Filed under Advisory

Service

SOX Readiness Support

Sarbanes-Oxley obligations rarely arrive as a surprise. What surprises people is how little of the required documentation exists when the clock starts. Your controls may be working perfectly well. If nobody wrote down how they run, who performs them and what evidence they leave, the first cycle becomes a scramble that eats the finance team alive.

A corner of an open-plan office workspace
8 things this engagement covers, and a 9-step process.

Who it is for

Who this is for.

  • 8 things this engagement covers, listed below with what each one includes.
  • A 9-step process, the same one on every engagement.
  • 6 questions answered on this page.

Overview

SOX readiness support is the preparation that happens before your first year under Section 404. It means documenting how each significant process runs, listing the risks in that process and the controls that address them, finding the places where a control is missing or poorly designed, and fixing those gaps while there is still time and nobody is watching the result.

Finalert provides readiness support and preparation. We build the narratives, the risk and control matrix and the evidence discipline before your first real cycle. We do not perform audits, we do not test controls to support an opinion, and we do not issue any opinion, certification or sign-off. That work stays with your auditor.

It also means building habits your team does not yet have: keeping evidence as a matter of routine, dating and signing reviews, and tracking remediation with owners and deadlines. We prepare the documentation and the discipline. Management makes its own assertions about internal control and your external auditor reaches its own conclusions.

Finalert supports U.S. companies preparing for Sarbanes-Oxley obligations, usually ahead of an initial public offering or a first year as an accelerated filer. The work is documentation and preparation, done early. Companies at this stage typically have competent finance teams running sensible processes with very little written down. A reconciliation gets reviewed, but the review leaves no dated signature. An access change gets approved verbally. A journal entry is checked by someone who also prepares entries. None of that is unusual in a private company, and all of it becomes a problem the moment the process has to be evidenced to an outside party.

We begin by mapping the significant processes: order to cash, procure to pay, payroll, inventory where relevant, treasury, financial close and reporting. Each one is written as a narrative that follows a transaction from start to ledger, naming systems, people and handoffs, with a flowchart alongside for the parts that are hard to describe in prose. These documents are written to be read by somebody outside your company, because eventually they will be. The first draft usually takes longer than expected, since the real process and the remembered process are rarely the same.

The risk and control matrix

From the narratives we build a risk and control matrix. For each process we state what could go wrong at each step, the financial statement assertion affected, the control that addresses it, who performs the control, how often it runs, whether it is preventive or detective, whether it is manual or system driven, and what evidence it leaves behind. That last column is the one most first drafts get wrong. A control nobody can evidence is, for these purposes, a control that did not happen.

The matrix exposes design gaps quickly. Common findings include controls that rely on one person doing incompatible things, review controls with no defined precision, no documented management review of significant estimates, no formal approval path for journal entries, and IT general controls with nothing written about access provisioning, change management or backups. We also document entity-level controls: tone and oversight at the board level, delegation of authority, the code of conduct and the whistleblower channel. Each gap goes on a remediation log with a named owner, a target date and a description of what finished looks like.

Remediation and the dry run

Remediation is tracked like project work rather than as a list of good intentions. Every item has an owner, a date and a definition of done, and we review the log on a set cadence so slipped dates get discussed early. Then, before your first real cycle, we run a dry run. Your team performs the controls as documented and retains the evidence, and we review whether the documentation matches what happened and whether the evidence would satisfy someone who was not in the room. Gaps found here are cheap to fix. Gaps found in the live cycle are not.

The scope boundaries are firm and we repeat them throughout the engagement. Finalert provides readiness support and preparation only. We do not perform audits. We do not test controls to support an opinion, and nothing we produce constitutes a testing opinion, a certification or a sign-off of any kind. We do not issue audit or attest opinions. We do not give legal advice and we do not act as your accountant of record. Management makes its own assertions about the effectiveness of internal control over financial reporting, and your external auditor reaches its own conclusions independently of us.

What you get

What the engagement covers.

8 items

  • Process narratives and flowcharts

    Written walkthroughs of each significant process from transaction origin to ledger, with flowcharts for the complicated parts, drafted to be read by someone outside your company.

  • Risk and control matrix

    Risks, affected assertions, the control addressing each one, the performer, the frequency, preventive or detective, manual or automated, and the evidence the control leaves behind.

  • Control design gap analysis

    Where a control is missing, imprecise, performed by the wrong person or impossible to evidence. Each gap is described in terms of what could go undetected, not just what is absent.

  • Entity-level control documentation

    Board and audit committee oversight, delegation of authority, the code of conduct, the whistleblower channel and the wider policy set, documented and organized so they are ready for review by others.

  • IT general control documentation

    Access provisioning and removal, periodic access reviews, change management, and backup and recovery for the systems that feed your financial statements, written up with evidence expectations.

  • Evidence and documentation discipline

    Standards for what a performed control should leave behind: dated signatures, retained support, review notes with a stated scope, and a consistent place the evidence is filed.

  • Remediation tracker with owners

    Every gap logged with an owner, a target date, a definition of done and a status, reviewed with your team on a fixed cadence so slippage surfaces early rather than at year end.

  • Dry run of the control cycle

    Your team performs the documented controls for a full period and retains evidence. We review whether documentation matches practice and whether the evidence would stand up to outside review.

How it runs

How the work runs.

Readiness runs as a staged program rather than as a single project, because a remediated control needs time in operation behind it before your first real cycle begins. Here is the order the work follows.

  1. 01

    Initial readiness assessment

    We establish your expected timeline, the entities and systems in scope, what documentation already exists and how far the current environment is from where it needs to be.

