Article

Corporate Conduct: Guidance From Afar

Jan 01, 0001

Long before Senator Paul Sarbanes and Representative Michael Oxley took it upon themselves to craft a federal law designed to thwart mega-accounting frauds like those at Enron, Tyco and WorldCom, a respected, retired Judge in South Africa named Mervyn King was hard at work fashioning a set of standards aimed at enhancing corporate board, audit committee and internal audit influence over governance and risk mitigation... including fraud risk.

By Peter Goldmann, CFE 

 

Long before Sen. Paul Sarbanes and Rep. Michael Oxley took it upon themselves to craft a federal law designed to thwart mega-accounting frauds like those at Enron, Tyco and WorldCom, a respected, retired judge in South Africa named Mervyn King was hard at work fashioning a set of standards aimed at enhancing corporate board, audit committee and internal audit influence over governance and risk mitigation... including fraud risk.

 

The first draft of the "King Report on Governance for South Africa" was published in 1994. It was considered by some to be groundbreaking work in the area of corporate governance. But it lacked much of the "muscle" that many felt was needed to keep businesses on an ethical path. Hence, "King II" was published in 2002. It introduced the key elements of board responsibility and risk management.

 

It was upon the foundation of King II that the current version, predictably dubbed "King III," was written, adding substantive standards for board conduct, risk mitigation and internal audit responsibility. The provisions in these key areas are all well worth reading by Americans for whom the gold standard of corporate governance continues to be Sarbanes-Oxley -- whose essential confinement to management’s responsibility for ensuring the effectiveness of internal controls (Section 404) seems rather inadequate in light of the massive frauds that were perpetrated during the boom years leading up to the recession of 2008.

 

Key Provisions 

Unlike most corporate governance codes (including Sarbanes-Oxley), King III is non-legislative, and is based on principles and practices. It also espouses an "apply or explain" approach, unique to the Netherlands until King, and now also found in the 2010 Combined Code from the United Kingdom.

 

The philosophy of King III consists of the three key elements of leadership, sustainability and good corporate citizenship. It views good governance in refreshingly simple terms, namely effective, ethical leadership. King III insists that leaders direct the company in order to achieve sustainable economic, social and environmental performance.

 

In a rather more philosophical vein than would likely be found in U.S. corporate governance laws and professional standards, King III defines "sustainability" as the primary moral and economic imperative of this century. Its view on corporate citizenship flows from a company's standing as a juristic person under the South African constitution and should operate in a sustainable manner.

 

This, of course, is nothing uniquely South African. It just so happens that the common sense view of how businesses should behave was born in that country (whose history, notably enough, is densely blemished by government and corporate conduct, which might well be defined as the egregious opposite of what King III espouses).

 

Another important distinction between King III and U.S. law is that, according to PricewaterhouseCoopers, "Almost all frameworks that enable management to assess internal financial controls draw on experiences gained in complying with Section 404 of the Sarbanes-Oxley Act (SOX). Unlike King III, SOX requires the external auditor to assess internal financial controls. As a result, much of the guidance in applying SOX came from the external auditors and did not always take management's requirements into consideration. Management best understands the risks that impact financial reporting."

 

Of course, a problem arises where management itself is breaking the law. However, that's where King III's unusually strong emphasis on the proactive role of the board comes into play. Unlike in the U.S., where boards continue to be ridden with CEO favoritism and general lack of independence, King III calls for carefully selected, independent-minded board members, including a risk committee of the board responsible for continuously assessing the management team’s adherence to responsible risk levels -- including fraud risk.

 

Key language in the King III code states, for example, that "The board should ensure that risk assessments are performed on a continuous basis (minimum annually) using a top-down approach." The document goes on to state that directors should ensure that the company has a "fraud risk plan" that outlines the organization's exposure and prevention measures.

 

Again, this reads more clearly and specifically with respect to management and the board's role in fraud risk control than most comparable U.S. laws and standards (with the distinct exception of the new, yet conspicuously under-publicized, December 2011 COSO Integrated Framework). However, the latter is centered around the importance of internal controls in assessing, mitigating and responding to risk and defines itself as "principle-based" as opposed to "risk-based" in the case of King III.

 

Importantly, the new COSO Framework does include one critical management imperative that King III lacks -- that of risk assessment (including fraud risk assessment). While King III does address the matter of risk management in considerable detail, it does not expressly call for management to conduct an annual risk assessment, as COSO does. Such assessments, specifically fraud risk assessments, are considered by a growing number of  large U.S. organizations to be integral to their overall risk mitigation strategies.

 

Everyone is Covered 

In contrast to its earlier versions, King III is applicable to all entities, public, private and non-profit. King encourages all entities to adopt the King III principles and to explain how these have been applied or are not applicable.

 

Risk Management 

Under King III, risk management is inseparable from the  company's strategic and business processes. The board is responsible for the risk management process (including company's risk appetite, capacity and tolerance limits) and may delegate risk management to a risk committee. According to the document, the risk committee: 

 

Can be comprised of executive, non-executive directors, management and independent risk management experts with a minimum of three members 

Should be chaired by a non-executive director and meet at least twice per annum 

Should consider risk maturity, risk management activities, significant risks, material losses or changes in risks, due diligence activities, IT risks and risk reporting. 

 

Appropriately, under King III, management is responsible for implementing the risk management process and risk management should be embedded in the company, practiced daily by staff, and risks should be assessed on an ongoing basis. The Board, meanwhile, is responsible for compliance with laws and applicable rules and standards and compliance should be entrenched in the company’s culture and values (it is vital to the risk management process). Risks of non-compliance should be identified and addressed through the company's risk management process (this may include a compliance function.)

 

Internal Audit's Critical Role 

King III places more emphasis on the role of internal audit by requiring the CAE to provide a written assessment of the system of internal controls and risk management to the board, as well as a written assessment of the internal financial controls to the audit committee. In addition, I/A should: 

 

Provide independent assurance on the governance processes, ethics, risk management, performance, business processes and internal controls (management to specify elements of control model against which the controls can be measured) 

Follow a risk based internal audit approach (plans should be used and endorsed by the Audit Committee) 

Be independently quality reviewed every 3 years. 

 

 

King III differs from Sarbanes-Oxley in that no attestation is required from external auditors on internal financial controls. The audit committee should make a statement to shareholders on the internal financial controls. This is intended to further raise the profile of internal audit.

 

The bottom line is that while the U.S. consistently generates some of the most sophisticated corporate governance and anti-fraud laws and standards, it does have competition from abroad. It may serve legislators and governance experts well to think "outside the country" to find new ideas that further promote their quest for best practices in fraud risk mitigation and enhancement of ethical corporate conduct.