CHAPTER 1 – Introduction
The corporate audit committee plays a key role in safeguarding shareholder
interests, yet it operates in a challenging environment (DeZoort, Hermanson,
Archambeault, & Reed, 2002). For the past two decades, audit committees have been the
focus of many corporate governance discussions (Gendron & Bédard, 2006). Given the
accounting scandals, financial crises, pressures to achieve growth, and economic
uncertainty of recent years, audit committees are facing increasing scrutiny to provide
effective oversight (DeZoort et al., 2002; Pomeroy, 2010; White, 2015). However,
research evidence on the nature of the audit committee’s oversight process is still
emerging. An enhanced understanding of audit committee processes would be useful for
leveraging audit committee resources to yield desired accounting and auditing outcomes.
The Sarbanes-Oxley Act (SOX) of 2002 requires that audit committees be established
“…for the purpose of overseeing the accounting and financial reporting processes
[emphasis added] of the issuer and audits of the financial statements of the issuer” (U.S.
House of Representatives, 2002). Similarly, the Blue Ribbon Committee (BRC, 1999) has
expressed concern with the effectiveness of audit committees, and its report includes
principles for best practices. The requirements and recommendations from these sources
have resulted in changes at the Securities Exchange Commission
(SEC) and the major U.S. stock exchanges, all aimed at strengthening audit committees
(Keinath & Walo, 2004). While SOX-led changes included strengthening the
composition (size, independence, and expertise) of the audit committee, little was done to
address underlying processes and practices.
Audit committee processes and practices are focused on three key areas of
responsibility: monitoring the financial reporting process, overseeing the internal control
systems, and overseeing the work of the internal and external auditors (Hermanson &
Rittenberg, 2003, p. 50). While audit committee oversight of financial reporting and the
audit function has received a great deal of attention, many sources have specifically
emphasized internal control oversight as a vital role of an audit committee. For example,
the BRC recognizes oversight of internal control as a key element of corporate
governance that should be formally documented in an audit committee charter (BRC,
1999). SOX’s reporting requirements also highlight the importance of monitoring internal
control over financial reporting (ICFR), and the Public Company Accounting Oversight
Board (PCAOB) asserts that audit committees can best add value to the corporations they
serve by supporting effective ICFR (PCAOB, 2015). Furthermore, practitioners recognize
that internal control should be at the top of the audit committee’s list of important
objectives (EY, 2014; Gelman, Rosenberg, & Freedman CPAs, 2015). Indeed, the
prominence of internal control has evolved because it is considered a critical determinant
of quality in financial reporting (Krishnan, 2005; PCAOB, 2007; Doyle, Ge, & McVay,
2007), and the role of the audit committee has similarly evolved as a corporation’s
gatekeeper for effective internal controls (Austin, 2012; White, 2015).
However, despite the increased emphasis on audit committees and ICFR, there is limited
information available within proxy statement disclosures and other financial reports to
provide insight into the actual practices of audit committees in overseeing ICFR.
In response to the increased emphasis on audit committees and over a decade of
financial reporting under the requirements of SOX, academic research has addressed the
monitoring functions of audit committees. Many archival studies examine relationships
between audit committee characteristics and financial reporting outcomes, such as
discretionary accruals (Naiker & Sharma, 2009; Tanyi & Smith, 2015) and restatements
(Krishnan & Visvanathan, 2007; Sharma & Iselin, 2012). Similarly, researchers have
investigated audit committee oversight of the audit function, emphasizing auditor
selection (Almer, Philbrick & Rupley, 2014), auditor changes (Robinson &
OwensJackson, 2009), and the procurement of non-audit services from the auditor
(Naiker, Sharma & Sharma, 2013). Likewise, the literature is rich with regard to archival
examinations of internal control and audit committee effectiveness under SOX. Notably,
post-SOX researchers have highlighted relationships between fewer internal control
problems and various indicators of audit committee expertise, such as proportion of
financial experts (Krishnan & Visvanathan, 2007; Zhang, Zhou, & Zhou, 2007),
accounting and supervisory experience (Hoitash, Hoitash, & Bédard, 2009), and
experience as a former audit partner (Naiker & Sharma, 2009).
Thus, the academic literature provides many insights into the desired inputs and
outcomes of effective audit committees among each of the three key areas of audit
committee responsibility – financial reporting, auditing, and internal control. Yet little
attention has been given to the “black box” that exists between these inputs and
outcomes. Recognizing the need for better information, shareholders are calling for the
“audit committee black box [to be] opened further” (Deloitte, 2013). Therefore, a deeper
level of understanding is necessary with regard to the audit committee’s specific
processes in fulfillment of its monitoring responsibilities. While audit committee
practices and activities comprising oversight of financial reporting and auditing were
investigated by Beasley, Carcello, Hermanson, and Neal (2009), there is little research on
audit committee internal control processes. Thus, despite the volume of research attention
to corporate governance and the role of audit committees, the processes related to audit
committee internal control oversight remain largely overlooked.
On one hand, the research void surrounding audit committees and internal control
oversight processes is surprising, given the broad recognition of internal controls as a
vital aspect of audit committee responsibility. DeZoort (1997, p. 208) finds, “Using a
multimethod approach, internal control evaluation was consistently listed and ranked as
the most important oversight responsibility [of the audit committee].” This emphasis on
internal control is reiterated by Carcello, Hermanson, and Neal (2002) and HassabElnaby,
Said, and Wolfe (2007), who find that 91 percent and 98 percent, respectively, of their
audit committee samples identified internal control monitoring as a key function of the
audit committee. Similarly, a 2014 KPMG survey finds that a majority of audit committee
members identified internal control and financial reporting risks as prioritized issues on
audit committee meeting agendas (KPMG, 2014).
On the other hand, the research void pertaining to audit committees and internal
control oversight processes may largely reflect the difficulty in gathering data on the
topic. Specifically, considering the lack of audit committee process-related disclosures
within financial reports, archival academic research does not lend itself well to providing
meaningful insights into “what” audit committees do. Thus, qualitative studies and
surveys are more appropriate for understanding processes, but the extant literature
pertaining to U.S. public company audit committee processes in the post-SOX era is
confined to small number of interview studies (Beasley et al., 2009; Cohen,
Krishnamoorthy, & Wright, 2010 and 2017; Cohen, Hayes, Krishnamoorthy, Monroe, &
Wright, 2013) that do not focus much attention on ICFR, and to survey studies
(HassabElnaby et al., 2007; Rupley, Almer, & Philbrick, 2011). Consequently, very little
evidence is available to provide insights into the critical ICFR-related activities
performed by audit committees.
Lack of attention to ICFR can have significant consequences. If internal controls
are weak, then financial statement misstatements are more likely. In addition, internal
control weaknesses create serious problems for companies in terms of an adverse opinion
under SOX Section 404, which may result in class action lawsuits, management turnover,
and auditor turnover (Rice, Weber, & Wu, 2015), as well as higher audit fees (Munsif,
Raghunandan, Rama, & Singhvi, 2011). SEC sanctions and other compliance issues may
also stem from internal control weaknesses (Hermanson & Ye, 2009; Rice et al., 2015).
Furthermore, remediation of internal control weaknesses requires significant financial
resources and human capital (Schneider et al., 2009). A recent decline in the number of
reported material weaknesses has raised question about whether internal control
deficiencies are being properly identified and disclosed (Croteau, 2014). In her keynote
address at the 2015 AICPA National Conference, SEC Chair Mary Jo White expressed
concern that the increasing workload of audit committees could dilute their ability to
focus on core responsibilities, including oversight of ICFR (White, 2015). In addition, the
PCAOB issued a written directive for auditors and audit committees to exercise greater
scrutiny in performing their internal control work (PCAOB, 2013). Yet, many audit
committee members feel seriously challenged in their internal control monitoring role,
and they often lack information needed to adequately fulfill their charge (KPMG, 2014).
Given that ICFR is “the bulwark of reliable financial reporting” (White, 2015) and has an
economically significant impact on company operations (Feng, Li, McVay, & Skaife,
2015), it is clear that the provision of reliable ICFR is an important practice and
regulatory issue. This study will begin to fill a void in the literature by providing insights
into audit committee processes in this key area of oversight responsibility.
The recently updated COSO Internal Control – Integrated Framework (COSO,
2013) delivers a refreshed perspective on internal control. The enhancements of the
updated framework have provided an opportunity for audit committees to consider their
processes for, and make desired improvements in, their internal control oversight
program. This is especially important in light of the lofty expectations that have emerged
for audit committees to evaluate the design and conduct of internal control. The timing of
the implementation of the revised COSO framework and the void in the academic
literature regarding audit committee oversight of ICFR serve to motivate an examination
of audit committee processes with regard to ICFR oversight.
In this study, I employ a survey approach to gather information about audit
committee oversight of ICFR. In light of the difficult environment in which audit
committees operate and the lack of academic research in such a critical corporate
governance function, this study provides detailed information about audit committee
processes and practices. I administered a survey to audit committee members to solicit
details about their work in overseeing ICFR and to capture their perceptions about
strategies, activities, and interactions with management and other governance
participants. Ultimately, this study delves into the details of the audit committee’s task of
getting comfortable with the company’s system of ICFR. My survey was developed, in
part, from the results of Beasley et al. (2009) and incorporates internal control points of
focus derived from the COSO (2013) framework. Beasley et al. (2009) had a very limited
focus on audit committee oversight of internal control, and my study expands the analysis
by emphasizing ICFR and measuring a range of participant expertise variables such as
certification, experience, tenure, multiple board positions, industry proficiency, and legal
expertise. In addition, I measure firm specific variables such as audit committee meeting
frequency, audit committee size, company size, and industry affiliation.
My results indicate that audit committee members are significantly engaged in
each of the five components of the COSO (2013) framework including oversight of the
control environment, risk assessment, control activities, information and communication,
and monitoring activities. Audit committees spend the most time in the monitoring
activities and control environment areas, and the least time in the information and
communication and control activities (related to revenue) areas. In addition, my analyses
suggest that three audit committee member characteristics are associated with overall
audit committee oversight of ICFR: age, CPA certification, and experience as an internal
auditor. The audit committee member’s age and internal audit experience are positively
associated with audit committee oversight of ICFR, yet audit committee members who
are certified CPAs are negatively associated with audit committee oversight of ICFR, a
finding that warrants additional research. Regarding company characteristics, audit
committee members serving large companies and those in regulated industries reported
higher levels of audit committee oversight of ICFR. However, none of the traditional
corporate governance variables – such as tenure, meeting frequency, and board size –
have a significant association with audit committee oversight of ICFR.
This is a foundational study exploring the process of how audit committees fulfill
their oversight responsibility regarding ICFR. Thus, this study of the audit committee
ICFR oversight process begins to answer the research calls for better understanding of the
processes involved in control risk oversight (DeZoort et al., 2002; Beasley et al., 2009;
Bédard & Gendron, 2010; Carcello, Hermanson, & Ye, 2011). Furthermore, in his
keynote address before the 2017 Journal of Accounting and Public Policy Conference,
SEC Chief Accountant Wesley Bricker stressed the important financial reporting function
of the audit committee, and encouraged researchers to “advance the understanding of the
role of audit committees in fostering effective internal control over financial reporting,
and the factors that strengthen or weaken audit committees’ effectiveness” (Bricker,
2017). Such understanding can aid investors who rely upon audit committee oversight;
likewise, it can encourage and assist audit committees themselves – individually and
collectively – in developing their approach to effective oversight. This study also
contributes to the growing body of research examining the effects of audit committee
expertise (DeZoort, 1998; DeZoort & Salterio, 2001), which is important for policy and
practice decisions regarding audit committee composition. Additionally, it complements
recent archival studies and provides practical insights into the relationships between audit
committee actions and characteristics of the company, its industry, and its audit
committee.
The remainder of this paper is organized as follows: In Chapter 2, I review prior
literature on audit committees and ICFR and explain the theories that apply. In Chapter 3,
I explain the research methods used to examine the audit committee processes. The
findings and conclusions are described in Chapters 4 and 5, respectively.
