Corviniti/Services/SOX & Internal Controls

Services / SOX & Internal Controls

SOX & Internal Controls

The five places SOX programs actually fail: scoping, IT general controls, the reports controls rely on, deficiency evaluation, and remediation timing. Each with the fix.

We build and run a SOX program sized to your actual risks, so a lean team can operate it and your auditors can rely on it.

Or call (347) 472-1115

Ro Sokhi, CPA, founder of Corviniti, on SOX readiness and internal controls advisory
Ro Sokhi Founder and CEO, Corviniti
In the press
Overview

SOX and internal controls: scoping, IT controls, deficiencies, and the 404 timeline

Key takeaways
  • What it is. A right-sized ICFR program: a top-down scope under COSO 2013, IT general controls and the reports your controls rely on, deficiency evaluation, remediation, and the 302 and 404 obligations on a newly public company's schedule.
  • Where it breaks. Programs scoped to the wrong risks, controls that depend on systems and reports nobody validated, and deficiencies evaluated too generously until an auditor evaluates them differently.
  • How we help. We design, document, test, and remediate ICFR for public companies and companies on the way there, sized so a lean finance team can actually operate it.

SOX failures are rarely about missing controls. They are about programs scoped to the wrong risks, controls that depend on systems and reports nobody validated, and deficiencies evaluated too generously until an auditor evaluates them differently. The mechanics below are where the judgment lives.

We design, document, test, and remediate ICFR for public companies and companies on the way there, sized so a lean finance team can actually operate the program. Each section states the requirement, then the fix.

Scoping

Scoping a SOX program from the top down

SOX scoping is a top-down risk assessment, refreshed every year, not a control inventory: scope to where a material misstatement could actually occur. The sequence runs from materiality to entity-level controls (assessed first), then the significant accounts and disclosures (by quantitative size and qualitative risk), the relevant assertions for each, what could go wrong at the assertion level, the significant processes and major classes of transactions, and finally selecting the controls, process-level and IT, that address each risk. The framework is COSO 2013: five components and seventeen principles, and a material weakness in a relevant principle means ICFR is not effective. Scoping also carries a fraud risk assessment (COSO Principle 8): incentives and pressures, opportunities, and rationalization, covering fraudulent reporting, asset misappropriation, and management override. A right-sized mid-cap program has dozens of key controls; each control beyond the risk-mapped set adds cost without assurance.

Scoping a SOX program from the top down, refreshed every year, to where a material misstatement could actually occur. The sequence: materiality, then entity-level controls assessed first, then significant accounts and disclosures by quantitative size and qualitative risk, then the relevant assertions (existence, completeness, valuation, rights, presentation), then what could go wrong for each assertion, then the significant processes and major classes of transactions, then selecting the process-level and IT controls that address each risk. The framework is COSO 2013: five components (control environment, risk assessment, control activities, information and communication, monitoring) and seventeen principles, and a material weakness in a relevant principle means ICFR is not effective. Scoping includes the fraud risk assessment under COSO Principle 8: incentives and pressures, opportunities, and rationalization, covering fraudulent financial reporting, asset misappropriation, and management override. A right-sized mid-cap program has dozens of key controls.
The top-down scoping sequence, COSO 2013, and the fraud risk assessment. Illustrative.
IT controls

IT general controls and the controls that rely on them

Automated controls and system-generated reports are only as reliable as the IT environment beneath them, which is why an integrated audit tests that environment layer by layer, application, database, operating system, and network. IT general controls cover three families over each layer: access (provisioning and deprovisioning tied to HR, user access reviews, privileged access, segregation of duties), change management (changes authorized, tested, and approved before production, developer access to production restricted), and operations (job scheduling, interfaces, and backups). The controls that depend on them are the automated application controls (three-way match, edit checks, tolerance limits, tested once and relied on while the ITGCs hold) and the automated control with a manual component, where a person reviews a system-generated report and the control is only as strong as the report and the ITGCs behind it. Under PCAOB AS 2201, when an IT general control fails the exposure extends to every automated control and report that touched the system.

