Thursday, May 24, 2018

IT Governance Enterprise Risk Issues

      Every enterprise faces a wide range of risks, including enterprise business operations, the business and related market factors, general economic conditions, and an endless list of other enterprise risk factors. In order to have effective IT governance practices, an enterprise needs to have an effective program for assessing and managing overall risks, significant risks within an enterprise, and specific risks facing IT operations. Exhibit 2.5 outlines some IT governance risk issues and summarizes some effective strategies for managing those risks.



     The theme of the risk requirements and strategies outlined in Exhibit 2.5 is that an enterprise needs to have an understanding of the various types of IT risks that it faces as well as the costs and alternative strategies for taking corrective actions if such risk events occur. An important term and concept here is what is called risk appetite. That is, how great of a risk is a senior manager and the overall enterprise willing to accept? The individual investor who places his money in AA-rated corporate bonds has a much lower appetite for risk than does the investor in speculative technology stocks. An understanding of enterprise risk issues is a requirement for implementing effectiveITgovernance processes.

IT Governance Enterprise Organization Issues

     IT governance issues and concerns extend well beyond just the IT department and its resources, and must include many enterprisewide issues and concerns. We should always consider the IT resource in an enterprise not as just one unique element but a specialized unit or component of the overall enterprise. Some of these governance issues are outlined in Exhibit 2.6. The message in this exhibit is that although IT management may develop governance processes and procedures affecting their own IT systems and operations, they should always think of them in the much larger context of the overall enterprise.



  Exhibit 2.6 also mentions jurisdiction and boundary issues as an IT governance component. Although not too many years ago an enterprise’s IT resources existed behind highly secured locked doors and often as a separate facility island from other enterprise operations, we must always think of IT operations as a key component in the continuous process of other enterprise operations. However, we should always remember that boundaries exist, and IT, finance, and other operations should recognize the boundaries between various areas of responsibility when establishing governance processes.


IT Governance Legislative and Regulatory Issues
      Legislative and regulatory rules and issues are important components of effective IT governance processes. Enterprise management should monitor these rules and take steps to assure their compliance.

IT Governance Security Issues
     Because enterprise IT operations are connected both internally and to outsiders through the Internet and many other data connections, security matters are major IT governance issues. Many IT consumers and users recognize that their systems and data are vulnerable to a wide range of outside intruders whose interests range from just disrupting someone’s IT operations to sabotaging systems and data for profit or gain. Effective IT security controls are an important element of IT governance. Today’s business executive should have a high-level general understanding of the more significant security issues that are important for effective IT governance. Although there are many and varied issues here, a business manager should understand IT security threats and risks but should seek specialized technical help within the enterprise to more effectively implement the types of IT governance security processes outlined in Exhibit 2.7.


IT Governance Internal, External Threats
 To more specific IT governance issues, an enterprise faces a wide range of internal and external security threats. The external threats can range from such matters as terrorist attacks to foreign government espionage to cloud computing risks and more. IT governance internal threat processes can often be better monitored and controlled. While we never know when some totally unexpected intruder will attack our IT systems, we can reduce the risks of internal threats by establishing strong internal policies and procedures.



WHAT IS IT GOVERNANCE?

         The discipline of IT governance is a subset and very important element of overall enterprise governance issues.
IT governance means different things to different people:
• IT governance is often used to describe the processes for deciding how money for IT resources should be spent. This IT governance process includes the prioritization and justification of IT investments. It includes controls on spending such as budgets and authorization levels.
• IT governance is often used to describe many different aspects of IT changes. At the low level, it is sometimes used to describe project management and control of a portfolio of IT-related projects.
• IT governance is used to make sure that IT change processes comply with regulatory requirements, both governmental laws and rules as well as professional standards.
• IT governance is the process of aligning IT change and expenditure to business requirements and expenditures. Sometimes it also covers the deployment of IT staff.
• IT governance is also used to describe the management and control of IT services.
• IT governance makes sure that day-to-day problem solving and support of all IT resources are aligned to business needs.