  2. 02

    Scoping significant processes

    We agree which processes and accounts matter, based on your financial statements and the areas where an error would matter most, so effort is not spread evenly across everything.

  3. 03

    Walkthroughs and narrative drafting

    We sit with the people performing each process, follow transactions end to end and write the narratives and flowcharts from what we observe rather than from the org chart.

  4. 04

    Build the risk and control matrix

    Risks, affected assertions, controls, performers, frequency, control type and expected evidence, assembled for each process in scope and then reviewed with your controller line by line for accuracy.

  5. 05

    Identify design gaps

    We mark controls that are missing, imprecise, conflicted by duties or unevidenceable, and describe the exposure each gap creates in terms your management can act on.

  6. 06

    Entity-level and ITGC documentation

    Governance, delegation of authority, the policy set, access management, change control and backup and recovery are documented and prepared for outside review alongside the process-level work.

  7. 07

    Remediation planning and tracking

    Each gap becomes a tracked item with an owner, a date and a definition of done. We review the log with your team on a set cadence until the list is cleared.

  8. 08

    Evidence routine rollout

    We train the control performers on what to retain and how to sign and date a review, then check the first weeks of evidence so the habit takes hold before it counts.

  9. 09

    Dry run and readiness handover

    Your team runs the documented controls for a full period. We review documentation against practice, log what needs fixing and hand a maintained package to your team.

Our approach

How we approach it.

Readiness work goes wrong when it produces binders nobody uses or a control environment too heavy for the company that has to run it. These are the rules we work to.

An empty glass meeting room

Six commitments shape how service runs here.

Preparation, never an opinion

We document, prepare and coach. We do not perform audits or test controls for an opinion, and nothing we issue is a certification or a sign-off. Your auditor owns that entirely.

Document the real process

Narratives describe what actually happens, including the workarounds. A tidy narrative that does not match practice fails the first walkthrough and costs you credibility early.

Right-sized control environment

We design controls your team can perform every month without burning out. An over-engineered matrix looks impressive and then quietly stops being performed by March.

Evidence by default

Every control we document says what it leaves behind. If a control cannot be evidenced, we redesign it rather than writing it up and hoping nobody asks.

Start earlier than feels necessary

Design gaps take a quarter or more to remediate and then need a period of operation behind them. We push clients to begin well before the first required cycle.

Management owns the assertion

Your management team, not Finalert, makes the assertions about internal control over financial reporting, and your auditor reaches its own conclusions. We prepare the documentation that sits behind the work.

Proof

What clients say, and what the work has done.

  • 110+ U.S. businesses served
  • 100% client satisfaction
  • 111 services we run

Finalert is an outstanding accounting, financial advisory and analytics company that delivers a wide range of services and solutions with the highest level of professionalism. Their expert team, with whom I have personally worked, possesses exceptional skills that enable customers to meet their financial and accounting needs seamlessly. Their dedication to excellence and customer satisfaction sets them apart, making them a trusted partner in the industry.

Wajdi Al MowafakDirector, Financial Business · Nonprofit
Recent engagement CWS Global Nonprofit & Humanitarian 50% faster month-end close Real-time grant and donor visibility Audit-ready compliance Read the case study

Questions

Common questions.

What CFOs and controllers ask us when Sarbanes-Oxley obligations are still a year or two out and the first cycle has not yet started.

When should we start readiness work?

Earlier than most companies do. Design gaps often take a full quarter to remediate, and a remediated control needs a period of operation behind it before the first real cycle. Working back from your expected filing date, twelve to eighteen months of preparation is comfortable. Six months is possible but means running documentation, remediation and the dry run in parallel with everything else.

Do you test our controls?

No. We do not test controls to support an opinion, and nothing we produce is a testing opinion, a certification or a sign-off. What we do is preparation: documenting the controls, identifying design gaps, tracking remediation and running a dry run so your team practices performing and evidencing controls. Your external auditor reaches its own conclusions entirely independently of our work.

Our processes work fine. Why write all this down?

Because under Section 404 a control has to be demonstrable to someone outside your company, not just effective in practice. A reconciliation reviewed carefully but signed by nobody leaves no trace that the review happened. Documentation and evidence discipline are what turn a process that works into a control that can be relied on and reviewed. Most of our early findings are evidence gaps, not process failures.

What are IT general controls and do we need them?

They are the controls around the systems that produce your financial data: how access is granted and removed, whether access is reviewed periodically, how changes to systems are approved and moved to production, and how data is backed up and recovered. If your ERP or accounting platform feeds the financial statements, these get documented. We prepare that documentation for review alongside the process work.

How much time will this take from our finance team?

The walkthrough phase is the heaviest, since we need real time with the people performing each process, usually a few hours each across a few weeks. Remediation effort depends on your gap list. The dry run runs inside a normal close, and one output of it is an honest estimate of the monthly cost of operating your control environment, which management usually needs before going public.

What is outside the scope of this engagement?

Finalert provides readiness support and preparation only. We do not perform audits, we do not test controls for an opinion, and we do not issue audit or attest opinions, certifications or sign-offs of any kind. We do not give legal advice and we do not act as your accountant of record. Management makes its own assertions about internal control and your external auditor owns its conclusions.

About SOX Readiness Support

Ready for numbers you can build on?

Talk to a Finalert consultant about your books, your reporting, or the decision you are trying to make.

110+ U.S. businesses served

What happens next

  1. A twenty-minute call An accountant on the line, not a salesperson.
  2. A scope and a price, in writing What the work covers, and what it costs.
  3. Onboarding on your schedule We start when you are ready, not before.

Monday to Friday, 8:00am to 5:00pm ET Cleveland and New York