Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Disclosure & Financial Reporting

Disclosure Controls and Procedures

Also known as: DC&P, Disclosure Controls
Simply put

Disclosure controls and procedures are the processes a public company puts in place to make sure that important information is gathered, reviewed, and reported accurately and on time in the filings it submits to securities regulators. Their purpose is to help ensure that material information reaches the people who prepare and certify the company's public reports so that required matters are disclosed fully and promptly. In short, they are the mechanisms that support complete and timely public disclosure.

Formal definition

Disclosure controls and procedures (DC&P) are controls and other procedures of a securities issuer designed to ensure that information required to be disclosed in reports filed or submitted under applicable securities laws (in the U.S. context, the Securities Exchange Act) is recorded, processed, summarized, and reported within the required time periods, and is accumulated and communicated to management to allow timely decisions regarding disclosure. DC&P are to be designed, maintained, and periodically evaluated to help ensure full and timely disclosure of matters required to be disclosed. Note that DC&P are broader than, but related to, internal control over financial reporting (ICFR): DC&P address the full range of disclosures in periodic reports, while ICFR focuses specifically on the reliability of financial reporting. As a compliance obligation, DC&P requirements arise from securities regulation and are jurisdiction-specific; the precise scope, certification requirements, and effective dates should be verified against the governing statutes, rules, and current regulatory guidance, and professional advice may be needed for particular filings.

Why it matters

Public companies operate under securities laws that require them to disclose material information fully and on time. Disclosure controls and procedures (DC&P) are the mechanisms that make this possible in practice: without a reliable process to capture, review, and route material information to the people who prepare and certify public filings, a company risks omitting or delaying disclosures that investors and regulators expect. In this sense, DC&P sit at the intersection of governance and compliance, translating a legal obligation into a repeatable internal process.

The stakes are significant because disclosure is a certified, regulator-facing activity rather than an internal matter alone. Regulators such as the SEC (in the U.S. context) require that DC&P be designed, maintained, and periodically evaluated, and recent enforcement discussion has emphasized that the adequacy of these processes can itself be a subject of regulatory scrutiny. Weaknesses in the way information is collected for public filings can expose a company to enforcement risk even where the underlying financial statements are not the primary concern.

It is worth noting that DC&P are broader than internal control over financial reporting (ICFR). ICFR focuses specifically on the reliability of financial reporting, whereas DC&P address the full range of disclosures in periodic reports, including non-financial matters. Treating the two as interchangeable can leave gaps in the disclosure process, since information that falls outside the financial statements still needs a controlled path to the people responsible for public reporting. The precise scope and certification requirements are jurisdiction-specific and should be verified against the governing statutes, rules, and current regulatory guidance.

Who it's relevant to

General Counsel and Securities/Disclosure Counsel
Legal teams advising on public filings rely on DC&P to ensure that matters required to be disclosed are identified and reported completely and on time. They often help design and assess these processes, and are typically attentive to how the scope and certification requirements apply under the governing securities laws for a given filing.
Chief Financial Officers and Senior Executives Who Certify Filings
Executives responsible for preparing and certifying a company's public reports depend on DC&P to accumulate and communicate material information to them so they can make timely decisions regarding disclosure. Effective DC&P support the completeness and timeliness of the information underlying their certifications.
Compliance Officers
Compliance professionals treat DC&P as a securities-regulation obligation that must be designed, maintained, and periodically evaluated. They are often involved in confirming that processes exist to capture material information across the organization and route it to those responsible for public reporting, and in tracking how requirements differ by jurisdiction.
Internal Auditors and Financial Reporting Teams
Those responsible for reporting and assurance need to distinguish DC&P from internal control over financial reporting (ICFR). Because DC&P address the full range of disclosures in periodic reports while ICFR focuses specifically on the reliability of financial reporting, these teams often help evaluate whether disclosure processes adequately cover non-financial as well as financial information.

Inside DC&P

Scope of Covered Disclosures
Disclosure controls and procedures are typically designed to address information required to be disclosed in reports filed or submitted under applicable securities laws, extending beyond financial statements to encompass narrative, qualitative, and non-financial information that management must communicate to the market.
Timely Accumulation and Communication
A core element is ensuring that material information is accumulated and communicated to those responsible for disclosure, including senior management, in a manner that allows timely decisions about what must be disclosed. The emphasis is on the flow of information within specified reporting timeframes.
Recording, Processing, Summarizing, and Reporting
These controls typically aim to provide reasonable assurance that relevant information is recorded, processed, summarized, and reported within the periods specified by applicable rules. This describes a process orientation rather than a single point-in-time check.
Management Certification and Evaluation
In many regimes, designated officers periodically evaluate the effectiveness of disclosure controls and procedures and may be required to certify conclusions about that effectiveness. This ties the concept to individual accountability at the senior level.
Relationship to Internal Control Over Financial Reporting (ICFR)
Disclosure controls are broader in scope than ICFR: they cover the full range of required disclosures, while ICFR focuses specifically on the reliability of financial reporting. The two overlap but are not synonymous, and this distinction is frequently a source of confusion.

Common questions

Answers to the questions practitioners most commonly ask about DC&P.