       IT governance deals primarily with the connection between an enterprise’s business focus and the IT-related management and operation of the enterprise. The concept highlights the importance of IT-related matters and emphasizes that strategic IT decisions should be owned by the most senior levels of corporate management, including the board of directors, rather than just IT management such as the chief information officer (CIO). Rather than arguing which is the correct definition of IT governance, enterprise senior managers should look at the similarities.

     Governance involves a mix of the following:
• Control of all aspects of IT work.
• Coordination between different pieces of IT-related work—such as new systemsdevelopment and IT infrastructure support.
• Measurement of the outcomes of IT systems and processes.
• Compliance with internal IT policies or regulations.
• Justification of the spending for all IT resources.
• IT and enterprise-wide accountability and transparency.
• Strong connections with the needs of IT customers, the broader enterprise, and other stakeholders.

      All of the IT governance objectives fit into an overall model, as shown in Exhibit 2.4. IT governance is bounded by performance management, strategic alignment, risk management, and value delivery concepts. In order to implement these, there is a need for strong policy and compliance practices, performance and risk management processes, and an overall understanding of appropriate value delivery. Exhibit 2.4 shows these concepts at a high level, but they will be referenced further in later chapters.





Saturday, May 19, 2018

SOxOfficer Disclosure Sign-off


SOxOfficer Disclosure Sign-off


Exhibit 2.3 is an example of an officer disclosure sign-off type of statement that officers will be requested to sign. While this exhibit is not an official PCAOB form, it is based on SEC documents, showing the types of things an officer will be asked to certify.

TITLE IV: ENHANCED FINANCIAL DISCLOSURES
This title of SOxis designed to correct some financial reporting disclosure problems, to tighten up conflict-of-interest rules for corporate officers and directors, to mandate a management assessment of internal controls, to require senior officer codes of conduct, and other matters.
Expanded Conflict-of-Interest Provisions, Disclosures, and Codes of Ethics
As an important element of enterprise governance, SOxrequires that corporations must adopt a code of ethics for their senior financial officers and disclose compliance with this code as part of their annual financial reporting. SOxdoes not address the content of these enterprise-wide codes of ethics, but focuses on the need for the same standards for senior officers as for all employees in the enterprise. SOx specifically requires that an enterprise’s code of ethics or conduct for its senior officers must reasonably promote:
• Honest and ethical conduct, including the ethical handling of actual or apparent conflicts of interest between personal and professional relationships;
• Full, fair, accurate, timely, and understandable disclosure in the enterprise financial reports; and
• Compliance with applicable governmental rules and regulations.
               
                Codes of Ethics
If an enterprise has a code of conduct, management should assure that this code applies to all members of the enterprise, is consistent with SOx, and that these ethical rules are communicated to all members of the enterprise, including the officers. The key governance issue here is making sure that the existing code of conduct covers the above SOxrules, that it has been communicated to senior management, and that these officers have agreed to comply with it.

Other SOxRules and Requirements
SOxalso includes a large and complex set of rules covering such areas as audit committee governance requirements, security analyst conflicts of interest, and other financial disclosure rules.

Thursday, May 17, 2018

SOx TITLE III: CORPORATE RESPONSIBILITY


SOx TITLE III: CORPORATE RESPONSIBILITY


SOx’s Title III regulations contain major regulatory rules for audit committees and prescribe audit committee performance standards and a large set of corporate governance rules. The firm’s external audit firm is to report directly to the audit committee, which is responsible for their compensation, oversight of the audit work, and the resolution of any disagreements between external audit and management.

