COSO-Aligned “SOX-Lite” Advisory

Build investor-grade controls now—right-sized for small teams, ready to scale toward public-company rigor.

 

Outcome: Close at T+6 (business days) using a D0–D10 close template compressed to D1–D6 as controls stabilize, with audit-defensible evidence.

 

What’s inside (scope & deliverables)

◉ ELC (Entity-Level Controls): board/audit oversight, code of conduct & anti-fraud, documented policies, quarterly CEO/CFO control certifications.

◉ ITGC & IPE (Information Produced by the Entity): access management (SSO/MFA, joiner-mover-leaver, quarterly access reviews), change control & backups/restore logs; IPE register (10–20 key reports) with parameters & C&A procedures (completeness/accuracy).

◉ Risk Assessment: COSO-based risk inventory & heatmap; linkage to processes and financial statement assertions.

◉ Process Walkthroughs: narrative + flowcharts for P2P/AP, O2C/Revenue, Payroll/Contractors, Inventory/COGS (if applicable), R2R/Close, Bank Reconciliation.

◉ RCMs (Risk/Control Matrices): design of key controls with owners, frequency, evidence, and SOD mapping (plus compensating controls for small teams).

◉ Close Calendar & Responsibilities: standard D0–D10 checklist compressed to T+6 finish; D1–D6 milestones, RACI, pre-close accrual playbooks, variance analysis package.

◉ Documentation Pack: bilingual (EN + CH) policies & SOPs, IPE evidence folders with naming standards, parameter screenshots, reviewer sign-offs.

◉ Pragmatic Test Plans: light, repeatable design & operating effectiveness scripts, targeted samples, defect log, remediation & re-test.

💧What we are not: audit or legal opinions. We design and evidence controls to audit expectations, coordinating with your auditor/underwriter/counsel.

 

Acceptance targets (binary, easy to verify)

◉ Latest month closed by T+6 (business days).

◉ Bank rec prepared & independently reviewed by T+5; exceptions cleared.

◉ Revenue cut-off saved with parameters; totals tied to GL; samples traced to source.

◉ IPE register complete with C&A steps; ≥3 key reports validated this quarter.

◉ SOD conflicts eliminated or mitigated with documented compensating reviews.