翻訳と辞書
Words near each other
・ Sowriyur
・ Sowt Gavaber
・ Sowthistle yellow vein virus
・ Sowti
・ Sowton
・ Sowwah Square Tower 1
・ Sowwah Square Tower 2
・ Sowwah Square Tower 3
・ Sowwah Square Tower 4
・ Sowy River
・ Sowy, Greater Poland Voivodeship
・ Sowy, Warmian-Masurian Voivodeship
・ SoX
・ Sox
・ SOX (operating system)
SOX 404 top–down risk assessment
・ Sox Appeal
・ Sox Fest '09
・ SOX gene family
・ Sox Harrison Stadium
・ Sox Raymond
・ Sox Walseth
・ SOX1
・ SOX10
・ SOX11
・ SOX12
・ SOX13
・ SOX14
・ SOX15
・ SOX18


Dictionary Lists
翻訳と辞書 辞書検索 [ 開発暫定版 ]
スポンサード リンク

SOX 404 top–down risk assessment : ウィキペディア英語版
SOX 404 top–down risk assessment

In financial auditing of public companies in the United States, SOX 404 top–down risk assessment (TDRA) is a financial risk assessment performed to comply with Section 404 of the Sarbanes-Oxley Act of 2002 (SOX 404). The term is used by the U.S. Public Company Accounting Oversight Board (PCAOB) and the Securities and Exchange Commission (SEC). The TDRA is used to determine the scope and required evidence to support management's testing of its internal controls under SOX404. It is also used by the external auditor to issue a formal opinion on the company's internal controls. However, as a result of the passage of Auditing Standard No. 5, which the SEC has since approved, external auditors are no longer required to provide an opinion on management's assessment of its own internal controls.
Detailed guidance about performing the TDRA is included with PCAOB Auditing Standard No. 5 (Release 2007-005 "An audit of internal control over financial reporting that is integrated with an audit of financial statements")〔(PCAOB Auditing Standard No. 5 )〕 and the SEC's interpretive guidance (Release 33-8810/34-55929) "Management's Report on Internal Control Over Financial Reporting".〔(SEC Interpretive Guidance )〕〔(SEC List of SOX Guidance )〕 This guidance is applicable for 2007 assessments for companies with 12/31 fiscal year-ends. The PCAOB release superseded the existing PCAOB Auditing Standard No. 2, while the SEC guidance is the first detailed guidance for management specifically.
The language used by the SEC chairman in announcing the new guidance was very direct: "Congress never intended that the 404 process should become inflexible, burdensome, and wasteful. The objective of Section 404 is to provide meaningful disclosure to investors about the effectiveness of a company’s internal controls systems, without creating unnecessary compliance burdens or wasting shareholder resources.” 〔(SEC Press Release 2007-101 )〕 Based on the 2007 guidance, SEC and PCAOB directed a significant reduction in costs associated with SOX 404 compliance, by focusing efforts on higher-risk areas and reducing efforts in lower-risk areas.
TDRA is a hierarchical framework that involves applying specific risk factors to determine the scope and evidence required in the assessment of internal control. Both the PCAOB and SEC guidance contain similar frameworks. At each step, qualitative or quantitative risk factors are used to focus the scope of the SOX404 assessment effort and determine the evidence required. Key steps include:
# identifying significant financial reporting elements (accounts or disclosures)
# identifying material financial statement risks within these accounts or disclosures
# determining which entity-level controls would address these risks with sufficient precision
# determining which transaction-level controls would address these risks in the absence of precise entity-level controls
# determining the nature, extent, and timing of evidence gathered to complete the assessment of in-scope controls

Management is required to document how it has interpreted and applied its TDRA to arrive at the scope of controls tested. In addition, the sufficiency of evidence required (i.e., the timing, nature, and extent of control testing) is based upon management (and the auditor's) TDRA. As such, TDRA has significant compliance cost implications for SOX404.
==Method==

The guidance is principles-based, providing significant flexibility in the TDRA approach. There are two major steps: 1) Determining the scope of controls to include in testing; and 2) Determining the nature, timing and extent of testing procedures to perform.

抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)
ウィキペディアで「SOX 404 top–down risk assessment」の詳細全文を読む



スポンサード リンク
翻訳と辞書 : 翻訳のためのインターネットリソース

Copyright(C) kotoba.ne.jp 1997-2016. All Rights Reserved.