SOX and ICFR governance workspace | Compliancify

Organize scope, financial-reporting risks, control ownership, evidence, testing, deficiencies, certifications, and disclosure review without implying auditor reliance or management conclusion.

Public scope

Structured context for people and machine readers.

This is a public product and knowledge surface. Illustrative workflows do not establish a professional conclusion, legal or tax advice, guaranteed outcome, or live customer implementation.

  • Scope & materiality
  • Entity-level controls
  • Process and IT-dependent controls
  • Testing & evidence
  • Deficiency evaluation
  • Certification & disclosure

Public knowledge 01

Source and applicability boundary

  1. 01

    SEC rules and company-specific filing obligations

  2. 02

    PCAOB standards apply to registered public-company audits

  3. 03

    Management and external-auditor conclusions remain separate

  4. 04

    Issuer status, reporting obligations, scope, materiality, control evaluation, deficiency severity, certification, and disclosure require company-specific legal, accounting, and audit assessment.

  5. 05

    Official starting point: https://www.sec.gov/rules-regulations/2003/06/managements-report-internal-control-over-financial-reporting-certification-disclosure-exchange-act

Public knowledge 02

Obligation and control themes

  1. 01

    Scope & materiality — Maintain entity, account, disclosure, location, system, service organization, process, and materiality scope decisions.

  2. 02

    Entity-level controls — Document oversight, ethics, risk assessment, competence, authority, communication, monitoring, and remediation governance.

  3. 03

    Process and IT-dependent controls — Relate financial assertions and risks to process, system, interface, report, automated, manual, and review controls.

  4. 04

    Testing & evidence — Define population, period, frequency, sample or automated approach, evidence expectation, reviewer challenge, and deviation handling.

  5. 05

    Deficiency evaluation — Aggregate deficiencies, assess likelihood and magnitude, consider compensating controls, route governance, and preserve conclusions.

  6. 06

    Certification & disclosure — Coordinate sub-certifications, disclosure-control inputs, management evaluation, legal review, and filing governance.

Public knowledge 03

Evidence and review expectations

  1. 01

    Scope & materiality: Scoping model, quantitative and qualitative factors, entity map, system map, changes, and approvals. Owner: Controllership owner. Reviewer: ICFR governance reviewer. State: Interpretation pending.

  2. 02

    Entity-level controls: Charters, policies, attestations, minutes, risk assessments, monitoring, issues, and action follow-up. Owner: Corporate controls owner. Reviewer: Audit committee liaison. State: Mapped.

  3. 03

    Process and IT-dependent controls: Narratives, flows, risk-control matrix, configurations, reports, calculations, approvals, and change records. Owner: Process owner. Reviewer: ICFR reviewer. State: Evidence requested.

  4. 04

    Testing & evidence: Population, selection, workpaper, evidence, deviation, review comments, conclusion, and sign-off. Owner: Testing owner. Reviewer: Testing reviewer. State: Reviewer decision.

  5. 05

    Deficiency evaluation: Issue facts, affected assertions, evaluation, aggregation, compensating evidence, decisions, and communications. Owner: Deficiency owner. Reviewer: Disclosure committee reviewer. State: Reassessment due.

  6. 06

    Certification & disclosure: Sub-certifications, representation inputs, evaluation record, committee materials, approvals, and filed disclosure. Owner: Disclosure owner. Reviewer: Legal and finance reviewer. State: Reviewer decision.

Public knowledge 04

Relationships without false equivalence

  1. 01

    COSO-based internal-control models

  2. 02

    SOC 1 service-organization assurance

  3. 03

    SEC cybersecurity disclosure governance