Notes:
- Sarbanes-Oxley Act (SOX) of 2002:Â Enacted in response to Enron and WorldCom, SOX revolutionized corporate governance by focusing on internal controls and accountability.
- Section 302: Corporate Responsibility for Financial Reports:
- Requires the CEO and CFO to personally certify the accuracy of financial reports and the effectiveness of disclosure controls.
- Liability:Â CEOs/CFOs can face criminal penalties (up to 20 years prison) for certifying false reports knowingly.
- Section 404: Management Assessment of Internal Controls:
- The Core Requirement: Management must annually assess and report on the effectiveness of Internal Control over Financial Reporting (ICFR).
- Auditor Attestation:Â For large accelerated filers, the external auditor must also attest to and report on management’s assessment.
- COSO Framework: Most companies use the Committee of Sponsoring Organizations (COSO) framework to design and test controls. It covers five components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring.
- Whistleblower Protections (SOX Section 806):
- Protects employees of public companies who report fraud from retaliation.
- Establishes a mechanism for employees to file complaints with the Department of Labor.
- Audit Committee Independence:
- Must be composed entirely of independent directors.
- Must have at least one “Financial Expert” (as defined by the SEC) to oversee the financial reporting process.
- Remediation of Deficiencies:
- If a “material weakness” (a deficiency that could lead to a material misstatement) is identified, management must disclose it and outline a remediation plan. Persistent material weaknesses can lead to delisting or loss of investor trust.