Blogs

Corpay (NYSE: CPAY) is a global leader in business payments, helping companies simplify and control vendor payments, international payments, and employee payments through modern financial technology solutions designed to help businesses move faster, smarter, and with greater confidence.   With cutting-edge technology, global expertise, and reliable customer support, Corpay helps companies save time, reduce costs, improve cash flow visibility, and mitigate fraud across every area of business spending, helping finance teams around the world keep business moving. Position Overview Corpay is seeking to recruit an Accounting Manager for our ...
On May 21 financial regulators in New York released new guidance to help businesses understand the cybersecurity measures they should implement when they find themselves in a "heightened threat environment.”  We’ll pause for moment here while everyone quietly mutters, “For pete’s sake, we’ve been working in a heightened threat environment since, like, 2011.” That may be true, but it’s also true that all businesses now operate in an even more heightened threat environment. That puts lots of pressure on internal audit and risk management teams — but in a roundabout way, it gives you more opportunity, too.  Your team sits at the crossroads of ...
Tuning Your Data Core for Global Mandates Welcome back to the May edition of Sustainability Industry Insights. As we look toward the second half of 2026, the push for global data transparency is hitting a critical inflection point. For US-based multinationals, domestic regulations are only one piece of the puzzle; international mandates are increasingly dictating how we manage our data. If you caught the latest episode of Sustainability Signals video , you saw me kick things off by tuning my mandolin. Why? Because it reminded me of a simple truth: an eight-string mandolin only sounds good when its pairs of strings are tuned to the exact same pitch. ...
SM Energy Company is an independent energy company focused on the exploration, exploitation, development, acquisition, and production of natural gas and crude oil in the United States. The company was founded in 1908, incorporated in 1915, and became a public company through an initial public offering in 1992. SM Energy trades on the New York Stock Exchange under the symbol SM. Position Overview As a Senior Accountant on the Financial Reporting team, you will be a primary contributor to the preparation of the Company's SEC filings, including Forms 10-K, 10-Q, and 8-K. The role carries meaningful responsibility and offers growth potential ...
As the SEC considers the future of Regulation S-K, Pro Groups wanted to better understand how practitioners are working through these disclosure requirements in the real world. We launched a survey to collect this feedback which helped inform a Pro Groups comment letter to the SEC and ensured practitioner voices were represented in the conversation. We received feedback from 42 practitioners across accounting and financial reporting roles in 19 U.S. states and Bermuda. How Member Feedback Shaped Our Comment Letter While respondents continue to see value in Regulation S-K as an important disclosure framework, the feedback ...
Not long ago the Institute of Internal Auditors released its annual North America Pulse of Internal Audit report , polling nearly 400 chief audit executives on their challenges, plans, and hopes for the next few years.    If we’re being frank, the findings were a bit of a buzzkill.    For example, the number of audit leaders reporting cuts to their budgets or teams jumped sharply. Respondents at SOX-compliant businesses said they will spend much of their time on controls testing and assurance, rather than on value-added work like advising senior management on risk. Indeed, across all businesses, SOX-compliant or not, respondents said they ...
Corporations everywhere are under pressure to embrace artificial intelligence as quickly as they can, and the latest incarnation of that trend is the rush to deploy AI agents: autonomous snippets of software code intelligent enough to execute tasks with little to no human oversight. That might sound nifty to operations teams looking to boost efficiency or to finance teams hoping to cut costs. For GRC teams, however, AI agents herald a new era of security, privacy, and business continuity risk — and you need to develop a capacity to assess those risks sooner rather than later.    Let’s consider what that will entail.   A Quick Review ...
A Month of Insights and Connection: GreenBiz 26 & NASRS Over the last few weeks, the Pro Groups team and I have spent a lot of time on the road, attending both Trellis Group's GreenBiz 26 in Phoenix and the NASRS conference in Denver. Beyond the incredible sessions and discussions, the real highlight has been connecting face-to-face as a team—and with so many of our peers in the community. After spending the last few weeks on the ground, if I had to sum up the mood of both conferences in one word, it would be: Reset. The energy at these events has been fantastic, and the tone wasn’t about bold new pledges; it was about discipline. The ...
Corporate executives of all stripes know that cybersecurity is, quite frankly, a mess: too many security weaknesses spread across too much of your business, especially among the third parties that have become an integral part of the modern corporate enterprise.   Internal audit and cybersecurity teams spend too much time chasing down those weaknesses and fixing them. Compliance and legal teams spend too much time dealing with investigations when a weakness turns into a security breach. Sales teams spend too much time filling out endless risk assessment questionnaires from would-be customers. Above all is the board, spending too much time worrying about ...
Financial reporting and SOX compliance teams are always looking for ways to reduce the risk of erroneous financial reporting, and one cutting-edge strategy to achieve that is through continuous controls monitoring.   The idea certainly sounds appealing. With clever use of technologies such as artificial intelligence, accounting and SOX compliance teams will be able to monitor all your organization’s transactions as those transactions happen, and then immediately intercept any exceptions that somehow evade your internal controls.  More efficiency, faster remediation, fewer surprises at audit time — what’s not to love?  The reality of ...