CHAPTER 2 – Literature Review
2.1 Background: Internal Control and Audit Committee Responsibilities for ICFR
“Internal control is a process, effected by an entity’s board of directors,
management and other personnel, designed to provide reasonable assurance regarding the
achievement of objectives relating to operations, reporting, and compliance” (COSO,
2013). Despite being best known for its role in promoting reliable financial reports
(Krishnan, 2005; PCAOB, 2007; Doyle et al., 2007), properly designed internal controls
can actually support every aspect of a company’s operations, including efficient use of
resources, accurate management measurements, and objective evaluation methods used in
monitoring compliance with laws and regulations (Gelman et al., 2015). While internal
control is widely recognized as a pillar of corporate governance, never has it received as
much attention as in the years since the passage of SOX.
SOX was enacted in response to massive accounting scandals at companies such
as Enron and WorldCom, and it specifically addresses the risk of material misstatement in
financial reporting (SOX, 2002). Recognizing internal control risk as an element of the
risk of material misstatement, SOX highlights the importance of internal controls through
its mandate for separate reporting on ICFR (SOX Section 404, 2002). SOX also formally
establishes audit committee responsibilities for handling complaints regarding matters
such as faulty internal control (SOX Section 301, 2002). In addition, SOX establishes
requirements for audit committee financial expertise. Specifically, at least one audit
committee member should be a financial statement expert with experience with internal
10
10
accounting controls (SOX Section 407, 2002). Thus, SOX has greatly expanded the audit
committee’s charge concerning ICFR.
The SEC and stock exchanges have subsequently implemented regulatory reforms
aimed at providing investors with greater protection through enhancements to corporate
audit functions. The result is that corporate audit committees are now more accountable
for improved corporate governance through a deeper focus on internal control. In
addition, PCAOB Auditing Standard No. 16, Communications with Audit Committees,
requires timely, detailed communications between external auditors and audit committees
on matters determined to be relevant to the audit committee’s oversight of the financial
reporting process (PCAOB, 2012), thus firmly implanting audit committees at the heart of
the communication network among participants in the corporate governance process.
Yet, given their independent status and lack of day-to-day contact with corporate
operations and stakeholders, little is known about how audit committees fulfill the scope
of their responsibilities. Prior research indicates that individual audit committee members
tend to report broad differences in their perceptions of their roles and the performance of
their responsibilities (DeZoort, 1997; Beasley et al., 2009). Furthermore, the lack of
research and authoritative directive on the internal control component of audit committee
oversight makes it especially difficult to establish a benchmark for effectiveness.
The Committee of Sponsoring Organizations of the Treadway Commission
(COSO, 1992), a private sector organization that provides thought leadership and
guidance on internal control, issued its original version of an internal control framework
in 1992. In May of 2013, COSO released its updated Internal Control – Integrated
Framework. Both the original and updated frameworks have gained broad acceptance,
both in the U.S. and internationally, among companies required to comply with Section
11
404 of SOX. While the updated framework retains COSO’s original definitions and five
components (control environment, risk assessment, control activities, information and
communication, and monitoring activities) of internal control, it offers renewed clarity by
explicitly stating 17 principles and 81 points of focus representing fundamental concepts
associated with its definition and components of internal control. These new principles
and points of focus provide companies the opportunity to take a fresh look at internal
controls to determine whether they are present and functioning to achieve the
organization’s objectives. Nevertheless, COSO continues to recognize that the evaluation
of a system of internal control requires the exercise of judgment (COSO, 2013).
2.2 Literature Overview
Numerous corporate governance studies have investigated audit committee
oversight variables, including inputs and outputs related to audit committee effectiveness.
These studies primarily focused on measures related to financial reporting and auditing
outcomes (see summary in Carcello et al., 2011), as opposed to internal control measures.
DeZoort et al. (2002) offer a research synthesis comprising dozens of studies focused on
four dimensions of audit committee inputs: composition, authority, resources, and
diligence. Similarly, Cohen, Krishnamoorthy, and Wright (2004) summarize the corporate
governance literature by examining issues of audit committee independence, knowledge
and expertise, power, and duties and responsibilities. More recently, Bédard and Gendron
(2010) examine the audit committee literature, emphasizing the dimensions of
composition, authority, resources, processes, and environment. Carcello et al. (2011)
review audit committee composition characteristics such as financial expertise, as well as
audit committee processes and judgments. Other studies examine audit committee
compensation (Carcello et al., 2011) and affiliations (Malik, 2014) as inputs to audit
12
committee effectiveness. Throughout these audit committee research summaries, the
mass of research on financial reporting and auditor oversight overshadows the few
studies addressing internal control oversight. The next three sections describe research on
the relationships between audit committees and ICFR.
2.3 Research Addressing U.S. Audit Committees and Internal Control: Proxies and
Internal Control Weaknesses
A number of studies examine audit committee responsibilities through proxy
statement disclosures. DeZoort (1997) surveyed 118 audit committee members to solicit
perceptions about assigned audit committee oversight responsibilities and overall audit
committee oversight. Despite finding a significant gap between their perceived
responsibilities and the assigned audit committee objectives listed in the proxy statement
for their respective companies, DeZoort (1997) found that internal control oversight was
consistently prioritized as the most critical audit committee oversight responsibility.
Carcello et al. (2002) sampled 150 proxy statements to compare assigned versus reported
responsibilities of the audit committee. Similar to DeZoort (1997), Carcello et al. (2002)
found differences between what companies report about their audit committee’s key tasks
and what was disclosed in their proxy statements. Furthermore, HassabElnaby et al.
(2007) conducted a survey study to compare audit committee members’ perceived versus
assigned responsibilities both pre-SOX and post-SOX. Although this study found an
increased level of audit committee engagement post-SOX, it also revealed that audit
committees still failed to recognize all of the responsibilities assigned to them in the
proxy statements (HassabElnaby et al., 2007). While each of these studies recognize the
importance of internal control oversight as a key audit committee responsibility, they also
each specifically call for a better understanding of the actual audit committee processes
used to fulfill this responsibility.
13
Other archival studies have explored relationships between internal control
problems and various measures of audit committee quality. Krishnan (2005) collected
data for 128 companies and examined the association between internal control problems
and three measures of audit committee quality: size, independence, and expertise. She
observed that independent audit committees and audit committees with financial
expertise are significantly less likely to have reportable conditions or material weaknesses
in internal control in the pre-SOX era. By contrast, Krishnan and Visvanathan (2007)
examined a sample of 90 companies reporting internal control weaknesses under SOX
section 404. They found that audit committees that meet more frequently and have a
smaller proportion of financial experts are more likely to report internal control
weaknesses. Likewise, Zhang et al. (2007) analyzed a matched sample of 416 companies
and found that audit committees with fewer financial experts are more likely to be
associated with internal control weaknesses in the post-SOX era. Hoitash et al. (2009)
expanded upon the work of Zhang et al. (2007) and found that audit committee members
having accounting and supervisory experience are associated with fewer internal control
material weaknesses. Also, Naiker and Sharma (2009) find the highest level of
accounting expertise – in the form of former audit partners serving on the audit
committee – is the strongest driver of audit committee oversight of internal control. The
consensus among these studies is that audit committee expertise and internal control
weaknesses are inversely related. However, Naiker and Sharma (2009) find that internal
control weaknesses are not significantly related to all types of audit committee financial
experts. Only former audit partners are associated with effective internal control, while
other audit committee members (without former audit partner experience) are not
associated with internal control weaknesses. This suggests some inconsistencies in the
processes underlying the internal control monitoring activities of audit committees.
14
While archival research may address associations between audit committee
characteristics and internal control issues, it is unable to consider the actual audit
committee processes that created these associations, and it cannot examine the processes
leading up to the issuance of the company’s internal control effectiveness report.
Although analyses of audit committee inputs are essential to understanding the various
accounting and auditing outcomes, how the process is undertaken by audit committees –
individually and collectively – is arguably equally essential. Yet audit committee
processes have received relatively little research attention (Carcello et al., 2011). Hence, I
examine the extant research that offers insights into the “black box” of audit committee
processes carried out in the fulfillment of their responsibilities. The next two sections
describe studies that provide insights into how audit committees carry out their duties.
2.4 Qualitative and Survey Research Addressing U.S. Audit Committee Processes in the
Post-SOX Era
Perhaps the broadest investigation of audit committee processes to date was
conducted by Beasley et al. (2009) via in-depth interviews of 42 individuals who serve on
U.S. public company audit committees. The purpose of the study was to delve into six
specific audit committee process areas to consider whether audit committees provide
substantive oversight of financial reporting as opposed to ceremonial surveillance aimed
at creating legitimacy. Overall, the findings indicate that post-SOX audit committee
members do strive to provide substantive oversight and avoid serving on audit
committees that are merely ceremonial in carrying out their responsibilities. However,
significant variability was found in audit committee processes. There was evidence of
both substantive and ceremonial monitoring in several process areas. Furthermore, some
interesting contrasts were noted in the audit committee members’ responses to questions,
and these variations were related to the audit committee members’ accounting expertise
15
and other company characteristics. On the topic of internal control, Beasley et al. (2009)
asked only one research question and found that audit committee members are clearly
dependent upon both internal and external auditors in evaluating the strength of the
company’s ICFR. They specifically call for further analysis of the processes related to
ICFR oversight in order to gain insights into how audit committees evaluate and
remediate internal control weaknesses (Beasley et al., 2009, p. 114).
While not directly related to audit committee processes, Cohen et al. (2010)
provide insight into the role of the audit committee. Specifically, the authors interviewed
30 experienced Big 4 audit partners and managers to consider whether their experiences
with corporate governance parties had changed in the post-SOX era. The authors had
conducted a similar interview study in the pre-SOX era (Cohen, Krishnamoorthy, &
Wright, 2002). Compared with their earlier findings, Cohen et al. (2010) found that the
corporate governance environment had improved considerably after the enactment of
SOX. In particular, the audit partners reported that, based on their interactions with the
audit committee, audit committees were reported to be “substantially more active,
diligent, knowledgeable, and powerful” (Cohen et al., 2010, p. 752), especially with
regard to their oversight of the internal control function (Cohen et al., 2010, p. 767).
However, while 88 percent of the respondents affirmed the role of the audit committee
with respect to internal control, only 17 percent acknowledged that this was a topic of
discussion in a typical audit committee meeting (Cohen et al., 2010, p. 760). Thus,
although the audit committee’s responsibility for ICFR oversight is clearly recognized,
this study found that it is rarely discussed in audit committee meetings. This suggests that
audit committees may be downplaying a critical element of their governance charge.
Further analysis of how audit committees carry out their duties with regard to ICFR
oversight is therefore warranted.
16
Cohen et al. (2013) also provide support for the importance of audit committees in
oversight of internal control. The authors conducted an interview study to further explore
the effectiveness of SOX regulation in achieving high quality financial reporting. Their
subjects were 22 experienced members of the boards of directors in U.S. corporations,
including 15 subjects who served on the audit committee in both the pre-SOX and
postSOX era. A major focus of this study was audit committee interactions with the
external auditors. Consistent with Cohen et al. (2010), this study found that SOX has
positively influenced the monitoring role of the corporate audit committee. When
presented with open-ended questions about changes in audit committees and their
interactions with the auditors, 14 percent of respondents cited more focus on internal
control and 35 percent reported more control-related discussions in meetings (Cohen et
al., 2013, p. 67). However, consistent with Beasley et al. (2009), this study found notable
variation in audit committee roles. Yet, with respect to the responsibility for internal
control oversight, details about audit committee processes were not disclosed beyond a
general recognition of an increased workload for the audit committee, including more
frequent meetings and often more complicated and adversarial relationships with the
auditors. Although there is clear recognition of the audit committee’s increased
responsibility for ICFR, there is little detailed evidence of any consensus regarding
process improvements enacted in fulfillment of this responsibility.
Cohen, Krishnamoorthy and Wright (2017) interviewed 32 corporate governance
participants (including “triads” of chief financial officers, audit committee members, and
external audit partners) representing eleven public companies. The research focus was on
enterprise risk management (ERM) and its impact on the financial reporting process.
Interview questions captured the perceptions of governance participants about the role of
audit committees in ERM and the role of ERM in achieving strong internal controls.
17
While the emphasis of this study was not on ICFR, it does acknowledge internal control
oversight as an essential governance function. However, although the strength of ICFR is
considered a key element of financial reporting, the study found little consensus among
the governance participants as to the role of the audit committee and the activities
performed in strengthening ERM and its focus on ICFR.
