All posts by admin

Cybersecurity – What the what??

After all the chaos and drama surrounding the most recent cybersecurity hack at Sony, the focus on this area has become even more intense.

Clearly, the first priority is doing whatever is possible to manage cybersecurity risk. Action steps must depend on each company’s specific situation, and there is no one-size-fits-all solution. To help in this regard PLI is presenting a One Hour Briefing on February 18, 2015 titled “ Cyber Security After Sony: Practice Points and Risk Mitigation Strategies”. You can learn more about the program at:

www.pli.edu/Content/Seminar/Cyber_Security_After_Sony_Practice_Points/_/N-4kZ1z120mn?fromsearch=false&ID=247142

We also have archived the webcast of our one-day program on managing cybersecurity at:

www.pli.edu/Content/OnDemand/Cybersecurity_2014_Managing_the_Risk/_/N-4nZ1z12f7s?fromsearch=false&ID=178337

From a disclosure perspective, the issues and the high public profile of the Sony hack raise the question whether cybersecurity risk should be disclosed in more detail or depth in upcoming filings. As a reminder, the SEC’s current guidance for cybersecurity risk disclosures is in CorpFin Disclosure Guidance Topic 2 at:

www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm

A point to remember for now, which is brought out in the Disclosure Guidance Topic, is this area may not be just a risk factor disclosure. Depending on the nature of the cybersecurity risk your company faces and cybersecurity issues you have encountered, disclosure in:

The business section
Legal proceedings
MD& A, and
The financial statements

may be necessary.

As always, we welcome your thoughts and feedback!

IFRS – The SAGA Continues

As most accountants have heard, Jim Schnurr, the new Chief Accountant at the SEC has been speaking about the SEC possibly continuing to consider the use of IFRS by domestic companies.

At the AICPA’s annual SEC/PCAOB conference in Washington, DC on Monday he delivered his latest update on the status of IFRS, and you can read that speech at:

www.sec.gov/News/Speech/Detail/Speech/1370543609306#.VIcHnYupqrI

In his speech he said “When I arrived at the Commission two months ago, Chair White asked me to take a hard look at where the staff had been on the issue and make a recommendation to her as to the path forward.”

While he did not say anything definite, it is clear the IFRS is no longer on the back burner!

He also said “Based on the progress of our collective efforts, I am hopeful to be in a position in the coming months to commence discussions with the Chair and the Commissioners about the different alternatives for potential further incorporation of IFRS and the related issues/concerns of each alternative with the objective of reaching a recommendation on what, if any, further incorporation or use of IFRS by US registrants would be permitted or required. And, of course, any rulemaking proposal that the Commission decides to consider would be subject to the normal notice and comment process.”

In the Q&A session Mr Schnurr elaborated on some ideas to incorporate, perhaps electively, IFRS information (in adition to US GAAP financial statements) into US registrant’s filings that would be useful for investors when comparing US registrants using US GAAP and those using IFRS. The ideas run the gamut of including IFRS measures in Selected Financial Data, IFRS data in MD&A, non-GAAP measures calculated using IFRS, and full financial statements in IFRS. He asked for feedback on these areas and input on additional ideas to consider.

So, this will not be a speedy process……

As always, your comments and thoughts are welcome!

Comment of the Week – Is it Material?

As we move towards the year-end reporting process one of the issues many of us, if not all of us, will have to deal with is materiality. Determining whether a particular issue or amount is material is not a simple question. When we decide that something is immaterial the SEC staff sometimes wants to “kick the tires” on that judgment.

Here is an example comment:

Note 1. Summary of Significant Accounting Policies, page 64

1. Please tell us in greater detail the facts and circumstances regarding the corrections to prior year’s income taxes and depreciation of properties. In your response, tell us how you complied with ASC 250-10-45-22 and SAB Topics 1M and 1N, and provide us with your materiality assessment. Please be detailed in your response.

This is a great example of finding an issue that affects prior years and deciding the issue is not material to the prior year or the current year. With that decision a restatement is not necessary.

In their comment the staff is not saying they disagree. But they do want to look more deeply into the judgments involved.

Those of course involve SAB Topic 1M, originally SAB 99 and the issues surrounding quantitative and qualitative materiality, along with Topic 1N, originally SAB 108, which requires evaluation of both the “roll-over” and “iron curtain” methods of evaluating the materiality of a misstatement.

You can find both of the SAB’s in the SAB Codification at the SEC’s website:

 www.sec.gov/interps/account/sabcode.htm

Here are two issues to be sure you deal with in your materiality memo.