IT general controls and the controls that rely on them. Automated controls and system-generated reports are only as reliable as the IT environment beneath them, tested layer by layer: application (ERP, billing, payroll, equity, consolidation), database, operating system, and network. IT general controls cover three families over each layer: access (provisioning and deprovisioning tied to HR, user access reviews, privileged access, segregation of duties), change management (changes authorized, tested, and approved before production, with developer access to production restricted), and operations (job scheduling, interfaces, and backups). Controls that rely on IT: automated application controls (three-way match, edit checks, tolerance limits, automated calculations, tested once and then relied on while the ITGCs hold) and the automated control with a manual component (a person reviews a system-generated report, and the control is only as strong as the report and the IT general controls behind it). What could go wrong: when an IT general control fails, the exposure extends to every automated control and report that touched the system, so one access or change gap can invalidate many downstream controls.
IT general controls, the IT layers, and the controls that depend on them, under PCAOB AS 2201. Illustrative.
IPE and SOC reports

Information produced by the entity (IPE) and SOC reports

A control is only as good as the information it uses. Information produced by the entity, the IPE behind key controls, is now a leading source of findings: for system-generated reports, validate the source, the query logic, and the parameters, then rely on ITGC for reports that do not change; for end-user spreadsheets, add version control, access restriction, input tie-outs, and formula protection; and keep evidence that the review happened. Outsourced processes push part of your control environment to a service organization: a SOC 1 Type 2 report covers that organization’s controls over a period (payroll, equity, hosting), and it helps only when you read it, map the complementary user entity controls to your own and perform them, and clear the exceptions, because a control gap at the service organization is your gap. Under PCAOB AS 2201 the auditor tests the completeness and accuracy of IPE, and the report nobody validated and the SOC 1 nobody read are the findings that surface most.

Information produced by the entity (IPE) and SOC reports in a SOX program. A control is only as good as the information it uses. IPE: for system-generated reports, validate the source, the query logic, and the parameters, then rely on ITGC for reports that do not change; for end-user spreadsheets, add version control, access restriction, input tie-outs, and formula protection; and keep evidence that the review happened, with parameters captured and totals tied to the ledger. SOC 1 reports for outsourced processes: a SOC 1 Type 2 covers a service organization's controls over a period (payroll, equity, hosting); read it, map the complementary user entity controls (CUECs) to your own and perform them, and clear the exceptions, because a control gap at the service organization is your gap. Under PCAOB AS 2201 the auditor tests the completeness and accuracy of information produced by the entity, and a SOC 1 helps only when its complementary user entity controls are mapped and performed. The report nobody validated and the SOC 1 nobody read are the findings that surface most.
Information produced by the entity and service-organization controls under PCAOB AS 2201. Illustrative.
The 404 timeline

When SOX obligations start: 302, 404(a), then the 404(b) audit

The certifications start at once; the audit can be years away, or not. For everyone, from listing: Section 302 certifications begin with the first periodic report, so disclosure controls must exist in the first quarter, and management’s 404(a) assessment is first required in the second annual report, the 2nd 10-K. Then the EGC question. An emerging growth company is exempt from the 404(b) auditor attestation for up to five years; you remain an EGC until the earliest of $1.235 billion in annual revenue, the fifth fiscal year after the IPO, $1 billion of non-convertible debt over three years, or large accelerated filer status (public float over $700 million). The 404(b) audit then kicks in one of two ways: if you fall out of EGC status at any of those triggers, the next annual report includes the attestation; and if you never qualified as an EGC at your IPO, or are already an accelerated or large accelerated filer, it applies from the second annual report, the 2nd 10-K. A smaller reporting company below the accelerated-filer thresholds stays exempt from 404(b), though 404(a) still applies.

When SOX obligations start after listing. Quarter one: Section 302 and 906 certifications begin, and disclosure controls and procedures must exist. Year two: management's 404(a) assessment is first required in the second annual report, the 2nd 10-K, after first-year transition relief. The 404(b) auditor attestation, the first SOX audit, is filer-status driven. An emerging growth company is exempt from 404(b) for up to five years: you stay an EGC until the earliest of $1.235 billion in annual revenue, the fifth fiscal year after the IPO, $1 billion of non-convertible debt over three years, or large accelerated filer status (public float over $700 million), and an EGC may present two audited years instead of three. A company that is not an EGC and is an accelerated or large accelerated filer includes the auditor's 404(b) attestation starting with its second annual report, the 2nd 10-K; a smaller reporting company below the accelerated-filer thresholds stays exempt from 404(b) though 404(a) still applies, and the 302 certifications and 404(a) assessment begin on the same schedule for everyone.
When Section 302, 404(a), and the first 404(b) audit apply, and the EGC exemption. Illustrative.

