The most popular and comprehensive Open Source ECM platform
Compliance: Eight Years of Sarbanes-Oxley
It’s been eight years now since the Senate merged their “Public Company Accounting Reform and Investor Protection Act” with the House’s “Corporate and Auditing Accountability and Responsibility Act”. The combined version is what we now know as the Sarbanes-Oxley Act . July 30th marked the 8 year anniversary of SOX.
It’s interesting that the final version of SOX was agreed to with near unanimous support. SOX passed the House 423 to 3, and the Senate 99 to 0. But if SOX were up for a vote today, it is pretty clear that there would be quite a bit of debate, and the results would probably be a lot more mixed. In the last eight years we’ve found that striking the right balance between the benefits of improved internal controls and the costs of audit and implementation is difficult.
The Sarbanes-Oxley Act requires publicly-traded companies to assess the quality of their internal controls and then have auditors review the adequacy of their assessment. This part of the code, known as Section 404, causes much pain for companies to implement. Some of the pain has been eased by the fact that recently the Public Company Accounting Oversight Board clarified the rather murky requirements of the original language of SOX.
Gradually some companies have bit the bullet and have full implementations of SOX. But many companies have evaded the need to adopt SOX. Smaller companies — those with less than $75 million — have been exempt from the law. The SEC repeatedly has postponed the need for smaller companies to comply with the SOX requirements.
But Mary Shapiro, the new SEC chairperson, has said, as reported in by the NY Times, there will be no more delays for smaller companies. “Since there will be no further commission extensions, it is important for all public companies and their auditors to act with deliberate speed to move toward full Section 404 compliance.”
Going forward, as fiscal years wind down for smaller companies they will need to include Section 404 compliance in their annual reports. For companies with fiscal years in sync with the calendar year, that means it will need to be part of annual reports made in early 2011.













