toppan merrill
  • Insights
  • About Us
  • Contact
  • Client Login

    Toppan Merrill Bridge™

    Content Control

    My Workspace

    Form N-MFP Online

    Toppan Merrill Document Delivery

    Toppan Merrill Insurance Solutions

    Section16Direct

    SEC Connect

    SOX Automation

  • EN

    English

    简体中文 (Simplified Chinese)

    繁體中文 (Traditional Chinese)

  •  
  • Capital Markets Transactions
    • Capital Markets Transactions

      Equity, Debt & IPO Offering Management Services

      M&A

       

       

       
       

      Capital Markets Transactions Resources

      Insights & Analysis

      Events

      SEC Resources

      EDGAR Resources

      XBRL Resources

       

       

      Capital Markets Transactions Products

      Bridge

      Built on the Microsoft® Office® platform, Bridge makes disclosure content management easier, faster and more accurate.

       

       

       

  • Regulatory Disclosure
    • Regulatory Disclosure for Corporations

      Annual Meeting & Proxy Solutions

      Annual Meeting & Proxy Consulting

      Periodic & Interim Reporting

      iXBRL and EDGAR for US-GAAP & IFRS Filers

      iXBRL for ESEF Filings

      SEDAR Filings

      Section 16 Filings

      Automated SOX Compliance

       

       

      Regulatory Disclosure for Investment Management

      Periodic & Interim Reporting and Prospectuses

      Component Content Management & Output

      Website Document Hosting

      Shareholder Preference Center

      Compliance Center for Variable Products

       

       

       

      Regulatory Disclosure Resources

      Insights & Analysis

      Events

      SEC Resources

      EDGAR Resources

      XBRL Resources

       

       

      Regulatory Disclosure Products

      Bridge

      Built on the Microsoft® Office® platform, Bridge makes disclosure content management easier, faster and more accurate.

       

       

      SOX Automation

      Intuitive SaaS technology that centralizes all business locations, processes, risks and controls delivering efficiency, transparency, and predictability of cost.

       

       

  • Sales & Marketing Communications
    • Sales and Marketing Communications

      Offerings

      Omni-channel communications

      Document Creation & Management

      Sales Enablement

      ADA Services

      Fulfillment & Distribution

      Printing Services

       

       

       

      Industries

      Financial Services

      Health Insurance

       

       

       

      Sales and Marketing Communications Resources

      Insights & Analysis

      Events

       

       

      Sales and Marketing Communications Products

      Connect

      Drive client engagement and streamline personalized, compliant communications from printing to leading-edge digital solutions.

       

       

       

  • Products
    TOPPAN MERRILL
    ConnectTM

    Connect helps drive client engagement and streamline personalized, compliant communications from printing to leading-edge digital solutions.

    TOPPAN MERRILL
    BridgeTM

    A seamless SaaS solution built on the Microsoft® Office® platform, Bridge is an intuitive technology that makes disclosure content management easier, faster and more accurate.

  • Resources
    •  
       

      Insights & Analysis

      Events

      SEC Resources

      XBRL Resources

      SEC EDGAR Resources, Definitions, and Processes

      Regulatory Compliance Glossary

       

       

       

toppan merrill
  • Capital Markets Transactions
    • Overview
    • Equity, Debt & IPO Offering Management Services
    • M&A
  • Regulatory Disclosure
    • For Corporations

      • Overview
      • Annual Meeting and Proxy Statement Solutions
      • Periodic & Interim Reporting
        • EDGAR & iXBRL for SEC Filings (US-GAAP & IFRS)
        • iXBRL for ESEF Filings
        • SEDAR Filings
        • Section 16 Filings
        • Automated SOX Compliance
    • For Investment

      • Overview
      • Prospectus for Investment Management
      • Periodic & Interim Reporting for Investment Management
        • Component Content Management & Output
        • Website Document Hosting
        • Shareholder Preference Center
        • Portfolio Specific Document Management for Variable Products
  • Sales & Marketing Communications
    • Overview
    • Offerings

      • Omni-Channel Communications
      • Document Creation & Management
      • Sales Enablement
      • ADA Services
      • Fulfillment & Distribution
      • Printing Services
    • Industries

      • Financial Services
      • Health Insurance
      • Dynamic Publishing for Health Insurance
  • Products
    • Connect
    • Bridge
    • SOX Automation
  • Resources
    • Insights & Analysis
    • Events
    • SEC Resources
    • SEC EDGAR Resources
    • XBRL Resources
    • glossary
  • Insights & Analysis
  • About Us
  • Contact
  • Client Login
    • Toppan Merrill BridgeTM
    • Content Control
    • My Workspace
    • Form N-MFP Online
    • Toppan Merrill Document Delivery
    • Toppan Merrill Insurance Solutions
    • Section16Direct
 

The A-B-Cs of SOX Compliance

By Elizabeth Epler Jones - Partner, AXIA Partners on 01 December, 2022
1 min read | Industry Insights Insights Home

The A-B-Cs of SOX Compliance

A Brief History of SOX

At its core, the Sarbanes-Oxley Act of 2002 (SOX or the Act) is a law that was enacted in 2002 to protect the investing public.