Turning to survey literature, HassabElnaby et al. (2007) surveyed 373 audit
committee members to obtain information about their perceptions of their oversight
responsibilities. These perceptions were compared with the companies’ proxy statement
disclosures regarding assigned oversight responsibilities. Despite finding significant gaps
between several perceived versus assigned responsibilities, one area of agreement was the
audit committee’s responsibility for reviewing the systems of internal control. Given the
level of consensus regarding this key aspect of financial reporting oversight, further
research is necessary to investigate the specific procedures and activities undertaken by
audit committees in fulfillment of this obligation.
In another study that recognized the importance of internal control and the role of
the audit committee in monitoring ICFR, Abbott, Parker, and Peters (2010) surveyed 134
chief internal auditors to examine the extent of audit committee involvement with the
internal audit function. They found a significant positive association between audit
committee oversight (vis-à-vis management oversight) and the percentage of the internal
audit budget devoted to ICFR-activities, but the study does not provide specific
information about the oversight processes. Future research can leverage these findings to
benchmark resource allocations and procedural details of the audit committee’s oversight
of the internal audit function.
Rupley et al. (2011) conducted a survey of 80 public company audit committee
members regarding their perceptions of effectiveness in monitoring financial reporting
18
and other aspects of audit committee responsibility. They found that one of the most
important responsibilities audit committees provide is monitoring systems of ICFR.
Although no details were extracted from the survey regarding the processes undertaken in
fulfilling this charge, this survey’s respondents indicated that maintaining independence,
financial literacy, and effective working relationships were key to carrying out their
oversight role.
In another recent survey study, Hermanson, Smith, and Stephens (2012) examined
internal auditors’ perceptions of the strength of their company’s ICFR. Based on
responses from 501 chief audit executives (CAEs) or other internal audit managers, this
study found that internal control strength is positively related to the company’s reporting
structure. Namely, when CAEs report directly to the audit committee, ICFR is perceived
to be stronger.
KPMG’s 2014 Global Audit Committee Survey presents a number of findings
indicative of the need for deeper analysis of audit committee processes regarding ICFR.
While 99 percent of the survey respondents claim to have an excellent or good
understanding of key financial and control risks, 72 percent desire more in-depth
information regarding financial risk management. In addition, 39 percent and 35 percent
of the sample, respectively, report that operational and control environment risks pose the
greatest challenges to their work and that they could be better prepared regarding internal
control issues. While 60 percent of U.S. respondents rate the quality of internal control
information they receive as good, nearly 40 percent claim that such information needs
improvement or is occasionally prone to issues. These findings suggest that more research
is warranted with regard to the audit committee’s process in monitoring ICFR. It is also
noteworthy that, as internal control was not the main focus of this survey, many of the
survey questions and/or reporting categories commingled ICFR with operational risk,
19
financial risk, and ethical compliance. Isolating internal control issues in future research
would be helpful in sharpening the focus on ICFR processes and could therefore help
audit committees refine their practices to become more effective in their settings.
As described in this section, the academic and professional literature provides
examples of studies that recognize the audit committee’s increased responsibility in the
post-SOX era. While there is widespread acceptance of the importance of the audit
committee’s internal control oversight role, there are very few details about the processes
that are carried out in fulfillment of this responsibility. Although others have considered
various issues on the periphery of audit committee oversight of ICFR, no prior study to
my knowledge has examined this issue to the extent proposed here.
2.5 Qualitative Research Addressing Non-U.S. Audit Committee Processes
Turley and Zaman (2007) performed a case study that examined audit committee
processes within a financial services company in the UK. Through interactions with key
members of the company’s corporate governance structure (the audit committee chair,
internal auditors, external auditors, and members of management), the authors gained
insights into audit committee processes. Their interviews and documentary evidence
reveal limited impact of the audit committee on matters of internal control; rather, they
find that audit committees tend to add value to the corporate governance processes and
outcomes in non-routine matters and in informal situations. This study suggests the
importance of informal processes within the audit committee’s contribution to effective
corporate governance.
Spira (1999) interviewed 21 U.K. audit committee participants, including audit
committee chairs, finance directors, internal auditors, and external auditors, finding
widespread variation in concepts of audit committee effectiveness between individual
20
subjects and companies. Surprisingly, the findings suggest that the ceremonial component
of audit committee questioning plays a significant reassuring role, providing comfort to
the company’s investors and creditors and instilling confidence in the corporate
governance structure.
Gendron, Bédard, and Gosselin (2004) interviewed 22 audit committee
participants (audit committee chairs and members, internal auditors, external auditors,
and key members of management) in three public companies in Canada. Their findings
indicate that audit committees are interested in the effectiveness of internal control, yet
they rely heavily on the work of internal and external auditors in assessing control. Audit
committees gained comfort with the strength of internal control and overall quality of
financial reporting by asking probing questions regarding the extent to which appropriate
measures are adopted to resolve issues and mitigate risks. This questioning process was
aimed at assessing the trustworthiness of corporate governance participants through the
degree of consistency in their responses.
A later study by Gendron and Bédard (2006), partially based on the same data
from interviews with audit committee participants in three public companies in Canada,
found significant variation in the practices carried out by audit committees. This study
examined the processes of trust construction among these audit committee participants.
This process requires mitigation of anxieties and transformation of anxieties into comfort
zones. It also describes respondents’ perceptions of the interactions that occurred within
audit committee meetings that create and develop individual and collective effectiveness.
Despite the diverse practices within the three corporate settings – including some
informal activities held outside the audit committee meeting – the underlying charge was
to gain comfort with the company’s financial reports and internal control.
21
Similar to Gendron and Bédard (2006), Sarens, DeBeelde, and Everaert (2009)
interviewed audit committee participants (CAEs or internal auditors and the audit
committee chair) in an attempt to uncover the factors contributing to their quest for
comfort with respect to the control environment and internal control in four Belgian
companies. Although diverse control environments and risk management structures were
found to exist within the study’s sample, audit committee comfort levels were enhanced
via the joint audit approach. The joint audit approach recognizes the collaborative efforts
of the audit committee, internal auditors, and external auditors.
Another study conducted by Zaman and Sarens (2013) examined audit committee
activities more deeply and found the existence of informal interactions between audit
committees and internal auditors. This study utilized a questionnaire completed by 187
CAEs from a variety of companies in the U.K. The survey results indicate that audit
committees engage in informal interactions with internal auditors in addition to their
more formal meetings. These informal meetings complement the formal meetings and
provide additional opportunities for the audit committee to monitor the effectiveness of
the company’s internal audit function; consequently, such informal activities play a
significant role in corporate governance.
Beattie, Fearnley, and Hines (2014) carried out another large-scale survey by
obtaining questionnaire responses from 498 audit committee participants linked to U.K.
listed companies, including audit committee chairs, chief financial officers (CFOs), and
audit partners. The purpose of the study was to investigate the extent of engagement
between the audit committees and their company CFOs and audit partners on important
financial reporting issues. The findings revealed that 37 percent of the reported
discussions occurred with all three levels of participation and the full audit committee; yet
35 percent of reported discussions involved neither the audit committee nor the audit
22
committee chair. These findings exposed incomplete levels of audit committee
engagement with financial reporting issues.
Overall, the non-U.S. literature offers a deep emphasis on several procedural
aspects of audit committees, generally aimed at assessing the effectiveness of audit
committees within the governance realm. Like the studies examining U.S company audit
committee processes, these non-U.S. studies typically are not primarily focused on the
internal control responsibilities of audit committees. In addition, the nature of audit
committee processes is likely to be different for U.S. and non-U.S. audit committees due
to the regulatory complexity and litigation risk faced by U.S companies.
2.6 Summary and Research Questions
A common theme in the audit committee process literature is that audit
committees are key players in the corporate governance realm, yet there is little evidence
regarding the procedural aspects of their role with regard to oversight of ICFR. Research
conducted in both the pre-SOX (Kalbers & Fogarty, 1993) and post-SOX environments
has recognized that attention to internal control requires considerable diligence on the
part of the audit committee, yet no study to date offers a comprehensive portrayal of audit
committee processes concerning internal control oversight. “Asking good questions is the
single most important thing that audit committees can do” (Beasley et al., 2009, p. 107),
but even this aspect of an audit committee’s charge is undeveloped – both in practice and
in the literature – especially with regard to internal control monitoring. Beasley et al.
(2009) find that audit committees engage with various members of management and both
internal and external auditors in the form of meetings and other written and oral
communications. While there is also evidence of engagement between corporate
governance participants in the form of collaborative efforts (Gendron et al., 2004; Sarens
23
et al., 2009; and Beattie et al., 2014) and informal processes (Gendron & Bédard, 2006;
Turley & Zaman, 2007; and Zaman & Sarens, 2013), more insights are needed into the
procedural aspects of these interactions and their focus on monitoring controls. This leads
to the following primary research question:
RQ: What processes and activities, both formal and informal, are undertaken by
U.S. public company audit committee members while fulfilling their
responsibility for oversight of ICFR?
2.7 Theoretical Development
In addressing the primary research question, three theoretical perspectives are
considered: agency theory, institutional theory, and comfort theory. First, the role of the
audit committee as a corporate governance monitor is generally explained from the
perspective of agency theory, where audit committees provide independent oversight of a
company’s managerial agents in order to protect the interests of the owner principals
(Jensen & Meckling, 1976). Consistent with agency theory, audit committee oversight
plays a role in reducing agency costs by ensuring that management does not act in a
selfserving manner; rather, that the owners’ interests are prioritized. Under this
perspective, audit committee members who participate in this study would be expected to
engage in substantive oversight of ICFR, while emphasizing the importance of
independence and expertise (Hermanson, Tompkins, Veliyath, & Ye, 2012).
The second dominant theory in corporate governance research is institutional
theory, which is based on distinct conventions of business interactions established to
boost the appearance of legitimacy. Over time and across companies, governance
mechanisms tend to become more similar – or isomorphic (DiMaggio & Powell, 1983).
Isomorphism may result from regulatory pressure (coercive isomorphism), imitation of
24
best practices (mimetic isomorphism), or using benchmarks and peer data (normative
isomorphism). Under this perspective, audit committee members who participate in this
study would be expected to emphasize any of these conditions that promote isomorphism,
such as engaging in ceremonial or informal activities, or following normative practices or
practices of peers.
The third theory considered in this study is comfort theory. This theory was
examined in an audit context by Pentland (1993), who observed audit engagements and
interviewed external auditors. As auditors strive to reduce discomfort caused by the
possibility of materially misstated financial statements, they activate audit rituals and
protocols (Pentland, 1993; Carrington & Catasús, 2007) to produce comfort. In addition,
Guénin-Paracini, Malsch, and Paillé (2014) recognize that comfort is an emotional as
well as a cognitive state of mind, whereby the emotional component depends upon body
senses and emotions to identify and assess audit risks, alleviate discomfort (fear), and
produce feelings of comfort. Auditors develop their comfort through the audit process,
using both formal protocols and emotions/senses, and then pass this comfort to financial
statement users through the audit opinion.
While Pentland’s (1993) study was conducted in an external audit environment,
the notion of developing comfort also is relevant in an audit committee context. For
example, Spira (1999) focuses on audit committee processes and the committee members’
pursuit of comfort regarding the company’s financial reporting. Gendron et al. (2004) and
Gendron and Bédard (2006) submit that audit committee meetings are comprised of
practices aimed at making members comfortable with their areas of responsibility,
including internal controls, financial reporting, and quality work by the auditors. Comfort
is acquired through audit committee members asking challenging questions and
reviewing management to assess the extent to which appropriate measures are in place.
25
Similarly, Sarens et al. (2014) assert that audit committee comfort is largely derived from
review and inquiry of the internal audit function.
Under the comfort perspective, audit committee members recognize their
responsibility regarding internal control oversight as a significant challenge which causes
them to experience discomfort, being fearful of failing to identify any existing material
weaknesses and the consequences thereof (Guénin-Paracini et al., 2014). Thus, those who
participate in this study would be expected to carry out a two-part approach. First, they
are likely to conduct a rational process to gather information about internal controls. In
this practical intelligence phase, audit committee members emphasize the cooperative
nature of their oversight functions, their discussions and interactions with other corporate
governance participants, and their ability to gain confidence – or comfort – from these
activities. Their interactions could exemplify rigorous (agency theory) or symbolic
(institutional theory) activities aimed at creating a collective state of comfort. Second,
respondents would be expected to rely on their emotions and body senses to identify and
alleviate discomfort caused by internal control risks. This involves honing their listening
and scanning skills and being conscious of their feelings regarding evidence obtained
(Guénin-Paracini et al., 2014). Thus, the combination of rational and emotional inputs to
the audit committee members’ decision processes are likely to yield an acceptable level of
comfort.
