Office of the Chief Accountant
Division of Corporation Finance:
Management's Report on Internal Control Over Financial Reporting and Disclosure in Exchange Act Periodic Reports
Frequently Asked Questions
The answers to these frequently asked questions represent the views of the staffs of the Office of the Chief Accountant and the Division of Corporation Finance. They are not rules, regulations or statements of the Securities and Exchange Commission. Further, the Commission has neither approved nor disapproved them.
Note: Since the adoption of the Commission's Rules on Management's Reports on Internal Control Over Financial Reporting and Certification of Disclosure in Exchange Act Periodic Reports (Release No. 34-47986, June 5, 2003), we have received questions regarding the implementation and interpretation of the rules. Questions on accounting matters related to management's report on internal control over financial reporting should be directed to Nancy Salisbury (firstname.lastname@example.org) or Esmeralda Rodriguez (email@example.com) in the Office of the Chief Accountant, Mail Stop 1103, 450 Fifth Street, NW, Washington, DC 20549; telephone: (202) 942-4400. Other disclosure and filing questions should be directed to Sean Harrison at (202) 942-2910, or Jonathan Ingram at (202) 942-2900 in the Division of Corporation Finance.
Q: Financial Accounting Standards Board (FASB) Interpretation No. 46 (revised December 2003), Consolidation of Variable Interest Entities An Interpretation of ARB No. 51, requires that registrants apply that guidance and, if applicable, consolidate entities based on characteristics other than voting control no later than the period ending March 15, 2004, or December 15, 2004 for small business issuers. In instances where the registrant lacks the ability to dictate or modify the internal controls of an entity consolidated pursuant to Interpretation No. 46, it may not have legal or contractual rights or authority to assess the internal controls of the consolidated entity even though that entity's financial information is included in the registrant's financial statements. Similarly, for entities accounted for via proportionate consolidation in accordance with Emerging Issues Task Force Issue No. 00-1 (EITF 00-1), management may not have the ability to assess the internal controls. How should management's report on internal control over financial reporting address these situations?
A: We would typically expect management's report on internal control over financial reporting to include controls at all consolidated entities, irrespective of the basis for consolidation. However, in a situation where the entity was in existence prior to December 15, 2003 and is consolidated by virtue of Interpretation No. 46 (i.e., would not have been consolidated in the absence of application of that guidance) and where the registrant does not have the right or authority to assess the internal controls of the consolidated entity and also lacks the ability, in practice, to make that assessment, we believe management's report on internal control over financial reporting should provide disclosure in the body of its Form 10-K or 10-KSB regarding such entities. For example, a registrant could refer readers to a discussion of the scope of management's report on internal control over financial reporting in a section of the annual report entitled "Scope of Management's Report on Internal Control Over Financial Reporting." The registrant should disclose in the body of the Form 10-K or 10-KSB that it has not evaluated the internal controls of the entity and should also note that the registrant's conclusion regarding the effectiveness of its internal control over financial reporting does not extend to the internal controls of the entity. The registrant should also disclose any key sub-totals, such as total and net assets, revenues and net income that result from consolidation of entities whose internal controls have not been assessed. The disclosure should note that the financial statements include the accounts of certain entities consolidated pursuant to FIN 46 or accounted for via proportionate consolidation in accordance with EITF 00-1 but that management has been unable to assess the effectiveness of internal control at those entities due to the fact that the registrant does not have the ability to dictate or modify the controls of the entities and does not have the ability, in practice, to assess those controls.
Q: Is a registrant required to evaluate the internal control over financial reporting of an equity method investment?
A: The accounts of an equity method investee are not consolidated on a line-by-line basis in the financial statements of the investor, and as such, controls over the recording of transactions into the investee's accounts are not part of the registrant's internal control structure. However, the registrant must have controls over the recording of amounts related to its investment that are recorded in the consolidated financial statements. Accordingly, a registrant would have to consider, among other things, the controls over: the selection of accounting methods for its investments, the recognition of equity method earnings and losses, its investment account balance, etc. For example, a registrant might require that, at least annually, its equity method investees provide audited financial statements as a control over the recognition of equity method earnings and losses. However, nothing precludes a registrant from evaluating the control over financial reporting of an equity method investment, and there may be circumstances where it is not only appropriate but also may be the most effective form of evaluation. For purposes of applying this guidance, we make no distinction between those equity method investments for which the registrant is required to file audited financial statements pursuant to Rule 3-09 of Regulation S-X and those where no such requirement is triggered.
