mandates a set of internal procedures designed to ensure accurate financial disclosure. The signing officers must certify that they are "responsible for establishing and maintaining internal controls" and "have designed such internal controls to ensure that material information relating to the company and its consolidated subsidiaries is made known to such officers by others within those entities, particularly during the period in which the periodic reports are being prepared".. The officers must "have evaluated the effectiveness of the company's internal controls as of a date within 90 days prior to the report" and "have presented in the report their conclusions about the effectiveness of their internal controls based on their evaluation as of that date". Id..
The SEC interpreted the intention of Sec. 302 in Final Rule 33–8124. In it, the SEC defines the new term "disclosure controls and procedures," which are distinct from "internal controls over financial reporting".Under both Section 302 and Section 404, Congress directed the SEC to promulgate regulations enforcing these provisions.
External auditors are required to issue an opinion on whether effective internal control over financial reporting was maintained in all material respects by management. This is in addition to the financial statement opinion regarding the accuracy of the financial statements. The requirement to issue a third opinion regarding management's assessment was removed in 2007.
A Lord & Benoit report, titled Bridging the Sarbanes-Oxley Disclosure Control Gap was filed with the SEC Subcommittee on internal controls which reported that those companies with ineffective internal controls, the expected rate of full and accurate disclosure under Section 302 will range between 8 and 15 percent. A full 9 out of every 10 companies with ineffective Section 404 controls self reported effective Section 302 controls in the same period end that an adverse Section 404 was reported, 90% in accurate without a Section 404 audit. http://www.section404.org/UserFiles/File/Lord_Benoit_Report_1_Bridging_the_Disclosure_Control_Gap.pdf
a. Rules To Prohibit. It shall be unlawful, in contravention of such rules or regulations as the Commission shall prescribe as necessary and appropriate in the public interest or for the protection of investors, for any officer or director of an issuer, or any other person acting under the direction thereof, to take any action to fraudulently influence, coerce, manipulate, or mislead any independent public or certified accountant engaged in the performance of an audit of the financial statements of that issuer for the purpose of rendering such financial statements materially misleading.
b. Enforcement. In any civil proceeding, the Commission shall have exclusive authority to enforce this section and any rule or regulation issued under this section.
c. No Preemption of Other Law. The provisions of subsection (a) shall be in addition to, and shall not supersede or preempt, any other provision of law or any rule or regulation issued thereunder.
d. Deadline for Rulemaking. The Commission shall—1. propose the rules or regulations required by this section, not later than 90 days after the date of enactment of this Act; and 2. issue final rules or regulations required by this section, not later than 270 days after that date of enactment.
The bankruptcy of Enron drew attention to off-balance sheet instruments that were used fraudulently. During 2010, the court examiner's review of the Lehman Brothers bankruptcy also brought these instruments back into focus, as Lehman had used an instrument called "Repo 105" to allegedly move assets and debt off-balance sheet to make its financial position look more favorable to investors. Sarbanes-Oxley required the disclosure of all material off-balance sheet items. It also required an SEC study and report to better understand the extent of usage of such instruments and whether accounting principles adequately addressed these instruments; the SEC report was issued June 15, 2005.Interim guidance was issued in May 2006, which was later finalized. Critics argued the SEC did not take adequate steps to regulate and monitor this activity.
The most contentious aspect of SOX is Section 404, which requires management and the external auditor to report on the adequacy of the company's internal control on financial reporting (ICFR). This is the most costly aspect of the legislation for companies to implement, as documenting and testing important financial manual and automated controls requires enormous effort.
Under Section 404 of the Act, management is required to produce an "internal control report" as part of each annual Exchange Act report. See 15 U.S.C. § 7262. The report must affirm "the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting". . The report must also "contain an assessment, as of the end of the most recent fiscal year of the Company, of the effectiveness of the internal control structure and procedures of the issuer for financial reporting". To do this, managers are generally adopting an internal control framework such as that described in COSO.
