- Annual ICFR Scoping & Risk Assessment — Finance · 13 steps
Perform annual SOX scoping from materiality and significant accounts through RMMs, key controls, fraud risk, concurrence, and RCM publication.
- Control Interim Testing Record — Internal Audit · 2 steps
Test a defined interim-period population using a documented sampling and attribute plan, then record exceptions and a bounded conclusion.
- Deficiency Evaluation & Committee — Finance · 2 steps
Evaluate SOX control deficiencies individually and in aggregate, obtain management challenge, and govern committee communication and disposition.
- External Audit Support & PBC — Finance · 1 steps
Govern external-audit PBC requests from intake and preparation through quality review, secure delivery, clarification, and complete request closure.
- Financial Controls Policy & Segregation-of-Duties Governance — Finance · 6 steps
The SOX PMO reapproves and communicates the financial-control policy suite, including entity-wide ITGC and period-end reporting oversight policies, on its annual cycle. Every quarter it also refreshes the segregation-of-duties conflict matrix, screens role design and system access for incompatible duties, and documents mitigating controls where segregation isn't practicable.
- Financial Systems Transaction Integrity Monitoring — Finance; with IT · 6 steps
Operate the recurring financial-systems transaction-integrity cycle each period on the existing financial-reporting Process — clearing rejected-input and suspense queues, dispositioning automated-processing exceptions, and reconciling interface transfers. Validate system-generated reports and spreadsheets before reliance, with configuration retested on every change and evidence captured as you go.
- Fraud Risk Assessment & Anti-Override Control Review — Finance; with Executive · 6 steps
Lead the annual (or event-triggered) fraud risk assessment across fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, opportunities, and rationalizations while explicitly rating the risk of management override of controls. Recalibrate the anti-override control set - journal-entry review criteria and significant-estimates scrutiny - and report refreshed results and mitigations to the audit committee.
- FSLI Significance Assessment — Finance · 1 steps
Assess quantitative and qualitative significance for a financial statement line item and approve its scoped assertions, locations, and process dependencies.
- Interim Operating Effectiveness Testing — Internal Audit; with Finance · 2 steps
Review program coverage and aggregate interim exceptions from approved Control tests, then agree auditor reliance and management actions.
- Management Assessment & Assertion — Finance · 2 steps
Assemble and govern management’s annual ICFR assessment record, including scope, test results, deficiencies, certifications, disclosures, and assertion approval.
- Period-End Roll-Forward / Rollover Testing — Internal Audit · 2 steps
Bridge an approved interim control test through period end by assessing change, remaining occurrences, incremental evidence, and unresolved exceptions.
- Period-End Roll-Forward Testing — Internal Audit; with Finance · 3 steps
Bridge interim testing to period end using the remaining population, control changes, additional evidence and a bounded combined conclusion.
- Physical Asset Custody & Count Program — Finance; with Facilities · 7 steps
Operate the standing physical-asset custody and count program each cycle — counting and reconciling cash, negotiable instruments, and accounting records to the books, verifying custody-log authorization, and confirming storage and retention safeguards — with audit-ready evidence captured as you go. Each cycle's instance operates the existing UC-FIN-10 custody-and-count Control, enriching that control's operating history rather than creating a new record.
- Process Walkthrough & Design Assessment — Internal Audit · 2 steps
Perform a SOX process walkthrough, update the ICFR narrative and control mapping, and document design observations for management follow-up.
- Production Operations & Processing Integrity Cycle — IT; with Finance · 6 steps
Run the scheduled production-processing cycle, resolve batch and monitoring incidents, verify recoverability and input/output integrity, and certify the evidence with owned carry-forwards.
- Quarterly 302/906 Sub-Certification Cascade — Finance; with Executive · 6 steps
The SOX PMO runs the quarterly sub-certification ritual that underpins the principal officers' Section 302 and 906 certifications: it maintains the certifier hierarchy, refreshes the questionnaire for period changes, launches the cascade from process owners through controllers to segment CFOs, chases completion to the cutoff, and triages every exception or qualification raised. Material items reach the disclosure committee before the CEO and CFO sign, and the certification population and its evidence are archived with the period's filing support.
- SOX Annual Planning & Risk Assessment — Finance · 2 steps
Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval.
- SOX Control Testing — Internal Audit · 2 steps
Native SAMPLE approves history, attributes and reproducible selection; TEST independently approves evidence, exceptions and the published SOX result for the fiscal year.
- SOX Deficiency Remediation — Finance · 7 steps
Track a control deficiency from initial identification and severity grading through root-cause analysis, remediation execution, and validated closure.
- SOX IPE Validation — Internal Audit; with Finance · 7 steps
Validate an Information Produced by the Entity (IPE) report for completeness and accuracy, then decide whether it is reliable control evidence or a deficiency.
- SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
- SOX Key Control Operation (Close Cycle) — Finance · 5 steps
Operate close-cycle reconciliations, management review and journal-entry approvals with validated IPE, independent review and a control-indexed period sub-certification.
- SOX Key Control TOD/TOE Test — Internal Audit; with Finance · 10 steps
Test key controls for design and operating effectiveness, including walkthrough, sampling, IPE linkage, exception handling, and reviewer sign-off.
- SOX Process Walkthrough — Finance; with Internal Audit · 7 steps
Capture an end-to-end process walkthrough and identify the key controls inside it, producing a walkthrough memo and draft control records.
- SOX Scoping Decision — Finance · 4 steps
Decide whether a process is SOX-relevant, then scope it or document the exclusion.
- Year-End Deficiency Aggregation & Severity Evaluation — Finance · 10 steps
Freeze the year-end deficiency register, prove its completeness against testing results, aggregate related deficiencies, and evaluate severity through compensating-control and prudent-official conclusions that feed 302/404 certifications and audit-committee reporting.
- Year-End Planning & Roll-Forward — Finance · 2 steps
Plan and govern SOX year-end and roll-forward coverage based on interim results, changes, deficiencies, remaining populations, and reporting deadlines.