Controls | Frequently asked questions
Who is this article for?
Users who have questions about the Disclosure Controls or Internal Controls databases in Audit Analytics.
Disclosure Controls and/or Internal Controls subscription.
Audit Analytics maintains two separate databases for controls assessments, corresponding to different sections of the Sarbanes-Oxley Act.
1. Understanding the two types of controls
The two databases correspond to different sections of the Sarbanes-Oxley Act:
- Disclosure Controls (DCs) — SOX Section 302: These controls ensure that material information is reported in a timely manner. DCs assessments are reported quarterly in 10-K, 10-Q, 20-F, 40-F, and their amendments
- Internal Controls over Financial Reporting (ICFR) — SOX Section 404: These controls ensure that transactions are reported completely and accurately. ICFR assessments are reported annually in 10-K, 20-F, 40-F, and their amendments. ICFR includes both a management report and, for certain filers, an auditor's report
Because of the relationship between DCs and ICFR, disclosure controls are often flagged as ineffective because of material weaknesses in internal controls. The DCs database captures weaknesses and deficiencies in both disclosure controls and internal controls, as well as changes in internal controls.
Note: For field-level detail, refer to the data dictionary for each database. See Understanding SOX 302 vs. SOX 404 databases for more information
2. Understanding effective versus not effective assessments
The meaning of "effective" and "not effective" differs between the two controls databases:
ICFR (SOX 404):
Controls are assessed as either effective or not effective. Controls are assessed as "not effective" when the company identifies a material weakness in management's report, or when the auditor's report states that ICFR is ineffective. A significant deficiency alone does not make controls ineffective under SOX 404.
DCs (SOX 302):
Controls are flagged as "not effective" when any of the following conditions exist:
- The registrant states that disclosure controls are "ineffective" or "not effective"
- The registrant qualifies the effectiveness of its disclosure controls
- The registrant identifies a material weakness that impacts the assessment
3. Understanding material weaknesses and significant deficiencies
Material weakness:
A deficiency, or combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis. Material weaknesses are captured in both the DCs and ICFR databases.
Significant deficiency:
A deficiency, or combination of deficiencies, that is less severe than a material weakness but important enough to merit the attention of those responsible for oversight. In ICFR, a significant deficiency does not require a company to declare controls ineffective, so it is generally not captured as a separate data point. In DCs, significant deficiencies are captured under "Other Notable Deficiencies / Disclosures."
Note: The number of weaknesses identified in an Internal Controls record (the count field) reflects the number of unique material weaknesses cited in the company's disclosure. This is not the same as the number of taxonomy tags, since a single weakness may involve multiple taxonomy classifications.