These theories are used to address the following overall research question, “How
do (i.e., what processes and activities are used?) audit committee members get
comfortable with the corporation’s internal control over financial reporting?” In
examining this broad question, I specifically consider five sub-research questions, which
are based on the five components of the COSO internal control framework:
26
RQa: What processes and activities are used by audit committee members to get
comfortable with the corporation’s control environment?
RQb: What processes and activities are used by audit committee members to get
comfortable with the corporation’s risk assessment?
RQc: What processes and activities are used by audit committee members to get
comfortable with the corporation’s control activities?
RQd: What processes and activities are used by audit committee members to get
comfortable with the corporation’s information and communication?
RQe: What processes and activities are used by audit committee members to get
comfortable with the corporation’s monitoring activities?
Finally, additional sub-research questions consider the effect of other variables
potentially associated with variations in audit committee ICFR oversight. Personal
characteristics of the individuals serving on audit committees are frequent indicators of
audit committee quality in the corporate governance literature. In particular, numerous
positive relationships have been found between audit committee expertise and various
financial reporting and corporate governance outcomes (Asare, Davidson, & Gramling,
2008; Hoitash et al., 2009; Sultana, 2015). Typical proxies for audit committee expertise
include audit committee tenure (Bédard, Chtourou, & Courteau, 2004; Hoitash et al.,
2009), number of directorships held (Barua, Rama, & Sharma, 2010; Hoitash et al.,
2009), industry proficiency (Cohen, Hoitash, Krishnamoorthy, & Wright, 2014), legal
expertise (Krishnan, Wen, & Zhao, 2011), professional certification (DeZoort,
Hermanson, & Houston, 2003 and 2008), and experience (Goh, 2009; Sultana, 2015). The
prevalence of audit committee member characteristics as variables of interest in corporate
governance studies motivates the following sub-research question:
27
RQf: Are variations in audit committee internal control oversight processes
associated with personal characteristics of the audit committee members?
Company characteristics are likely to affect the oversight of internal control. For
instance, Carcello, Hermanson, and Raghunandan (2005) examined the impact of
company size, leverage, cash flows, and industry affiliation on a company’s investment in
and monitoring of its internal audit budget. Also, Beattie et al. (2014) considered
company size in their analysis of audit committee engagement with other corporate
governance participants. Similarly, this study seeks to answer the following sub-research
question:
RQg: Are variations in audit committee internal control oversight processes
associated with company characteristics?
Finally, Beasley’s (1996) seminal study found an inverse association between the
percentage of independent board members and financial statement fraud. Thus, I consider
board independence in my study. Other studies find that independent audit committee
members tend to support the external auditors in disputes with management (DeZoort &
Salterio, 2001) and are linked to favorable investor perceptions of reliable financial
reporting (Farber, 2005). Since the enactment of SOX, public company audit committees
are required to be independent; therefore, an examination of audit committee
independence in this study is unnecessary. Focusing on the post-SOX academic literature,
numerous studies analyze the number of audit committee meetings in relation to a
company’s accounting conservatism (Sultana, 2015), stock price performance (Farber,
2005), investment in their internal audit function (Barua et al., 2010), and external
auditors’ perceived audit risk (Stewart & Munro, 2007). Moreover, audit committee
meeting frequency has been found to be associated with material weaknesses in internal
28
control (Krishnan & Visvanathan, 2007; Hoitash et al., 2009). In addition, several studies
examine the size of the audit committee or board of directors in relation to corporate
governance and financial reporting outcomes (Krishnan, 2005; Krishnan & Visvanathan,
2007; Goh, 2009). These studies establish a foundation for considering board and audit
committee characteristics in examining audit committee ICFR processes, leading to the
following sub-research question:
RQh: Are variations in audit committee internal control oversight processes
associated with board of director and audit committee characteristics?
Collectively, these proposed research questions and sub-research questions are
expected to provide a relevant and important focus for enhanced understanding of audit
committee oversight of internal control.
CHAPTER 3 – Methodology
In this study, I employ a survey approach to gather information about audit
committee ICFR oversight processes. The following sections of this chapter outline the
methodological selections: research design, survey questionnaire and measurement,
analytical approach, pretest, and sample and data collection.
3.1 Research Design
I administered a cross-sectional survey to U.S. public company audit committee
members to solicit details about their processes, practices, and strategies for providing
ICFR oversight. Data were collected via a paper-based survey instrument mailed using
the United States Postal Service. Both quantitative (interval scale) and qualitative
(openended) questions were included in the survey. This approach provides direct
measures as well as details about audit committee processes affecting internal control
oversight.
3.2 Survey Questionnaire and Measurement
My survey instrument was developed, in part, from the results of Beasley et al.
(2009) and expands upon findings from the KPMG Global Audit Committee Survey
(KPMG, 2014) to uncover details about the processes employed by audit committee
members to oversee ICFR. The survey measures (a) the extent to which audit committees
engage in specific activities to provide internal control oversight, and (b) the extent of
time devoted to internal control oversight activities. I also examine open-ended responses
30
from individual participants about their oversight activities, and I examine other related
corporate governance variables.
31
The dependent variables are measured within Section I of the survey instrument,
which is divided into five sub-sections based on the components of the COSO (2013)
framework as summarized below:
Control environment. The control environment embodies the foundation for
carrying out internal controls within an organization, including its integrity and ethical
values, and all relevant parameters enabling accountability for performance.
Risk assessment. Risk assessment involves the processes for identifying and
assessing factors that threaten the organization’s achievement of its objectives.
Control activities. Control activities are the policies and procedures carried out to
mitigate the threats identified through the risk assessment process. In this study, I
examine only control activities related to the revenue cycle, a common area of focus in
most companies.
Information and communication. Information and communication represents both
internal and external exchanges that support the functioning of internal control.
Monitoring activities. Monitoring activities are comprised of ongoing and separate
evaluations conducted to ascertain the effectiveness of internal control.
For each of the five COSO components, I operationalize the audit committee
members’ internal control oversight activities by measuring their extent of engagement in
selected actions from COSO’s points of focus. Specific survey questions were developed
to elicit responses bearing details about audit committee processes with regard to internal
control oversight of key financial reporting areas and cycles. Participants were asked to
31
rate each item considering the extent of actions performed to address the construct. For
the scale, I use 7-point interval scales with endpoints labeled “Not at all” and “A great
deal.” Next, participants were asked to rate the extent to which they devoted time to the
construct, using a 5-point interval scale with endpoints labeled “None” and “A lot.”
Finally, an open-ended question was posed within each of the survey’s sub-sections,
asking participants to elaborate on their responses and/or describe other key oversight
activities.
The use of 7-point and 5-point interval scales is recommended by Dillman, Smyth
and Christian (2014), and such scales are common in the accounting literature (Eutsler &
Lang, 2015). The endpoints of these scales indicate opposite extremes in terms of the
extent of action or time addressed in the respective questions, thus allowing me to capture
a measure of the extent of audit committee engagement or time spent on internal control
oversight activities.
The independent variables in this study are measured within Section II of the
survey instrument, where participants’ demographic information is requested. These
independent variables include a range of corporate governance and personal variables
such as board independence, audit committee meeting frequency, audit committee size,
company size and industry, and various characteristics of the audit committee member
such as education, experience, professional certification, industry proficiency, and
multiple board positions. This data was self-reported by the participants.
To reduce the likelihood of common methods variance in the survey, ex ante
measures were taken, such as using different scale types (Podsakoff, MacKenzie, &
Podsakoff, 2012). Survey questions were designed as self-reported measures that were
addressed by participants deemed to be the most knowledgeable about internal control
32
oversight variables. The survey cover letter and instrument are presented in Appendix A
and B.
3.3 Analytical Approach
Given the structure of the survey and the nature of the sub-research questions, a
regression model was developed as follows:
AC_OVERSIGHT = ƒ{PERS_CHAR, COMP_CHAR, BOD_CHAR, AC_CHAR}
The dependent variable – audit committee oversight (AC_OVERSIGHT) –
captures an audit committee member’s overall engagement in internal control oversight.
AC_OVERSIGHT is comprised of five specific dependent variables, represented by each
of the components of internal control per the COSO framework (COSO, 2013), including
the control environment (CE), risk assessment (RA), control activities (CA), information
and communication (IC), and monitoring activities (MA). Each of these specific
dependent variables was measured on an interval scale indicating the extent of
engagement in a particular internal control oversight action – as suggested by the COSO
(2013) points of focus – and the extent of time devoted to such oversight activities.
The independent variables are grouped into four categories: personal
characteristics of the audit committee member (PERS_CHAR); company characteristics
(COMP_CHAR); board of directors characteristics (BOD_CHAR); and attributes of the
audit committee (AC_CHAR). I examine a host of individual variables within these
categories. For example, PERS_CHAR is measured by the participants’ age, gender,
professional certification, tenure on the audit committee, number of directorships held,
designation as a financial expert, and other indicators of expertise and experience.
COMP_CHAR is measured by company industry affiliation, company size in terms of
total revenues, SEC filing category, whether the company has reported a material
33
weakness in internal control, and other corporate governance indicators pertaining to the
company’s internal audit and risk management functions. BOD_CHAR is measured by
size of the board of directors, proportion of independent members, and indication of
whether the board chair is also the company’s chief executive officer, as reported by the
participants. Finally, AC_CHAR is measured by size of the audit committee, meeting
frequency, and proportion of financial and/or industry experts. Each of these variables
was self-reported by the participants.
I ensured the anonymity of the survey results to encourage participants to be
candid and thorough in their responses. However, I had no control over the environment
in which the participants responded to the survey. Also, each respondent may not be a
prototypical representative of his or her organization’s audit committee. Despite its
inherent limitations, this study provides awareness regarding audit committee internal
control oversight processes.
3.4 Pretest
Due to the exploratory nature of this study and its potential contributions to
policy, practice, and future research, it is critical that the survey questions adequately
capture the audit committee’s activities with respect to each component of internal
control. To evaluate the content validity of the survey instrument, the questions
comprising each construct were reviewed by a panel of audit experts, including
representatives experienced with audit committee service, public accounting, internal
auditing, and academic research. The pretest participants also evaluated the readability
and understandability of the survey. Revisions were made to the survey instrument based
on feedback received from the pretest participants.
3.5 Sample and Data Collection
34
A list of potential study participants was compiled from the Audit
Analytics database. Through Audit Analytics, I was able to identify U.S. public
company audit committee members with at least one year of audit committee
service. I limited my sample to one audit committee member per company (to
avoid sample bias resulting from multiple responses from the same company
where oversight activities would be expected to be the same), and omitted
companies with negative earnings in the past year (to avoid financially distressed
companies where audit committee attention may be diverted from ICFR oversight
to prioritize prevailing economic issues and strategic risks/reactions). A random
selection technique was applied to identify one audit committee member per
company, and then I utilized various Internet websites such as fec.gov,
zabasearch.com, and whitepages.com to attempt to locate each potential
participant’s primary business or home address (Wilkins, Hermanson, & Cohen,
2016; Wilbanks, Hermanson, & Sharma, 2017).
Because I anticipated the need for 120 observations, my initial participant list
targeted 600 audit committee members. This assumed a 20 percent response rate,
consistent with Wilkins et al. (2016) and Wilbanks et al. (2017). Per Hair, Black, Babin,
and Anderson (2010), 15-20 observations are desired for each independent variable. Up to
eight proxies for the independent variables were expected to be examined for their
relationship with audit committee oversight of ICFR, therefore a minimum sample size of
120 (15 x 8) is appropriate. Due to difficulties in determining the accuracy of addresses
and my desire to avoid the need for a second mailing, I increased my mailing list to
include 872 potential participants. This list initially included 1,400 randomly-selected
companies, less 528 companies that were eliminated because (a) their principal address
was in a non-English speaking country, or (b) the record included no recent shareholder
35
proxy statement from which to obtain biographical information about the audit committee
members.