Q: If a registrant consummates a material purchase business combination during its fiscal year, must the internal control over financial reporting of the acquired business be included in management's report on internal control over financial reporting for that fiscal year?
A: As discussed above, we would typically expect management's report on internal control over financial reporting to include controls at all consolidated entities. However, we acknowledge that it might not always be possible to conduct an assessment of an acquired business's internal control over financial reporting in the period between the consummation date and the date of management's assessment. In such instances, we would not object to management referring in the report to a discussion in the registrant's Form 10-K or 10-KSB regarding the scope of the assessment and to such disclosure noting that management excluded the acquired business from management's report on internal control over financial reporting. If such a reference is made, however, management must identify the acquired business excluded and indicate the significance of the acquired business to the registrant's consolidated financial statements. Notwithstanding management's exclusion of an acquired business's internal controls from its annual assessment, a registrant must disclose any material change to its internal control over financial reporting due to the acquisition pursuant to Exchange Act Rule 13a-15(d) or 15d-15(d), whichever applies. In addition, the period in which management may omit an assessment of an acquired business's internal control over financial reporting from its assessment of the registrant's internal control may not extend beyond one year from the date of acquisition, nor may such assessment be omitted from more than one annual management report on internal control over financial reporting.
Q: If management, the accountant, or both conclude in a report included in a timely filed Form 10-K or 10-KSB that the registrant's internal control over financial reporting is not effective, would the registrant still be considered timely and current for purposes of Rule 144 and Forms S-2, S-3, and S-8 eligibility?
A: Yes, as long as the registrant's other reporting obligations are timely satisfied. As has previously been the case, the auditor's report on the audit of the financial statements must be unqualified.
Q: May management qualify its conclusions by saying that the registrant's internal control over financial reporting are effective subject to certain qualifications or exceptions or express similar positions?
A: No. Management may not state that the registrant's controls and procedures are effective except to the extent that certain problems have been identified or express similar qualified conclusions. Rather, management must take those problems into account when concluding whether the registrant's internal control over financial reporting is effective. Management may state that controls are ineffective for specific reasons. In addition, management may not conclude that the registrant's internal control over financial reporting is effective if a material weakness exists in the registrant's internal control over financial reporting.
Q: If management's report on internal control over financial reporting does not identify a material weakness but the accountant's attestation report does, or vice versa, does this constitute a disagreement between the registrant and the auditor that must be reported pursuant to Item 304 of Regulation S-K or S-B?
A: No, unless the situation results in a change in auditor that would require disclosure under Item 304 of Regulation S-K or S-B. However, such differences in identification of material weaknesses could trigger other disclosure obligations.
Q: When should a registrant determine whether it is an accelerated filer for purposes of determining when it must comply with Items 308(a) and (b) of Regulations S-K and S-B?
A: As provided in Exchange Act Rule 12b-2, a registrant that is not already subject to accelerated filing should determine whether it is an accelerated filer at the end of its fiscal year, based on the market value of its public float of its common equity as of the last business day of its most recently completed second fiscal quarter. Consideration should also be given to the other components of the Rule 12b-2 definition (i.e. the registrant has been subject to Exchange Act reporting for at least 12 months, has filed at least one annual report, and is not eligible to use Forms 10-KSB and 10-QSB).
Q: Is a registrant required to provide management's report on internal control over financial reporting, and the related auditor attestation report, when filing a transition report on Form 10-K or 10-KSB?
A: Yes. Because transition reports filed on Forms 10-K or 10-KSB (whether by rule or by election) must contain audited financial statements, they must also include management's report on internal control, subject to the transition provisions specified in Release No. 34-47986. The transition provisions relating to management's report on internal control should be applied to the transition period as if it were a fiscal year. Transition reports on Form 10-Q or 10-QSB are not required to include a management report on internal control.
