SOX Professionals Group

 View Only
  • 1.  SOX Finding Reporting Questions

    Posted 10-30-2023 12:45 PM

    Hi all, 

    I'm looking for a few insights in how you all report your SOX findings to management/board of directors/audit committee.

    Currently, if a control breaks down, we're reporting it to our SOX Committee (management) and Audit Committee, even if the breakdown didn't have financial impact.

    For instance, a user was granted access to a SOX system without a provisioning ticket.  The access was warranted by his/her role, but the control requires a provisioning ticket.

    There's no actual impact in this finding, but the control broke down.  I hate taking these types of findings to executive management, but given that the control that mitigates the risk didn't operate, we feel that it's a deficiency.  Are you taking a similar approach, or would you classify this type of finding as a "near miss" or an operational issue that isn't a SOX deficiency?

    Thanks!



    ------------------------------
    Darren McCombs
    SOX Compliance Manager
    First Busey Corporation
    ------------------------------


  • 2.  RE: SOX Finding Reporting Questions

    Posted 10-30-2023 02:03 PM

    In your example, I recommend first concluding whether it was a SOX control deficiency or not.  It sounds like there was a breakdown in the access provisioning control process.  Depending on root cause and your population/sample size, there may be the ability to rationalize it as an isolated exception and not a control deficiency (in consultation with your auditors).  If you do conclude a deficiency, the next step is the impact assessment where you then determine if there was financial impact.  When reporting to the Audit Committee, the amount of detail in discussion and supporting materials could be weighted based on the risk/impact of each deficiency.   For example, summary numbers for low risk/impact deficiencies and detailed discussion (issue, impact, remediation) on higher risk/impact deficiencies.  



    ------------------------------
    Nick Tobkin
    Director of Cybersecurity
    Target
    ------------------------------



  • 3.  RE: SOX Finding Reporting Questions

    Posted 10-30-2023 02:16 PM
    Edited by Darren McCombs 10-30-2023 04:20 PM

    Thanks for the response.  To your point, in the example above, we expanded the sample to deem the issue isolated.

    Other examples would be (we're a bank) in regard to loan approvals.  The control is automated system routing for proper approval. The routing is based on manual inputs, which are often wrong; however, the loans are manually routed to the right person 95% of the time.  There is often no actual financial reporting impact because even though the automated control fails, the loans receive proper approval under policy due to informal processes.  So, we report SOX findings because the control isn't reliable. 

    I think in most cases my brain leans toward the thinking that, the control is the mitigant to the risk of material misstatement, so if it breaks down, even though the uncovered finding didn't impact financial reporting directly, the control has a gap in operating effectiveness.  One of our external auditors said this week that they wouldn't report a SOX deficiency because the breakdown that we found didn't impact financial reporting....so I'm just trying to reconcile that.  There are many times that I don't want to take a small finding to management, but I also don't want to underreport where work needs done to better cover the risk, if that makes sense.



    ------------------------------
    Darren McCombs
    SOX Compliance Manager
    First Busey Corporation
    ------------------------------



  • 4.  RE: SOX Finding Reporting Questions

    Posted 10-31-2023 11:31 AM

    We are a bank as well; I try my best to summarize the deficiencies to the Audit Committee.   I provide our SOX Committee with all of the details.  I provide the Audit Committee with a very high level summary of the "exceptions", issues we deemed not a control deficiency.   



    ------------------------------
    Rena Harris
    SOX Compliance Manager
    Investar Bank
    ------------------------------



  • 5.  RE: SOX Finding Reporting Questions

    Posted 02-28-2024 02:39 PM
    Edited by Raymond Rengifo 02-28-2024 02:41 PM

    A little late to the party, but wanted to provide my thoughts given my experience with Audit Committee needs. While the access for the user was appropriate, it was a breakdown of the control over a SOX system, which means that this is a SOX issue. 

    As far as communicating to the audit committee. I'd say take the approach of providing an executive summary (1 pager) slide which goes though progress, and whether there are critical open items/issues  and the areas impacted. I usually include the details in the appendix. They don't care as to whether we failed a GITC, they care whether it has impact that needs to be disclosed in the 10K item 9a (typically material weaknesses).

    Hope that helps.



    ------------------------------
    Raymond Rengifo
    Director - SOX Compliance
    Tredegar Corporation
    ------------------------------