My survey was mailed to 516 home addresses, 148 business addresses, and 208
corporate addresses of potential participants. Following Dillman et al. (2014), the surveys
were mailed using the United States Postal Service Priority Service. I included
personalized request letters on colored letterhead signed by the chair of my dissertation
committee, as well as my own personal request letter and hand-stamped return envelopes
(Dillman et al., 2014). Appendix A shows the personalized request letter, and Appendix
B shows my personal request on the first page of the survey
instrument.
Forty-seven survey packets (5.4 percent of the mailing) were returned for
inaccurate or incomplete addresses, resulting in an adjusted sample size of 826. In total,
176 U.S. public company audit committee members completed my survey, resulting in a
21.3 percent response rate. This response rate is consistent with expectations for audit
committee surveys (Kalbers & Fogarty, 1993; DeZoort & Salterio, 2001; Wilkins et al.,
2016; Wilbanks et al., 2017).
For purposes of participation in this study, 167 useable responses were received
from the 176 completed surveys. Nine survey responses were unusable because they were
unreliable (i.e., straight-line scale responses with no responses to the open-ended
questions), or were considered invalid because the respondent was no longer serving on
an audit committee (which may indicate that his/her responses do not reflect the audit
committee’s current practices). Forty-one survey responses were partially incomplete
(i.e., some questions within the sub-sections measuring the independent variables were
not answered) but were still useable for other parts of the analyses. In 88 (52.7 percent) of
the surveys received, the participants provided written comments to elaborate on their
36
responses to the survey questions. One hundred twenty-six (126) participants completed
every question within each of the five sub-sections of the survey, as well as all necessary
demographic questions, thus providing feedback appropriate for inclusion in the
regression analysis described in Chapter 4. The sample size of 126 audit committee
members is above the required minimum of observations for the independent variables in
the final regression model.
CHAPTER 4 – Data Analysis and Findings
4.1 Participant Characteristics
Table 1 presents information about the 167 audit committee members who
participated in the survey. As shown in Panel A, the participants’ age range is 43-85, with
a mean of 64.8. Over 77 percent of the participants are age 60 or older. Most are male
(91%) and well-educated with a bachelor’s degree (37.1%), master’s degree (43.7%), JD
(7.2%), and/or doctorate or some other type of advanced degree (9%). Many of the
participants are CPAs (31.7%) or hold some other type of professional certification
(21.0%), and many reported prior or current experience in external auditing (29.9%),
internal auditing (13.2%), or as a CEO (53.3%), CFO (43.7%), and/or Controller
(22.8%).
While 53.9 percent of the participants are currently retired, others reported current
job titles of Chairman/Director/Partner (19.1%), CEO/President (14.4%), Vice President
(3.6%), CFO (3.0%), or Other (5.4%). In terms of industry experience, many participants
are experienced in regulated industries such as Finance/Banking/Insurance, which
accounted for the highest percentage of participants (24.5%), followed by Service
Organizations (14.9%), Electronics/Technology (13.2%), Manufacturing/Industrial
(10.8%), Pharma/Healthcare (9.6%), Retail/Consumer Products (7.2%), Energy/Utilities
38
39
(5.4%), Telecommunications/Media (4.2%), Transportation/Logistics (3.0%), and Other
(4.8%).
Regarding audit committee experience, the participants’ years of audit committee
service ranges from 2-35 years, with a mean of 12.78 years. Many participants (107, or
64.1%) reported currently serving on one audit committee, 41 (24.5%) are serving on two
audit committees, 18 (10.8%) are serving on three audit committees, and only one
participant (0.6%) is serving on four audit committees. No one reported currently serving
on more than four audit committees, yet participants reported having served a range of 1-
18 audit committees during their careers (with a mean of 2.89). Most of the participants
have experience as an audit committee’s designated financial expert and/or the audit
committee chair (66.5% and 65.9%, respectively), while only 22.2 percent have served on
the audit committee for a company that had reported a material weakness in internal
control.
Table 1 presents additional information about the participants’ board of directors
experience. Collectively, this demographic information presents a sample of highlyskilled
participants in terms of accounting, audit committee, and governance experience.
TABLE 1.
Characteristics of Participants (n = 167 audit committee members)
Panel A: Percentages Number Percent
Age 43-49 4 2.4%
50-59 30 18.0%
60-69 90 53.9%
70-79 35 20.9%
80-85 5 3.0%
No response 3 1.8%
39
Gender
Male
152
91.0%
Female
11
6.6%
No response
4
2.4%
Education (Highest Level)
Bachelor’s
62
37.1%
Master’s
73
43.7%
JD
12
7.2%
PhD/DBA/MD
15
9.0%
No response
5
3.0%
Professional Certification
CPA
53
31.7%
Other
35
21.0%
Professional Experience
External auditor
50
29.9%
Internal auditor
22
13.2%
CEO
89
53.3%
CFO
73
43.7%
Controller
38
22.8%
Current Job Title
Retired
90
53.9%
Chairman/Director/Partner
32
19.1%
CEO/President
24
14.4%
Vice President
6
3.6%
CFO
5
3.0%
Other
9
5.4%
No response
1
0.6%
Primary Industry Experience
Finance/Banking/Insurance
41
24.5%
Service organizations
25
14.9%
Electronics/Technology
22
13.2%
Manufacturing/Industrial
18
10.8%
Pharma/Healthcare
16
9.6%
Retail/Consumer products
12
7.2%
Energy/Utilities
9
5.4%
Telecommunications/Media
7
4.2%
Transportation/Logistics
5
3.0%
Various/Other
8
4.8%
No response
4
2.4%
Number of Boards of Directors
Currently Served
1
90
53.9%
2
45
26.9%
3
28
16.8%
4
4
2.4%
40
Total Number of Boards of
Directors Ever Served
1
45
26.9%
2
32
19.2%
3
25
15.0%
4
15
9.0%
5
15
9.0%
6-18
35
20.9%
Years of Board of Directors
Experience
2-10
57
34.1%
11-20
72
43.1%
21-30
24
14.4%
31-50
14
8.4%
Number of Audit Committees
Currently Served
1
107
64.1%
2
41
24.5%
3
18
10.8%
4
1
0.6%
Total Number of
Audit Committees Ever Served
1
61
36.5%
2
34
20.3%
3
26
15.6%
4
12
7.2%
5
17
10.2%
6-18
17
10.2%
Years of Audit Committee
Experience
2
6
3.6%
3-5
20
12.0%
6-10
50
29.9%
11-20
69
41.3%
21-35
20
12.0%
No response
2
1.2%
Experience as Designated Audit
Committee Financial Expert
Yes
111
66.5%
No
55
32.9%
No response
1
0.6%
41
Designated Financial Expert for
Focal Company Audit Committee
Yes
100
59.9%
No
67
40.1%
Experience as
Audit Committee Chair
Chair for
Focal Company Audit Committee
Served on Audit Committee for any
Company Reporting a
Material Weakness
Panel B: Means
Yes
110
65.9%
No
57
34.1%
Yes
90
53.9%
No
77
46.1%
Yes
37
22.2%
No
129
77.2%
No response
1
0.6%
n
Min
Max
Mean
SD
167
1
4
1.69
.84
167
1
18
3.62
2.82
167
2
50
15.79
9.27
167
1
4
1.48
.71
167
1
18
2.89
2.26
42
Number of Public Company
Boards of Directors Currently
Served
Total Number of Public Company
Boards of Directors ever Served
Years of Board of Directors
Experience
Number of Public Company
Audit Committees Currently
Served
Total Number of Public Company
Audit Committees ever Served
Years of Audit Committee
Experience
4.2 Company Characteristics
Table 2 presents information about the focal companies served by the audit
committee members participating in this survey. A majority of the focal companies
(55.7%) have over $500 million in annual revenues, and most (73.1%) are in
nonregulated industries. Most of these focal companies (74.2%) use the COSO
framework, and a few (10.8%) had reported a material weakness in internal control. A
majority have an in-house internal audit function (62.3%) and a dedicated risk
management function (65.3%) beyond the board of directors.
The focal companies in this study have between 3-20 board of directors members,
with a mean of 8.88 board members. In a majority (54.5%) of these companies, at least
165
1
35
12.78
7.34
43
75 percent of the board members are independent of management, and 59.3 percent have
a board chairman other than the company’s CEO. The audit committees of these
companies consist of 2-10 members, with a mean of 4.01 members. These audit
committees hold between zero (one participant) and 12 (two participants) in-person
meetings annually, with a mean of 4.39 in-person meetings per year. In addition, in 63.5
percent of the focal companies, over 60 percent of the audit committee members are
considered financial experts. Collectively, this demographic information presents a
sample comprised of a variety of companies in terms of their size, industry, and
governance characteristics.
Panel A: Percentages
Number
Percent
Revenues
Under $250 million
52
31.1%
$250 to $500 million
20
12.0%
$501 million to $1 billion
21
12.6%
Over $1 billion
72
43.1%
No response
2
1.2%
Industry
Non-regulated
122
73.1%
Regulated (financial services or
insurance)
37
22.1%
No response
8
4.8%
SEC Filing Category
Large accelerated
48
28.7%
Accelerated
51
30.5%
Non-accelerated
35
21.0%
No response
33
19.8%
Reported Material Weakness
Yes
18
10.8%
No
145
86.8%
No response
4
2.4%
Uses COSO Framework
Yes
124
74.2%
TABLE 2.
Characteristics of Focal Companies
44
No
21
12.6%
No response
22
13.2%
Internal Audit Function
In-house
104
62.3%
Outsourced
28
16.7%
Co-sourced
22
13.2%
No internal audit function
8
4.8%
No response
5
3.0%
Internal Audit Primary Reporting
Responsibility
Board of directors
54
32.3%
Management
8
4.8%
Both board and management
81
48.5%
No response and N/A
24
14.4%
Risk Management Function
Dedicated Chief Risk Officer
(CRO)
19
11.4%
Risk Committee
38
22.8%
Both
CRO and Risk Committee
52
31.1%
Board of directors only
54
32.3%
No response
4
2.4%
Number of Members on the
Board of Directors
3-5
8
4.8%
6-8
69
41.3%
9-11
60
35.9%
12-20
23
13.8%
No response
7
4.2%
Proportion of Board Members
Independent of Management
50-75%
31
18.6%
75-90%
72
43.1%
90-99%
19
11.4%
No response
45
26.9%
Number of Members on the Audit
Committee
2
2
1.2%
3
64
38.3%
4
54
32.3%
5
25
15.0%
6
11
6.6%
7-10
5
3.0%
No response
6
3.6%
45
Proportion of Audit Committee
Members with Financial
Expertise
20-40%
23
13.7%
41-60%
20
12.0%
61-80%
30
18.0%
81-99%
4
2.4%
100%
72
43.1%
No response
18
10.8%
Number of In-person Audit
Committee Meetings per Year
0-2
14
8.4%
3-4
80
47.9%
5-6
62
37.1%
7-12
6
3.6%
No response
5
3.0%
CEO is also Board Chair
Yes
64
38.3%
No
99
59.3%
No response
4
2.4%
Panel B: Means n Min Max Mean SD
Number of Members of the Full
Board of Directors 160 3 20 8.88 2.60
Number of Members of the Audit
Committee 161 2 10 4.01 1.21
Number of In-person Meetings of
the Audit Committee per Year 162 0 12 4.39 1.59
4.3 Descriptive Statistics: Audit Committee Oversight of Internal Control
46
Table 3 presents descriptive information about the individual measures within
each of the five categories of dependent variables representing the components of the
COSO framework: control environment (CE), risk assessment (RA), control activities
(CA), information and communication (IC), and monitoring activities (MA). These
measures represent each of the first five research questions in this study, addressing the
processes and activities that are used by audit committee members to get comfortable
with each of the five COSO components, respectively. The extent of audit committee
engagement in various relevant actions was assessed using a 7-point scale response to 5-6
statements for each of the five component constructs. The scales were labeled with
endpoints “Not at all” at 0 and “A great deal” at 6, with a “Moderate” label at the
midpoint (3). Our discussion below focuses on major apparent patterns, rather than
detailed statistical testing across the numerous individual items.