First, SAB 99 provides a list of example issues that could make a quantitatively small amount qualitatively material. One “mistake” that companies still make is to view the list of qualitative factors in the SAB as a complete list. One of the worst flaws in a SAB 99 memo can be to list the factors in the SAB and conclude none of them apply and conclude the issue or amount is not material. You must go beyond this list and evaluate whether any other factors make the amount qualitatively material.

Second, and likely the most important advice in every materiality decision, is ALWAYS write your SAB 99 memo when you make the decision, don’t put yourself in a position of having to write it well afterwards!

As always, your thoughts and comments are welcome!

Heads up on Hedging: Hedge Accounting Back on the Agenda!

When the FASB created new hedge accounting requirements with the adoption of SFAS 133 (long ago…) many companies found that the burden of the new requirements and the technical complexity they presented made it simply impractical to use hedge accounting.

As a result, in many cases, the economics of a company’s risk management activities was not conveyed in their financial statements.

The FASB and IASB’s path towards new, and hopefully better, accounting for hedging activities has been almost as winding and twisting as actually trying to qualify for hedge accounting. Both boards originally put hedge accounting in the overall financial instruments project. When the complexity of this project increased, both boards moved hedge accounting to a back burner, and eventually it fell by the wayside for the FASB while the IASB did revise their hedge guidance.

The FASB met on November 5 to vote on whether to move this project to the active project agenda. The board materials included the following list of areas where changes may be considered:

      • Hedge effectiveness requirements
      • Component hedging for financial and non-financial hedged items
        (A potentially great way to match risk management and accounting)
      • Elimination of the short-cut and critical terms effectiveness assessment tools
        (New effectiveness requirements would make them obsolete)
      • Voluntary de-designation of a hedging relationship
        (Should this opportunity be removed)?
      • Recording ineffectiveness for under-effective cash flow hedges(How to measure this issue in the income statement)
      • Adjusting the benchmark interest rates
      • Simplifying hedge accounting documentation requirements
        (Oh please do this!)
      • Reviewing disclosure requirements

Hopefully the Board may move towards some targeted changes and improvements to hedge accounting in a direct fashion, which would be welcome changes for all of us using hedge accounting, and which may make it feasible for some of us who do not use hedge accounting because of the burdensome requirements to reconsider this decision, and get a conceptually better accounting outcome for our risk management activities.

When-fore art thou revenue recognition?

With every revenue recognition workshop we have presented to date participants have had strong opinions on the new standard’s implementation date. (For public companies the new standard must be implemented for periods beginning after December 15, 2016, years after December 15, 2017 for non-public companies.)

The FASB and IASB put this date into the public discussion well before the final standard was issued. That said, as soon as the final standard was published late last May constituents began voicing concerns about the feasibility of meeting this date. (Yes, given the protracted timing building new accounting standards many of us still don’t pay attention to the standard setting process until the new standard is final!)

In June and July, after feedback from constituents about the effective date began to flow in, the board indicated that they would be listening and be ready to react to this feedback.

At the Transition Resource Group meeting on October 31, 2015, it became clear that, as they always do, the board is listening.   At this meeting of the FASB Vice Chair Jim Kroeker announced that the Board and the FASB Staff will conduct additional outreach with both public and private companies over the next several months to gauge their progress in preparing to implement the new revenue recognition standard.

Mr. Kroeker emphasized that the Board is considering whether or not to defer the effective date of the new revenue standard. He also said that a decision will be made no later than the second quarter of 2015.

You can check out the archived webcast of the entire TRG meeting at:

www.fasb.org/cs/ContentServer?c=Page&pagename=FASB%2FPage%2FSectionPage&cid=1176164066683

As always, your thoughts and comments are appreciated!

Do you think the date should be deferred? Lets us know, and we will summarize everyone’s thoughts!

VIE Redux, and Perhaps a Bit Under the Radar…

The FASB is very close to finalizing new guidance that is expected to have a significant impact on VIE consolidation accounting. This new standard will require revisiting many, if not most, VIE determinations. It will change many existing VIE determinations.

The ASU is expected to be issued before the end of this year and to be effective in 2016 for public companies, with early adoption allowed.

This project has been in process for a long time, and the final stages are sneaking up on many of us. Because of the information that this redetermination will require, companies should:

  • Get out in front of determining what information they will need,
  • Proactively deal with the issues they may encounter in obtaining this information, and
  • Develop the new processes and controls these changes will necessitate.

During the development of the ASU most of the focus has been on investment management companies. The new VIE approach will have a significant impact in this industry. However, it will also impact most limited partnerships and will have a variety of other impacts.

