Share on LinkedInShare on LinkedIn

ARTICLE · 29 MAY 2003

Complying with the SEC´s New Certification and Disclosure

United StatesFinance and Banking

In all the hue and cry over the Sarbanes-Oxley Act of 2002, and the blizzard of coverage it has received in the mainstream press and by law firms recently, far more attention has been given to the form and substance of the certifications to be made by the CEO and the CFO in quarterly and annual reports than has been paid to the equally important question of how issuers should go about designing and implementing processes that will provide the CEO and the CFO with an appropriate basis for making the required certifications. The possibility of obtaining internal back-up certifications from officers, business unit heads, and key accounting personnel about the information for which they are responsible has been offered as one way to address this concern, and that may be advisable in some instances. However, simply adding an internal-certification requirement without at the same time reevaluating the entire process by which the required reports are developed is clearly an inadequate response. A far more rigorous process is called for by Sarbanes-Oxley, and by new rules recently published by the SEC to implement the certification requirements of the Act.

The New Requirement: "Disclosure Controls and Procedures"

Under the SEC's new rules, every public company is required to maintain and continuously evaluate "disclosure controls and procedures" that are designed to ensure that the information that is required to be disclosed by the issuer in the reports it files with the SEC is recorded, processed, summarized, and reported as required by the SEC's rules in a timely manner. In adopting this requirement, the SEC made clear that it sees an important distinction between the disclosure controls and procedures that it is requiring companies to develop and implement and the internal controls that its rules have previously required companies to have in place for financial reporting and asset control purposes. While internal controls will continue to play a critical role in assuring that financial data in a company's reports serve their intended purpose, disclosure controls and procedures must function more broadly to address the overall quality and timeliness of the company's disclosures generally. In addition to ensuring the timely collection and evaluation of financial and other business information called for by the specific requirements of the SEC's rules, the issuer's disclosure controls and procedures must be designed to capture all information that is relevant to an assessment of important developments and risks pertaining to the issuer's business.

This distinction between internal controls and disclosure controls and procedures is reflected in the certification requirement set forth in the rules. Each CEO and CFO must certify that:

  • The certifying officer has reviewed the report that is being filed;
  • Based on the certifying officer's knowledge, the report does not contain any material misstatements or omissions;
  • Based on the certifying officer's knowledge, the financial content of the report fairly presents in all material respects the financial condition, results of operations, and cash flows of the issuer;
  • The certifying officers are responsible for establishing and maintaining disclosure controls and procedures and have:
    • Designed such disclosure controls and procedures to ensure that material information is make known to them by others within the organization;
    • Evaluated the effectiveness of the issuer's disclosure controls and procedures as of a date within 90 days before filing; and
    • Presented in the report their conclusions about the effectiveness of the disclosure controls and procedures based on that evaluation;
  • The certifying officers have disclosed, based on their most recent evaluation, to the issuer's auditors and audit committee:
    • All significant deficiencies in the design or operation of internal controls which could adversely affect the issuer's financial reporting and have identified for the auditors any material weaknesses in internal controls; and
    • Any fraud, whether or not material, that involved management or employees with a significant role in internal controls, and
  • The certifying officers have indicated in the report whether there were significant changes in internal controls or in other factors that could significantly affect internal controls since the last evaluation, including corrective actions taken with regard to significant deficiencies and material weaknesses.

As noted, public companies have long been required to maintain internal controls to enable them to prepare accurate financial statements and maintain control over their assets. This area, which has been primarily the domain of a company's internal and external auditors, deserves renewed attention in light of the foregoing certification requirements, and all public companies should be carefully reviewing their internal controls with their internal and external auditors in response to the new rules. Disclosure controls and procedures, on the other hand, have existed in some form or fashion for most issuers but have never been the subject of substantive federal regulation.

The new rules impose on each reporting issuer an independent obligation to maintain adequate disclosure controls and procedures, and to evaluate their effectiveness within 90 days of the filing of any required report, so that its CEO and CFO will have an appropriate basis for making the required certifications. However, the new rules do not dictate the content of the required disclosure controls and procedures, nor do they tell issuers what procedures should be followed in making the required quarterly evaluation. Instead, the SEC simply indicated that it expected each issuer to develop a review and evaluation process "that is consistent with its business and internal management and supervisory practices."