Are disclosure controls and procedures the same thing as internal control over financial reporting (ICFR)?
No, though the two often overlap and are sometimes confused. Disclosure controls and procedures are typically understood to be broader in scope: they are designed to ensure that information required to be disclosed in a company's reports is recorded, processed, summarized, and reported within required timeframes, and that it is accumulated and communicated to management to allow timely decisions about disclosure. This can encompass both financial and non-financial information. Internal control over financial reporting, by contrast, focuses specifically on the reliability of financial reporting and the preparation of financial statements. In many frameworks the two overlap where financial information is concerned, but disclosure controls also reach material information that may fall outside the financial statements. The precise boundaries can vary by jurisdiction and should be confirmed against the applicable regulatory source.
Does having disclosure controls and procedures in place guarantee that all material information will be disclosed correctly?
No. Like any system of controls, disclosure controls and procedures are designed to reduce risk to an acceptable level rather than to eliminate it. They typically provide reasonable, not absolute, assurance that required information is captured, evaluated, and reported appropriately. Limitations such as human judgment, the possibility of management override, resource constraints, and the inherent difficulty of assessing materiality mean that even well-designed controls can fail. Certifications and evaluations associated with these controls generally reflect this reasonable-assurance standard rather than a guarantee of outcome.
Who is typically responsible for evaluating the effectiveness of disclosure controls and procedures?
Responsibility for the design, maintenance, and evaluation of disclosure controls generally rests with management, and in many regulatory contexts specific senior officers are involved in periodic evaluations and related certifications. It is common practice to establish a disclosure committee or a similar cross-functional group to support this work, drawing on personnel from finance, legal, compliance, investor relations, and operations. The board or an audit committee often provides oversight. The exact allocation of responsibilities depends on the organization's structure, sector, and applicable regulatory requirements, and roles should be documented clearly.
How often should disclosure controls and procedures be evaluated?
Evaluation is commonly tied to reporting cycles, so that the effectiveness of the controls can be assessed in connection with the periodic reports being filed. Many organizations also perform ongoing monitoring between formal evaluation points and revisit their controls when significant changes occur, such as a new business line, an acquisition, a change in reporting obligations, or an identified control deficiency. The specific frequency and timing expectations depend on the applicable regulatory framework and should be verified against the primary source rather than assumed.
What role does a disclosure committee play in supporting these controls?
A disclosure committee, where established, typically serves as a coordinating body that helps ensure material information flows to the people responsible for disclosure decisions on a timely basis. In practice such committees often review draft filings and disclosures, consider materiality questions, gather input from relevant functions, and support senior management in reaching disclosure conclusions. The committee is generally a leading-practice mechanism rather than a universally mandated body; its composition, charter, and authority vary by organization and should be tailored to the entity's size, complexity, and reporting obligations.
How should organizations document their disclosure controls and procedures?
Documentation commonly includes a description of the processes by which information is identified, gathered, evaluated for materiality, and escalated to those making disclosure decisions, along with defined roles, responsibilities, and timelines. Many organizations also retain evidence of periodic evaluations, sub-certifications from process owners, meeting records of any disclosure committee, and records of how identified deficiencies were addressed. Clear, contemporaneous documentation supports the ability to demonstrate that controls were designed and operating as intended. The level of formality that is appropriate depends on the organization's size, complexity, and regulatory environment, and specific documentation expectations should be confirmed against the applicable requirements.

Common misconceptions

Disclosure controls and internal control over financial reporting are the same thing.
They overlap but differ in scope. ICFR concerns the reliability of financial reporting, whereas disclosure controls and procedures typically extend to all information required to be disclosed, including qualitative and non-financial matters. Treating them as identical can leave gaps in the disclosure of non-financial material information.
Effective disclosure controls guarantee that all material information will be disclosed accurately and on time.
Like other control systems, disclosure controls are generally designed to provide reasonable, not absolute, assurance. They reduce the likelihood of failures but cannot eliminate the risk of error, judgment lapses, or override, and their effectiveness depends on consistent operation and periodic evaluation.
Disclosure controls are solely the responsibility of the finance or accounting function.
Because required disclosures often depend on information originating across the business, effective controls typically require input and communication from multiple functions, with accountability resting at the senior management level rather than in a single department.

Best practices

Clearly delineate the scope of disclosure controls from internal control over financial reporting, documenting how each addresses financial versus broader qualitative and non-financial required disclosures.
Establish defined channels for accumulating and communicating material information to those responsible for disclosure decisions, so that relevant matters reach senior management within applicable reporting timeframes.
Involve functions beyond finance, such as legal, operations, and other business units, in identifying information that may require disclosure, recognizing that material information often originates outside accounting.
Conduct and document periodic evaluations of the effectiveness of disclosure controls and procedures, retaining evidence that supports any required management certifications.
Frame the objective of these controls as providing reasonable assurance rather than a guarantee, and review them regularly to reflect changes in the business, applicable rules, and reporting obligations.
Confirm specific requirements, certification obligations, and effective dates against the primary regulatory sources applicable to your jurisdiction and sector, seeking professional advice where interpretation is required.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide