The Most Important Criteria for “China SOX” Success

China’s Basic Standard for Enterprise Internalrisk management and internal controls
Control (C-SOX) is coming into effect soon, and while-          Have executives visibly
some of the implementation guidelines are not yet“own” the C-SOX implementation
clear, the core of the regulation is in place.-          Establish a “whistleblower”
The purpose of C-SOX is to increase themechanism and fraud reporting hotline to alter the
effectiveness of internal controls in listed Chinesecompany to potential problems
companies, thus reducing risks for companies andManagement will need to be visible in its support for
their stakeholders.  Companies must evaluate theirC-SOX and ensure that a sense of urgency is felt
internal controls, publish an evaluation report on anacross all offices and regions.  This means creating a
annual basis and audit the effectiveness of theirproject team with adequate representation from the
internal controls.  These are new concepts to manyentire business, and one with the political clout
organizations in China, and as a result there is somerequired to overcome institutional resistance to
resistance and confusion to deal with.  Many Chinesechange.
companies have poor risk management systems,Although responsibility for risk management and
inadequate business data and patchy ITcompliance ultimately sits with the CEO and Board of
infrastructures.  However, these are not the biggestDirectors, forward-thinking companies will move to
challenges facing companies that will be required topush responsibility to various parts of the
comply with C-SOX.organization.  C-SOX projects require participation
The biggest challenge for China SOX (and hence, thefrom many levels of an organization, and for
top criteria for success) is company culture.  Nocompliance projects to succeed, companies must
amount of money, software or consultants canmake their staff an active participant on the
compare with the beneficial effects of enlightenedintegrated project team.
and committed management.  For C-SOX to reallyIndustry leaders involve much of the organization in
succeed, companies have to embrace risktheir C-SOX implementation process and go beyond
management as a concept, adopt internal controlthe minimum requirements imposed by the Basic
frameworks and change their corporate culture.Standard for Enterprise Internal Control to improve
What does that mean?  For organizations to get theoperating results while introducing business
most benefits of C-SOX compliance, they must:improvements throughout the organization.
-          Foster openness and transparency inMany companies in China do not currently have this
the companykind of culture, and that is going to mean extra time
-          Be open to self-evaluation andand effort and required for proper implementation of
self-criticism (of the management team and allthe Basic Standard for Enterprise Internal Control. 
employees)Companies that see this as an opportunity to refresh
-          Report on perceived risks in a timelyand improve their corporate culture will be rewarded
fashionwith a quicker process and more tangible business
-          Provide training on the benefits ofbenefits.