Steps You Should Take Now

In the June 2002 release in which it first proposed that issuers be required to adopt disclosure controls and procedures, the SEC noted that "most companies already maintain internal systems, either formal or informal, for gathering . . . information to satisfy their Exchange Act reporting obligations." It is no doubt true that most companies, through custom and practice, have developed informal processes for completing and filing their SEC reports in a timely fashion and in accordance with law. However it also is no doubt true that systems and procedures that might have easily passed muster a few years ago would clearly fail to make the grade today, and every SEC reporting company should respond to the new rules by undertaking an immediate effort to identify, rationalize, improve upon (where necessary), and formalize its disclosure controls and procedures.

Unfortunately, due to the wide variety of organizations that are subject to this new requirement, it is impossible for anyone to prescribe a single set of controls and procedures that will be appropriate for every company. As a result, many of the suggestions we make below may be inappropriate to your company or may need to be adapted to fit your company's needs. What is most important is that each company, and its CEO and CFO, conduct a critical evaluation of its disclosure controls and procedures initially, and thereafter within 90 days before the filing of each annual and quarterly report, to assure that they are sufficient to enable the company to prepare complete and accurate SEC reports on a timely basis and to apprise the CEO and CFO of material information concerning the company.

Step One: Inventory your existing procedures.

As noted, the new rules do not require you to discard existing processes that have served your company well in the past and start over. Instead, the first step toward establishing appropriate disclosure controls and procedures should be to identify and describe the disclosure controls and procedures you already have in place to satisfy filing obligations, so that they may be critically evaluated for effectiveness. Depending on the nature of your current processes, implementing appropriate disclosure controls and procedures may simply be a matter of making incremental additions to or modifying your existing controls and procedures--or you may be starting from a cleaner slate. In any event, starting your disclosure controls and procedures assessment with an understanding of your current procedures should help minimize disruption to the normal financial reporting process, reduce incremental compliance burdens, and make it easier to transition company personnel into the new regime. This inventory of your existing procedures will then become the starting point for developing disclosure controls and procedures that are both appropriate to your organization and sufficient to satisfy the law.

Appoint an SEC Reports Committee.

The only concrete suggestion offered by the SEC when it adopted the new rules was to appoint a committee that would be responsible for making materiality determinations and otherwise causing the appropriate filings and reports to be prepared on a timely basis and in conformity with the requirements of the securities laws. This committee, which will be referred to for convenience as the SEC Reports Committee, should report directly to the CEO and CFO, who bear the ultimate responsibility under the law for the results of the committee's work. The SEC suggested the following members for the SEC Reports Committee:

  • The principal accounting officer or controller
  • The principal risk-management officer
  • The chief investor relations officer

The SEC also suggested that the general counsel or senior in-house attorney with securities compliance responsibility also be a member, but we believe it may be preferable to designate such persons as 'counsel' to the committee as opposed to making them actual members. This precaution may afford some committee communications the protection of the attorney-client privilege, although the availability of the privilege would depend on the facts of the situation, and may be very limited.

There are several other persons whom you may wish to consider as members, recognizing that you will not want the committee to become so large as to become unmanageable:

  • The company's director of SEC or financial reporting or any other person with significant SEC reports-drafting responsibility
  • A representative from the internal-audit function
  • A representative from the corporate secretary's office

The CEO or CFO may serve on the SEC Reports Committee, but it is clearly not necessary for either of them to do so.

Finally, there are some persons you may wish to invite to meetings of the SEC Reports Committee, but who would not be considered members of the committee. They include:

  • Information sources, including operational and financial representatives from major business units and personnel with responsibility for completing discrete SEC disclosure items
  • A representative from the independent auditors
  • A representative from outside counsel

Meetings of the SEC Reports Committee.

The SEC Reports Committee should meet at least once before the filing of a Form 10-Q. With respect to Form 10-Ks and other documents in the annual reporting cycle such as the proxy statement and annual report to shareholders, more frequent meetings will likely be needed.