This is for you if

  • You are newly public, or about to be, and the 302, 404(a), and 404(b) dates are approaching.
  • You received a material weakness or significant deficiency and the remediation clock is running.
  • Your program has grown past what your team can operate and needs right-sizing.
  • Your auditors keep finding IPE and ITGC exceptions.

What you get

  • Scoping and risk assessment The top-down scoping memo and a right-sized key control set, refreshed annually.
  • Documentation and testing Narratives, matrices, ITGC and IPE procedures, and the management testing program with workpapers.
  • Deficiency evaluations Severity memos with the exposure math shown, calibrated with your auditors before year-end.
  • Remediation execution Root-cause fixes sequenced to bank operating instances, retested with evidence to closure.
How We Help

What we deliver

On a SOX engagement, you get a program your team can run and your auditors can rely on.

Scoping and risk assessmentThe top-down scoping memo and a right-sized key control set, refreshed annually.
Documentation and testingNarratives, matrices, ITGC and IPE procedures, and the management testing program with workpapers.
Deficiency evaluationsSeverity memos with the exposure math shown, calibrated with your auditors before year-end.
Remediation executionRoot-cause fixes sequenced to bank operating instances, retested with evidence to closure.

When companies bring us in

  • You are newly public, or about to be, and the 302, 404(a), and 404(b) dates are approaching.
  • You received a material weakness or significant deficiency and the remediation clock is running.
  • Your program has grown past what your team can operate and needs right-sizing.
  • Your auditors keep finding IPE and ITGC exceptions.
Our Experience

Where we have done this work

Engagement Notes

First-year programs after non-traditional listings

SOX stand-ups for companies that became registrants through reverse mergers and SPAC combinations, including a streaming media fact pattern: scoping from a top-down risk assessment, certifications-critical controls in quarter one, ITGC and IPE foundations, and a 404(a) assessment delivered on the second annual report timeline.

Engagement Notes

Material weakness remediation with the clock running

Remediation programs where the closure date mattered: root-cause analysis, controls redesigned early in the fiscal year to bank operating instances, management retesting with evidence, and severity evaluations with the exposure math documented, so year-end conclusions were calibrated with the auditors instead of contested.

The Detail

The gaps, and how we close each one

Issue 01

Scoping: a top-down risk assessment, not a control inventoryRisk Assessment

Over-scoped programs collapse under their own weight; under-scoped programs miss the account where the misstatement lives. Both start the same way: scoping by listing controls instead of by assessing where a material misstatement could actually occur.

The treatment

Scope top-down every year: set materiality, identify significant accounts and disclosures using both quantitative size and qualitative risk (estimation, complexity, fraud susceptibility, change), map them to the processes and locations that generate them, and only then identify the key controls that address each risk of material misstatement, including the entity-level controls that operate above the transaction cycles. Anchor the program in COSO 2013, whose five components and seventeen principles the SEC expects as the control framework, and run the fraud risk assessment the framework requires (COSO Principle 8): assess incentives and pressures, opportunities, and rationalization across fraudulent reporting, asset misappropriation, and management override, and map each fraud risk to a specific control. Multi-location businesses allocate coverage by where the risk sits, not evenly. The scoping memo is refreshed for the year’s changes, acquisitions (which get their own transition decisions), new systems, new revenue streams, because last year’s scope applied to this year’s business is how programs drift into irrelevance. A right-sized program for most mid-cap filers is dozens of key controls, not hundreds; every control past the risk-mapped set is cost without assurance.

What we do: We run the top-down risk assessment and deliver the scoping memo and right-sized key control set, refreshed each year.

