- Annual ICFR Scoping & Risk Assessment — Finance · 13 steps
Perform annual SOX scoping from materiality and significant accounts through RMMs, key controls, fraud risk, concurrence, and RCM publication.
- Change & Release Management (CAB) — IT; with Finance · 7 steps
Operate the weekly Change Advisory Board and the per-change pipeline for every application, database, infrastructure, configuration, and procedure change: request intake, security and risk impact analysis, environment segregation and configuration-baseline verification, acceptance testing, CAB authorization, and controlled deployment with rollback plans and post-implementation verification. Emergency changes follow the expedited path and are ratified at the next CAB, all under one evidence set.
- Control Library Lifecycle — Risk Management; with Finance · 3 steps
Review proposed controls for duplication, classification and risk-policy-process linkage; govern publication and rework, then review operating changes and preserve history when a control is retired.
- Deficiency Evaluation & Committee — Finance · 2 steps
Evaluate SOX control deficiencies individually and in aggregate, obtain management challenge, and govern committee communication and disposition.
- External Audit Support & PBC — Finance · 1 steps
Govern external-audit PBC requests from intake and preparation through quality review, secure delivery, clarification, and complete request closure.
- Financial Controls Policy & Segregation-of-Duties Governance — Finance · 6 steps
The SOX PMO reapproves and communicates the financial-control policy suite, including entity-wide ITGC and period-end reporting oversight policies, on its annual cycle. Every quarter it also refreshes the segregation-of-duties conflict matrix, screens role design and system access for incompatible duties, and documents mitigating controls where segregation isn't practicable.
- Financial Systems Transaction Integrity Monitoring — Finance; with IT · 6 steps
Operate the recurring financial-systems transaction-integrity cycle each period on the existing financial-reporting Process — clearing rejected-input and suspense queues, dispositioning automated-processing exceptions, and reconciling interface transfers. Validate system-generated reports and spreadsheets before reliance, with configuration retested on every change and evidence captured as you go.
- Fraud Risk Assessment & Anti-Override Control Review — Finance; with Executive · 6 steps
Lead the annual (or event-triggered) fraud risk assessment across fraudulent reporting, asset misappropriation, and corruption, evaluating incentives, opportunities, and rationalizations while explicitly rating the risk of management override of controls. Recalibrate the anti-override control set - journal-entry review criteria and significant-estimates scrutiny - and report refreshed results and mitigations to the audit committee.
- FSLI Significance Assessment — Finance · 1 steps
Assess quantitative and qualitative significance for a financial statement line item and approve its scoped assertions, locations, and process dependencies.
- Interim Operating Effectiveness Testing — Internal Audit; with Finance · 2 steps
Review program coverage and aggregate interim exceptions from approved Control tests, then agree auditor reliance and management actions.
- Management Assessment & Assertion — Finance · 2 steps
Assemble and govern management’s annual ICFR assessment record, including scope, test results, deficiencies, certifications, disclosures, and assertion approval.
- Monthly Financial Close — Finance · 3 steps
Reconcile the period, review proposed adjustments independently, and post and close through authorized ledger operators with a named period package.
- Period-End Roll-Forward Testing — Internal Audit; with Finance · 3 steps
Bridge interim testing to period end using the remaining population, control changes, additional evidence and a bounded combined conclusion.
- Physical Asset Custody & Count Program — Finance; with Facilities · 7 steps
Operate the standing physical-asset custody and count program each cycle — counting and reconciling cash, negotiable instruments, and accounting records to the books, verifying custody-log authorization, and confirming storage and retention safeguards — with audit-ready evidence captured as you go. Each cycle's instance operates the existing UC-FIN-10 custody-and-count Control, enriching that control's operating history rather than creating a new record.
- Production Operations & Processing Integrity Cycle — IT; with Finance · 6 steps
Run the scheduled production-processing cycle, resolve batch and monitoring incidents, verify recoverability and input/output integrity, and certify the evidence with owned carry-forwards.
- Quarterly 302/906 Sub-Certification Cascade — Finance; with Executive · 6 steps
The SOX PMO runs the quarterly sub-certification ritual that underpins the principal officers' Section 302 and 906 certifications: it maintains the certifier hierarchy, refreshes the questionnaire for period changes, launches the cascade from process owners through controllers to segment CFOs, chases completion to the cutoff, and triages every exception or qualification raised. Material items reach the disclosure committee before the CEO and CFO sign, and the certification population and its evidence are archived with the period's filing support.
- SOX Annual Planning & Risk Assessment — Finance · 2 steps
Plan the annual SOX program through materiality, entity and account scoping, risk and control mapping, reliance strategy, calendar, and governance approval.
- SOX Deficiency Remediation — Finance · 7 steps
Track a control deficiency from initial identification and severity grading through root-cause analysis, remediation execution, and validated closure.
- SOX IPE Validation — Internal Audit; with Finance · 7 steps
Validate an Information Produced by the Entity (IPE) report for completeness and accuracy, then decide whether it is reliable control evidence or a deficiency.
- SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
- SOX Key Control Operation (Close Cycle) — Finance · 5 steps
Operate close-cycle reconciliations, management review and journal-entry approvals with validated IPE, independent review and a control-indexed period sub-certification.
- SOX Key Control TOD/TOE Test — Internal Audit; with Finance · 10 steps
Test key controls for design and operating effectiveness, including walkthrough, sampling, IPE linkage, exception handling, and reviewer sign-off.
- SOX Process Walkthrough — Finance; with Internal Audit · 7 steps
Capture an end-to-end process walkthrough and identify the key controls inside it, producing a walkthrough memo and draft control records.
- SOX Scoping Decision — Finance · 4 steps
Decide whether a process is SOX-relevant, then scope it or document the exclusion.
- User Access Review & Recertification — IT; with Finance · 5 steps
Quarterly user access review: extract entitlements, certify with managers, revoke and evidence removals across in-scope systems.
- Year-End Deficiency Aggregation & Severity Evaluation — Finance · 10 steps
Freeze the year-end deficiency register, prove its completeness against testing results, aggregate related deficiencies, and evaluate severity through compensating-control and prudent-official conclusions that feed 302/404 certifications and audit-committee reporting.
- Year-End Planning & Roll-Forward — Finance · 2 steps
Plan and govern SOX year-end and roll-forward coverage based on interim results, changes, deficiencies, remaining populations, and reporting deadlines.