The most significant areas that will be affected include:

  • Whether or not a limited partnership and similar entities are VIEs, and in particular the impact of kick-out rights,
  • When a general partner should consolidate a limited partnership, and again the impact of kick-out rights,
  • When and how variable interests held by the reporting entity’s related parties or de facto agents should affect consolidation conclusions,
  • How a fee paid to a decision maker or service provider by a VIE should affect the consolidation determination, and
  • When to require disclosures for a limited partnership that is a VIE but not consolidated by the reporting entity.

You can learn more about the project and its impact at:

http://www.fasb.org/jsp/FASB/FASBContent_C/ProjectUpdatePage&cid=1176157176582

As always, your thoughts and comments are welcome!

 

The TRG Rides Again! (More Revenue Recognition Issues to Discuss)

The IASB/FASB Transition Resource Group for Revenue Recognition is going to meet again on October 31, 2014. (Seems like a fitting day for this meeting!) In case you have not followed the TRG, this group will not issue guidance. Their mission is to identify issues, discuss them, and share their thoughts on each issue. The FASB and IASB will then decide what action, if any, will be taken on each issue.

The agenda for the meeting includes:

  • Customer options for additional goods and services and nonrefundable upfront fees
  • Presentation of a contract as a contract asset or a contract liability
  • Determining the nature of a license of intellectual property
  • Distinct in the context of the contract
  • Contract enforceability and termination clauses

As you may know the new standard requires a significant amount of judgment (as well as disclosure of significant judgments!) Each of these areas are complex and will require interpretation and judgment under the new revenue recognition model. This should be a very interesting discussion.

Coordinating the meeting between the IASB group in England and the FASB group in the US presents some interesting logistical challenges, and the meeting will actually begin at 7:00 AM EDT. It is scheduled to run until 2:00 EDT, so the time allocated will allow deep discussion of each issue!

The full agenda, the related Memos discussing each issue, information from the TRG’s first meeting and a description of the TRG’s processes can be found at:

www.fasb.org/cs/ContentServer?c=Page&pagename=FASB%2FPage%2FSectionPage&cid=1176164066683

As always, your thoughts and comments are welcome!

Comment of the Week (or so) Cybersecurity Risks Galore

Cybersecurity risk is again in the news. It seems like each cybersecurity incident is bigger and scarier than the breaches before. Clearly, the financial, reputational and other costs associated with these crimes are growing. Perhaps more importantly the efforts and costs associated with the prevention of these events are becoming more significant.

As we approach year end giving appropriate thought to cybersecurity disclosures will be an important discussion for most companies. As a reminder, the SEC’s existing guidance for cybersecurity disclosures is in Corp Fin’s Disclosure Guidance Topic 2, which you can find at:

www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm

The drive for more substantive disclosure, including information about the actual costs of cybersecurity breaches to a specific company and cybersecurity prevention costs are themes in the Corp Fin guidance, and these comments help emphasize the important issues in disclosures about cybersecurity risks.

In this comment the staff reminds the registrant about Disclosure Guidance Topic 2:

Technology security risks and environmental and pollution risks could potentially impact our financial results, page 11

6. It appears that this risk factor addresses two separate risks: (1) technology security risks and (2) environmental risks. In future filings, please revise your risk factor disclosure to address these risks under separate headings. Also, with respect to the technology security risks, to the extent that these risks may relate to cybersecurity threats, in future filings please clarify your disclosure accordingly as well as consider the Division of Corporation Finance’s Disclosure Guidance Topic No 2, which is available on our website at http://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.

Notice the focus on qualitative and quantitative disclosure in this comment:

3. Your risk factor disclosure should provide sufficient qualitative and quantitative disclosure to enable a reader to assess the impact that these risks may have on your results of operations. In this regard, we note the following:

Your risk factor “Our business could be adversely affected by incidents…” on page 9 does not provide sufficient qualitative disclosure for one to understand which aspects of your business operations may expose you to these risks nor does it identify the actual risks or provide examples of past system failures or accidents;

Your risk factor “Technology security risks and environmental and pollution risks could potentially impact our financial results” on page 11 does not specify to what “certain information and technology security risks” you may be exposed.

This comment shows how details should be included to help readers understand the nature and magnitude of the risk:

Our business could be negatively impacted by security threats, including cybersecurity threats…

31. We note your disclosure that an unauthorized party was able to gain access to your computer network “in a prior fiscal year.” So that an investor is better able to understand the materiality of this cybersecurity incident, please revise your disclosure to identify when the cyber incident occurred and describe any material costs or consequences to you as a result of the incident. Please also further describe your cyber security insurance policy, including any material limits on coverage.

