On January 29, 2019, the SEC announced four settlements with publicly-traded companies electricity grid australia for failure to maintain adequate internal control over financial reporting (ICFR). None of the companies was charged with making false or inaccurate statements, either about its ICFR or otherwise; indeed, each had repeatedly disclosed material weaknesses in ICFR over many years.

Section 13(b)(2) of the Exchange Act imposes record keeping requirements on public companies and requires them to “maintain a system of internal accounting controls.” [1] That has been true since 1977, when these provisions were added to the Exchange Act by the Foreign Corrupt Practices Act. The broadly worded statutory requirement was given specific content in 2003 when the SEC adopted a specific regulatory framework, based on Section 404 of the 2002 Sarbanes-Oxley Act, that requires a public company to (1) maintain ICFR, (2) assess its effectiveness annually, (3) disclose the assessment in the annual report and (4) (with some exceptions) disclose the report of the independent auditor on the effectiveness of ICFR. The framework is provided primarily by Rule 13a–15, [2] and it is often referred to as “SOX 404.”

After the adoption of the SOX 404 framework, questions arose about whether filing an annual report that discloses material weaknesses and ineffective ICFR has other consequences under the SEC’s rules. In particular, the SEC took the view that such a report does not make a company ineligible to use short-form registration under the Securities Act of 1933. [3]

There have been some SEC enforcement actions for Rule 13a–15 violations. The SEC has included charges of violating the ICFR maintenance requirement where the company has also engaged in intentional misconduct or had to restate prior disclosures. [4] The SEC has also cited violations of the ICFR evaluation requirement in a 2018 action against Primoris for violating the maintenance requirement. [5]

More recently, ICFR has been a focus of public statements by SEC staff. In a December 2018 speech, SEC Chief Accountant Wesley Bricker encouraged ongoing attention to the adequacy of and basis for a company's assessment of the effectiveness of ICFR. [6] The speech emphasized that "internal controls are the first line of defense against . . . material errors or fraud in financial reporting," a remark that is repeated almost verbatim in Mr. Bricker's quote in the SEC press release announcing the settled ICFR-related charges. [7] The Settled Charges

There are some differences in the charges against the four companies, reflecting differing circumstances. Each company was found to have violated both the general statutory requirement to maintain sufficient internal accounting controls (Exchange Act Section 13(b)(2)(B)) and the specific regulatory requirement to maintain ICFR (Rule 13a–15(a)). In addition, Simec and Lifeway failed even to evaluate the effectiveness of ICFR for two reporting periods, so they were found to have also violated the requirement to evaluate ICFR (Rule 13a–15(c)). [8] Finally, Lifeway restated its financial statements three times during the years in question, and it was found to have violated the requirements to keep accurate books and records (Section 13(b)(2)(A)) and to file periodic reports (Rule 13a–1).

The two orders finding only violations of the ICFR maintenance requirements (Digital Turbine and CytoDyn) are the most instructive. While the SEC has previously found violations of the maintenance requirements, those cases typically targeted companies that were found to have engaged in other misconduct as well. Here there is no finding of any other misconduct—in fact, the two companies had complied with the evaluation requirement (finding their ICFR to be ineffective) and the disclosure requirement (disclosing their findings).

At what point does persistent ineffectiveness ripen into a violation of the ICFR maintenance requirement? In these cases the persistence was egregious—seven years for Digital Turbine and nine years for CytoDyn—but it seems safe to guess that the line can be crossed much faster than that, depending on the circumstances. In general, last week’s SEC actions signal to companies that they should undertake quick and effective remediation efforts for control deficiencies they identify.

Time will tell whether the SEC is interested in bringing more cases predicated solely on controls violations and, if so, what specific substantive obligations it may consider ripe for action. But, in the meantime, the current cases reinforce the SEC's recent focus on controls over the quality of information being disseminated to investors. Other such recent cases include the SEC's September 2018 settlement with Tesla for not having disclosure controls over the Twitter feed of its CEO Elon Musk, [9] and its October 2018 findings on whether certain public companies that were victims of cyber-related frauds violated the statutory requirement to maintain internal controls. [10] Endnotes