Table 3, Panel A (shown below), presents participants’ perceptions of their audit
committee’s activities with regard to oversight of the control environment. The
participants are most engaged in discussions with external auditors (mean of 5.59 on a
scale of 0-6; SD = 0.84), management (mean = 5.46; SD = 0.83), and internal auditors
(mean = 5.33; SD = 1.31). Several participants expressed the importance of these
interactions and the audit committee’s responsibilities for overseeing the control
environment, and many provided written comments such as the following:
The control environment is at the heart of the value of audit data. (audit
committee member)
We put a lot of emphasis on tone-at-the-top. (audit committee chair)
The control environment is a key area of focus, and the internal auditors
report to the audit committee at every meeting regarding its status. (audit
committee chair)
47
Discussions with internal and external auditors, as well as management,
are a part of every audit committee meeting. (audit committee chair)
Very good relationships exist between the audit committee and the
company’s internal and external auditors. Conversations are transparent;
this allows the process to the open and efficient. (audit committee chair)
On the other hand, some participant comments acknowledged their audit
committee’s limited engagement in oversight of the company’s control environment. For
example:
We rely on our internal and external auditors to assess the control
environment, holding executive sessions with representatives of both
groups at every meeting. (audit committee member)
Regarding oversight of risk assessment (Panel B), the survey question that
received the highest ranking pertained to discussions with management about new
accounting standards and their impact on financial reporting (mean = 5.27 on a scale of 0-
6; SD = 1.03). Also highly rated were survey questions pertaining to internal audit’s role
in monitoring fraud risks (mean = 5.13; SD = 1.20) and management’s role in monitoring
ICFR risks (mean = 5.12; SD = 1.27), suggesting that audit committee members consider
these activities to be relatively important. Several participants provided comments to
highlight the importance of the risk assessment area. Many who serve on audit
committees of regulated focal companies commented that a thorough risk assessment is
mandatory. Further, similar to the control environment, many participants reported that
their audit committees regularly consulted with internal and external auditors in fulfilling
their responsibilities in this area, while a few commented on their audit committee’s
practice of having a “deep dive” discussion of one selected risk topic at each meeting.
More than any other area, participant comments regarding risk assessment oversight
48
indicated that the full board – as well as various members of management – prioritizes
this area of responsibility.
Risk assessment is much more than an audit committee topic; it’s one of the
primary responsibilities of the Board. (audit committee member)
Risk assessment is a very worthwhile practice for the audit committee. The
key to a successful risk assessment is the process used and having the right
members of management on the company’s assessment team. (audit
committee member)
For risk assessment, other than the risks related to financial reporting,
considering what the audit committee is doing without also considering
what other board committees and the full board are doing can result in an
incomplete or misleading picture. (audit committee member)
Financial risk is the primary responsibility of this audit committee. (audit
committee member)
Significant time is devoted here, but it’s very repetitive year-to-year. (audit
committee member)
The survey questions on the audit committee’s extent of engagement in oversight
of control activities pertaining to revenue processes received lower ratings, on average
(all less than 4.50 on a scale of 0-6), than the other four areas (Panel C). This suggests
that while audit committee members engage in oversight of control activities, they do not
consider this aspect to have the most importance. For example, several participants
commented that this was not a significant area for their audit committees, due to the
nature of their focal company and its industry. Insurance and healthcare organizations and
other balance sheet-driven companies may not be significantly engaged in oversight
activities related to revenue processes and thus may have rated this area lower. In
addition, several participants indicated that their audit committees do not get involved in
overseeing control activities, especially concerning details such as reviewing internal
control documentation for revenue processes. One participant commented:
49
The questions in this area are a level below the audit committee. Instead,
our audit committee relies more on SOX risk assessment processes and the
results of internal and external audit testing. (audit committee chair)
However, many other participants commented that their audit committees were
particularly attuned to control activities pertaining to revenue processes, given their focal
companies’ complex revenue recognition policies. Furthermore, others mentioned the
importance of the control activities in this area, especially with regard to new revenue
recognition criteria. A few such comments include:
Our oversight role is increasing to some extent in 2017 when
implementing new revenue recognition requirements. (audit committee
chair)
The upcoming new accounting rules are requiring more focused efforts on
the part of audit committees in assessing company readiness for adoption
of these new rules. (audit committee chair)
Revenue recognition is probably the hottest hot spot in accounting today,
and the rules are changing again. This is one of the reasons internal audit
departments are having an increasing amount of difficulty in keeping up,
and companies are increasingly outsourcing internal audit. (audit
committee member)
Regarding oversight of information and communication (Panel D), the survey
question that was rated most favorably pertained to discussions with management
regarding the quality of the company’s significant accounting policies and practices and
their impact on financial reporting (mean = 5.09 on a scale of 0-6; SD = 1.03). Responses
to the two survey questions pertaining to controls over IT and cybersecurity had relatively
low (means = 4.71 and 4.55, respectively); yet, many participants provided comments
regarding their extent of engagement in evaluating and discussing these aspects of
information and communication oversight. Two participants specifically referred to this
area as an increasing priority. One participant stated:
50
Information and communication processes require constant monitoring and
improvement. (audit committee member)
Regarding oversight of monitoring activities, participant ratings on the survey
questions were relatively high (Panel E). Participants indicated that their audit
committees analyze communications from the external auditors regarding internal control
over financial reporting (mean = 5.54 on a scale of 0-6; SD = 0.73), and also that they
follow up on the status of external audit communications regarding ICFR (mean = 5.47;
SD = 0.82). A few participants commented that the audit committee still spends
significant time monitoring SOX compliance. Many participants commented that
monitoring activities are the most important of the internal control oversight areas.
Monitoring activities are critical for audit committees. These topics were
reviewed at every audit committee meeting with both internal and external
auditors (not necessarily at the same time). (audit committee member)
These area represents the core activity of our audit committee. (audit committee
chair)
This area receives a great deal of attention from the audit committee. It is
discussed at every meeting. (audit committee chair)
External auditors are being pushed to demand more and more from their
clients, which puts greater emphasis on the monitoring activities of the
audit committee. (audit committee member)
TABLE 3.
Descriptive Statistics: Extent to which the Audit Committee Engages in its own Actions
Regarding Oversight of ICFR
Panel A: Control Environment (CE) n Min Max Mean SD
Allocate time for discussions with external
auditors without management being present
167
0
6
5.59
0.84
51
Meet with company management in appropriate
forums to enable audit committee members to
ask probing questions
167
2
6
5.46
0.83
Allocate time for discussions with internal
auditors without management being present
159
0
6
5.33
1.31
Meet at least once annually with appropriate
parties to accomplish the following:
a) Review the performance of management in
demonstrating appropriate tone at the top
166
0
6
5.10
1.28
b) Review executive compensation packages
and evaluate the inherent pressures for performance
c) Discuss the company’s policies for attracting
and retaining competent
personnel with financial reporting
experience
166
0
6
4.57
1.45
d) Evaluate the objectivity of the internal audit
team
157
0
6
4.96
1.31
Has criteria and procedures in place for calling
special and/or urgent meetings as necessary
167
0
6
4.96
1.20
At least annually, review the following:
a) Competencey requirements for all personnel
serving in key financial reporting and
internal audit roles
166
0
6
4.63
1.48
b) Employee suggestions (including issues
raised through a whistle blower hotline)
regarding ICFR, and considers the adequacy
of management’s response
164
0
6
4.95
1.37
Panel B: Risk Assessment (RA)
n
Min
Max
Mean
SD
Discuss with management any new accounting
standards and their impact on financial
reporting
164
0
6
5.27
1.03
Discuss with the chief audit executive the fraud
risks that are being monitored by the internal
audit team
158
0
6
5.13
1.20
52
159 0 6 4.69 1.72
At least once annually, discuss with management
the methods used by management for
identifying, assessing, and managing risks
related to ICFR
164
0
6
5.12
1.27
Review and approve management’s risk
assessment documentation
164
0
6
4.86
1.47
Review and analyze updates to components of
the company’s internal controls that have been
53
changed or removed by management and the
potential impact on financial reporting
Interview members of management and
161
0
6
4.70
1.35
evaluate their views on ICFR
163
0
6
4.17
1.60
Panel C: Control Activities (CA)
n
Min
Max
Mean
SD
Review policies and procedures for the
deployment of internal control activities
covering the company’s revenue processes
162
0
6
4.48
1.38
Discuss with management its methodology for
mapping identified revenue-related risks to
control activities
163
0
6
4.33
1.39
Meet with appropriate members of management
to discuss the methodology and rationale for
accounting for uncollectible receivables and
other revenue-related accounts requiring
estimation
159
0
6
4.30
1.48
Meet with appropriate members of management
to discuss and evaluate the company’s mix of
preventative and detective control activities
over revenue processes
162
0
6
4.29
1.39
Inquire of internal auditors about their review
of documentation (such as data flow diagrams,
flow-charts, narratives, etc.) for the design of
the revenue process flows that support the
company’s ICFR, and whether they are
comfortable with the adequacy of the design
157
0
6
4.21
1.53
Panel D: Information and Communication (IC)
n
Min
Max
Mean
SD
54
Discuss with management the quality of the
company’s significant accounting policies and
practices and their impact on financial reporting
166
2
6
5.09
1.03
Consider the competence of IT personnel and the
effectiveness of the IT infrastructure in
supporting the company’s financial reporting
policies and procedures
165
0
6
4.71
1.39
Approve and update guidelines for management
to provide complete and relevant financial and
internal control information to the audit
committee in advance of each meeting 165 0 6 4.70 1.31
Discuss with management the approach to
communicating the company’s policies and
procedures regarding ICFR so that they are
applied consistently throughout the organization 166 0 6 4.58 1.37
Discuss with management the appropriateness
of monitoring security over automated
functions 166 0 6 4.55 1.34
Panel E: Monitoring Activities (MA) n Min Max Mean SD
Analyze communications from the external
auditors regarding ICFR 163 2 6 5.54 0.73
Follow up on the status of external audit
communications regarding ICFR, including the
55
quality and effectiveness of management’s
response 163 1 6 5.47 0.82
Follow up on the status of internal audit
findings regarding ICFR, including the quality
and effective-ness of management’s response 158 0 6 5.27 1.10
Analyze internal audit findings regarding ICFR 159 0 6 5.27 1.06
Discuss management’s assessment of ICFR
under SOX Section 404(a) before the report is
issued 164 1 6 5.23 1.02
Overall, participants’ highest ratings of the extent of actions devoted to oversight
of ICFR were in the areas of the control environment (CE), risk assessment (RA), and
monitoring activities (MA). Each of these areas has several individual means of 5.00 or
higher and are described as areas of emphasis in participant reponses to open-ended
questions. Conversely, within the area of control activities (CA) for revenue processes,
the reported means for the individual questions are considerably lower (all less than
4.50). This is consistent with many participants’ comments that their revenue processes
were relatively straightforward, or for those whose revenue process were more complex,
the audit committee often relied upon the auditors to provide primarly CA oversight.
56
Similarly, the reported means for information and communication (IC) are relatively low
(between 4.55 and 5.09), which is likely due to its requirement for more detailed
oversight – as would customarily be expected of management and the auditors.
In terms of individual actions receiving the most audit committee attention, the
highest-rated survey question was reported for the control environment component, in
which participants reported a high level of engagement in private discussions with
external auditors without management being present (mean = 5.59). This indicates audit
committees’ independence from manangement in exercising its oversight responsibilities.
Also within the control environment component, participants were reportedly involved in
meetings with company management appropriate for asking probing questions (mean =
5.46), demonstrating the audit committee’s commitment to integrity and ethical values by
emphasizing oversight of tone at the top. Some individual monitoring activities were also
highly rated, including (1) analyzing communications from external auditors regarding
ICFR (mean = 5.54) and (2) following up on the status of – and response to – external
auditor communications regarding ICFR (mean = 5.47). These monitoring activities
emphasize audit committee attention to ongoing and separate evaluations. Overall, the
highest rated survey questions demonstrate substantial consensus among audit committee
members with regard to overseeing the external audit function and tone at the top.
Table 3 also calls attention to actions that receive the least audit committee
attention. The lowest rated survey question was reported in the risk assessment area,
pertaining to the audit committee’s action to interview members of management and
evaluate their views on ICFR (mean = 4.17 on a scale of 0-6; SD = 1.60). In addition, the
control activities area indicates several low ratings; the lowest rated survey question in
57
this area pertains to the audit committee’s inquiry of internal auditors regarding their
opinions about the adequacy of documentation supporting the design of ICFR for
revenues processes and their reviews of such documentation (mean = 4.21; SD = 1.53).