And this comment emphasizes the need for MD&A discussion if related costs are material:

Item 1A. Risk Factors “Security breaches and other disruptions or misuse of our network and information systems could affect our ability to conduct our business effectively,” page 12

1. We note your disclosure that during 2012 the ******* computer network was the target of a cyber-attack that you believe was sponsored by a foreign government, designed to interfere with your journalism and undermine your reporting. We also note your disclosure that you have implemented controls and taken other preventative actions to further strengthen your systems against future attacks. If the amount of the increased expenditures in cybersecurity protection measures was or is expected to be material to your financial statements, please revise your discussion in MD&A to discuss these increased expenditures. Also, if material, please revise the notes to your financial statements to disclose how you are accounting for these expenditures, including the capitalization of any costs related to internal use software.

Hope all this helps, and as usual your comments and thoughts are welcome!

Up-to-date with Conflict Minerals

As many of us discovered in the run-up to the first Form SD for reporting about conflict minerals (which was due June 2 of this year), there was substantial uncertainty about how to fulfill this Dodd-Frank created reporting obligation. Uncertainty about what sort of procedures should support the report, how to draft the report and late-breaking legal wrangling about the rule were only a few of the challenges in the first compliance cycle.

Hopefully the second year of this requirement will be a bit less chaotic. To help reduce the chaos and hopefully bring some order to the process we are presenting a one-hour briefing on October 24, 2014 entitled:

SEC’s Conflict Minerals Rules: What We Learned from 2013 and What Happens Next

Here is a summary of the briefing:

So what did we learn from the filings? For the 1300+ public companies and over 250,000 private companies that sought to trace the use of 3TG, the Form SDs and CMRs (Conflict Mineral Reports) provide insights into the struggles that companies have within their supply chains to identify sources and manage data, and to report their compliance efforts and results to customers, the SEC and other constituencies. Public company compliance efforts also impact non-reporting suppliers and will impact interactions with supply chains as the next round of due diligence and reporting gets underway.

Hope this helps, and you can learn more at:

www.pli.edu/Content/Seminar/SECs_Conflict_Minerals_Rules_What_We_Learned/_/N-4kZ1z127tk?fromsearch=false&ID=234693

As always, your thoughts and comments are welcome!

The Season of ICFR

(Our apologies, the post is longer than usual, but it’s an important one)

Pumpkins, glorious foliage, and frost signal the arrival of Fall in NH, as well as hunting season.  Alas for many accountants, Fall signals the beginning of the assessment of internal control over financial reporting as calendar-year companies and their auditors start their interim testing and hunt for material weaknesses.  This year will likely be especially challenging due to recent PCAOB inspection report ICFR findings and guidance such as Staff Audit Practice Alert No. 11: Considerations for Audits of Internal Control over Financial Reporting, issued in October 2013.  The SEC has weighed in over the last year as well.  So, we thought it might be helpful as we start the ICFR season to increase your awareness of the PCAOB and SEC concerns over ICFR assessments and audits and point you to some resources worth reading.

Let’s start with the PCAOB.  It is no secret that the PCAOB inspection staff has focused on ICFR audits and has not been happy with a lot of them.  If this is news to you, just take a look at the inspection reports issued to the Big 4 over the last few years. The inspections staff expects the firms to show progress in addressing inspection findings in the next audit cycle, so the pressure is on.  As a result, it is very likely that your auditors will be changing their audit methodology in some way this year, which will ultimately trickle down to what you do.  So our recommendation to registrants is to be pro-active: read the last 2 inspection reports your auditor received (you can find them at http://pcaobus.org/Inspections/Pages/PublicReports.aspx), read Staff Alert No. 11 (find it at http://pcaobus.org/Standards/QandA/10-24-2013_SAPA_11.pdf), and talk to your auditors about anticipated changes in your audit and their expectations.  And if you have an appetite for more, see an interesting speech by Board Member Jeanette Franzel at http://pcaobus.org/News/Speech/Pages/03262014_IIA.aspx.

The SEC has also expressed concern that some of the PCAOB’s inspection findings “are likely indicators of similar problems with management’s evaluation” (see Deputy Chief Accountant Brian Croteau’s speech last December at www.sec.gov/News/Speech/Detail/Speech/1370540472057#.VC6uXEuppZg)

For years, the SEC has voiced its concern that material weakness findings are lagging indicators, discovered as a result of a restatement, and not a leading indicator discovered in the ICFR assessment in time to prevent a restatement.  Case in point is the recent SEC Enforcement case against JDA Software Group.  The SEC investigation found that the company had inadequate internal controls over financial reporting, specifically in the area of revenue recognition, resulting in a multi year restatement.  And from Mr, Croteau’s remarks cited above there are more ICFR enforcement cases in the pipeline…

We hope this helps – happy hunting!

As always, we would love to hear your comments!