To help alleviate the high costs of compliance, guidance and practice have continued to evolve. The Public Company Accounting Oversight Board (PCAOB) approved Auditing Standard No. 5 for public accounting firms on July 25, 2007.This standard superseded Auditing Standard No. 2, the initial guidance provided in 2004. The SEC also released its interpretive guidance on June 27, 2007. It is generally consistent with the PCAOB's guidance, but intended to provide guidance for management. Both management and the external auditor are responsible for performing their assessment in the context of a top-down risk assessment, which requires management to base both the scope of its assessment and evidence gathered on risk. This gives management wider discretion in its assessment approach. These two standards together require management to:
SOX 404 compliance costs represent a tax on inefficiency, encouraging companies to centralize and automate their financial reporting systems. This is apparent in the comparative costs of companies with decentralized operations and systems, versus those with centralized, more efficient systems. For example, the 2007 Financial Executives International (FEI) survey indicated average compliance costs for decentralized companies were $1.9 million, while centralized company costs were $1.3 million.Costs of evaluating manual control procedures are dramatically reduced through automation.
The cost of complying with SOX 404 impacts smaller companies disproportionately, as there is a significant fixed cost involved in completing the assessment. For example, during 2004 U.S. companies with revenues exceeding $5 billion spent 0.06% of revenue on SOX compliance, while companies with less than $100 million in revenue spent 2.55%.
This disparity is a focal point of 2007 SEC and U.S. Senate action.The PCAOB intends to issue further guidance to help companies scale their assessment based on company size and complexity during 2007. The SEC issued their guidance to management in June, 2007.
After the SEC and PCAOB issued their guidance, the SEC required smaller public companies (non-accelerated filers) with fiscal years ending after December 15, 2007 to document a Management Assessment of their Internal Controls over Financial Reporting (ICFR). Outside auditors of non-accelerated filers however opine or test internal controls under PCAOB (Public Company Accounting Oversight Board) Auditing Standards for years ending after December 15, 2008. Another extension was granted by the SEC for the outside auditor assessment until years ending after December 15, 2009. The reason for the timing disparity was to address the House Committee on Small Business concern that the cost of complying with Section 404 of the Sarbanes–Oxley Act of 2002 was still unknown and could therefore be disproportionately high for smaller publicly held companies.On October 2, 2009, the SEC granted another extension for the outside auditor assessment until fiscal years ending after June 15, 2010. The SEC stated in their release that the extension was granted so that the SEC's Office of Economic Analysis could complete a study of whether additional guidance provided to company managers and auditors in 2007 was effective in reducing the costs of compliance. They also stated that there will be no further extensions in the future.
On September 15, 2010 the SEC issued final rule 33–9142 the permanently exempts registrants that are neither accelerated nor large accelerated filers as defined by Rule 12b-2 of the Securities and Exchange Act of 1934 from Section 404(b) internal control audit requirement.
Section 802(a) of the SOX,states:
Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both.
Section 806 of the Sarbanes–Oxley Act, also known as the whistleblower-protection provision, prohibits any "officer, employee, contractor, subcontractor, or agent" of a publicly traded company from retaliating against "an employee" for disclosing reasonably perceived potential or actual violations of the six enumerated categories of protected conduct in Section 806 (securities fraud, shareholder fraud, bank fraud, a violation of any SEC rule or regulation, mail fraud, or wire fraud).Section 806 prohibits a broad range of retaliatory adverse employment actions, including discharging, demoting, suspending, threatening, harassing, or in any other manner discriminating against a whistleblower. Recently a federal court of appeals held that merely "outing" or disclosing the identity of a whistleblower is actionable retaliation.
Remedies under Section 806 include:
(A) reinstatement with the same seniority status that the employee would have had, but for the discrimination;
(B) the amount of back pay, with interest; and
(C) compensation for any special damages sustained as a result of the discrimination, including litigation costs, expert witness fees, and reasonable attorney fees.
A claim under the anti-retaliation provision of the Sarbanes–Oxley Act must be filed initially at the Occupational Safety and Health Administration at the U.S. Department of Labor. OSHA will perform an investigation and if they conclude that the employer violated SOX, OSHA can order preliminary reinstatement.OSHA is required to dismiss the complaint if the complaint fails to make a prima facie showing that the protected activity was a "contributing factor" in the adverse employment action.
