Support the company’s SOX readiness by proposing, standardizing, and documenting processes and internal controls that meet compliance requirements while remaining practical and proportionate to the business. Work closely with control owners across relevant functions to implement these controls, and serve as the technical point of contact for external consultants and auditors throughout the audit cycle.
1. Internal Control & Compliance
- Scoping & Documentation: Develop risk assessments across entities, accounts, and processes; maintain risk control matrices (RCMs), process flowcharts, narratives, and SOPs.
- Control Optimization: Propose lean, automated control improvements to minimize manual effort and documentation while meeting compliance requirements.
- Change Integration: Assess new and evolving business processes and incorporate fit-for-purpose controls in a timely manner.
- Control Design & Gap Assessment: Assess control design across financial reporting cycles against the COSO Framework.
- Stakeholder Alignment: Work with process owners to explain controls, address concerns, and ensure agreed controls are implemented in daily operations.
- Process Standardization: Standardize control language and evidence across entities to ensure continuous audit-readiness.
- IT Collaboration: Collaborate with the IT Team to resolve control deficiencies and strengthen ITGC before testing and external audit.
- Testing & Remediation: Execute operating effectiveness testing, evaluate gap risks, and track remediation plans.
2. External Audit Coordination
- Act as the technical point of contact for external consultants/auditors in walkthroughs, testing and discussions regarding audit findings.
- Prepare and explain requested information and audit evidence, and address differences in views on control design when needed.
- Track and drive audit findings through to closure.
3. Compliance Operations & Framework Sustainment
- Review processes and underlying controls to support broader compliance and regulatory filings.
- Sustain the control framework post-certification through periodic refreshes, system update alignments, and next-cycle readiness.
- Train control owners on their control responsibilities and the purpose behind each control.
4. Reporting
- Consolidate testing results and deficiency logs to report key control risks to the CFO and executive management.