Financial Expert
SEC regulations define a “financial expert” as a person who, through education and experience, has:
• An understanding of generally accepted accounting principles and financial statements;
• Experience applying such generally accepted accounting principles in connection with the accounting for estimates, accruals, and reserves that are generally comparable to the estimates, accruals, and reserves, if any, used in the registrant’s financial statements;
• Experience preparing or auditing financial statements that present accounting issues that are generally comparable to those raised by the registrant’s financial statements;
• Experience with internal controls and procedures for financial reporting; and
• An understanding of audit committee functions.

                SOxTitle III
In some respects, an audit committee member is being asked to put herself or himself in the potential line of fire if the enterprise is ever questioned regarding some financial or internal control decision. The SOxlegislation also calls for audit committees to establish procedures to receive, retain, and treat complaints and handle whistleblower information regarding questionable accounting and auditing matters.

The signing officer, as part of what is referred to as Section 302, must certify that:
• The signing officer has reviewed the report.
• Based on that signing officer’s knowledge, the financial statements do not contain any materially untrue or misleading information.
• Again based on the signing officer’s knowledge, the financial statements fairly represent the financial conditions and results of operations of the enterprise.
• The signing officer is responsible for:
- Establishing and maintaining internal controls.
- Having designed these internal controls to ensure that material information about the enterprise and its subsidiaries was made known to the signing officerduring the period when the reports were prepared.
- Having evaluated the enterprise’s internal controls within 90 days prior to the release of the report.
- Having presented in these financial reports the signing officer’s evaluation of the effectiveness of these internal controls as of that report date.

The signing officer should disclose to the external auditors, audit committee, and other directors that any significant deficiencies in the design and operation of internal controls that could affect the reliability of the reported financial data have been disclosed to the enterprise’s auditors. The signing officer should also indicate whether there were internal controls or other changes that could significantly impact those controls, including corrective actions, subsequent to the date of the internal control evaluation.

Monday, May 14, 2018

AS5 Rules and Internal Audit


AS5 Rules and Internal Audit



Shortly after SOx became law in the United States, the PCAOB released its AS2 guidance that called for external auditors to take very conservative and detailed approaches on their audits of financial statements. AS2 mandated a “look-at-everything” detailed audit approach, and enterprise external audit bills became much more expensive in those first SOx years. AS5 is a set of standards for the external auditors who review and certify published financial statements, and these rules are also important for internal auditors as well. AS5 introduces risk-based rules with an emphasis on the effectiveness of internal controls that are more oriented to enterprise facts and circumstances. In addition, AS5 calls for external auditors to consider including reviews of appropriate internal audit reports in their financial statement audit reviews. It allows external auditors to place more emphasis on management’s ability to establish and document key internal controls.

AS5
AS5 has three broad objectives:
1. Focus internal control audits on the most important matters.
2. Eliminate audit procedures that are unnecessary to achieve their intended benefits.
3. Make the financial audit clearly scalable to fit the size and the complexity of any enterprise.

AS5 calls for an assessment of the competence and objectivity of the internal auditors at an enterprise. Competence means the attainment and maintenance of a level of understanding and knowledge that enables persons to perform the tasks assigned to them, and objectivity means the ability to perform those tasks impartially and with intellectual honesty. AS5 calls for an external auditor evaluation of whether factors are present that either inhibit or promote a person’s ability to perform with the necessary degree of objectivity the work the auditor plans to use.

OTHER SOx RULES—TITLE II: AUDITOR INDEPENDENCE
 Internal and external auditors have historically been separate and independent resources. External auditors were responsible for assessing the fairness of an enterprise’s internal control systems and the resultant published financial reports, while internal auditors served management in a wide variety of other areas.

Limitations on External Auditor Services

SOx prohibits public accounting firms from providing other services, including:
• Financial information systems design and implementations.
• Book keeping and financial statement services.
• Management and human resources functions.
• Other prohibited services.

The overall SOx theme here is that external auditors are authorized to audit the financial statements of their client enterprises, and that is about all. SOx allows that beyond the prohibited activities listed, external auditors can engage in other non-audit services only if those services are approved in advance by the audit committee.