Issue 02

IT general controls: the layer everything else stands onITGC

Every automated control, every system-generated report, and every calculated balance inherits its reliability from IT general controls. When ITGCs fail, access, change management, operations, the failure cascades into every control that touched the system, which is why ITGC findings multiply.

The treatment

Cover the three families over every financially relevant system, including the ones outside the ERP (billing, payroll, equity, consolidation tools): access, provisioning and deprovisioning tied to HR events, periodic user access reviews with evidence of action taken, privileged access restricted and monitored, and segregation-of-duties conflicts identified with mitigations documented; change management, changes authorized, tested, and approved before production, with developer access to production either prevented or monitored; operations, job scheduling, interfaces, and backup monitoring for the processes financial data rides on. SOC 1 reports cover the service-organization side, but only if someone reads them: map the CUECs to your own controls and clear the exceptions. When an ITGC fails, the evaluation extends to every dependent application control and report, so the cheapest control in the program to keep healthy is this layer.

What we do: We document and test access, change, and operations controls across every financially relevant system, and map the SOC 1 CUECs to your controls.

Issue 03

Information produced by the entity: the reports your controls trustIPE / Key Reports

A review control is only as good as the report being reviewed. Auditors now test whether the queries, parameters, and spreadsheets behind key reports are complete and accurate under PCAOB AS 2201, and IPE has become one of the most common sources of findings in mature programs.

The treatment

Inventory the reports and spreadsheets that key controls rely on, then establish completeness and accuracy for each: for system reports, validate the source, the logic or query, and the parameters, either through a baseline validation plus ITGC reliance for unchanged reports, or through control-owner procedures each time (tie totals to the ledger, verify the parameter set); for end-user spreadsheets, add version control, access restriction, input tie-outs, and formula protection proportional to their role. The control description should say what the owner does to validate the IPE, and the evidence should show it happened, a screenshot of parameters, a tie-out initialed. Programs that treat IPE as part of the control, rather than an audit afterthought, stop donating findings in this category.

What we do: We inventory the key reports and spreadsheets and build the completeness and accuracy procedures into the controls that use them.

Facing a deadline, a deficiency, or a program that is not working? Talk to us before year-end testing starts.

Talk to an Expert
Issue 04

Deficiency evaluation: severity is about could, not didDeficiency → SD → MW

The most contested judgment in SOX: is this exception a deficiency, a significant deficiency, or a material weakness? Teams evaluate what did happen; the framework requires evaluating what could have, and the gap between those two is where auditor disagreements live.

The treatment

Evaluate severity on magnitude and likelihood of potential misstatement, not the actual error found: the exposure is the population the control covers, considering volume, the amounts that could flow through, and whether compensating controls would catch a misstatement at the same precision. A material weakness exists when there is a reasonable possibility a material misstatement would not be prevented or detected timely; a significant deficiency is less severe but merits attention; and the indicators, restatement, fraud by senior management, an auditor-identified material misstatement, weigh heavily toward MW. Then aggregate: individually minor deficiencies clustering in one account, process, or COSO component can combine into something severe. Write the evaluation memo per deficiency with the exposure math shown, and calibrate conclusions with the auditors before year-end, because a Q4 severity dispute is a disclosure event, not a discussion.

What we do: We write the severity evaluation per deficiency with the exposure math shown, and calibrate conclusions with your auditors before year-end.

From our engagements: the fact pattern we see most after reverse mergers and SPAC combinations is a first-year program discovering that exceptions dismissed as one-offs aggregate into a material weakness. The evaluation discipline, exposure math per deficiency, is what keeps that conclusion in management's hands instead of the auditor's.
Issue 05

Remediation timing: when a material weakness actually closesRemediation

Companies announce remediation plans quickly and then discover the hard rule: a material weakness is not remediated when the fix is designed, or even implemented. It closes when the new control has operated effectively long enough to test, and the calendar math surprises boards every year.