In the sixteen year period from the passage of the Sarbanes Oxley Act in 2002 through December 31, 2018, a total of 1039 cases have been filed with the Department of Labor of which 62 were still pending before the Department of Labor as of January 1, 2019.
|Case||Court||Date of Decision||Holding|
|Gilmore v. Parametric Technology Company||ALJ||Feb 6, 2003||First case decided under SOX. Employee protection provisions of Section 806 were not to be applied retroactively to conduct which occurred before the Sarbanes-Oxley Act of 2002 became law.|
|Digital Realty Trust v. Somers||US Supreme Court||Feb 21, 2018||Whistleblowers who report internally without first reporting to the SEC must rely on §806 protection and are not covered by Dodd Frank anti-retaliation provisions.|
|Sylvester v. Parexel Int'l LLC||ARB||May 25, 2011||Whistleblower need not wait until illegal conduct occurs to make a complaint, so long as the employee reasonably believes that the violation is likely to happen.|
|Palmer v. Illinois Central Railroad Company||ARB||Sep 30, 2016||Respondents can use all relevant admissible evidence to rebut Complainant's evidence that "it is more likely that not that the employee's protected activity was a contributing factor in the employer's adverse action.|
|Turin v. Amtrust Financial Services||ARB||Mar 29, 2013||Parties may privately agree to extend the deadline to file a whistleblower complaint.|
|Zinn v. American Commercial Airlines||ARB||Dec 17, 2013||Company did not violate Section 806 where the Company demonstrated by clear and convincing evidence that its decision to terminate was based on the employee's insubordination.|
|Lawson v. FMR||US Supreme Court||Mar 14, 2014||The anti-retaliation protection provided to whistleblowers by SOX applies to employees of private companies that contract with public companies.|
|Zulfer v. Playboy Enterprises||CDCA||Mar 5, 2014||$6 million jury verdict to a former Playboy accounting executive who alleged that her employment was terminated in retaliation for disclosing to her former employer's Chief Financial Officer and Chief Compliance Officer concerns about accruing discretionary executive bonuses without Board approval.|
|Wadler v. Bio-Rad Laboratories||NDCA||Feb 6, 2017||$11 million jury verdict to a former Bio-Rad Laboratories Inc. General Counsel who was terminated after reporting potential violations of the Foreign Corrupt Practices Act.|
|Perez v. Progenics Pharmaceuticals, Inc.||SDNY||Sep 9, 2016||$5 million jury verdict to a former senior manager at Progenics Pharmaceuticals, Inc. who was terminated in retaliation for his disclosure to executives that the company was committing fraud against shareholders by making inaccurate representations about the results of a clinical trial. The award included $2.7 million in Front Pay from age at decision date (58) through retirement.|
§ 1350. Section 906 states: Failure of corporate officers to certify financial reports
(a) Certification of Periodic Financial Reports.— Each periodic report containing financial statements filed by an issuer with the Securities Exchange Commission pursuant to section 13(a) or 15(d) of the Securities Exchange Act of 1934 (15 U.S.C. 78m (a) or 78o (d)) shall be accompanied by a written statement by the chief executive officer and chief financial officer (or equivalent thereof) of the issuer.
(b) Content.— The statement required under subsection (a) shall certify that the periodic report containing the financial statements fully complies with the requirements of section 13(a) or 15(d) of the Securities Exchange Act of  1934 (15 U.S.C. 78m or 78o (d)) and that information contained in the periodic report fairly presents, in all material respects, the financial condition and results of operations of the issuer.
(c) Criminal Penalties.— Whoever— (1) certifies any statement as set forth in subsections (a) and (b) of this section knowing that the periodic report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than $1,000,000 or imprisoned not more than 10 years, or both; or
(2) willfully certifies any statement as set forth in subsections (a) and (b) of this section knowing that the periodic report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than $5,000,000, or imprisoned not more than 20 years, or both.