More significant than the number of meetings are the preparation for and agenda set for a meeting.  Before a meeting discussing a draft SEC report, attendees should receive, sufficiently ahead of time to permit a meaningful review, a packet or binder of materials which would include the draft SEC report that is under consideration, as well as any other materials that may be helpful to the committee, such as the prior period filing, backup financial or operational reports, and materials illustrating how other industry participants or competitors are dealing with disclosure issues that may also be facing the issuer.

In preparation for a particular report, the committee's meeting agenda should be carefully considered, with a view toward focusing the committee's attention on potential disclosure issues that may not yet have been fully developed or properly addressed. In addition to discussing the various materials that were provided in advance of the meeting, the committee should discuss any material changes to prior period disclosures that are reflected in the draft, material developments in the issuer's business since the prior filing, and any other unusual issues that may have been arisen in the course of preparing the draft.

For quarterly and annual reports, it is particularly important to inquire about the conduct and results of the quarterly review or annual audit of the company's financial statements. In making any inquiries to financial attendees, including the independent auditors, it may be useful to reiterate that materiality is not judged exclusively by GAAP for disclosure purposes, but rather includes anything material to a reasonable shareholder or investor. In general, the committee's inquiries should be designed to apprise the committee of any unusual inquiries that were made or responses received by the company's internal or external auditors, any weaknesses or deficiencies that may have been identified in the company's internal controls, and any significant disagreements that may have occurred between the company and its auditors during the course of the audit.

Inquiries of attendees from the operational side of the business may be equally important. These attendees may be the best information sources for non-financial data. Operational attendees, including from major business units, could be asked about business trends, including product and service demand and supply, major customer developments, and competition issues. Legal or risk-management attendees may also serve as information sources for litigation and other contingent liabilities.

Clearly, it may not be practical to include, in a single meeting, all of the individuals of whom the committee may wish to make inquiries along the lines suggested above. The committee's procedures may instead provide for delegating certain inquiries to individual committee members, who would then report back to the committee, or for certain key individuals to provide written reports to the committee that would specifically address the particular matters the committee would inquire about if the individuals were present. However, the committee should remain responsible for assuring that all appropriate inquiries are in fact made, and for ensuring that its timetable and procedures allow for appropriate follow-up by the committee to any information that it may choose to collect outside of a formal meeting.

Involving the CEO and CFO.

The whole point of the certification requirement is to motivate senior management to take an active role in the SEC reporting process. Consequently, the CEO and CFO should read the report draft before filing. It is probably most efficient for the certifying officers to read a draft that has already been subjected to the SEC Reports Committee process, although time constraints may require a simultaneous circulation to the committee and the certifying officers.

The certifying officers should be provided with the same packet or binder of materials the SEC Reports Committee received before its meeting, or a similar packet of materials that includes those items that the SEC Reports Committee believes may be of particular interest to the certifying officers. A marked version of the report showing the changes made as a consequence of the SEC Reports Committee's review might also be included. A written summary of the major matters and issues discussed in the meeting could also be included, but this information could also be conveyed in a meeting between the committee designee and the certifying officers.

After giving the certifying officers an opportunity to read the draft report that emerged from the committee process, a designee from the committee should meet with the CEO and CFO. Just as auditors have "required communications" they must engage in with the audit committee in connection with an annual audit, we think the meeting between the committee or its designee and the certifying officers should be required to cover certain critical matters, such as the following:

  • General summary of the SEC Reports Committee meetings, including the procedures followed by the committee and the persons involved in the process
  • Discussion of the major issues, disputes, and similar matters uncovered or raised during the committee process, including the committee's resolution, recommendations, or consensus on those matters
  • Solicitation of any comments from the CEO and CFO on the report
  • Discussion of matters related to the required quarterly evaluation of disclosure controls and procedures

Use of a Disclosure Coordinator.

