Public companies must maintain controls designed to ensure that information required to be disclosed is recorded, processed, summarised and reported within the required periods, and communicated to management to allow timely decisions.
Distinct from internal control over financial reporting, which addresses the reliability of financial reporting. Disclosure controls are broader, covering non-financial disclosure as well.
Components. A disclosure committee with representation from finance, legal, operations and investor relations; a sub-certification process gathering representations from business unit leaders; a calendar; and a documented review of drafts.
Evaluation. Management evaluates effectiveness as of the end of each period and discloses the conclusion.
Certifications. Principal executive and financial officers certify the report’s accuracy, the design and evaluation of controls, and disclosure to the auditors and audit committee of significant deficiencies and of any fraud involving management or employees with a significant role in controls.
Consequences. A false certification carries civil and criminal exposure, and certifications have been the basis of enforcement where the underlying process was inadequate.
Sub-certifications are the practical mechanism, and their value depends on the certifying managers understanding what they are attesting to rather than signing a form.