Newsletters Welcome, Guest Log In | Register

Governance and Risk

From regulatory compliance to corporate governance structure, everyone is involved

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

1

Sarbox Delay Doesn't Mean 'Take It Easy'

Posted by Lora Bentley Feb 22, 2008 3:25:00 PM

Smaller companies may be able to breathe a little easier now that they don't have to worry about external auditors checking out their internal controls until 2009. However, the delay doesn't mean they should sit back and do nothing.

 

Small Business Times writer William Gienke says small public companies should take advantage of the extra year the Securities and Exchange Commission has given them to fine-tune their internal controls and make sure their assessments are accurate before subjecting them to third-party scrutiny.

 

Moreover, he says that even private companies and non-profit organizations will benefit from the lessons small businesses learn as they come into compliance with Sarbanes-Oxley. What has been regulated for public companies is simply good business for others.

Add a comment Leave a comment on this blog post.
Feb 28, 2008 9:13 PM Guest Richard Archer  says:

Unfortunately, if experience is any indicator, "sit back and do nothing" is exactly what many small companies will do.  That is likely to be especially true if the management of the companies believes that delaying compliance work could continue to result in a large number of companies not being close to compliance as the deadline looms, thus pressuring the SEC to grant additional compliance extensions.  That tactic has worked for multiple extensions so far, even though an approach for compliance relief was first introduced for smaller public companies in April-June 2006 with the release of COSO for Smaller Public Companies and the SEC's response to its smaller company advisory group which began the promotion of a risk-based compliance approach for smaller companies, rather than the extensive, big audit firm driven AS2 approach.  If companies had begun implementing a planned, coordinated, staged compliance approach at that time, they would have been able to meet the previous smaller company compliance deadline of December 2007 for first SOX audit, instead of continuing to press for more and more delays.  So, a very small minority of companies will begin a very cost effective, planned, staged compliance program.  Most of the others will wait.  If the SEC doesn't then grant further extensions, those companies will scream about the high cost of intensive, short time-frame compliance efforts and SOX critics will use those cost experiences to further gut investor protection objectives of controls system compliance regs.  But just as for large companies, much of the cost of SOX compliance will not be caused by SOX, but by the companies delays in implementing compliance efforts and catching up on years of neglect of their systems of internal control.

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Performance Under Pressure: The State of Enterprise Web Application Quality and Availability

This research study finds that Web application issues are an all-too-common problem and examines these Web-based enterprise application issues from two perspectives: that of an online customer and that of a site manager.

Applications for Mid-size Businesses

Applications that mid-sized businesses can use to improve operational efficiency, accelerate growth, and maintain profitability.

Network Optimization

Network management tools and tips to increase network speed and efficiency, regardless of office location.

Greening IT with Server Consolidation

Learn how virtualization reduces the TCO of managing your date, while contributing towards your sustainability efforts.

Data Management

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

ITIL V3 Foundation - Complete Certification Kit

Enhance your IT career by getting your ITIL Foundation Certificate. It's fast and easy with this complete resource. The 186-page eBook and companion online training course is guaranteed to help you pass the ITIL exam.

Learn more >

Budget & Finance Toolkit for IT - 2010 Edition

What kind of year are you planning in 2010?  Growth or continued "survival mode"?  Download a comprehensive collection of templates, forms, instruction and advice that will help you to plan and submit your 2010 IT Budget.

Learn more >