Section 1107 of the SOXstates:
Whoever knowingly, with the intent to retaliate, takes any action harmful to any person, including interference with the lawful employment or livelihood of any person, for providing to a law enforcement officer any truthful information relating to the commission or possible commission of any federal offense, shall be fined under this title, imprisoned not more than 10 years, or both.
One of the highlights of the law was a provision that allowed the SEC to force a company's CEO or CFO to disgorge any executive compensation (such as bonus pay or proceeds from stock sales) earned within a year of misconduct that results in an earnings restatement. However, according to Gretchen Morgenson of The New York Times , such clawbacks have actually been rare, due in part to the requirement that the misconduct must be either deliberate or reckless. The SEC did not attempt to claw back any executive compensation until 2007, and as of December 2013 had only brought 31 cases, 13 of which were begun after 2010. However, according to Dan Whalen of the accounting research firm Audit Analytics, the threat of clawbacks, and the time-consuming litigation associated with them, has forced companies to tighten their financial reporting standards.
Congressman Ron Paul and others such as former Arkansas governor Mike Huckabee have contended that SOX was an unnecessary and costly government intrusion into corporate management that places U.S. corporations at a competitive disadvantage with foreign firms, driving businesses out of the United States. In an April 14, 2005 speech before the U.S. House of Representatives, Paul stated
These regulations are damaging American capital markets by providing an incentive for small US firms and foreign firms to deregister from US stock exchanges. According to a study by a researcher at the Wharton Business School, the number of American companies deregistering from public stock exchanges nearly tripled during the year after Sarbanes–Oxley became law, while the New York Stock Exchange had only 10 new foreign listings in all of 2004. The reluctance of small businesses and foreign firms to register on American stock exchanges is easily understood when one considers the costs Sarbanes–Oxley imposes on businesses. According to a survey by Korn/Ferry International, Sarbanes–Oxley cost Fortune 500 companies an average of $5.1 million in compliance expenses in 2004, while a study by the law firm of Foley and Lardner found the Act increased costs associated with being a publicly held company by 130 percent.
A research study published by Joseph Piotroski of Stanford University and Suraj Srinivasan of Harvard Business School titled "Regulation and Bonding: Sarbanes Oxley Act and the Flow of International Listings" in the Journal of Accounting Research in 2008 found that following the act's passage, smaller international companies were more likely to list in stock exchanges in the U.K. rather than U.S. stock exchanges.
During the financial crisis of 2007–2010, critics blamed Sarbanes–Oxley for the low number of Initial Public Offerings (IPOs) on American stock exchanges during 2008. In November 2008, Newt Gingrich and co-author David W. Kralik called on Congress to repeal Sarbanes–Oxley.
A 2012 Wall St. Journal editorial stated, "One reason the U.S. economy isn't creating enough jobs is that it's not creating enough employers ... For the third year in a row the world's leading exchange for new stock offerings was located not in New York, but in Hong Kong ... Given that the U.S. is still home to the world's largest economy, there's no reason it shouldn't have the most vibrant equity markets—unless regulation is holding back the creation of new public companies. On that score it's getting harder for backers of the Sarbanes-Oxley accounting law to explain away each disappointing year since its 2002 enactment as some kind of temporary or unrelated setback."
Former Federal Reserve Chairman Alan Greenspan praised the Sarbanes–Oxley Act in 2005: "I am surprised that the Sarbanes–Oxley Act, so rapidly developed and enacted, has functioned as well as it has ... the act importantly reinforced the principle that shareholders own our corporations and that corporate managers should be working on behalf of shareholders to allocate business resources to their optimum use."
SOX has been praised by a cross-section of financial industry experts, citing improved investor confidence and more accurate, reliable financial statements. The CEO and CFO are now required to unequivocally take ownership for their financial statements under Section 302, which was not the case prior to SOX. Further, auditor conflicts of interest have been addressed, by prohibiting auditors from also having lucrative consulting agreements with the firms they audit under Section 201. SEC Chairman Christopher Cox stated in 2007: "Sarbanes–Oxley helped restore trust in U.S. markets by increasing accountability, speeding up reporting, and making audits more independent."
