Driving SOX Compliance for an Online Travel Company
One of the largest online travel companies in India, a foreign private issuer, listed on NASDAQ
The business situation
A US SPAC acquired the company. The listing regulations require their auditors to attest and report on management’s assessment of the company’s internal controls
The company’s Emerging Growth Company (EGC) status expired in the year, and considering that it was the first year of 404(b) certification, the company needed support:
In testing the control environment (including MRCs, IPE testing) and developing a mitigation plan for deficiencies identified
Identification of all applications impacting key processes and performing ITGC
Mitigation of gaps, which were ineffective due to lack of review evidence, and follow-up action
Our team’s role
RCM Assessment
Conducted an assessment of the company’s current state of RCMs
Design Gap Identification
Identified gaps in the design of controls
Effectiveness Testing
Performed operating effectiveness testing of controls, including MRC (Mitigating Risk Controls), IPE (Information Produced by the Entity), and EUC (End-User Computing)
Management Reporting
Prepared internal and external management reporting
Remediation Planning
Developed a remediation plan for exceptions identified in the client’s MRCs and IPEs
The value our team added
Through comprehensive testing and close collaboration with management, our team identified critical areas where control documentation and implementation required strengthening
We developed a tailored mitigation plan targeting these key weaknesses, ensuring that both the design and execution of controls were enhanced. Specifically, we facilitated improvements in the documentation and rigor of Mitigating Risk Controls (MRCs) and Information Produced by the Entity (IPE), aligning them with stringent SOX compliance requirements
These enhancements not only strengthened the company’s control environment but also improved transparency, audit readiness, and overall risk management effectiveness
Stay Ahead of Regulatory Demands
From Design Gaps to Mitigation Plans, We Support Effective, Evidence-Based Controls