Leveraging Advanced Technology to Modernize SOX Compliance | Deloitte US has been saved
By Lindsay Rosenfeld, Audit & Assurance Partner, Deloitte & Touche LLP and Laura Wong, Audit & Assurance Senior Manager, Deloitte & Touche LLP
Is your SOX compliance program keeping up with the latest available SOX technology? Rapid advances in technology, including automation; data analytics; governance, risk, and controls (GRC) platforms; and Generative Artificial Intelligence (GenAI), could mean that compliance programs implemented just a few years ago may be missing out on important enhancements. Programs implemented even farther back, that have rarely been revisited, may be forgoing even larger gains—from increased efficiency to enhanced quality to reduced costs.
Let’s look at the latest SOX technology and how it can modernize your SOX compliance program.
Modern GRC platforms have moved the needle extensively for SOX compliance programs in recent years. These specialized platforms are designed to consolidate and streamline control and compliance management, including documentation requests, related control testing, and workflow around issues and deficiencies.
GRC platforms can increase SOX program efficiency by centralizing requests and responses, providing real-time status of testing and issue remediation progress, enhancing visibility and reporting with visualization dashboards, and increasing accountability through better assignment of roles and responsibilities.
Data analytics can also play a leading role in modernizing SOX compliance. Analytics tools process large volumes of data to identify patterns, visualize trends, and improve insights for better decision-making. These capabilities allow financial professionals to continuously monitor SOX controls and transactions to detect risks and other issues in real time. This continuous approach is more effective than traditional sample-based testing, because it can identify relevant risks more efficiently and carefully, resulting in timely and accurate risk management.
Many companies that have fallen behind the technology curve may still be relying on a largely manual controls environment built on high volumes of repetitive tasks. One way to remedy this situation is through automation and modernization of manual compliance processes. Automating repetitive, resource-intensive tasks not only transforms efficiency, but it can also free up accounting, finance, SOX, and internal audit professionals to focus on higher-value strategic initiatives.
In addition to automating business processes, today’s automated control testing tools can simplify these efforts by effectively integrating with GRC platforms, data analytics, and GenAI technology. This creates a unified data environment that provides a single source of truth. This level of automation also helps detect potential risks and control deficiencies early, leading to increased efficiency, fewer errors, and better risk management.
More SOX automation platforms are incorporating AI, particularly GenAI, to revolutionize SOX compliance. GenAI has the potential to be a SOX game-changer by harnessing large language model technology and natural language processing capabilities. Deloitte leverages GenAI to provide guidance to an organization’s risk and controls agenda through:
GenAI also has the power to automate, accelerate, and generally improve many other aspects of the SOX compliance life cycle—from risk assessment and controls design to monitoring, remediation, reporting, and testing. The technology can bring speed and efficiency to a SOX ecosystem and improve the strategic focus of SOX and internal audit professionals (see our recent Pulse blog “Leveraging Generative AI for modernized SOX compliance”) for more information on how GenAI is modernizing SOX compliance programs).
Leveraging modern technology can transform your SOX program in a variety of ways and lead to important long-term benefits, including:
Deloitte has a long history of delivering SOX and internal controls over financial reporting services to a wide range of clients. We have the experience and professional oversight to effectively integrate and adapt advanced technology to meet the requirements of a rapidly changing business landscape as well as specific business circumstances. For more information, visit our SOX and internal control over financial reporting services page, and feel free to reach out to us with questions.
The services described herein are illustrative in nature and are intended to demonstrate our experience and capabilities in these areas; however, due to independence restrictions that may apply to audit clients (including affiliates) of Deloitte & Touche LLP, we may be unable to provide certain services based on individual facts and circumstances.
This publication contains general information only and Deloitte is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte shall not be responsible for any loss sustained by any person who relies on this publication.
About Deloitte
Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the “Deloitte” name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.
Copyright © 2024 Deloitte Development LLC. All rights reserved.
Lindsay is an Audit & Assurance partner with 24 years of external audit and advisory experience. As the national market offering leader for governance, risk, and controls within Deloitte's Accounting & Reporting Advisory practice, Lindsay specializes in SOX readiness and the modernization of SOX and internal control programs. She also assists companies in implementing technology solutions to manage these programs effectively. Lindsay serves large public and private multinational clients based in the United States and abroad, with a primary focus on the automotive industry. However, her expertise extends across various industries, leveraging her extensive network within Deloitte to provide comprehensive support in accounting, internal audit, risk management, transformation, technology, HR transformation, ESG initiatives, and more. With deep experience in both US GAAP and IFRS technical accounting matters, Lindsay is well-versed in the accounting and reporting requirements for complex transactions, including revenue recognition, business combinations, goodwill impairment, warranty, pension and OPEB, income taxes, carve-out/spin-off transactions, and initial public offerings. Lindsay's international experience includes a three-year assignment in Italy, where she focused on foreign private issuers with IFRS to US GAAP reconciliations. This global perspective further enhances her ability to navigate and address the diverse challenges faced by her clients.