Q: Is a registrant required to disclose changes or improvements to controls made as a result of preparing for the registrant's first management report on internal control over financial reporting?
A: Generally we expect a registrant to make periodic improvements to internal controls and would welcome disclosure of all material changes to controls, whether or not made in advance of the compliance date of the rules under Section 404 of the Sarbanes-Oxley Act. However, we would not object if a registrant did not disclose changes made in preparation for the registrant's first management report on internal control over financial reporting. However, if the registrant were to identify a material weakness, it should carefully consider whether that fact should be disclosed, as well as changes made in response to the material weakness.
After the registrant's first management report on internal control over financial reporting, pursuant to Item 308 of Regulations S-K or S-B, the registrant is required to identify and disclose any material changes in the registrant's internal control over financial reporting in each quarterly and annual report. This would encompass disclosing a change (including an improvement) to internal control over financial reporting that was not necessarily in response to an identified significant deficiency or material weakness (i.e. the implementation of a new information system) if it materially affected the registrant's internal control over financial reporting. Materiality, as with all materiality judgments in this area, would be determined upon the basis of the impact on internal control over financial reporting and the materiality standard articulated in TSC Industries, Inc. v. Northway, Inc. 426 U.S. 438 (1976) and Basic Inc. v. Levinson, 485 U.S. 224 (1988). This would also include disclosing a change to internal control over financial reporting related to a business combination for which the acquired entity that has been or will be excluded from an annual management report on internal control over financial reporting as contemplated in Question 3 above. As an alternative to ongoing disclosure for such changes in internal control over financial reporting, a registrant may choose to disclose all such changes to internal control over financial reporting in the annual report in which its assessment that encompasses the acquired business is included.
Q: The definition of the term "internal control over financial reporting" does not encompass a registrant's compliance with applicable laws and regulations, with the exception of compliance with the applicable laws and regulations directly related to the preparation of financial statements, such as the Commission's financial reporting requirements. Are all aspects of the rules promulgated under the Sarbanes-Oxley Act, for example, within that definition?
A: No. While, it may be possible to connect the violation of any law, rule or regulation to the financial statements by observing that if the violation is significant enough it will have a material impact on the registrant's financial statements, we do not believe that compliance with all laws fits within the definition. The Commission's financial reporting requirements and the Internal Revenue Code are examples of regulations that are directly related to the preparation of the financial statements. Conversely, rules requiring disclosure as to the existence of a code of ethics or disclosure as to the existence of an audit committee financial expert are examples of rules promulgated under the Sarbanes-Oxley Act that are not directly related to the preparation of financial statements.
However, as part of management's evaluation of a registrant's disclosure controls and procedures, management must appropriately consider the registrant's compliance with other laws, rules and regulations. Such consideration should include assessing whether the registrant (1) adequately monitors such compliance, and (2) has appropriate disclosure controls and procedures to ensure that required disclosure of legal or regulatory matters is provided. Evaluation of disclosure controls and procedures and internal control over financial reporting in respect of compliance with applicable laws or regulations does intersect at certain points, including, for example, whether the registrant has controls to ensure that the effects of non-compliance with laws, rules and regulations are recorded in the registrant's financial statements, including the recognition of probable losses under FASB Statement No. 5, Accounting for Contingencies.
Q: Must identified significant deficiencies be disclosed either as part of management's report on internal control over financial reporting or elsewhere in a registrant's periodic reports?
A: A registrant is obligated to identify and publicly disclose all material weaknesses. If management identifies a significant deficiency it is not obligated by virtue of that fact to publicly disclose the existence or nature of the significant deficiency. However, if management identifies a significant deficiency that, when combined with other significant deficiencies, is determined to be a material weakness, management must disclose the material weakness and, to the extent material to an understanding of the disclosure, the nature of the significant deficiencies. In addition, if a material change is made to either disclosure controls and procedures or to internal control over financial reporting in response to a significant deficiency, the registrant is required to disclose such change and should consider whether it is necessary to discuss further the nature of the significant deficiency in order to render the disclosure not misleading. A registrant's auditor that is aware of a significant deficiency is required to communicate the significant deficiency to the audit committee as required by PCAOB Auditing Standard No. 2.