 

Leading into that year, there were a rash of corporate scandals that involved the likes of Enron, WorldCom, (etc.). Massive amounts of investor money was lost in the capital markets. Everything was questioned, and accounting giant, Andersen fell as a result.

 

Meanwhile, in Washington D.C., Senator Paul Sarbanes and Representative Michael Oxley worked on separate bills to clean up corporate accountability and transparency and increase auditor accountability and responsibility. These two bills were ultimately combined and presented to Congress as the Sarbanes-Oxley Act of 2002.

 

Both houses voted on and approved the Act – without change – on July 24, 2002: 423 to 3 in the House, and 99 to 0 in the Senate. Then-President George W. Bush signed it into law on July 30, 2002.


Basic SOX


The Act itself is comprised of 11 titles, and while all titles are important, there are four that typically are of heightened interest to public registrants: Titles I, III, IV, and IX.

  • Title I: The PCAOB is born

    The first title of the Act established the Public Company Accounting Oversight Board (PCAOB) to oversee the public accounting firms and ultimately protect investors. Essentially, the PCAOB audits the auditors.

  • Title III: Corporate accountability at the highest level

    Title III elevated corporate responsibility with the §302 requirement that Chief Executive and Chief Financial Officers must now personally attest that “financial information included in the report, fairly present in all material respects the financial condition and results of operations of the issuer”. In other words, the “I didn’t know about it” response is no longer a viable excuse for those at the top. We see the exact language in exhibits 31.1 and 31.2 of a registrant’s periodic reports.

  • Title IV: Refined and modernized reporting

    Within Title IV, §404 created the requirement for management’s assessment of Internal Controls Over Financial Reporting (ICFR). Fundamentally, ICFR processes and activities (internal controls) govern the transparency, completeness, and accuracy of the financial reporting data included in public filings.

  • Title IX: The PCAOB carries a big stick

    Intricately tied to §302 mentioned above, Title IX's §906 further drives home the concept of corporate accountability at the highest level with new white-collar crime sentencing guidelines for those corporate officers who either failed to or willingly/falsely certified their financial reports. For the first time, both fines and imprisonment for INDIVIDUALS were penalties available for use by the Securities and Exchange Commission (SEC).


Compliance with SOX


While the phrase “SOX Compliance” typically, brings to mind adherence to §404 mandates, §302 and §906 disclosures are equally important to feed §404 results and vice versa.


Keeping in mind that §302 and §906 are directed more to individual principal officers, and §404 results encompass the entirety of the organization, we will focus the rest of our SOX primer on §404.


§404 is split into two parts - §404(a) and §404(b), and all public registrants, no matter the filing status, are required to comply with §404(a), which is management’s assessment of ICFR.

 

Let me repeat that: All public companies must comply with SOX §404(a).


Management must make a definitive statement at year-end (and update each quarter-end) noting whether their ICFR is both designed and operating effectively. Companies must also retain enough evidence to support that conclusion.


Further, depending on the filing status of the public registrant, public market float, etc., §404(b) could trigger, and the company’s external audit firm would also be required to issue a separate audit opinion on the company’s ICFR.


If Management’s Assessment under §404(a) is the test of compliance, the measuring stick is the COSO Framework.


The A-B-Cs of SOX Compliance - COSO 2013 Framework

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) was organized in 1985, “to help organizations improve performance by developing thought leadership that enhances internal control, risk management, governance and fraud deterrence.” The initial COSO – Integrated Framework was published in 1992. It was revised and reissued in May 2013, and it is now commonly referred to as COSO 2013. Included in the five core elements shown in the COSO cube, COSO 2013 incorporates 17 principles and 79 points of focus.


As part of a company’s §404(a) assessment, in addition to determining that an entity’s controls are designed and operating effectively, management must now make a statement that the 17 COSO principles are also “present and functioning” as part of their §404(a) assessment.

 

Deficiency Evaluation and Reporting


At the end of the day, management must report any deficiencies. PCAOB’s Auditing Standard 2201 (AS 2201) defines the different levels of deficiencies (control deficiencies, significant deficiencies, and material weaknesses), and the reporting/communication requirements vary depending on the level of deficiency identified.

  • Control deficiencies must be reported to management.

  • Significant deficiencies must go to both management and the Audit Committee.

  • Material weaknesses must be publicly reported in an entity’s Form 10-Ks and Form 10-Qs.

The PCAOB advises that if there are one or more material weaknesses within a company’s ICFR, the ICFR cannot be considered effective. AS 2201 further tells us that “the severity of a deficiency does not depend on whether a misstatement actually has occurred but rather on whether there is a reasonable possibility that the company's controls will fail to prevent or detect a misstatement.”


This is an important distinction: whereas the traditional substantive financial audit focuses on actual errors found, audits and assessments of ICFR focus both on actual errors as well as the total potential for error. If an error or misstatement is found during the substantive financial audit, the external auditors will immediately turn to ICFR to determine which control, or set of controls, failed. This could then lead to a reportable event.