The Financial Executives International (FEI) 2007 study and research by the Institute of Internal Auditors (IIA) also indicate SOX has improved investor confidence in financial reporting, a primary objective of the legislation. The IIA study also indicated improvements in board, audit committee, and senior management engagement in financial reporting and improvements in financial controls.
Financial restatements increased significantly in the wake of the SOX legislation, as companies "cleaned up" their books. Glass, Lewis & Co. LLC is a San Francisco-based firm that tracks the volume of do-overs by public companies. Its March 2006 report, "Getting It Wrong the First Time," shows 1,295 restatements of financial earnings in 2005 for companies listed on U.S. securities markets, almost twice the number for 2004. "That's about one restatement for every 12 public companies—up from one for every 23 in 2004," says the report.
One fraud uncovered by the Securities and Exchange Commission (SEC) in November 2009 : VALU) against its mutual fund shareholders. The fraud was first reported to the SEC in 2004 by the then Value Line Fund (NASDAQ : VLIFX) portfolio manager and Chief Quantitative Strategist, Mr. John (Jack) R. Dempsey of Easton, Connecticut, who was required to sign a Code of Business Ethics as part of SOX. Restitution totaling $34 million was placed in a fair fund and returned to the affected Value Line mutual fund investors. The Commission ordered Value Line to pay a total of $43,705,765 in disgorgement, prejudgment interest and civil penalty, and ordered Buttner, CEO and Henigson, COO to pay civil penalties of $1,000,000 and $250,000, respectively. The Commission further imposed officer and director bars and broker-dealer, investment adviser, and investment company associational bars ("Associational Bars") against Buttner and Henigson. No criminal charges were filed.may be directly credited to Sarbanes-Oxley. The fraud, which spanned nearly 20 years and involved over $24 million, was committed by Value Line (NASDAQ
The Sarbanes–Oxley Act has been praised for nurturing an ethical culture as it forces top management to be transparent and employees to be responsible for their acts whilst protecting whistleblowers.Indeed, courts have held that top management may be in violation of its obligation to assess and disclose material weaknesses in its internal control over financial reporting when it ignores an employee's concerns that could impact the company's SEC filings.
A lawsuit ( Free Enterprise Fund v. Public Company Accounting Oversight Board ) was filed in 2006 challenging the constitutionality of the PCAOB. The complaint argues that because the PCAOB has regulatory powers over the accounting industry, its officers should be appointed by the President, rather than the SEC.Further, because the law lacks a "severability clause," if part of the law is judged unconstitutional, so is the remainder. If the plaintiff prevails, the U.S. Congress may have to devise a different method of officer appointment. Further, the other parts of the law may be open to revision. The lawsuit was dismissed from a District Court; the decision was upheld by the Court of Appeals on August 22, 2008. Judge Kavanaugh, in his dissent, argued strongly against the constitutionality of the law. On May 18, 2009, the United States Supreme Court agreed to hear this case. On December 7, 2009, it heard the oral arguments. On June 28, 2010, the United States Supreme Court unanimously turned away a broad challenge to the law, but ruled 5–4 that a section related to appointments violates the Constitution's separation of powers mandate. The act remains "fully operative as a law" pending a process correction.
In its March 4, 2014 Lawson v. FMR LLC decision the United States Supreme Court rejected a narrow reading of the SOX whistleblower protection and instead held that the anti-retaliation protection that the Sarbanes–Oxley Act of 2002 provided to whistleblowers applies also to employees of a public company's private contractors and subcontractors, including the attorneys and accountants who prepare the SEC filings of public companies.Subsequent interpretations of Lawson, however, suggest that the disclosures of a contractor's employee are protected only if those disclosures pertain to fraud perpetrated by a publicly traded company, as opposed to wrongdoing by a private contractor.
In its February 25, 2015 Yates v. United States (2015) decision the US Supreme Court sided with Yates by reversing the previous judgement, with a plurality of the justices reading the Act to cover "only objects one can use to record or preserve information, not all objects in the physical world". Justice Samuel Alito concurred in the judgment and noted that the statute's nouns and verbs only applies to filekeeping and not fish.
