Direct and indirect impact of Sarbanes-Oxley hits private companies
Companies considering IPOs or mergers must now address accountability issues
Computerworld - When Congress passed the Sarbanes-Oxley Act one year ago this month, the mandates to put more stringent controls on corporate accounting practices were primarily aimed at public companies. But executives, consultants and lawyers are starting to realize that there are both direct and indirect implications for privately held businesses as well.
For instance, public and private companies alike have to adhere to the so-called whistleblower provision of the law, under which employees must be permitted to anonymously notify regulators of any potential wrongdoing within a company, said John Hagerty, an analyst at AMR Research Inc. in Boston.
In addition, privately held companies would have to take many of the steps required to demonstrate compliance with Sarbanes-Oxley if they decided to go public or agreed to merge with a public company.
Although the whistleblower provision probably doesn't pose any major IT implications for most companies, the stock-offering and merger considerations do. Just like their publicly traded peers, privately held businesses could be forced to make substantial changes to their system infrastructures and data-reporting capabilities, according to Hagerty and others.
"If you're thinking of going public or it's even in the realm of possibility for you, this is sure as heck something that you'd better plan for," said Robert Handler, an analyst at Meta Group Inc. in Stamford, Conn.
In a survey of 1,400 chief financial officers at private companies that was published in this month's Journal of Accountancy, 44% said they are either reviewing or changing the accounting procedures within their organizations as a result of Sarbanes-Oxley.
In addition, public companies involved in potential acquisition deals with privately held businesses are beginning to push them to document their internal accounting controls and processes, said Jocelyn Arel, a partner at law firm Testa, Hurwitz & Thibeault LLP in Boston. "We're starting to see that in the due diligence process that buyers are going through," said Arel, who is co-chairman of the firm's corporate finance and securities group.
Fred Pauls, corporate records manager at J.R. Simplot Co. in Boise, Idaho, said the privately held agribusiness has already taken steps to address the mandates of Sarbanes-Oxley because it has government contracts that require compliance with the law.
J.R. Simplot, which has annual revenue of more than $3 billion, last year began using an automated records management system developed by Colorado Springs-based Optika Inc. to help index its purchase-order system so it complies with Sarbanes-Oxley record-keeping requirements.
"We do comply in most cases with Sarbanes-Oxley due to previous [internal financial control] policies, and this software system is a key part of that," Pauls said.
In the future, he said, J.R. Simplot will likely take advantage of a link that's already in place between Optika's Acorde Records Management software and J.D. Edwards & Co.'s financial applications "to accommodate other financial reporting provisions of Sarbanes-Oxley."
Read more about Gov't Legislation/Regulation in Computerworld's Gov't Legislation/Regulation Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Gov't Legislation/Regulation White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Gov't Legislation/Regulation Webcasts