IT Risk Services Brochure

SOX Section 404

The Sarbanes-Oxley Act of 2002 (SOX) has created challenges and opportunities for publicly traded companies, changing the way they do business.

Enacted to restore public confidence and trust in our nation's corporate sector, the act demands greater accountability for financial management and reporting practices for companies registered with the Securities and Exchange Commission (SEC). While sox does not directly apply to nonpublic companies or not-for-profits, these organizations also are adopting many of 404's provisions.

The act charges management with the responsibility for annually assessing the design and operating effectiveness of internal control over financial reporting and requires external auditors to annually audit and issue a report on the effectiveness of the company's internal controls.

Help from BKD

BKD has developed a customized approach to Section 404 compliance that meets the spirit and letter of the law. Though management is responsible for meeting the Section 404 requirements, we can help with initial assessments, specific phases, end-of-process reviews or outsourcing staff.

We also can take a lead role in helping management meet Section 404 requirements. Our four-phased approach covers planning, training, documenting and testing. This approach is typically driven by answers to these questions:

  • What documentation, monitoring and testing of controls already exist?
  • How complex is the organization?
  • What internal audit or other resources can be deployed?
  • What kind of information technology does your company depend on?
  • What is your company's culture with regard to “doing things right”?

For more details about our approach, ask your local BKD advisor or read our Section 404 Speakers’ Bureau topics.

Effect on Nonpublic Companies

Many nonpublic organizations and not-for-profits also are looking at Section 404-related issues, or internal audit outsourcing, as opportunities to improve business effectiveness and efficiency. These entities are proactively evaluating their corporate governance environment and considering adopting 404 rules that are not otherwise required. BKD can assist not-for-profit entities in understanding the implications and costs of SOX compliance.

Need a Resource?

To keep pace with 404, we offer this sample of related resources.

Regulations
Summary of Sarbanes-Oxley Act of 200Code of Federal RegulationsFinal rules issued by the SECPCAOB Rule MakingU.S. Code of Laws

Internal Control
COSO Home PagInformeation Systems Audit and Control Association (COBIT)

Professional Associations
AICPAFinancial Executives International Advocate Sarbanes-Oxley

 

Cindy Boyle

Partner
IT Risk Services

Cindy Boyle

Partner

IT Risk Services

Financial Services, Not-for-Profit & Government, Inf, Comm & Entertainment

400 W. Capitol Avenue, Suite 2500
P.O. Box 3667
Little Rock, AR 72203-3667 (72201)

Little Rock
501.372.1040

Ronald Hulshizer

Senior Managing Consultant

Ronald Hulshizer

Senior Managing Consultant

Financial Services

Two Leadership Square South Tower
211 N. Robinson Avenue, Suite 600
Oklahoma, City, OK 73102-9421

Oklahoma City
405.842.7977

Matthew Lathrom

Managing Consultant

Matthew Lathrom

Managing Consultant

Other

1201 Walnut Street
Suite 1700
Kansas City, MO 64106-2246

Kansas City
816.221.6300

Cindy Boyle

Partner
IT Risk Services

Cindy Boyle

Partner

IT Risk Services

Financial Services, Not-for-Profit & Government, Inf, Comm & Entertainment

400 W. Capitol Avenue, Suite 2500
P.O. Box 3667
Little Rock, AR 72203-3667 (72201)

Little Rock
501.372.1040

Ronald Hulshizer

Senior Managing Consultant

Ronald Hulshizer

Senior Managing Consultant

Financial Services

Two Leadership Square South Tower
211 N. Robinson Avenue, Suite 600
Oklahoma, City, OK 73102-9421

Oklahoma City
405.842.7977

Matthew Lathrom

Managing Consultant

Matthew Lathrom

Managing Consultant

Other

1201 Walnut Street
Suite 1700
Kansas City, MO 64106-2246

Kansas City
816.221.6300

Larry McLaughlin

Managing Consultant

Larry McLaughlin

Managing Consultant

Not-for-Profit & Government

14241 Dallas Parkway
Suite 1100
Dallas, Texas 75254-2961

Dallas
972.702.8262

Laura Patrick

Managing Consultant

Laura Patrick

Managing Consultant

Other

910 E. St. Louis Street, Suite 200
P.O. Box 1190
Springfield, MO 65806-2523

Springfield
417.865.8701

Rod Walsh

Director
IT Risk Services

Rod Walsh

Director

IT Risk Services

Other

1201 Walnut Street
Suite 1700
Kansas City, MO 64106-2246

Kansas City
816.221.6300