Free Subscription to CFO Magazine

CFOs Seek Sarbox Triage

(continued)

The CFO finds it interesting that the biggest risks didn't end up being financial ones. The most-often-cited threats include impairment of the company's brand image and breeches of customers' privacy. Nolop says that executives were already made aware of financial risks through the company's routine business activities; for example, during efforts to obtain financing for customers, they learned a great deal about the effects of interest-rate fluctuations. Hedging and other mitigation techniques are already in place at the company for such exposures, he says.

In comparison to a "procedural" approach to regulatory compliance, which tends to treat risks as stemming from isolated business units, the ERM approach looks at the ripple effect throughout the entire company and beyond, according to Nolop. Concerning supply-chain risk, for instance, executives first consider what they would do if the company ran out of certain parts, then address how they'd respond if the parts suppliers ran out themselves.

Ironically, ERM can be a less efficient process than simple Sarbox compliance. For Sarbanes-Oxley — as CFOS know all too well — regulators and auditors have provided pages and pages of implementation guidance. On the other hand, says Nolop, an enterprisewide approach to risk "means you flounder a little bit to come up with the best processes and procedures. But in the end," he adds, "you are able to go where the analysis takes you, and you come up with better understanding."


Reader CommentsDisplaying 3 of 3

  • Jacob James

    Feb 17, 2006 10:48 AM ET

    Going overboard

    It is typical of US regulators to go overboard.AS 2 is a clear example.While there is merit in having Internal controls … more

  • Jessica Byrnes

    Feb 13, 2006 5:20 PM ET

    CFOs Seek Sarbox Triage

    If RTFM means what I think it means, I agree with Edda Junka. Go to our website and see a full copy of TFM beautifully … more

  • edda junke

    Feb 13, 2006 12:23 PM ET

    CFOs should RTFM

    Why is this news? The PCAOB and SEC have included risk-based assessments in SOX since AS-2 (at least). And they … more

Post a comment | View all comments

advertisement

Related White Papers

» More Related White Papers

Business Solutions Center

» More Business Solutions Center Links

advertisement

We Deliver

Newsletters

Webcasts

Enter your email address to begin receiving updates on these topics.