While both of these questions represent specific audit committee approaches or examples
that relate to COSO points of focus within their respective internal control areas, the
participant responses suggest that there is relatively little consensus among audit
committee members about their real world application. The similar nature of these
lowrated questions suggests that audit committees are least engaged in activities that
involve detailed oversight, such as interaction with individual members of the company’s
governance structure to discuss their views on ICFR policies and/or documentation.
Table 4 (shown below) provides summated results for the questions comprising
each of the five sections of the survey, corresponding with each of the five components
of the COSO framework. In addition, Table 4 presents results for the survey questions
pertaining to participants’ perceptions of the extent of time devoted to oversight in each
of the five sections. The extent of time devoted to each component was assessed based
on a 5-point scale response to one overall statement for each of the five constructs. The
scales were labeled with endpoints “None” at 0 and “A lot” at 4, with “Some” at the
midpoint (2). Thus, Table 4 provides a cumulative view of participant responses for each
COSO component (addressing this study’s research questions RQa through RQe) and in
total.
58
Mean SD
SUMRA (max 36 possible) 156 4 36 29.49
5.51
OverallRA (0 – 4 scale) 164 1 4 3.11
0.81
SUMCA (max 30 possible) 152 0 30 21.76
5.85
OverallCA (0 – 4 scale) 164 0 4 2.82
0.89
SUMIC (max 30 possible) 164 4 30 23.63
5.02
OverallIC (0 – 4 scale) 166 1 4 2.90
0.81
SUMMA (max 30 possible) 158 12 30 26.78
3.98
OverallMA (0 – 4 scale) 162 1 4 3.36
0.70
SUMofSUMS (max 186 possible) 130 54 186 153.23
23.90
SUMOverall (max 20 possible) 157 5 20 15.55
Variable Definitions:
SUMCE Calculated variable = sum of audit committee members’
perceptions of oversight of the control environment (CE)
3.00
measured on a 7-point scale anchored 0 = Not at all and 6 = A
great deal for 10 questions (shown in Table 3, Panel A) regarding
extent of oversight activities performed (possible total score
range 0 – 60)
OverallCE Audit committee members’ perceptions of the extent of time
devoted to overseeing the controls environment, including
management’s commitment to integrity and the ethical values of
the organization, measured on a 5-point scale anchored at 0 =
None and 4 = A lot
SUMRA Calculated variable = sum of audit committee members’
perceptions of risk assessment (RA) oversight, measured on a
7point scale anchored 0 = Not at all and 6 = A great deal for six
questions (shown in Table 3, Panel B) regarding extent of
oversight activities performed (possible total score range 0 – 36)
TABLE
4
.
Descriptive Statistics for Dependent Variables
Variable
n
Min
Max
SUMCE
(
max 60 possible
)
145
16
60
50.67
7.69
OverallCE
(0
–
4
scale
)
164
1
4
3.33
0.74
59
OverallRA
Audit committee members’ perceptions of the extent of time
devoted to overseeing the company’s risk assessment, including
risk identification, risk management, and risk response,
measured on a 5-point scale anchored 0 = None and 4 = A lot
SUMCA
Calculated variable = sum of audit committee members’
perceptions of control activities (CA) oversight relative to
revenue processes, measured on a 7-point scale anchored 0 = Not
at all and 6 = A great deal for five questions (shown in Table 3,
Panel C) regarding extent of oversight activities performed
(possible total score range 0 – 30)
OverallCA
Audit committee members’ perceptions of the extent of time
devoted to overseeing the company’s control activities for
revenue processes, including mapping identified risks to
controls, evaluating technology dependencies, and developing
appropriate policies and procedures, measured on a 5-point scale
anchored 0 = None and 4 = A lot
SUMIC
Calculated variable = sum of audit committee members’
perceptions of information and communication (IC) oversight,
measured on a 7-point scale anchored 0 = Not at all and 6 = A
great deal for five questions (shown in Table 3, Panel D)
regarding extent of oversight activities performed (possible total
score range 0 – 30)
OverallIC
Audit committee members’ perceptions of the extent of time
devoted to overseeing the company’s information and
communication, including the exchange of internal and external
information to support internal controls, measured on a 5-point
scale anchored 0 = None and 4 = A lot
SUMMA
Calculated variable = sum of audit committee members’
perceptions of monitoring activities (MA) oversight, measured
on a 7-point scale anchored 0 = Not at all and 6 = A great deal
for five questions (shown in Table 3, Panel E) regarding extent
of oversight activities performed (possible total score range 0 –
30)
60
OverallMA
Audit committee members’ perceptions of the extent of time
devoted to overseeing the company’s monitoring activities,
including its use of performance metrics and its response to
identified deficiencies in internal control, measured on a 5-point
scale anchored 0 = None and 4 = A lot
SUMofSUMS
Calculated variable = SUMCE + SUMRA + SUMCA + SUMIC
+ SUMMA measuring audit committee members’ perceptions
of their cumulative extent of internal control oversight
engagement (possible total score range 0 – 186)
SUMOverall
Calculated variable = OverallCE + OverallRA + OverallCA +
OverallIC + OverallMA measuring audit committee members’
perceptions of the total extent of time devoted to overseeing the
company’s ICFR (possible total score range 0 – 20)
Overall, participants’ audit committees appear to be most actively engaged in
oversight of monitoring activities (SUMMA Mean = 26.78 out of 30; SD = 3.98) and the
control environment (SUMCE Mean = 50.67 out of 60; SD = 7.69). Similarly, when
considering the summated ratings of the extent of time devoted by the audit committee,
participants indicated that they dedicate the most time to monitoring activities
(OverallMA Mean = 3.36 out of 4; SD = 0.70) and the control environment (OverallCE
Mean = 3.33 out of 4; SD = 0.74). Based on paired t-tests (p < 0.05), OverallMA =
OverallCE > OverallRA > OverallIC = OverallCA. Hence, in terms of both oversight
activities and time devoted by the audit committee, attention to the control environment
and monitoring activities are both highly rated. On the other hand, attention to control
activities (related to revenue) and information and communication receive the least
attention overall. Thus, when reporting the areas of most and least emphasis, participant
responses are consistent in terms of both extent of actions and time devoted to oversight
of ICFR.
61
It follows that the cumulative measures of participants’ actions and time devoted
to oversight of ICFR (SUMofSUMS and SUMOverall, respectively) are highly
correlated (r = .831, p = .000). Consequently, both SUMofSUMS and SUMOverall are
alternative cumulative measures of the dependent variable in this study –
AC_OVERSIGHT. In the following analyses, SUMofSUMS is used as the dependent
variable, as it captures the majority of the data points addressed by the survey
participants, while SUMOverall results are provided in footnotes (as this measure
arguably is not as fine as SUMofSUMS since it has a much smaller possible range).
4.4 Multiple Regression Results
I use multiple regression analysis to explore the relationship between the
aggregated AC_OVERSIGHT dependent variable (SUMofSUMS) and the independent
variables (PERS_CHAR, COMP_CHAR, BOD_CHAR, and AC_CHAR). Due to the
exploratory nature of the analysis, I use two-tailed tests and focus on p-values < 0.10.
Numerous iterations were considered, as the survey captured data for over 50
possible independent variables. Table 5 presents descriptive statistics for the independent
variables in the final model. There are three variables related to the participants and two
related to their companies. None of board or audit committee characteristics was
significant (i.e., no significant findings related to RQh).
TABLE 5.
Descriptive Statistics for Independent Variables (n = 167)
Personal Characteristics of Audit Committee Member
62
Mean SD
Age (AGE) 64.78
7.13
Number
Percent
CPA Certification (CPA)
53
31.7%
Internal Audit Experience (IAExp)
22
13.2%
Characteristics of Audit Committee Company
Revenue Greater than $500 million (RVGT500mm)
93
55.7%
Regulated Industry - Finance or Insurance (FINorINS)
37
22.1%
Table 5 shows that three measures of audit committee members’ personal
characteristics are included in the model – age, CPA certification, and internal audit
experience. The audit committee members’ average age is 64.78 years, consistent with
the average age in other recent audit committee studies. In studies conducted by both
Bierstaker, Cohen, DeZoort, & Hermanson (2012) and Wilbanks et al. (2017), the mean
age was 62.2 years, while the mean age of Rummell’s (2016) sample was 63. Regarding
professional certification as a CPA, this study’s sample is comprised of 31.7 percent
CPAs, whereas Rummell (2016) and Wilbanks et al. (2017) used samples comprised of
committee members, number of audit committee financial experts, proportion of financial experts on audit
committee, number of audit committee members with industry expertise, proportion of industry experts on
audit committee, audit committee meeting frequency – in person and via phone). In addition, the timing of
the response (received early/late – within/beyond six weeks of mailing date) was not significant (p =
0.759). The sample sizes vary substantially across models due to missing data. Due in part to reduced
sample sizes, some significant variables in Table 6 become insignificant in some of these analyses. Also,
some additional variables added to the model are similar to variables already in the model. For instance,
AGE is correlated with board experience, audit committee experience, and whether the audit committee
member is retired. Regarding company characteristics, regulated industry (FINorINS) is similar to whether
the company has a CRO.
Min
Max
43
85
63
37.6 percent and 35.8 percent CPAs, respectively. Thus, these personal characteristics of
this study’s sample of audit committee members are comparable to other recent audit
committee studies. However, a somewhat unique aspect of this study’s sample is its
consideration of audit committee members who are experienced internal auditors (not
directly examined in some prior studies); 13.2 percent of this study’s participants have
internal audit experience.
The model also includes two measures of audit committee company
characteristics – revenue and industry – which are similar to companies used in other
recent audit committee studies. Table 5 shows that 55.7 percent of the audit committee
members in this study served focal companies with revenues over $500 million;
Bierstaker et al. (2012) use a sample where 55 percent of the companies have annual
revenues over $500 million. Similarly, 22.1 percent of this study’s sample is companies
in regulated finance or insurance industries, compared to 21.8 percent in Wilbanks et al.
(2017) and 28.4 percent in Rummell (2016). The similarities of these samples suggest
that the samples are consistent with prior audit committee research.
In Table 6 (shown below), I examine the association between audit committee
oversight of ICFR (SUMofSUMS) and audit committee member personal characteristics
(AGE, CPA, and IAExp) and company characteristics (RVGT500mm and FINorINS).
The analysis uses robust standard errors (HC3) as necessary due to heteroskedasticity (in
Table 6 and the other analyses). The maximum VIF is 1.07, indicating that
multicollinearity is not a concern.
64
I find the overall model to be significant with F = 6.72, p = 0.0001, R² = 19.96
percent. Related to research question RQf, audit committee members’ age and experience
as an internal auditor are positively associated with their extent of audit committee
internal control oversight, while CPA certification is negatively associated with internal
control oversight. Older audit committee members may have a mix of personal and
professional experiences that translate favorably to their audit committee oversight roles
(Dao, Huang, & Zhu, 2013). For example, in this study, age is correlated with board
experience, audit committee experience, and whether the audit committee member is
retired. Similarly, since audit committees tend to rely upon the company’s internal audit
function to assist in audit committee oversight responsibilities (Schneider, 2009), it
follows that those audit committee members having internal audit experience may carry
out their oversight role more extensively than audit committee members without internal
audit experience. However, the reason behind the negative sign for CPA is less clear. It is
possible that audit committee members who are CPAs may not be reporting extensive
audit committee activity in fulfilling this role because they perceive it to be so similar to
the external auditor’s role, which may impact their ratings of the extent of the audit
committee’s engagement in oversight actions (i.e., as audit committee members, they are
doing less than external auditors are doing, so the ratings of audit committee activity are
low). Alternatively, the negative relationship could indicate that CPAs are more
ceremonial and informal in carrying out certain oversight responsibilities than non-CPAs
on the audit committee.
Further, related to research question RQg, I find that the audit committee
company’s revenue and regulated industry are found to be positively associated with
65
audit committee internal control oversight. It is not surprising that larger companies and
those operating in regulated industries are more vigilant in prioritizing their governance
activities and have audit committees that carry out their oversight roles more extensively
than smaller and unregulated companies. Finally, related to research question RQh, I
found none of the board or audit committee variables to be significant.
TABLE 6.