Close scrutiny of corporate governance and greater responsibility placed on directors to vouch for the reports submitted to the SEC and other federal agencies, have resulted in the growth of software solutions aimed at reducing the complexity, time and expense involved in creating the reports. [ citation needed ]This trend accelerated in 2008 with the passage of the Dodd–Frank Wall Street Reform and Consumer Protection Act. Software as a service (SaaS) products allow corporate directors and internal auditors to assemble and analyze financial and other relevant data—including unstructured data—and create the needed reports quickly and without the need of an outside vendor.
|Wikisource has original text related to this article:|
An audit is a systematic and independent examination of books, accounts, statutory records, documents and vouchers of an organization to ascertain how far the financial statements as well as non-financial disclosures present a true and fair view of the concern. It also attempts to ensure that the books of accounts are properly maintained by the concern as required by law. Auditing has become such a ubiquitous phenomenon in the corporate and the public sector that academics started identifying an "Audit Society". The auditor perceives and recognizes the propositions before them for examination, obtains evidence, evaluates the same and formulates an opinion on the basis of his judgement which is communicated through their auditing report.
A financial audit is conducted to provide an opinion whether "financial statements" are stated in accordance with specified criteria. Normally, the criteria are international accounting standards, although auditors may conduct audits of financial statements prepared using the cash basis or some other basis of accounting appropriate for the organisation. In providing an opinion whether financial statements are fairly stated in accordance with accounting standards, the auditor gathers evidence to determine whether the statements contain material errors or other misstatements.
An audit committee is a committee of an organisation's board of directors which is responsible for oversight of the financial reporting process, selection of the independent auditor, and receipt of audit results both internal and external.
An auditor's report is considered an essential tool when reporting financial information to users, particularly in business. Since many third-party users prefer, or even require financial information to be certified by an independent external auditor, many audiotapes rely on auditor reports to certify their information in order to attract investors, obtain loans, and improve public appearance. Some have even stated that financial information without an auditor's report is "essentially worthless" for investing purposes.
In business and accounting, information technology controls are specific activities performed by persons or systems designed to ensure that business objectives are met. They are a subset of an enterprise's internal control. IT control objectives relate to the confidentiality, integrity, and availability of data and the overall management of the IT function of the business enterprise. IT controls are often described in two categories: IT general controls (ITGC) and IT application controls. ITGC include controls over the Information Technology (IT) environment, computer operations, access to programs and data, program development and program changes. IT application controls refer to transaction processing controls, sometimes called "input-processing-output" controls. Information technology controls have been given increased prominence in corporations listed in the United States by the Sarbanes-Oxley Act. The COBIT Framework is a widely used framework promulgated by the IT Governance Institute, which defines a variety of ITGC and application control objectives and recommended evaluation approaches. IT departments in organizations are often led by a Chief Information Officer (CIO), who is responsible for ensuring effective information technology controls are utilized.
An external auditor performs an audit, in accordance with specific laws or rules, of the financial statements of a company, government entity, other legal entity, or organization, and is independent of the entity being audited. Users of these entities' financial information, such as investors, government agencies, and the general public, rely on the external auditor to present an unbiased and independent audit report.
The Public Company Accounting Oversight Board (PCAOB) is a private-sector, nonprofit corporation created by the Sarbanes–Oxley Act of 2002 to oversee the audits of public companies and other issuers in order to protect the interests of investors and further the public interest in the preparation of informative, accurate and independent audit reports. The PCAOB also oversees the audits of broker-dealers, including compliance reports filed pursuant to federal securities laws, to promote investor protection. All PCAOB rules and standards must be approved by the U.S. Securities and Exchange Commission (SEC).
Internal auditing is an independent, objective assurance and consulting activity designed to add value to and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control and governance processes. Internal auditing achieves this by providing insight and recommendations based on analyses and assessments of data and business processes. With commitment to integrity and accountability, internal auditing provides value to governing bodies and senior management as an objective source of independent advice. Professionals called internal auditors are employed by organizations to perform the internal auditing activity.
The Financial Instruments and Exchange Act, promulgated on June 14, 2006, is the main statute codifying securities law and regulating securities companies in Japan.