On January 13, 2026, SEC Chairman Paul S. Atkins issued a Statement titled “ Statement on Reforming Regulation S-K .” In his Statement Chairman Atkins notes:   “Over the past forty-plus years, that repository (Regulation S-K) has grown from the size of a gym locker to the size of an artificial-intelligence data center. Today, the disclosure that companies provide in response to the myriad requirements of Regulation S-K does not always reflect information that a reasonable investor would consider important in making an investment or voting decision.”   Chairman Atkins has instructed the Division of Corporation Finance to conduct ...
Another amazing year is in the books, and it’s all thanks to members like you. You showed up time after time. You engaged in discussions, read blogs, attended webinars, and supported chapters. You helped make 2025 our best year yet. Before we ring in 2026, we’ve compiled the ultimate 'Best of Q4' list just for you. Scroll down to unwrap the top discussions, replays, and blogs that defined our community! Community News Navigate Your Community with Purpose As we start winding down for the holidays and ramping up for a busy reporting season (looking at your financial reporters), time is your most valuable asset. We continue to optimize ...
Internal audit teams at companies preparing to go public face a tricky balancing act in their journey toward Sarbanes-Oxely readiness. Namely, how do you keep sight of the risk assessment forest through the documentation trees?  That is, documenting your internal controls is always going to be an important part of SOX readiness — but it’s not necessarily the most important part. The most important part is the risk assessment that management should undertake, to understand what its most material risks are.  And yet, far too often, internal audit teams get bogged down in the minutiae of cross-walking frameworks and documenting controls at the expense ...
Good data governance is the cornerstone of any successful GRC program, so today let’s talk about something that can often be a mortal threat to good data governance — unstructured data. Unstructured data is just what the name suggests: data that exists somewhere within your enterprise, but lacks any specific structure to help you understand the information it contains. Examples include…  Text-based data , such as emails on an employee’s laptop, AI-generated marketing materials, or customer reviews left on your corporate website Multimedia data including audio recordings, training videos, security camera footage, or photos posted to a departmental ...
On August 13, 2025, the SEC announced a new “ statistics and data visualization page ” that provides a wealth of capital market statistics including information about public offerings, exempt offerings and number and categories of reporting issuers. According to the SEC’s Press Release , the new webpage provides: “Data Visualizations: interactive graphics based on statistics Statistics Table: fundamental statistics regularly updated with the most recently available data Statistics Guide: description, calculation method, and data source for each metric Statistics Download: all available statistics in the table ...
DISCLAIMER: This blog post is no longer current or valid as of July 16. The COSO draft corporate governance framework referenced in this post has been removed and is no longer available for public comment.  Global businesses need a system of internal controls that can withstand scrutiny from any direction. So today let’s turn our eyes to the United Kingdom, where a new “Failure to Prevent Fraud” offense could pose some significant challenges for compliance and internal audit teams later this year.  Good corporate governance is about getting your organization to pursue its business objectives — financial targets, market expansion, ethical business ...
By Matt Kelly Global businesses need a system of internal controls that can withstand scrutiny from any direction. So today let’s turn our eyes to the United Kingdom, where a new “Failure to Prevent Fraud” offense could pose some significant challenges for compliance and internal audit teams later this year.  As the name implies, the law (going into effect Sept. 1) exposes companies doing business in the U.K. to criminal liability if they fail to prevent fraud that happens within their enterprise — but companies can avoid that liability if they have implemented “reasonable procedures” meant to prevent fraud from happening. The question for internal ...
By Matt Kelly Artificial intelligence is transforming all parts of the corporate enterprise — including, unfortunately, frauds launched against your enterprise. Which means your anti-fraud controls must transform too, or else you’ll never keep pace with the threat that AI-enhanced fraud poses.  That’s not likely to be an easy task. Fraudsters are hatching ingenious ways to use AI in furtherance of their schemes, with the potential for severe financial or data losses to your company. Moreover, most laws and regulations imposing a duty of care to prevent fraud are “technology agnostic,” in the sense that it doesn’t matter what specific tricks fraudsters ...
By Matt Kelly, Radical Compliance For more than 20 years now, internal audit and corporate accounting teams have strived to build effective internal accounting controls — necessary for strong financial reporting, Sarbanes-Oxley compliance, anti-fraud programs, and more.    Along the way, however, a pattern cropped up that hasn’t yet received the attention it deserves: internal  accounting  controls have converged with internal  cybersecurity  controls.  For example, recall the CrowdStrike disaster from 2024, when businesses around the world came to a screeching halt thanks to a  flawed software update that cybersecurity firm CrowdStrike ...
The days of a cybersecurity breach being only “an IT issue” are over. During his years as an internal audit leader, Grant Ostler, Executive Advisor of Pro Groups, survived two cybersecurity incidents. And while he can confidently say it is never fun, it’s much more painful to go through one without a dry run first. Pro Groups, the community for accounting & finance, sustainability, and audit & risk professionals, invited a few members from the Las Vegas chapter to run through a simulated cybersecurity incident to share how they would respond.    Historically, auditors, controllers, and sustainability professionals haven’t been involved in ...