← Back to Articles

Your Material Weakness Disclosure Is A Software Deadline

Somewhere in Item 9A of your last annual report there is a paragraph that names a control that did not operate, and a plan to fix it. Finance, counsel, the audit committee and the auditor all read it as a governance sentence. It is also a commitment to produce a specific kind of record, by a specific date, in a volume an auditor can sample.

Records at that volume are produced by systems. The disclosure contains a software obligation that nobody in the room reads as one because nobody in it builds software.

Over the trailing twelve months, SEC full-text search returns 682 filings disclosing a material weakness and 139 filings reporting non-reliance on previously issued financial statements. Those are filings, not companies, but the population is large and concentrated in companies with no internal product team to hand the software obligation to.

A finance controller reviewing audit records with a remote audit committee on a large video screen
A dated promise to produce evidence.

What The Paragraph Actually Commits You To

A remediation plan is judged by an evidence test. Under the standard governing audits of internal control over financial reporting (PCAOB, AS 2201), the auditor forms an opinion on whether the control operated effectively over a period, which means selecting from a population and inspecting what each selection left behind. The standard on audit evidence (PCAOB, AS 1105) sets what counts: evidence must be sufficient and appropriate, and inspection of records is one of the few procedures that produces it.

There must be a population that can be listed. Each item must carry who performed the step, when relative to its period, which version of the input was used, and a different person who reviewed it. The records must be retained long enough to be sampled, and created when the work happened rather than assembled afterwards. That is a specification, not a policy.

The auditor is not testing whether the control was performed. They are testing whether the performance left a record they can pull.

Remediation Plans Are Written In The Wrong Language

Most remediation plans are written in three registers: staffing, policy and enhanced review. None produces a record. Enhanced review is the most common and the weakest: it commits to attention, which is invisible afterwards and depletes when the period closes.

A fourth register appears less often: the step is changed so performing it produces a record the performer cannot skip. Only it reliably changes the audit result, and it requires software.

What the plan saysWhat a tester can pull
We hired a senior analystAn organization chart
We documented the procedureA document, undated in practice
Management performs additional reviewAn email, if it was kept
The step needs a stamped approval to completeA list: names, times, versions, exceptions

Only the last row survives contact with a sample.

Why The Gap Survives Every Meeting

Everyone in the room is telling the truth. The controller says the reconciliation is reviewed, and it is. The auditor says they cannot test it, and they cannot, because the review left an email, a saved file and a memory. Neither statement produces the next action, because it is a small piece of software and nobody in the conversation owns software.

Information technology owns the enterprise system, not the missing step. The step that failed usually lives in the twenty percent of the process the enterprise system was never built to do, where a spreadsheet became the system of record for one slice of the close.

The determinants of weaknesses in internal control over financial reporting (Doyle, Ge & McVay, Journal of Accounting and Economics, 2007) found disclosed weaknesses concentrated in firms that are smaller, younger, financially weaker, more complex, growing rapidly, or restructuring. That describes a company between sixty and two hundred million dollars in revenue that has just acquired something. The effect of internal control deficiencies on firm risk and cost of equity (Ashbaugh-Skaife, Collins, Kinney & LaFond, Journal of Accounting Research, 2009) reports that firms disclosing deficiencies carry higher cost of equity, and that the effect moves on remediation. Remediation is priced.

Read The Paragraph As A Specification

Rewrite each sentence in this form: who performs the step, over what population, in what order, producing what record, retained where, reviewed by whom, before what date. A sentence that cannot be rewritten is an intention, and it will be tested as one.

The sentences that can be rewritten fall into two groups. Some describe records your systems already produce; the work is to find and retain them. The rest describe records that exist nowhere, and each is a bounded piece of software: a form that will not submit without a stamped approver, a queue that holds exceptions until someone dispositions them, a log that records what was used and when. That second group is usually a single workflow, rarely a whole platform, and almost never a new enterprise system implementation.

First Steps

  1. Print the remediation paragraph and mark every verb. Circle each verb of attention: reviews, monitors, oversees, ensures. Those sentences will not survive an audit sample.
  2. For one, ask for the last three instances. The answer is what the auditor will get.
  3. Specify that step in the form above. If it fits on a page, it is buildable this quarter.

Turn The Sentence Into A Deliverable

The obligation in your filing has a date attached to it. The distance between a plan written in policy language and a buildable specification is normally a single conversation with somebody who builds this kind of system, followed by a first release.

A fifteen-minute call, nothing paid, nothing signed, takes one remediation sentence apart: what the record must contain, where it comes from, what has to be built, and what it costs. If the honest answer is that your systems already produce the evidence and the work is retention and reporting, that is the answer you get, and it saves you a build.

Where something has to be built, it runs as a monthly engineering partnership, with the targets each release must meet written before it starts. Paid-for deliverables transfer to you monthly, with the documentation and the run guide. After that, $10,000 a month puts one accountable person on keeping the system running, with a monthly report of what ran and what changed, which is itself the artifact an audit committee likes to receive.

References

  1. Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements. PCAOB Auditing Standards.
  2. Public Company Accounting Oversight Board. AS 1105: Audit Evidence. PCAOB Auditing Standards.
  3. Doyle, J., Ge, W., & McVay, S. Determinants of Weaknesses in Internal Control over Financial Reporting. Journal of Accounting and Economics, 2007.
  4. Ashbaugh-Skaife, H., Collins, D. W., Kinney, W. R., & LaFond, R. The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity. Journal of Accounting Research, 2009.

NEXT · TO PRODUCTION

Check your position.

Two minutes. Your main blocker and first move.

15 minutes · no charge · with Omar