20 Years After Passage of Sarbanes-Oxley Act, Companies Face Continuing Struggle to Moderate Compliance Costs, Finds New Protiviti Survey

By Research Associate and Content Manager, Sheridan LePlatt

  • Protiviti finds that hours devoted to SOX compliance increased for 53% of companies across most industries, company sizes and reporting types.

  • Companies need to explore alternative delivery models and automation for SOX compliance to drive a more effective and efficient execution strategy in the face of numerous challenges.

  • Companies that are beyond their second year of SOX compliance, average annual costs for SOX compliance went up 18% from 2021 to 2022.

The thirteenth annual Sarbanes-Oxley (SOX) Compliance Survey, conducted by global consulting firm Protiviti, finds that hours devoted to SOX compliance increased for 53% of companies across most industries, company sizes and reporting types. Coinciding with the 20th anniversary of the passage of the U.S Sarbanes-Oxley (SOX) Act, the 2022 survey results illustrate the need for companies to explore alternative delivery models and automation for SOX compliance to drive a more effective and efficient execution strategy in the face of continued cost pressures, intensifying scrutiny from external auditors (due to guidance from the U.S. PCAOB), labor shortages, remote and hybrid working models, and other challenges.

The survey found that for companies that are beyond their second year of SOX compliance, average annual costs for SOX compliance went up 18% from 2021 to 2022. Thirty percent of surveyed companies beyond their second year of SOX compliance spent more than $2 million in their most recent fiscal year, versus 24% the prior year. While companies are increasing their use of automation and external resources, there is still significant opportunity to moderate cost increases for SOX compliance.

Andrew Struthers, Protiviti

“Today internal audit and finance leaders have a menu of options available to innovate and streamline their SOX compliance programs and lessen internal burdens, from technology tools that support automation, provide workflow capabilities and support document management, to alternative delivery models, such as centers of excellence managed internally or by an external outsourcing partner,” said Andrew Struthers-Kennedy, a Protiviti managing director and global leader of the firm’s Internal Audit and Financial Advisory practice. “The ongoing war for talent underscores the urgency for internal audit leaders to explore the staffing and retention advantages that alternative service delivery models can yield. Delivery center organizational structures offer internal audit teams the ability to focus on strategic contributions and avoid burnout and turnover related to certain repetitive and routine SOX program activities.”

To demonstrate the potential for savings from automation, for an organization with 200 controls, a reduction of one hour in, for example, testing for operating control effectiveness can result in 200 saved person hours and yield significant benefits in effectiveness and population coverage.

In addition to increasing their investment in supporting automation, survey respondents signaled increasing interest in leveraging internal shared services models and partnerships with third parties that operate external centers of excellence for controls testing. On average, 41% of surveyed organizations’ SOX compliance costs are for outsourced resources, either onshore or offshore, up from 37% in 2021. Fifty-four percent of surveyed companies are leveraging audit management and GRC platforms; two out of five organizations are using data analytics and visualization platforms; and one in three are using segregation of duties analysis tools and continuous monitoring. However, companies utilize technology tools on an average of 25% of their overall SOX compliance program activities, leaving significant room for improvement.

The Protiviti report, titled "SOX Compliance Amid Rising Costs, Labor Shortages and Other Post-Pandemic Challenges," is based on a survey of more than 560 audit, compliance and finance leaders and professionals, representing a wide range of industries. The survey was conducted with support from AuditBoard, a leading cloud-based audit, risk and security compliance management platform, in March and April of 2022.

To read more, please visit: https://www.protiviti.com/US-en/insights

Staff Reports