Understanding Internal Control Over Financial Reporting

Internal Control over Financial Reporting (ICFR) continues to be an intense focus of regulators. After the SEC recently fined a number of companies for failing to remedy material weaknesses in ICFR, the PCAOB released a Staff Preview of its 2018 Inspection Observations, highlighting the testing of ICFR remains a common audit deficiency. ICFR remains an important component to fostering confidence in a company’s financial reporting, and ultimately, trust in our capital markets. To assist in these concerns, the Center for Audit Quality (CAQ) has updated and re-released its popular Guide to Internal Control over Financial Reporting as an overview to assist stakeholders in understanding key ICFR concepts, roles and responsibilities, and what ICFR means for companies, investors, and the markets. This publication includes the addition of significant research demonstrating the importance and impact of ICFR and integrated audits on the quality of financial reporting at a time when the SEC is proposing amendments to tailor filer definitions potentially reducing the number of companies subject to the auditor ICFR attestation requirement under Section 404(b) of the Sarbanes-Oxley Act (SOX).

Background

Internal Control over Financial Reporting (ICFR) has been required for public companies and included as part of issuer audits for more than a decade. Often the conversation around ICFR is based on regulatory expectations, but an equally important conversation focuses on the intent of those regulations which is to increase trust in financial reporting by establishing reliable systems and controls.

As a result of SOX, most large public issuers are required to have an integrated audit performed[1], which includes an external auditor’s assessment of the effectiveness of the company’s ICFR (in addition to management’s annual assessment of internal control effectiveness). All issuer audits are subject to reviews performed by the PCAOB.

Current State of Affairs

SEC Activities Impacting ICFR

In January 2019, the SEC announced settled charges against four public companies for failing to maintain ICFR for seven to ten consecutive annual reporting periods. Two of the charged companies also failed to complete the required evaluation of the effectiveness of ICFR for two consecutive annual reporting periods. SEC Chief Accountant Wesley Bricker is quoted in the release saying, “Adequate internal controls are the first line of defense in detecting and preventing material errors or fraud in financial reporting… When internal control deficiencies are left unaddressed, financial reporting quality can suffer.” This action further supports the intent of the regulators and underlying regulations: to protect and enhance the trust in our capital markets.

Meanwhile, in May, the SEC voted on proposed amendments to the accelerated filer and large accelerated filer definitions intended to reduce costs for certain lower-revenue companies as a potential means for such companies to redirect the savings into growing their companies by investing in research and human capital and helping promote capital formation. Under the proposal, smaller reporting companies (SRCs) with less than $100 million in revenue would not be required to obtain an attestation from an independent external auditor on ICFR. The proposal would not change other key provisions of SOX, such as the independent audit committee requirements, CEO and CFO certifications on financial reports, or the requirement that companies continue to establish, maintain, and assess the effectiveness of ICFR. For more on the SEC’s proposal, refer to BDO’s Alert here.

PCAOB 2018 Inspections Observations on ICFR

Also in May 2019, the Division of Registration and Inspections staff of the PCAOB issued a preview of its observations related to 2018 inspections of audits of public companies, which considered approximately 700 audits performed by over 160 audit firms. The information is primarily for auditors’ consideration in planning and performing upcoming audits and for audit committees in engaging with and overseeing the external auditors. While there were a number of good practices observed regarding efforts of improved audit quality, the PCAOB noted ICFR as a continuing area of common audit deficiencies[2]. Specifically, the PCAOB cited observations where:

CAQ Guide to ICFR

In May 2019, in its efforts to continually improve audit quality and to enhance investor confidence and public trust in the global capital markets, the CAQ re-issued its Guide to Internal Control Over Financial Reporting ICFR to educate stakeholders on the purpose and benefits of ICFR. The guide provides an overview of the structure and design of ICFR and stresses the importance of internal processes and controls to the integrity of financial reporting. The guide explains what ICFR is and describes management’s responsibility for implementing effective ICFR. It also discusses the responsibilities of the audit committee to oversee ICFR and of the independent auditor to audit the effectiveness of the company’s ICFR.

As a reminder, public companies are required to establish and maintain a system of internal accounting controls sufficient to provide reasonable assurance that transactions are recorded as necessary to permit preparation of financial statements in accordance with GAAP. SOX added a requirement under Section 404(a) that management annually assess the effectiveness of the company’s ICFR and report the results to the public. SOX further requires most large issuers under section 404(b) to have an integrated audit performed by their external auditor.

Key ICFR Concepts