The treatment

Work backward from the operating-effectiveness requirement: the redesigned control must operate for a sufficient period to conclude on effectiveness, which for a monthly control means multiple months of instances and for a quarterly control can mean most of a year, so a fix implemented in Q3 frequently cannot support closure that fiscal year. Sequence accordingly: root cause first (a people failure, a design gap, and a missing report each get different fixes), implement early in the year to bank operating instances, retest with evidence, and keep the disclosure honest in the interim: the MW persists in each 10-K and 10-Q until closure, with remediation status described. Management concludes on remediation with its own testing; where 404(b) applies, the auditors reach their own conclusion. The pattern that works is boring: fix early, test twice, disclose plainly.

What we do: We sequence remediation to bank operating instances early, retest with evidence, and keep the disclosure current until closure.

Issue 06

First-year 404: the timeline nobody budgets correctly404(a) / 404(b)

Newly public companies, IPOs, de-SPACs, direct listings, hit the SOX sequence on a schedule set by their filings, not their readiness. The certifications start immediately; the assessments follow; and the build takes longer than the window unless it started before listing.

The treatment

Map the actual sequence to your dates: Section 302 certifications begin with the first periodic report after listing, which means disclosure controls and the sub-certification process must exist in the first quarter, not the first year. Management’s 404(a) assessment is generally first required in the second annual report, using the newly-public-company transition relief for the first one. Auditor attestation under 404(b) depends on filer status. An emerging growth company is exempt for up to five years: you remain an EGC until the earliest of $1.235 billion in annual revenue, the fifth fiscal year after the IPO, $1 billion of non-convertible debt over three years, or large accelerated filer status. A company that is not an EGC and is an accelerated or large accelerated filer includes the auditor’s attestation, its first SOX audit, with the second annual report, the 2nd 10-K; smaller reporting companies below the accelerated-filer thresholds stay exempt, a status worth confirming annually rather than assuming. De-SPAC combinations inherit the operating company’s control environment on day one with none of the buildup a traditional IPO forces, which is why the documented-from-scratch timeline of twelve to eighteen months should start at signing. We sequence the build to the filing calendar: certifications-critical controls first, then cycles, then the testing program.

What we do: We map the 302, 404(a), and 404(b) dates to your filings and build the program in that order.

FAQ

Frequently asked questions

When does SOX apply to us?

SOX 302 certifications apply from your first periodic report as a public company. Management’s 404(a) assessment typically begins with your second annual report, and auditor attestation under 404(b) depends on your filer status. Emerging growth companies get relief from 404(b) for up to five years.

How long does SOX readiness take?

Building documentation from scratch takes 12 to 18 months for most companies. Starting earlier means the work happens on your schedule instead of the SEC’s.

We received a material weakness. What now?

Root-cause analysis first, then remediation with evidence. A material weakness closes only when the fixed control has operated effectively for a sufficient period, so speed of diagnosis matters.

Can a small finance team really sustain SOX?

Yes, if the framework is right-sized. Over-scoped programs fail because teams cannot operate them. We scope to what is material and design controls that fit how your team already works.

Do you test controls or just document them?

Both. We design, document, and operate management testing programs, and we coordinate directly with external auditors on their testing.

Sources & authorities

Primary sources for this page

  • Internal control over financial reporting. SOX Section 404: management’s assessment and, for non-exempt filers, the auditor’s attestation.
  • Certifications. SOX Section 302: the CEO and CFO certifications that begin with the first periodic report.
  • Integrated audit. PCAOB AS 2201: the auditor’s testing of ICFR, the information produced by the entity, and IT general controls.
  • Control framework. COSO 2013: the five components and seventeen principles, including the Principle 8 fraud risk assessment.
  • Emerging growth companies. Securities Act Section 2(a)(19) and the JOBS Act: the EGC definition and the 404(b) exemption for up to five years.
  • Filer status. Exchange Act Rule 12b-2: the accelerated and large accelerated filer thresholds that trigger the auditor attestation.

This page summarizes SEC rules and staff guidance for general information, and is not accounting or legal advice. Rules change; confirm the current text before you rely on it.

Contact Us

Contact Us to Learn More

Call: (347) 472-1115
Email: info@corviniti.com

The best way to get started is to complete the form below. Tell us a bit about your business and we will advise on how best to get started.

We will get back to you within 24 hours.

Ro Sokhi, CPA
Ro Sokhi, CPA
Founder & CEO · Big Four experience · 20+ years

We will get back to you within 24 hours.