One of the members of the SEC Reports Committee should be designated as the "disclosure coordinator," whose responsibilities could include any or all of the following:

  • Preparation of meeting agenda and materials for SEC Reports Committee meetings
  • Monitoring competitors' filings and analyst and industry reports
  • Monitoring published forecasts and other forward-looking statements to assure that they are updated as and when required
  • Serving as "point person" for the committee in addressing the question of whether an 8-K report must be filed when a material event occurs, and causing the 8-K to be prepared and filed in a manner that is consistent with the company's disclosure controls and procedures, taking into account the applicable time constraints
  • Keeping a written record of meetings of the committee, and following up on matters that cannot be finally resolved at a committee meeting
  • Meeting with the CEO and CFO after the draft report has emerged from the SEC Reports Committee and been read by the CEO and CFO
  • Following up on questions or comments raised by the CEO and CFO as a consequence of their review
  • Keeping appropriate written records of the company's disclosure controls and procedures, as well as the application of the those controls and procedures to each particular report

Develop Report Drafting Practices and Capabilities.

The area where most companies probably already have disclosure controls and procedures of some sort in place is in the report-drafting stage. Nevertheless, to the extent these practices have amounted to informal customs, the time has come to give them shape and definition, and to consider how they can be improved. Report drafters probably already have a list, whether or not written, of 'go-to' personnel for the collection of certain non-financial data, such as executive-compensation information. Companies should educate information sources on what exactly they are being asked to provide to the report drafters. The company then should critically examine the report drafters' existing methods of collecting information necessary for the assembly of SEC reports, asking themselves questions such as:

  • Are the report drafters asking the right people for the right information?
  • Are they receiving data in the most efficient format?
  • Do the information sources understand the purposes for which the information is being solicited?

The persons who prepare the initial draft of SEC reports should develop checklists for the completion of SEC reports, recognizing that over-reliance on checklists and to-the-letter compliance with line-item disclosure requirements can lead report drafters to overlook the company's general obligation to present the required information in a manner that includes all material facts relating to the matter being disclosed. The company also should revisit and perhaps revise the report drafters' timelines for completing reports, building in additional time for the SEC Reports Committee process, review of the reports by the CEO and CFO, and other steps that may be required as a consequence of the disclosure controls and procedures and internal controls assessments that may ultimately be adopted.

Subordinate Certifications.

Many public companies have already adopted the practice of obtaining certain certifications, typically tracking the certifications being made by the company's senior officers, from subordinate officers with SEC reporting responsibilities. These backup certifications may have the beneficial effect of focusing subordinate officers on the reporting process and on observing adequate disclosure controls and procedures. In some organizations, however, subordinate officers who are not accustomed to giving such certifications may be reluctant to provide them, regardless of the quality of their work on the reports, while others may routinely provide the certification, notwithstanding any reservations they may have, out of a concern that to do otherwise could jeopardize their jobs.

Whether to solicit backup certifications from subordinate officers, which officers to solicit, and the form of these certifications are matters within the discretion of the company, and are decisions heavily dependent on the company's particular circumstances. What is important to recognize, however, is that subordinate certifications will not be considered an acceptable substitute for disclosure controls and procedures that can reasonably be expected to result in timely and accurate disclosures.

Moreover, to enhance the likelihood that subordinate certifications will be viewed as well-considered disclosure controls and procedures and not mere window-dressing, any such certifications should be crafted to take into account the particular certifying individual's position and responsibilities, and not simply mimic the certifications being provided by the CEO and CFO.

Role of Outside Advisors.

Consultation with outside accountants and counsel on a routine basis has been fairly commonplace in the past. In light of the new requirements, it is important to identify the specific ways in which these advisors can help companies satisfy their reporting obligations. That can perhaps best be accomplished by consulting directly with these advisors, who are familiar with both the company and the applicable legal requirements. However, it is equally important to recognize the limitations of relying on outside advisors. Outside advisors are not as intimate with the day-to-day operations of the company as internal participants in the process. Although they can provide advice, based on the facts presented to them, decision-making on the content of SEC reports must be left to the final disclosure decision-makers--usually the CEO and CFO.

Role of the Audit Committee.

