Categories
Blog

Day 21 of One Month to More Effective Internal Controls-Revenue Recognition, Internal Controls and Compliance

Financial Accounting Standards Board (FASB) issued Accounting Standards Update No. 2014-09, Revenue from Contracts with Customers (Topic 606) for public business entities, certain not-for-profit entities, and certain employee benefit plans. The amendments become effective for public entities for annual reporting periods beginning after December 15, 2017. In other words, we are now less than six months away from a new Revenue Recognition (“new rev rec”) standard, which may significantly impact the compliance profession, compliance programs, and compliance practitioners. I visited with Joe Howell, Executive Vice President (EVP) at Workiva Inc., and asked him if he could walk me through some key changes and how they might impact compliance. FASB recognized that its revenue recognition requirements around the U.S. generally accepted accounting principles (GAAP) differed from those in the International Financial Reporting Standards (IFRS) and that both sets of requirements needed improvement. This led to a project by FASB and the International Accounting Standards Board (IASB) to jointly clarify the principles for recognizing revenue and to develop a common converged revenue standard for GAAP and IFRS. Hence the new rev rec standard. The implementation will be a massive undertaking. According to Howell, “The accounting standard is 700 pages long, and in the US accounting literature, it replaces over 200 other pieces of accounting guidance on revenue.” The official name is “Revenue from Contracts with Customers,” and Howell noted there are a “lot of surprises, and the thing that is true for almost everybody is that they are going to be facing some level of change in the way they account and report revenue. They will most certainly have to change how they disclose their revenue-related things. Included in the revenue standards are over six pages worth of new disclosure requirements.” One of the key differences in this new rev rec standard is that it requires companies to disclose new information beyond data a company might have been required to release in the past. Howell thinks this will pressure auditors “to get comfortable with what the company provided them and which they incorporated into their decision-making process in forming an opinion. This is quite different for disclosure control because the auditor’s typically not relying on those.” This will create risks for auditors adjusting to the new rev rec standard because as they learn more about it and apply it going forward into 2018, they may have to revisit prior reporting and revise some of it. This is important to the compliance profession and the compliance practitioner because internal controls over financial reporting involved in implementing this new standard are critical to the effective use of implementation and how you implement it. The Securities and Exchange Commission (SEC) has said explicitly in several public statements and through their early comment letters on disclosures made in advance of implementation that companies must inform the SEC about the accounting policies that they are changing and how this new standard will affect a company’s accounting processes, and finally how those effects are going to be managed. Howell believes “The SEC is making it clear that this is a real compliance issue.” Moreover, the SEC has indicated that these disclosures are central to the new rev rec standard. Howell said, “typically, if a company has some sort of failure in their disclosures for an accounting standard, they’re treated under section Sarbanes-Oxley (SOX) Section 302 of the SEC rules, and that has a level of significance or liability, which is much lower than the liability that a company might face under SOX Section 404, which has to do with the actual internal controls over financial reporting.” While disclosure of internal controls might not typically bring Section 404 scrutiny, they may now do so under the new rev rec standard. Howell articulated that when performing a financial audit, an auditor would usually not rely on a disclosure control in the past. However, under the new rev rec standard, if there is a change during the year in how an auditor views a disclosure control, it could require them “to go back and either figure out if the audit work that they did is tainted and they need to go back and do that work in the form of substantive testing, or they need to go back to see if there were mitigating controls that were in place that still allowed them to rely on the internal control processes to get comfortable with what the company provided them and which they incorporated into their decision-making process in forming an opinion. This is quite different for disclosure control because the auditor’s typically not relying on those.” Of course, this is overlaid with the requirements of effective internal controls under the Foreign Corrupt Practices Act (FCPA) and the lack of materiality standards. One only need to consider the Wells Fargo fraudulent accounts scandal to see how a lack of materiality does not prevent the types of risk from moving forward to become huge public relations disasters, hundreds of millions of dollars in fines and costs estimated at over $1bn for failures of internal controls. Yet there are other tie-ins into compliance that the compliance practitioner needs to understand and prepare for going forward. The prior rev rec standard was rules-based. As a lawyer, that was an approach I was quite comfortable with both from a learning standpoint and communicating with business folks. But now, the standard is much more judgment-based, and when a standard is more judgment based, there can be more room for manipulation. Howell explained the response by compliance is “making sure that you have changes in the business processes necessary to gather the information that has not previously been required to continue to monitor; how that information is factoring into the judgments that managers must make as they report their revenue under the new standard; and that those judgments themselves are properly documented.” This final point demonstrates the convergence and overlap between the compliance profession, compliance programs, and compliance practitioners going forward. Compliance internal controls are in place to both detect and prevent. They can also be used to gather the information that will be presented to auditors under the new rev rec standard. Many professionals are focused on the new rev rec from the auditing and implementation perspective. However, suppose you are a Chief Compliance Officer (CCO). In that case, you might want to go down the hall and have a cup of coffee with your Chief Financial Officer (CFO) and find out what internal controls might be changing or that they might be adding and consider how that will impact compliance in your organization.

Three Key Takeaways

  1. An effective internal controls system provides reasonable assurance of the entity’s objectives relating to operations, reporting, and compliance.
  2. There are two over-arching requirements for effective internal controls. First, each of the five components is present and functional. Second are the five components operating together in an integrated approach.
  3. You can use the Tem Hallmarks of an Effective Compliance Program for an anti-corruption compliance program as your guide to testing against.

