SEC Launches Dedicated Unit to Hunt Accounting Fraud
The SEC has just stood up a new enforcement unit focused specifically on accounting fraud. For most people in the C-suite, this looks like another bureaucratic shift in Washington. For the person actually maintaining the ledger, it is a direct threat to their weekend plans.
When a regulator builds a dedicated unit, they aren't looking for clerical errors. They are hunting for intent. This isn't about whether you followed the GAAP manual to the letter; it is about why certain revenue figures were recognised in Q3 instead of Q4.
I have sat on both sides of this table. The company always presents a slide deck showing a "mature" control framework. I hate that word. In my experience, when someone describes their process as mature, it usually means they've been doing the same thing for five years and have stopped questioning if it actually works. They've mistaken habit for security.
The real test is simpler: what would you show the assessor on a Tuesday?
If an auditor asks to see the supporting evidence for a specific high-value transaction from eighteen months ago, can you produce the original source document in ten minutes? Or do you have to spend three days "reconstructing" the trail through emails and spreadsheets? If it's the latter, you don't have a control. You have a memory exercise.
The SEC's win against a former CEO over a revenue scheme proves that they are no longer content with just fining the corporate entity. They are going after individuals. This shifts the risk profile for the mid-level controller who was told to "make the numbers work" by a superior.
Some will argue that this is overkill, especially since the SEC has simultaneously eased some disclosure requirements. They'll say the regulator is sending mixed signals.
They're wrong.
The SEC is simply narrowing its focus. They are less interested in your narrative disclosures and more interested in whether your revenue numbers are fiction. By easing the paperwork, they are removing the noise so they can hear the alarms more clearly.
This creates a second-order effect that hits the external auditors first. The firms signing off on these books know that if the new enforcement unit finds fraud, the auditor is the first person the SEC will blame for negligence. Expect your external audit fees to climb and your sample sizes to grow. Your auditors are now terrified of being the one who missed the "revenue adjustment" in a hidden tab.
Look at the fallout from other sectors. OSF HealthCare just paid just over half a million dollars to settle federal privacy claims. Unlimited Technology Systems saw 3.8 million patient records exposed. In those cases, the failure was technical. Accounting fraud is different because it's often a failure of will.
If you are the one implementing these controls, stop looking at the framework. Stop reading the policy documents that tell you what "should" happen. Instead, pick five random transactions from last quarter. Try to find every piece of evidence that justifies their recognition without asking anyone for help.
If you can't do that by lunch, your process isn't mature. It is fragile.
The new unit will likely start with the firms that have had recent "discretionary monitors" or those who have used reverse stock splits to stay compliant with bid-price rules. They are looking for patterns of desperation.
Check your spreadsheets for cells with hard-coded numbers where there should be formulas. That is usually where the bodies are buried.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- SEC Nets Win In Suit Over Ex-CEO's Alleged Revenue Scheme - Law360 Compliance Week (Google News)
- Norway’s $2 trillion sovereign fund opposes SEC plan to scrap climate reporting rules - Crypto Briefing Compliance Week (Google News)
- SEC launches new enforcement unit aimed at accounting fraud - CFO Dive Compliance Week (Google News)
- OSF HealthCare Pays $552,250 in Federal Privacy… - inkl Data Privacy (Google News)
- EU-US Data Privacy Framework Under the Spotlight Following FTC Independence Ruling - The National Law Review Data Privacy (Google News)
- Data Breach at Unlimited Technology Systems Exposes 3.8 Million Patients - kobaran.com InfoSec Compliance (Google News)
- Unlimited Technology Systems Data Breach Affects 3.8 Million Patients - The HIPAA Journal InfoSec Compliance (Google News)
- PRIVACY ALERT: Lifespan Physicians Group Under Investigation for Data Breach of Over 290,000 Patient Records - KITV Data Privacy (Google News)