Skip to main content
Compliance

Auditors oppose NYSE proposal to push back internal-audit timeline

The exchange wants to give newly public companies five years to set up internal audit functions, instead of one.

4 min read

TOPICS: Compliance / Corporate Governance & Ethics / Corporate Governance

Internal audit professionals aren’t happy with the NYSE’s proposal to loosen internal audit requirements for newly public companies.

The exchange on July 31 informed the SEC that it wanted to roll back its requirement that newly public companies establish an internal audit function within one year, and proposed making the requirement five years instead. The comment period for the proposal ended September 8.

CFO Brew examined the more than 100 comment letters posted on the SEC website and found that the vast majority either expressed concerns with the proposal or stated outright opposition to it. This includes a joint letter from industry organizations including, among others, the Institute of Internal Auditors (IIA), Association of Certified Fraud Examiners (ACFE), the risk-management society RIMS, and the Interfaith Center on Corporate Responsibility.

The letter reads, in part: “We come to this issue from different seats…but we share one conviction: independent, ongoing assurance over a public company’s risks and internal controls is foundational, and the proposal would defer it for half a decade.”

Anthony Pugliese, president and CEO of the IIA, said in a news release that extending the internal audit requirement to five years “is far too long for a public company to operate without the ongoing, objective assurance an internal audit function provides.”

How we got here. The IIA-led coalition noted the internal-audit requirement was adopted as part of the NYSE’s “post-Enron governance reforms” and has been in place for decades.

But the requirement has proven burdensome, the NYSE argued in statements it filed with the SEC. The stock exchange has found that “[o]ver time, issuers have expressed concern that developing a capable internal audit function within the first year of listing presents challenges as issuers adjust to life as a newly public company,” according to an Aug. 13 notice from the SEC.

Other regulatory requirements “provide sufficient assurance” that companies “are appropriately managing risk” during the five-year ramp-up period, the NYSE added, including its mandate that companies have an audit committee made up of at least three independent directors, and SOX Section 404 requirements for internal control structures. (Never mind that the SEC wants to roll back SOX 404(b) requirements for some filers.)

News built for finance pros

CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.

What’s more, the NYSE said, other companies could instead list on the Nasdaq, which carries no such internal-audit function requirement. Because the NYSE’s competitor has even looser restrictions, the NYSE stated it “does not believe that providing an extended transition period for its internal audit function should raise concern,” per the SEC notice.

Practitioners (mostly) aren’t buying it. In arguing that issuers find its one-year requirement to be a barrier, the NYSE “does not identify the number or characteristics of affected issuers,” nor does it “present the value added by internal audit or assess the potential governance and risk-management costs of delaying an internal audit function,” according to a letter signed by Brad Schafer, an accounting professor at Kennesaw State University

Richard Chambers, former president and CEO of the IIA and founder of Richard F. Chambers & Associates, wrote in a recent post on Accounting Today that, while he understands this is “a competitive issue” for the NYSE when compared with other stock exchanges, “solving that competitive problem by weakening a governance safeguard is the wrong trade.”

Jeffrey Mahoney, general counsel of the Council of Institutional Investors, wrote in a comment letter that his group believes that if the NYSE had “properly considered the SEC’s proposed exemptions from” SOX requirements, it “may have concluded that there would not be sufficient assurance that issuers listed on the [e]xchange could appropriately manage risk” in the proposed five-year window.

CFO Brew found at least one supportive comment among the bunch. The letter, authored by John Heagy, a senior manager at Cherry Bekaert, notes that internal audit has turned into a “check the box exercise” and that “[five] years may be excessive, but [one] year is fast.”

About the author

Alex Zank

Alex Zank is a reporter with CFO Brew who covers risk management and regulatory compliance topics. Prior to CFO Brew, he covered the property/casualty insurance industry.

CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.