For more information on improving your internal controls management process, visit this month’s sponsor Workiva at workiva.com. The new FASB rev rec standard has significant implications for the compliance practitioner going forward.]]>

Categories
Compliance Kitchen

State Department ISN Update


The State Department’s ISN restricts 8 entities for proliferation activities and bans U.S. government procurement.  The Kitchen reviews this action in more detail.

Categories
This Week in FCPA

Episode 266 – the Charlie Watts Tribute edition


As drumheads worldwide mourn the death of Rolling Stones drummer Charlies Watts and Jay goes ‘on the road’; Tom is joined by special guest host, Kristy Grant-Hart to look at some of this week’s top compliance and ethics stories which caught their interest on This Week in FCPA in the Charlie Watts Tribute edition. 

Stories

1.     Is ESG replacement for government inaction? Lawrence Heim in practicalESG.
2.     Why compliance should lead the ESG effort. Kristy Grant-Hart in Compliance Kristy
3.     What did the current Freddie Mac CCO learn from the 2008 financial crisis? Mengqi Sun in WSJ Risk and Compliance Journal.
4.     What is ‘intentional integrity’? Aly McDevitt in Compliance Week.
5.     Defense industry struggles with cybersecurity. Matt Kelly in Radical Compliance.
6.     How has the pandemic impacted the ABC fight in Latin America? Geert Aalbers in the FCPA Blog.
7.     More oral argument as both sides appeal Hoskins trial verdict. Dylan Tokar in WSJ Risk & Compliance Journal.
8.     Debunking attacks on the Business Roundtable’s Statement on the Purpose of a Corporation. Marty Lipton in Harvard Law School Forum on Corporate Governance
9.     The Mozambique hidden debt scandal. Rick Messick in GAB.
10.  What happens to compliance when you have a fractured C-Suite?  Mike Volkov in Corruption Crime and Compliance.

 

Podcasts and Events

11.  On Innovation in Compliance this week I interview Kristy Grant-Hart, Joe Murphy and Kirsten Liston about their latest book, The Compliance Entrepreneur. Check out the show here.
12.  On The Compliance Life, in August I visit with Kortney Nordrum CCO at Deluxe. In Episode 1, from Red Wing to Israel. In Episode 2, From Freddie Mac to the law. In Episode 3, how Kortney found her professional passion – Compliance.
13.  Compliance Week is having an open house this month as they have dropped their firewall. You can check out the entire publication for no charge. Check it out here.
14.  Breaking News features The Compliance Handbook, 2nd edition. Check out the Breaking News feature here. Purchase The Compliance Handbook, 2nd edition here. Find out more about The Compliance Handbook, 2nd edition in an upcoming Zoom webinar, on Wednesday, September 1 at 8:30 AM ET; hosted by the Azevedo Sette law firm and Charles River Associates. To RSVP email tcintra@azevedosette.br
15.  Join K2 Integrity September 15 for a round-table discussion as we reflect on the 20th Anniversary of September 11 and consider its impact on countering terrorist financing and illicit financing, and the continuing risks to national security. The roundtable will include members of the team that spearheaded the post-9/11 counter illicit finance regime: Juan Zarate, Chip Poncy, Danny McGlynn, moderated by Dr. Michele L. Malvesti. Information and Registration here.
16.  The week of 9/11, Tom will run a 6-part special podcast series on Looking Back on 9/11. In this series he will visit with professionals from a variety of compliance perspectives who will discuss how 9/11 changed our profession, including three who were in NYC during the attacks. Check it out on the Compliance Podcast Network.
17.  Tom pays tribute to Charlie Watts.
Tom Fox is the Voice of Compliance and can be reached at tfox@tfoxlaw.com. Special guest host Kristy Grant-Hart can be reached at kgranthart@sparkcompliance.com.

Categories
Creativity and Compliance

Debunking Comedy & Compliance Concerns


Where does creativity fit into compliance? In more places than you think. Problem-solving, accountability, communication, and connection – they all take creativity. Join Tom Fox and Ronnie Feldman on Creativity and Compliance, part of the Compliance Podcast Network. In this episode, Tom and Ronnie look at the common objections to using comedy in compliance training and communications and debunk them all.

  • Well, we’re a conservative company
  • We don’t do humor here or we tried humor once and it didn’t work
  • Employees already get tons of communications, so we don’t have an appetite for more compliance communications.
  • We need to focus on our core training first
  • We’re global so humor doesn’t work

Resources:
Ronnie Feldman (LinkedIn)
Learnings & Entertainments (LinkedIn)
Ronnie Feldman (Twitter)
Learnings & Entertainments (Website)
60-Second Communication & Awareness Shorts – A variety of short, customizable, quick-hitter “commercials” including songs & jingles, video shorts, newsletter graphics & Gifs, and more. Promote integrity, compliance, the Code, the helpline and the E&C team as helpful advisors and coaches.
Workplace Tonight Show! Micro-learning – a library of 1-10-minute trainings and communications wrapped in the style of a late-night variety show, that explains corporate risk topics and why employees should care.
Custom Live & Digital Programing – We’ll develop programming that fits your culture and balances the seriousness of the subject matter with a more engaging delivery.
Tales from the Hotline – check out some samples.

Categories
Daily Compliance News

August 27, 2021 the Will Holmes Tell a Tale edition


In today’s edition of Daily Compliance News:

  • Will Elizabeth Holmes tell her story at trial? (WSJ)
  • Investigation of an investigation. (WSJ)
  • Capitol police officers sue Trump over insurrection. (NYT)
  • 50 more SPAC lawsuits? (Reuters)