SOX & its applicability
Mandating stringent financial reporting and internal controls, enabled seamlessly through RiskUniVerse.
Please share your contact details to receive the latest updates and insights
Applicability of SOX
What is SOX?
- SOX stands for the Sarbanes-Oxley Act which is a federal law passed in 2002 applicable to all US listed companies
- The objective of SOX is to protect investors and the public by improving the accuracy and reliability of corporate disclosures.
- SOX Act mandates stringent financial reporting and the implementation of robust internal controls to prevent fraudulent activities
Applicability
- All publicly held companies in US, including subsidiaries
- Any international company that have registered equity or debt securities with the SEC
- Any accounting firm or other third party that provides financial services to either of the above

SOX Objectives
Enhancing transparency of Financial Reporting
Promoting Accountability
Detecting & Preventing Fraud
Ensuring Data Security
Improving Corporate Governance
4 key Sections
Section 401
- Financial statements and their requirements to be accurate and presented without any misstatement (including all material off-balance sheet liabilities, obligations, and transactions)
Section 404
- Management is responsible for an adequate" internal control structure, and an assessment by management of the effectiveness of the control structure.
- Any shortcomings in these controls must be reported. Registered external auditors must attest to the accuracy of the company management’s assertion
Section 302
- Senior corporate officers personally certify in writing that the company’s financial statements comply with the SEC disclosure requirements and fairly present in all material aspects the operations and financial condition of the issuer
- Officers are subject to criminal penalties including prison terms for any inaccuracies
Section 906
- Section 906 of SOX imposes penalties upto $5M/20 years imprisonment on CEOs/CFOs who willfully certify noncompliant financial reports, &
- Penalties upto $1M/10 years for knowing false certifications, ensuring executive accountability for financial accuracy.
Our SOX Approach and Key Deliverables
Setup Phase
Design and Operating Effectiveness Phase
Reporting Phase
Planning and scoping
- Identify relevant/ key risks including fraud risks and establish materiality
- Perform scoping of significant accounts and assertions, processes, business units/entities
- Understand the nature and extent of previously identified control deficiencies
- Establish milestones, calendars and protocols
- Agree overall objectives
- Focus on existing control deficiencies and prepare remediation plans
Deliverables
- Project plan
- Materiality rationale
- Scope of accounts, processes and business units/entities
- Fraud risk factor considerations

Process evaluation and documentation
- Assess the current tone at the top and document ELC matrix
- Perform walkthroughs, prepare/update process flow charts and RCMs based on identified PRPs
- Identification of key manual and application controls (including review controls precision & IPEs)
- Perform test of design including identifying control attributes
- Test IT general controls (ITGC) based on identified RAFITs
- Preliminary evaluation of SOC 1 report
Deliverables
- Process flow, Narratives, and Risk Control Matrix
- ELC, Process and ITGC RCM
- Control design workpapers with test conclusions
- Listing of identified design gaps (SICD)
Evaluate operating effectiveness of controls
- Develop OE testing strategy (Interim and year end)
- Identify population for each key control and define sampling size
- Perform management testing and retain evidences (including ITACs and review controls)
- Test IT and manual user reports (IPE) for completeness and accuracy
- Identify mitigating controls for deficiencies identified
- Final evaluation of SOC 1 report and bridge letters
Deliverables
- Test scripts
- Listing of control deficiencies (SICD) and identify mitigating controls
- Remediation Plan for deficiencies

Gap remediation and reporting
- Identification of gaps in process and set-up remediation plans
- Communicate conclusions of control testing
- Draft management report for internal and external stake holders
- Prepare remediation plan for deficiencies noted and discuss next steps with control owners
- Identify areas for further improvements and develop plan for next year
Deliverables
- Management conclusion for 302 and 404 certification
- Ongoing remediation plan
- Handholding calls with control owners
- Plan for future improvements

Revolutionize your control testing with Uniqus GRC Solution (Risk UniVerse)

The platform serves as a centralized repository for housing organizational risks and controls, enabling users to assess controls, maintain audit-ready evidence, and foster seamless communication among stakeholders. Below are some key benefits of the tool:

- Accurate and Consistent data for Audit readiness
- Documentation exchange within the tool
- Centralized Data & Workflows. Increased visibility and Stakeholder’s trust through audit trail
- Automated escalation and notification mech
- Interactive Dashboards for status tracking and reporting
- Flexible framework, allows users to tailor control frameworks to match their specific compliance needs.
- Automated Planning and Scoping
- Real-time control testing status tracking
We are well-positioned to serve you

- Experienced global engagement team - SOX management testing, COSO framework and USGAAP
- IT personnel are an integral part of the engagement team
- Understanding of regulatory environment and key considerations
- Familiarity with audit process of large audit firms
- Tech enabled and streamlined project management approach
- Truly an extension of management team
- No independence conflicts
Increased reliance by External Auditors
Year 1
- Design corporate governance structure
- Conduct risk assessment and scoping for key areas
- Document high-risk processes with flow charts
- Perform walkthroughs and document processes
- Execute SOX testing plan (Design and Test of Operating Effectiveness, TOE)
- Using standardized External Auditor Templates
Year 2
- Focusing on high-priority risk areas
- Automating ITGCs increases audit efficiency
- Recommend modifying sample sizes based on risk-based testing, focusing on areas with higher material impact
- Modify roll forward approach
- Optimize level of documentation in areas of non reliance
Beyond
- Optimizing audit efficiency and effectiveness through risk-based approaches, automation, standardization, and focused documentation
- Continuous review of process narratives
- Revisit risk assessment and scoping based on change in business
- Execute SOX testing plan periodically
Trusted By

















Case study
Assistance in SOX implementation and management testing for a Space Telecommunications company
The company is building the first and only space-based cellular broadband network accessible directly by everyday smartphones, designed for both commercial and government applications, listed on the NASDAQ exchange.
The company’s Emerging Growth Company (EGC) status expired on June 30, 2024, and considering that it was the first year of 404(b) certification, the company needed support:
- In understanding the processes, assessing the need for controls and documenting process flows and RCMs
- In testing the control environment (including ELCs, ITGCs, MRCs, IPE testing) and developing a mitigation plan for deficiencies identified
- In identification of all applications impacting key processes, and performing ITGC testing
- In mitigation of deficiencies due to lack of review evidence, precision levels applied, and follow-up action

