Internal Controls After Sarbanes-Oxley: Revisiting Corporate Law's "Duty of Care as Responsibility for Systems"
Revisiting section 3.4.2 of Clark's Corporate Law ('Duty of Care as Responsibility for Systems") reminds us, however, that the internal controls story actually goes back many decades, and that many of the strategic issues that are at the heart of section 404 have long been contentious. My Article will briefly update Clark's account through the late 1980s and 1990s before returning to Sarbanes-Oxley and rulemaking thereunder by the SEC and the newly created Public Company Accounting Oversight Board ("PCAOB"). My main point builds on one of Clark's but digs deeper. Internal controls requirements, whether federal or state, are incoherent unless and until one articulates clearly for whose benefit they exist, and to what end. There are, in fact, a number of competing articulations. The failure to identify a single and coherent rationale creates significant uncertainty, which has been exploited by players in the legal, accounting, consulting, and information technology fields. Companies are probably spending more time and resources on 404 compliance than a reasonable reading of the legislation and the rules necessarily requires, heavily influenced by those who gain from issuer over-compliance. This rent-seeking compromises the political viability and substantive quality of what is at the heart a beneficial statutory reform.
31 J. Corp. L. 949-973 (2006)
Scholarly Commons Citation
Langevoort, Donald C., "Internal Controls After Sarbanes-Oxley: Revisiting Corporate Law's "Duty of Care as Responsibility for Systems"" (2006). Georgetown Law Faculty Publications and Other Works. 144.