Internal control, as defined by accounting and auditing, is a process for assuring of an organization's objectives in operational effectiveness and efficiency, reliable financial reporting, and compliance with laws, regulations and policies. A broad concept, internal control involves everything that controls risks to an organization.
In financial auditing of public companies in the United States, SOX 404 top–down risk assessment (TDRA) is a financial risk assessment performed to comply with Section 404 of the Sarbanes-Oxley Act of 2002. The term is used by the U.S. Public Company Accounting Oversight Board (PCAOB) and the Securities and Exchange Commission (SEC). The TDRA is used to determine the scope and required evidence to support management's testing of its internal controls under SOX404. It is also used by the external auditor to issue a formal opinion on the company's internal controls. However, as a result of the passage of Auditing Standard No. 5, which the SEC has since approved, external auditors are no longer required to provide an opinion on management's assessment of its own internal controls.
In the United States, the Auditing Standards Board (ASB) is the senior technical committee designated by the American Institute of Certified Public Accountants (AICPA) to issue auditing, attestation, and quality control statements, standards and guidance to certified public accountants (CPAs) for non-public company audits. Created in October 1978, it is composed of 19 members representing various industries and sectors, including public accountants and private, educational, and governmental entities. It issues pronouncements in the form of statements, interpretations, and guidelines, which all CPAs must adhere to when performing audits and attestations.
The Center for Audit Quality (CAQ) is an autonomous, nonpartisan, nonprofit public policy advocacy organization based in Washington, DC. It is affiliated with the American Institute of CPAs.
Auditor independence refers to the independence of the internal auditor or of the external auditor from parties that may have a financial interest in the business being audited. Independence requires integrity and an objective approach to the audit process. The concept requires the auditor to carry out his or her work freely and in an objective manner.
Entity-level controls are internal controls that help to ensure that management directives pertaining to the entire entity are carried out. They are the second level of a top-down approach to understanding the risks of an organization. Generally, entity refers to the entire company.
Zabihollah Rezaee is an Iranian-born/American accountant the Thompson-Hill Chair of Excellence' and Professor of accounting at the University of Memphis.
Certified Sarbanes-Oxley Professional (CSOXP) is a credential awarded by the governance, risk & compliance group. The CSOXP credential communicates that certified professionals have the knowledge listed below:
The Model Audit Rule 205, Model Audit Rule, or MAR 205 are the commonly applied terms for the Annual Financial Reporting Model Regulation. Model Audit Rule is a financial reporting regulation applicable to insurance companies, and borrows significantly from the Sarbanes Oxley Act of 2002. The Model Audit Rule is co-developed by the American Institute of Certified Public Accountants (“AICPA”) and National Association of Insurance Commissioners (“NAIC”) and issued by NAIC with revisions in 2006 and has taken effect in 2010.
The Audit Integrity and Job Protection Act is a bill that was introduced into the United States House of Representatives during the 113th United States Congress. The bill would "amend the Sarbanes-Oxley Act of 2002 (SOX) to deny the Public Company Accounting Oversight Board any authority to require that audits conducted for a particular issuer of securities in accordance with SOX standards be conducted by specific auditors, or that such audits be conducted for an issuer by different auditors on a rotating basis," according to a summary by the Congressional Research Service. The bill passed the House 321-62 on July 8, 2013.
Statement on Standards for Attestation Engagements no. 16 is a largely American auditing standard for service organizations, superseding Statement on Auditing Standards no. 70. The "service auditor’s examination" of SAS 70 is replaced by a System and Organization Controls (SOC) report. SSAE 16 was issued in April 2010, and became effective in June 2011. Many organizations that followed SAS 70 have now shifted to SSAE 16. Some service organizations use the SSAE 16 report status to show they are more capable, and also encourage their prospective end-users to make having an SSAE 16 a standard part of new vendor selection criteria. Public companies in the United States fall under the Public Company Accounting Reform and Investor Protection Act, also known as Sarbanes–Oxley or SOX. However, there are also a number of provisions of the Act that apply to privately held companies.
Auditors have responded to the demands of the PCAOB and the SEC by turning up the pressure on their clients to improve documentation