DAVID SIDON
‘Real opportunity’

At least two Massachusetts banks are contemplating stock buy-back plans to avoid being subject to the U.S. Securities and Exchange Commission’s new guidance regarding small public companies’ compliance with Section 404 of the Sarbanes-Oxley Act of 2002.

However, there is still plenty of confusion regarding how the SEC expects small public companies to comply with the measure, which was designed to tighten financial accounting and reporting practices in the wake of several high-profile corporate scandals at the start of the decade.

Small public banks and other companies – those with a market cap below $75 million – have argued for relief from Section 404 due to the cost and resources necessary to comply with its triple-check system. Until recently, some smaller institutions were hoping to avoid the time-consuming and costly measures it will take to follow the same risk-analysis procedures required of larger public companies as stipulated by Sarbanes-Oxley.

However, industry watchers believe the wait-and-see game is over, and any bank that was hoping this would be a non-issue could be facing an 18-month deadline to comply. That time frame could be tight, according to some industry experts.

The new guidance, titled “Internal Control Over Financial Reporting – Guidance for Small Public Companies,” was released on July 11 by the Committee of Sponsoring Organizations (COSO) of the Treadway Commission. Although designed to aid small companies facing a compliance deadline in getting on track, David Sidon, manager of The Navis Group in Danvers, which offers consulting services to financial institutions in risk assessment and regulatory compliance, said the new guidance raises more questions than it answers.

“It doesn’t really help that much,” said Sidon. “Banks are going to have a hard time with it. A lot of them haven’t started because they thought it [the need for small public firms to comply] was going away. They [now] have 18 months for an 18-month project.”

The SEC recently put out a concept release on the matter and is looking for input, said John Heine, spokesman for the regulatory agency. Heine said no official decisions have been made when it comes to how, when or even if small public companies must comply with Section 404.

A report of the SEC Advisory Committee on Smaller Public Companies released on April 23 recommended that small public companies should not have to comply with Section 404 of Sarbanes-Oxley. Heine said even that recommendation is still under consideration. However, several area bankers are no longer counting a reprieve, since the new guidance and statements from the SEC suggest all filers will soon be required to comply.

“The expected actions will also include SEC inspections of [company accounting oversight board] efforts to improve Section 404 oversight and a brief further postponement of the Section 404 requirements for the smallest company filers, although ultimately all public companies will be required to comply with the internal control reporting requirements of Section 404,” the SEC stated in a May 17 release.

The release went on the say the SEC could “issue a short postponement of the effective date of the commission’s rules implementing Section 404 for non-accelerated filers. It is anticipated that any such postponement would nonetheless require all filers to comply with the management assessment required by Section 404(a) of Sarbanes-Oxley for fiscal years beginning on or after Dec. 16, 2006.”

Heine said the SEC is looking at several avenues and could not say when a more formal deadline or decision might be released.

Sidon said the compliance expectation for small public banks and other smaller companies was put on hold for an undetermined amount of time, which some believed could be indefinite after the advisory committee suggested exemption for small institutions. While several bankers saw it as a relief and put the issue on the back burner, others continued to prepare compliance measures, but at a slower pace. He said bankers are now looking at the new guidance, the SEC’s concept report and the potential deadline as a sign that they will soon be required to comply.

Although he would not release the names, Sidon said there are at least two public banks that are hoping to buy back enough stock shares to fall below the threshold that triggers filing Section 404 documentation with the SEC.

“It’s a double-edged sword,” he said, noting that ideally companies want their stock to grow, which could be hindered by a stock buyback, but the costs of compliance also could hurt company profits.

In other cases, smaller banks may put themselves up for sale. Once acquired by a larger institution the financial reporting responsibilities will be shifted to a larger institution more able to bear the costs of compliance. Sidon said he knows of one local bank that sees this as a viable option. Sidon said the new guidance or complying with Section 404 in and of itself should not lead to a dramatic increase in bank mergers, but for banks already struggling with compliance costs and profits, it just might be “the final nail in the coffin.”

“When the law first came out, big companies were expected to do it right away. [The SEC] let the smaller companies have a little more time,” said Sidon. “The bottom line of the whole guidance is do you know where your risks are. But then it begs the question of where is it documented. That’s the burden, getting it down on paper.”

But the burden doesn’t stop there. For banks already operating in a heavily regulated atmosphere, the idea of having yet another costly regulation to deal with can be onerous. Section 404 requires all the areas of risk to be established, evaluated and tested. Then everything needs to be documented. After that an audit is done of the institution’s self-evaluation and scores. In addition to that an independent external audit is conducted. Not only does a lot of time and energy go into preparing for this, but the cost adds up, said Jon K. Skarin, director of federal regulatory and legislative policy for the Massachusetts Bankers Association.

‘An Obligation’
David Richards, president of the Institute of Internal Auditors in Altamonte Springs, Fla., also said that the process is perhaps costing companies more than it has to. He said his institution submitted a letter to the SEC saying the third element of the triple-check system – the independent audit – is unnecessary for small public firms. The IIA is one of the five groups that make up COSO, but the recommendation to relieve companies from the final audit came directly from IIA, said Richards.

Skarin said the cost of complying with Section 404 can be quite significant, especially for small institutions, and on average can cost a bank approximately $900,000 annually.

Richards said the costs of external audits can even reach millions of dollars depending on the company’s size. “If you are starting from scratch, you are going to have a huge expense upfront,” he said.

“This is an additional audit,” said Skarin, who added that banks already have a series of mandated checks and balances in place that is continuing to evolve. “There is a lot more time and money directed at compliance than there ever has been in the past. The compliance issues change as the industry evolves and changes.”

Richards said the bigger picture is that banks and all companies can adopt the guidance as best practices even if not mandated to comply. He said the COSO guidance, which was first created as a best practices document in 1992, does serve a purpose. While larger companies have adopted the first set of guidance as a method for complying with Section 404, smaller companies should adopt the newer COSO guidelines regardless of what the SEC decides, he said.

“I think there are a lot of small companies that say, ‘We don’t need to be concerned about ethics. We are too small to be concerned about ethics.’ You have an obligation,” Richards said. “Even though the SEC might draw the line in the sand, the same manager is still accountable.”

He also said that what COSO has produced is framework, not a checklist. Different industries and companies will need to tailor it to their specific business, he said.

“If an organization doesn’t go through this process, it really doesn’t know where its risks are.”

The SEC asked COSO to produce the guidance for small businesses. Richards said while working on the new guidance, the group found that there really weren’t that many differences. The same principles still apply and the same benefit of assessing risks was there.

“It is really a validation of what we said in 1992,” he said. “The COSO guidance is really designed to provide framework. It really doesn’t matter what the SEC decides on Section 404. There really isn’t a get out of jail free card for small businesses.”

Sidon said that once banks get past their initial reaction of having to deal with an added layer of regulatory burden, evaluating where potential problems and risks lie is a benefit.

“There’s a real opportunity here,” said Sidon.

Sidon said it gives institutions the chance to really question why they do certain things, asking if policies are in place out of tradition or because they serve a specific purpose. He said banks might determine areas in which they can be more efficient as well as uncover potential hazards that may have gone overlooked.

“If they [banks] end up doing it just for compliance, they won’t get a lot out of it,” said Sidon.

Questions Surround Sarbanes-Oxley Compliance

by Banker & Tradesman time to read: 6 min
0