Audit Committee Preapproval of Services
 Section 202 of SOx’s Title I specifies that the audit committee must approve all audit and non-audit services in advance. This would relieve the strain of lengthy audit committee business matters, but put even more responsibility on a few audit committee members over and above the many new legal responsibilities mandated by SOx.

External Audit Partner Rotation
External auditors have always communicated regularly with their audit committees in the course of the audit engagement, as well as for any other matters of concern. External auditors are required to report on a timely basis all accounting policies and practices used, alternative treatments of financial information discussed with management, the possible alternative treatments, and the approach preferred by the external auditor. External auditors must report to their audit committee any alternative accounting treatments, the approach preferred by the external auditors, and management’s approach.

Conflicts of Interest and Mandatory Rotations of External Audit Firms
It had once been common for members of the external audit firm team to get job appointments for senior financial positions at their audit clients. This really says that an audit partner cannot leave an audit engagement to begin working as a senior executive of the same firm that was just audited. While staff members and managers can still move from the public accounting firm team to various positions in the auditee enterprise, this prohibition is limited to public accounting partners.

Sunday, May 13, 2018

SOx Section 404 Rules


SOx Section 404 Rules
SOx Section 404 rules state that an enterprise is responsible for reviewing, documenting, and testing its own internal accounting controls, with those review results then passed on to the enterprise’s external auditors, who are charged with reviewing and attesting to that work as part of their review of the reported financial statements.

Section 404 Internal Controls Assessments
Management always has had the overall responsibility for designing and implementing internal controls over their enterprise’s operations. SOx Section 404 requires an annual internal controls report, with the following information elements, as part of an SEC-mandated Form 10K annual report:• A formal management statement acknowledging the enterprise’s responsibility for establishing and maintaining an adequate internal control structure and procedures for financial reporting; and• An assessment, as of the end of the most recent fiscal year, of the effectiveness of the enterprise’s internal control structure and procedures for financial reporting.

The external audit firm that issued the supporting audit report is required to review and report on management’s assessment of its internal financial controls. Management is required to report on the quality of their internal controls, and their public accounting firm must audit or attest that management developed an internal controls report in addition to their normal financial statement audit. Management has always been responsible for preparing their periodic financial reports, and the external auditors then audited those financial numbers and certified that they were fairly stated. With SOx Section 404, management is responsible for documenting and testing their internal financial controls as well as to report on their effectiveness. External auditors then review the supporting materials leading up to that internal financial controls report to assert that the report is an accurate description of the internal control environment.

Under SOx Section 404, management is required to report on the adequacy of their internal controls, with their external auditors attesting to the management-developed internal control reports. Under Section 404 procedures, the enterprise builds and documents its own internal control processes, then an independent party such as internal audit reviews and tests those internal controls, and finally the external auditors review and attest to the adequacy of this process.

Identifying Key Processes to Launch a Section 404 Compliance Review
Whether based on IT systems or primarily manual procedures performed on a regular basis, every enterprise has basic processes that are normally considered in terms of their basic accounting cycles, including:
Revenue cycle. Processes dealing with sales or other enterprise revenue.
Direct expenditures cycle. Expenditures for material or direct production costs.
Indirect expenditures cycle. Operating costs that cannot be directly tied to production activities but are necessary for overall business operations.
Payroll cycle. Covers all personnel compensation.
• Inventory cycle. Although inventory will eventually be applied as direct production expenditures, time-based processes are needed for holding inventory until applied to production.
Fixed assets cycle. Property and equipment require separate accounting processes, such as periodic depreciation accounting over time.
General controls IT cycle. This set of processes covers IT controls that are general or applicable to all IT operations.

