The Impacts of the Sarbanes-Oxley Act of 2002 on Internal Controls 1
The Impacts of the Sarbanes-Oxley Act of 2002 on
Internal Controls
Daniel Pendergast
The College of Saint Rose
The Impacts of the Sarbanes-Oxley Act of 2002 on Internal Controls 2
Abstract
On July 30, 2002, the Sarbanes-Oxley Act (SOX) was regulated due to the many
accounting scandals that took place between the years of 2000 and 2002 by companies such as
Enron, WorldCom, and Global Crossing. The purpose of the Sarbanes-Oxley, specifically Section
404, was to require public companies to establish effective internal control in the hopes of
preventing material misstatements in their financial records. The purpose of this paper is to
outlines the positive and negative impacts that the Sarbanes-Oxley Act of 2002 had on entities that
are required to comply with the new regulations. The Sarbanes-Oxley Act of 2002 was introduced
by Paul Sarbanes and Michael Oxley Sarbanes-Oxley and contains eleven titles, all with a
common goal of strengthening accountability of upper-level management as well as accounting
responsibilities. The Committee of Sponsoring Organization Internal control defines internal
control as “a process affected by an entity’s board of directors, management, and other personnel,
designed to provide reasonable assurance regarding the achievement of objectives (Dowling &
Jahmani, 2015, p. 129).
Requirements of Management
It has been proven that companies with weaknesses in internal controls are more likely to
increase the chances of having errors in their financial statements. Material misstatements in a
company’s financial statements are a major concern in the world of business. The main purpose of
an audit underlines both an internal and external auditors and management’s responsibility of
detecting and preventing fraud. The Sarbanes-Oxley Act brings to life to new methods of
accounting that managers of public companies are to use in order to prevent fraud from occurring.
Upper-level management must now authorize his or her company’s financial statements prior to
being submitted. The Sarbanes-Oxley Act now also requires management to report on any
The Impacts of the Sarbanes-Oxley Act of 2002 on Internal Controls 3
internal controls put into place, and then writes up an evaluation of those controls and how they
are impacting the company.
The internal control report must include: a statement of management’s responsibility for
establishing and maintaining adequate internal control over financial reporting for the
company; management’s assessment of the effectiveness of the company’s internal control
over financial reporting as of the end of the company’s most recent fiscal year; a statement
identifying the framework used by management to evaluate the effectiveness of the
company’s internal control over financial reporting; and a statement that the registered
public accounting firm that audited the company’s financial statements included in the
annual report has issued an attestation report on management’s assessment of the
company’s internal control over financial reporting. Under the new rules, a company is
required to file the registered public accounting firm’s attestation report as part of the
annual report. Furthermore, we are adding a requirement that management evaluate any
change in the company’s internal control over financial reporting that occurred during a
fiscal quarter that has materially affected, or is reasonably likely to materially affect, the
company’s internal control over financial reporting. (“Final Rule: Management’s Report on
Internal Control Over Financial Reporting and Certification of Disclosure in Exchange Act
Periodic Reports, 2008)
Management’s job under the new Sarbanes-Oxley is to plan out and put together a
company’s internal control system. Having strong internal controls make fraud harder to commit,
but they can’t totally eliminate the chances of any misrepresentations due to the fact that they have
the last say and can override those controls. Managers who are intent on committing fraud have
The Impacts of the Sarbanes-Oxley Act of 2002 on Internal Controls 4
an incentive to design weaknesses into the system of controls because the benefits to fraud are
more enticing to dishonest managers when the system of controls is weak (Patterson & Smith,
2007, p. 428).
Internal Control Testing
The main purpose of the Public Company Accounting Oversight Board (PCAOB) is to
oversee the auditors of public companies in order to protect the interests of investors and further
the public interest in the preparation of informative, fair, and independent audit reports(“Public
Company Accounting Oversight Board (PCAOB)”). The Public Company Accounting Oversight
Board has outlined three types of deficiencies that point out weaknesses of internal controls within
a company. They include control deficiencies, significant deficiency, and material weaknesses.