Q: Many registrants with global operations have a lag in reporting the financial results of certain foreign subsidiaries for financial reporting purposes. For example, a registrant with a December 31 year-end may consolidate the operations of certain foreign subsidiaries with a November 30 year-end. Is this difference in period ends also acceptable in relation to the assessment of internal control over financial reporting?
Q: The Commission's adopting release for its rules pursuant to Section 404 of the Sarbanes-Oxley Act (Release No. 34-47986) provides that the terms "significant deficiency" and "material weakness" have the same meaning for purposes of those rules as they do under generally accepted auditing standards and attestation standards. PCAOB Auditing Standard No. 2 modified the definitions of the terms "significant deficiency" and "material weakness." Does the Commission staff intend to look to the definitions as they existed when the adopting release was issued or as they have been revised by the PCAOB?
A: When the Commission published its adopting release, the Commission expressed an intention to incorporate the definitions of "significant deficiency" and "material weakness" as they exist in the standards used by auditors of public companies. Looking to the definitions as revised by the PCAOB is consistent with this intention and, accordingly, the SEC staff will apply the PCAOB definitions in interpreting the Commission rules in this area.
Q: In many situations, a registrant relies on a third party service provider to perform certain functions where the outsourced activity affects the initiation, authorization, recording, processing or reporting of transactions in the registrant's financial statements, such as payroll. In assessing internal controls over financial reporting, management may rely on a Type 2 SAS 70 report performed by the auditors of the third party service providers. If the auditors of the third party service provider are the same as the auditors of the registrant, may management still rely on that report? Additionally, may management rely on a Type 2 SAS 70 report on the third party based on a different year-end?
A: In situations where management has outsourced certain functions to third party service provider(s), management maintains a responsibility to assess the controls over the outsourced operations. However, management would be able to rely on the Type 2 SAS 70 report even if the auditors for both companies were the same. On the other hand, if management were to engage the registrant's audit firm to also prepare the Type 2 SAS 70 report on the service organization, management would not be able to rely on that report for purposes of assessing internal control over financial reporting. Management would be able to rely on a Type 2 SAS 70 report on the service provider that is as of a different year-end. Note, however, that management is still responsible for maintaining and evaluating, as appropriate, controls over the flow of information to and from the service organization.
Q: What is the impact of combining the auditor's attestation report on management's assessment of internal controls over financial reporting with the audit report on the financial statements?
A: Item 2-02 of Regulation S-X permits the auditor to combine the attestation report on management's assessment on internal control with the auditor's report on the financial statements. However, in determining whether to combine the reports, the auditor should take into account any issues that may arise if its audit report on the financial statements is expected to be reissued or incorporated by reference into a filing under the Securities Act.
Q: Will the SEC be providing guidance on specific considerations relating to internal control over financial reporting for small business issuers?
A: Although the Commission's final rule implementing Section 404 of the Act does not distinguish between large and small issuers, the Commission, as noted in the release accompanying the final rule, recognized that many smaller issuers might encounter difficulties in evaluating their internal control over financial reporting. The SEC staff would support efforts by bodies such as COSO to develop an internal control framework specifically for smaller issuers.
Q: To what extent may management rely on the registrant's auditor to assist in its development of an assessment process and documentation process in preparation of issuing management's report on internal control over financial reporting?
A: The auditor is allowed to provide limited assistance to management in documenting internal controls and making recommendations for changes to internal controls. However, management has the ultimate responsibility for the assessment, documentation and testing of the registrant's internal controls over financial reporting.
Q: What sources of guidance are available to management to assist them in fulfilling their responsibilities regarding management's assessment and documentation of the internal control over financial reporting?
A: Several sources of guidance are available on the topic of management's assessment of internal control including, for example: the existing books and records requirements; the Commission's final rule on Management's Reports on Internal Control Over Financial Reporting and Certification of Disclosure in Exchange Act Periodic Reports (Release No. 34-47986); and, as referenced in the release on the final rule, the reports published by the Committee of Sponsoring Organizations of the Treadway Commission on internal control.