Internal Audit’s Role
Even though SOx does not give specific responsibilities to internal audits, they are an important resource for the completion of Section 404 internal control assessments. Under SOx, a separate and independent function within the enterprise—often internal or IT audit—reviews and documents the internal controls covering key processes, identifies key control points, and then tests those identified controls. External audit would then review that work and attest to their adequacy. For many enterprises, IT audit can be a key resource for performing these internal controls reviews for technology-based processes.

Section 404 Internal Control Review


Exhibit 2.2 outlines some planning considerations for a Section 404 internal control review to be performed by an enterprise’s internal auditors, who can play a major role in helping senior management establish Section 404 compliance. Our objective is not to provide internal audit guidance but to give a senior manager an idea of these IT internal audit processes.

Fundamental Governance Concepts and Sarbanes-Oxley Rules

      Enterprise IT Governance
 The term enterprise IT governance is not new, but is a concept that has a meant different things to different people.  As a response to ongoing cycles of business frauds and failures particularly in the latter decades of the past century, there has been an increased emphasis on embellishing enterprise codes of conduct and establishing what are called corporate ethics departments. Strong enterprise governance emphasized general operations and with little emphasis on IT systems and operations.

Sarbanes-Oxley Act
 The Sarbanes-Oxley Act is a U.S law enacted in 2002 to improve public company financial reporting, audit, and enterprise governance processes.  It first had a major impact on businesses in the United States and now is recognized worldwide. Although SOx’s auditing and internal control rules have directly changed many external auditor and IT financial practices, Sox has also had a major impact on IT governance. A general understanding of SOx, with an emphasis on its Section 404 internal accounting control rules, is a key knowledge requirement for all senior managers.

Sarbanes-Oxley Act Key IT Governance Elements
The official name of SOx is the Public Accounting Reform and Investor Protection Act. It become law in 2002, with most of the final detailed rules and regulations. Its title being a bit long and mostly refer as SOx, SOX, or Sarbox. SOx introducted a series of totally changed processes for external auditing and gave new governance responsibilities to senior executives and board members. SOx established the Public Company Accounting Oversight Board (PCAOB), a rule setting authority under the Securities and Exchange Commission (SEC) that issues financial auditing standards and monitors external auditor governance.

SOx Key Provisions Summary

Exhibit 2.1 summarizes the major titles or section of SOx Titles I and IV. Our intent is not to describe all sections of SOx or to reproduce the full text of this legislation – it can be found on the Web – but to highlight portions of the law that are most significant to interested business professionals.

SOx Title I: Public Company Accounting Oversight Board
SOx introduced significant new rules for external auditors. Prior to SOx, the American Institute of Certified Public Accountants (AICPA) had guidance-setting responsibility for all external auditors and their public accounting firms through its overall responsibility for the Certified Public Accountant (CPA) certification. While state boards of accountancy actually licensed CPAs, the AICPA previously had overall responsibility for the profession. External audit standards also were set by the AICPA’s Auditing Standards Board (ASB). Although basic standards—called generally accepted auditing standards (GAAS)—have been in place over the years, newer auditing standards were released as numbered Statements on Auditing Standards (SASs). Much of GAAS was just good auditing practices, such as that accounting transactions must be backed by appropriate documentation, while the SASs covered specific areas requiring better definition.

SOx Title I External Audit Process rules:
• PCAOB administration and public accounting firm registration.
• Auditing, quality control, and independence standards.
• Audit workpapers retention.
• Scope of internal control testing.

     Title IV: Enhanced Financial Disclosures and Section 404
 SOx Title IV is designed to correct some financial reporting disclosure problems, to tighten up conflict-of-interest rules for corporate officers and directors, to mandate a management assessment of internal controls, to require senior officer codes of conduct, and other matters. The most significant nugget for most senior managers is Section 404 on Management’s Assessment of Internal Controls. SOx requires that all annual 10K reports must contain an internal controls report stating management’s responsibility for establishing and maintaining an adequate system of internal controls as well as management’s assessment, as of the fiscal year ending date, on the effectiveness of those installed internal control procedures.