 

Engage in a SOX Compliance Program Now


The A-B-Cs of SOX Compliance - COSO 2013 Framework_1

SOX very specifically focuses on the Reporting slice of the COSO cube.
One of the main purposes of SOX is to provide transparency to the investing public. Are all transactions completely AND accurately disclosed in the company’s financial statements and footnotes? Is the financial information readily available such that a reasonable investor could understand and make a well-informed decision?


Now that you know a little more about SOX, I suspect these questions are flooding in:

  • What are the benefits of SOX compliance?

  • How do I get started building a SOX compliance program?

  • When should I get started with SOX compliance?

  • How should I budget for SOX compliance?

  • Is there any way to automate the SOX compliance process?

I hope you enjoyed this SOX primer. Click here if you have questions and would like to speak with a Toppan Merrill SOX compliance expert.

 

Click here to learn more about building an automated SOX compliance program for your company or watch this short video.

 


 

Elizabeth Epler Jones, CPA – Partner, AXIA Partners

Elizabeth Epler Jones

Elizabeth has been involved with SOX compliance since the Act became law in 2002. She currently leads the Compliance Practice for AXIA Partners. Elizabeth and her team consult with companies looking to accelerate the efficiency and effectiveness of their SOX compliance management program through Toppan Merrill’s SOX Automation platform


 

Share

Share on twitter Share on linkedin Share on facebook
Previous ArticleHow Customers Shop for Health Plans Through Digital Marketing
Next Article5 CMS-Required Documents Health Plan Marketers Must Know

Subscribe

Subscribe

Subscribe

Subscribe

Elizabeth Epler Jones - Partner, AXIA Partners



toppanmerrill.com


Show more posts from author

Capital Markets & Compliance;
 

Expert Support

The best-in-class partner for complex, secure communications. Contact Toppan Merrill today.

Contact Us

Subscribe to the Toppan Merrill Blog

Gain actionable insight on industry trends, best practices & successful strategies to help your business.

Subscribe

Blog Categories

  • Industry Trends
  • Shareholder Communications
  • 40 Act SEC Regulations
  • Digital Communications
  • Toppan Merrill Connect
  • Content Management
  • Print/Fulfillment

Blog Categories

  • Industry Trends
  • Shareholder Communications
  • 40 Act SEC Regulations
  • Digital Communications
  • Toppan Merrill Connect
  • Content Management
  • Print/Fulfillment

Blog Categories

  • Member Communications
  • Section 508 Compliance
  • Digital Communications
  • Toppan Merrill Connect

Blog Categories

  • Industry trends
  • Shareholder communications
  • 40 act SEC regulations
  • Digital communications
  • Toppan Merrill connect
  • Content management
  • Print/fulfillment

Most Popular Articles

Most Popular Articles

Most Popular Articles

Most Popular Articles

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar
Toppan Merrill Corporate Video

Regulatory Resources

  • SEC Resources
  • EDGAR Resources
  • XBRL Resources

Toppan Merrill Corporate Video

2023 Compliance Calendar

Toppan Merrill 2023 Compliance Calendar_DIGITAL_Page_01
Download

Interactive Digital Compliance Calendar

2022 Interactive Digital Compliance Calendar

View Calendar

Latest Blogs

Latest Blogs

Latest Blogs

Latest Blogs

ToppanMerrill logo

Expand Possible.

twitter linkedin

Solutions

  • Capital Markets Transactions
  • Regulatory Disclosures for Corporations
  • Regulatory Disclosures for Investment Management Companies
  • Financial Services Marketing & Communications
  • Health Insurance Marketing & Communications
  • Election Services

Technologies

  • Toppan Merrill Connect™
  • Toppan Merrill Bridge™

Blog

  • Insights

About Toppan Merrill

  • About Toppan Merrill
  • Operating Principles
  • Careers

Get In Touch

  • Contact Us

TERMS OF USE | PRIVACY NOTICE | TOPPAN MERRILL SERVICES AGREEMENT | TOPPAN MERRILL SUPPLIERS | GLOSSARY

© Toppan Merrill 2022

ToppanMerrill logo
Expand Possible.
` twitter linkedin
Solutions
  • Capital Markets Transactions
  • Regulatory Disclosures for Corporations
  • Regulatory Disclosures for Investment Management Companies
  • Financial Services Marketing & Communications
  • Health Insurance Marketing & Communications
  • Election Services
Technologies
  • Toppan Merrill ConnecTM
  • Toppan Merrill BridgeTM
BLOG
  • Insights
About Toppan Merrill
  • About Toppan Merrill
  • Operating Principles
  • Careers
Get In Touch
  • Contact Us

TERMS OF USE | PRIVACY NOTICE | TOPPAN MERRILL SERVICES AGREEMENT | TOPPAN MERRILL SUPPLIERS | GLOSSARY

© Toppan Merrill 2019