Regression Results for Dependent Variable Cumulative Oversight (SUMofSUMS) (n =
126)
t-stat p-value
0.56 0.27 2.09 0.039
CPA
-13.61
4.39
-3.10
0.002
IAExp
9.35
5.13
1.82
0.071
RVGT500mm
15.13
4.18
3.62
0.000
FINorINS
8.29
4.31
1.92
0.057
R² = 0.1996
F-statistic = 6.72 p
= 0.0000
In Table 7 below, I provide a disaggregated analysis of the association between
internal control oversight and various personal and company characteristics of the audit
committee members. Specifically, I separately examine the relationships between the
independent variables from Tables 5 and 6 and each of the COSO internal control
framework components (oversight of the control environment in Panel A; risk
assessment in Panel B; control activities in Panel C, information and communication in
Variable
Coefficient
Std.
Error
AGE
66
Panel D, and Monitoring in Panel E). Each of these disaggregated models demonstrates a
significant relationship between the internal control oversight variable and certain audit
committee member personal and/or company characteristics (all five Model F-statistics
are significant at the 0.05 level or lower, and the R²s range from 10 percent to 18
percent).
For both the control environment (SUMCE) and risk assessment (SUMRA)
models, company size and the audit committee member’s professional CPA certification
are the most significant independent variables. However, for the information and
communication (SUMMIC) and monitoring activities (SUMMA) models, only company
size is significant; whereas, for the control activities model, the significant independent
variables are age and professional CPA certification. At this level of disaggregated
analysis, the most noteworthy independent variable is company size (RVGT500mm),
which is positively associated with the audit committee’s oversight of ICFR and is
significant in four of the five disaggregated internal control models. Furthermore, a
negative relationship exists between an audit committee member’s professional
certification as a CPA and his or her engagement in ICFR oversight, and is significant in
three of the five models. Finally, the individual variables of AGE, internal audit
experience (IAExp) and industry affiliation (FINorINS) are significant in only one of the
five models.
67
TABLE 7.
Regression Results for Dependent Sub-Variables
Panel A – Dependent Variable Control Environment Oversight (SUMCE)
Variable Coefficient Std. Error t-stat p-value
AGE
-0.05
0.10
-0.52
0.605
CPA
-3.33
1.53
-2.18
0.031
IAExp
2.80
1.60
1.74
0.084
RVGT500mm
4.63
1.30
3.56
0.001
FINorINS
1.86
1.41
1.32
0.190
R² = 0.1331
F-statistic = 4.18 p
= 0.0015
Panel B – Dependent Variable Risk Assessment Oversight (SUMRA)16
Variable Coefficient Std. Error t-stat
p-value
AGE
0.10
0.08
1.22
0.226
CPA
-2.84
0.94
-3.02
0.003
IAExp
1.87
0.98
1.90
0.059
RVGT500mm
3.45
0.88
3.90
0.000
FINorINS
1.33
0.91
1.46
0.147
R² = 0.1807
F-statistic = 5.78 p
= 0.0001
Panel C – Dependent Variable Control Activities Oversight (SUMCA)
Variable Coefficient Std. Error t-stat
p-value
AGE
0.22
0.07
3.04
0.003
CPA
-3.26
1.00
-3.24
0.001
IAExp
0.53
1.46
0.36
0.718
RVGT500mm
1.40
0.97
1.44
0.152
68
FINorINS
1.09
1.12
0.97
0.336
Adj. R² = 0.1049
F-statistic = 4.35 p = 0.0010
Panel D – Dependent Variable Information and Communication Oversight (SUMIC)
Variable Coefficient Std. Error t-stat p-value
AGE
0.09
0.06
1.62
0.108
CPA
-1.18
0.84
-1.41
0.160
IAExp
1.09
1.17
0.93
0.352
RVGT500mm
3.00
0.80
3.73
0.000
FINorINS
1.81
0.93
1.94
0.054
Adj. R² = 0.1080
F-statistic = 4.73 p
= 0.0005
Panel E – Dependent Variable Monitoring Activities Oversight (SUMMA)19
Variable Coefficient Std. Error t-stat p-value
AGE
0.03
0.04
0.76
0.446
CPA
-0.89
0.70
-1.27
0.206
IAExp
1.32
0.84
1.57
0.118
RVGT500mm
2.22
0.71
3.12
0.002
FINorINS
1.00
0.67
1.49
0.138
R² = 0.1063
F-statistic = 2.43 p
= 0.0377
Overall, the primary analyses using SUMofSUMS indicate several interesting
relationships. First, I find that certain personal characteristics of audit committee
members are directly related to oversight of ICFR. Specifically, the age and internal audit
69
experience of the audit committee members are positively related to the extent of audit
committee oversight of ICFR. This finding also comes through in Panels B and C of
Table 7, which present a positive relationship between age and oversight of control
activies and a positive relationship between internal audit experience and oversight of
risk assessment processes. However, the audit committee member’s status as a CPA is
negatively related to audit committee oversight of ICFR, as indicated in Table 6 for the
overall model, as well as in Panels A, B, and C of Table 7. This indicates that audit
committee members who are CPAs serve on audit committees that devote less time and
attention to internal control oversight than do non-CPAs. These findings pertain to RQf –
Are variations in audit committee internal control oversight processes associated with
personal characteristics of the audit committee member?
Second, Tables 6 and 7 (Panels A, B, D, and E) show that audit committee
oversight of ICFR is significantly impacted by the size of the company and its affiliation
in a regulated industry (finance or insurance). This finding addresses RQg – Are
variations in audit committee and internal control oversight processes associated with
company characteristics? – and suggests that audit committee members serving large and
regulated corporations devote more time and attention to oversight of ICFR than those in
smaller companies operating in other industries. Accordingly, audit committee members
serving larger organizations must be extrememly vigilant in fulfilling their responsibility
for addressing their companies’ complexities, and audit committee members serving
regulated industries must be vigiliant in addressing their companies’ compliance and
litigation risks.
70
Finally, among the many variables presented in this study, none pertaining to the
board of directors or audit committee characteristics were found to be significantly
related to the audit committee’s overall oversight of ICFR. In other words, none of the
traditional corporate governance variables were found to be significant in explaining the
extent of an audit committee’s actions and time devoted to oversight of ICFR. Thus, in
addressing research question RQf, this study finds no evidence that variations in audit
committee internal control oversight processes are associated with board of director and
audit committee characteristics.
CHAPTER 5 – Conclusions, Limitations and Future Research In
this study, I examine the association between (a) personal characteristics of audit
committee members, (b) characteristics of the companies served by the audit
committee member participants, (c) characteristics of the company’s board of directors,
and (d) characteristics of the company’s audit committee and the audit committee’s
oversight of ICFR. Internal control is a critical area of audit committee oversight, as
noted by many survey participants in this study, including the following:
Overseeing internal controls is the single toughest job the audit committee
has in terms of normal business. The committee can evaluate the internal
audit group’s professionalism and approach and seek the external auditors’
opinion about the group, but at the end of the day the committee is relying
on somebody else’s opinion and attestation. (audit committee member)
Despite the critical nature of its charge, we know little about audit committee
processes pertaining to internal control oversight. The disparity is likely a reflection of
the difficulty in obtaining data about audit committee processes. This study employs a
survey to gather rich data from audit committee members about the processes they use to
monitor and oversee ICFR. One hundred twenty-six (126) survey responses from audit
committee members serving public companies were analyzed in the regression model in
this study, and an additional 41 audit committee members provided responses used in
other analyses.
72
71
5.1 Conclusions
The primary results indicate that audit committees are engaged in processes that
are aligned with the points of focus from the COSO (2013) framework, yet the responses
to open-ended survey questions suggest wide variation in audit committee practices. Such
variability may reflect a range of audit committee oversight from highly substantive
(agency theory) to more ceremonial (institutional theory). Further, the audit committee
members’ focus on discussions with others may reflect protocols that audit committee
members use to achieve “comfort” that the company’s controls are effective. I find links
between audit committee oversight of ICFR and (a) personal characteristics of the audit
committee member and (b) characteristics of the companies served by the audit
committee member participants. On the other hand, I find no significant links between
audit committee oversight of ICFR and traditional corporate governance indicators
pertaining to characteristics of the company’s board of directors and audit committee.
These overall findings both confirm and contest the findings of other governance
research that has examined audit committee processes. Specifically, I find that audit
committees are most engaged in internal control processes concerned with oversight of
monitoring activities and the control environment. Consistent with agency theory (Jensen
& Meckling, 1976), participants provided the highest ratings for actions related to the
provision of independent oversight of managagement and the external auditors. On the
other hand, the lowest ratings for audit committee actions are in the area of control
activities, followed by information and communication then risk assessment.
Consistently, many of the survey participants’ written comments indicate that other
corporate governance actors in their companies have primary responsibility for
overseeing these components of internal control.
73
The study’s findings regarding the personal characteristics of audit committee
members yield three measures that are associated with oversight of ICFR. I find that the
age of the audit committee member and his or her experience in an internal auditing role
are both positive indicators of more extensive oversight of ICFR. However, if the audit
committee member is a CPA, I find a negative association with audit committee oversight
of ICFR. This suggests that CPAs are serving audit committees that are less thorough in
exercising ICFR oversight responsibilities than are non-CPAs. The reasoning behind this
association wants further research. Perhaps this negative association may be due to the
similarities in oversight responsibilities of audit committees and external auditors who are
CPAs. For instance, CPAs may not actually be less engaged that non-CPAs; rather, their
scale ratings may be lower because they perceive their oversight activities as less
extensive and less time-consuming than audit committee members who are not
accustomed to performing oversight activities on a frequent basis. Further research is
needed to better understand the potential relationship between CPAs and audit committee
oversight of ICFR.
Regarding characteristics of the company, revenues and regulated industry were
both found to be positively associated with audit committee oversight of ICFR. In
particular, the largest companies – those with revenues greater than $500 million – have
more extensive audit committee oversight processes than smaller companies. Similarly,
companies in regulated finance and insurance industries have more extensive audit
committee oversight processes than non-regulated industries.
I believe this study makes a significant contribution to the literature in several
ways. First, for the academic researcher, this study begins to address the many calls in the
literature for details about audit committee internal control oversight processes and
practices. Second, for the regulator, it can aid in understanding audit committee
74
characteristics and processes that involve greater scrutiny and improved compliance, thus
stimulating future requirements aimed toward the provision of better information to
investors. Third, for the practitioner, it provides information relevant to audit committee
oversight that may help to prevent internal control failures, financial statement
misstatements, and their costly repercussions. Finally, this study provides important
practical insights into the linkages between audit committee processes and points of focus
from the COSO (2013) framework. These results deepen our understanding of audit
committee processes in the key area of internal control oversight.
5.2 Limitations
Like all studies, this study is subject to inherent limitations. First, the study’s
survey method for finding participant addresses through publicly available information
and using the United States Postal Service for delivery of survey instruments resulted in
the return of survey mailings for lack of deliverability. This can result in selection bias
which may reduce the sample’s representativeness of the population. Second, participants
may have been reluctant to divulge what might be perceived as shortcomings in their
extent of audit committee engagement. Given the fact that the survey questions are based
on points of focus from the COSO (2013) framework, participants may have perceived
and provided a favorable response. Yet the written comments provided by many
participants offered clarifications pertaining to specific actions within their oversight
processes, which suggest that this social desirability bias is not pervasive in this study.
Third, some judgment was required in interpreting written descriptions of audit
committee actions. However, most of the written responses were clear, and since the
written responses were an optional supplement to the scale questions in the survey, this is
not considered to be a pervasive issue with the study results.
75
5.3 Future Research
Future research is needed in several areas related to this study, especially with
regard to the composition of the audit committee and the personal characteristics that
influence effective audit committee oversight practices. In particular, more information
about the role of CPAs serving on audit committees could enhance our understanding of
the implications of this type of expertise. Additional research into audit committee
member expertise and biases could also provide useful information to companies and
regulators for improving ICFR. Similarly, more information is needed regarding the
association between traditional governance variables and the audit committee’s level of
activity in overseeing ICFR. Furthermore, continued research into audit committee
processes is needed to raise awareness of the diverse practices regarding oversight of
ICFR. Deeper analysis into these issues could offer further insights into the “black box”
of audit committee processes and potentially benefit company stakeholders.