Do the certifying officers need to meet with the audit committee before the filing of a quarterly or annual report to discuss the report? The Sarbanes-Oxley Act does not require it, but proposed New York Stock Exchange listing standards would, and such a meeting may well become an SEC Reports Committee "best practice," regardless of whether it is legally required.

Many companies convene an audit committee meeting before each earnings release. However, the draft SEC report relating to the time period covered by the earnings release would not ordinarily be ready at that time. To enable the audit committee to provide meaningful input into the report preparation process, companies may have to accelerate even more the preparation of SEC reports in order to squeeze the SEC Reports Committee and CEO/CFO review process in before the audit committee meeting, or schedule an additional audit committee meeting per quarter--neither of which is likely to be an attractive option. CEOs and CFOs should consult with their audit committees to work out the best solution to this problem.

Evaluation of Disclosure Controls and Procedures.

The new rules require that, within 90 days before the filing of each quarterly and annual report, "an evaluation must be carried out under the supervision and with the participation of the issuer's management, including the issuer's [CEO and CFO], of the effectiveness of the design and operation of the issuer's disclosure controls and procedures." Consequently, any issuer's disclosure controls and procedures must include a process for quarterly evaluation under the supervision and with the participation of the CEO and CFO.

The SEC has provided no guidance as to how to evaluate disclosure controls and procedures. Each company must therefore develop its own set of inquiries and "tests of disclosure controls." We believe the evaluation can begin either at the SEC Reports Committee level or the certifying officer review level, but it seems clear that active involvement by the certifying officers is required.

The disclosure coordinator can serve as agent for the CEO and CFO in performing tests of disclosure controls. These may include "spot checks" to see if information sources have been polled--for instance, the disclosure coordinator might call a major business unit operational manager and determine whether the report drafters solicited information from him or her. For persons who submit comments to the report, the disclosure coordinator could attempt to confirm whether all the comments were appropriately addressed.

Written Record and Policies.

We have suggested that the disclosure coordinator be charged with creating a record of the disclosure controls and procedures observed with respect to each SEC report. The level of detail of this record is a matter of judgment. Documentation regarding the operation of and compliance with disclosure controls and procedures and the required evaluation process should generally be summary in nature but must be sufficient to evidence the procedures that were followed. An overly detailed record that documents every question raised throughout the process is unnecessarily time-consuming and may expose the company to the risk that records made in good faith might be misconstrued by plaintiff's attorneys seeking to make a case against the company. Particularly as these procedures are being developed, it is important that issuers consult with their counsel about the appropriate form and substance of this documentation to avoid creating a record that could harm the company in future litigation.

Creating the Right Disclosure Environment.

The most carefully crafted disclosure controls and procedures will likely fail if senior management does not maintain and communicate the right disclosure environment and philosophy--one of candor and recognition of the duty of the company and its senior officers to keep investors and shareholders informed about the matters covered by the company's SEC reports. This attitude should be clearly conveyed to subordinate officers, both in words and in the company's actions. This disclosure environment should encourage the reporting of material information by lower-level employees to those individuals who will be involved in the reporting process. Persons who may have access to material information should know who serves on the SEC Reports Committee and should be able to inform the SEC Reports Committee or the audit committee of matters anonymously and without fear of retaliation. Employees should be made to understand that reporting such material information is viewed favorably by senior management, because it enables the company and its senior management to fulfill important legal and moral obligations to its shareholders and investors.

In responding to the new rules, most public companies will be navigating, at least to some extent, in uncharted waters. It is important that all reporting companies take steps to demonstrate the kind of commitment to enhanced disclosure controls and procedures that is contemplated by the new rules. However, in light of the very real risk that a company's good faith attempts to comply with the new rules might ultimately be used against it in future litigation, it is important to proceed with caution and to work closely with your securities counsel as you seek to develop appropriate disclosure controls and procedures, including required quarterly evaluation processes.

The information contained in this article is not intended as legal advice or as an opinion on specific facts.  For more information about these issues, please contact Dan Falstad at 404-815-6500, or contact us through our Web site at www.KilpatrickStockton.com.

The content of this article does not constitute legal advice and should not be relied on in that way. Specific advice should be sought about your specific circumstances.

 

See more popular content from