Methodology
The SOX lifecycle, stage by stage.
Business process and IT workstreams run in parallel and both feed deficiency evaluation.
Plan
- 01Planning & scoping
- 02Entity-level controls
Business process track
- 03Risk assessment
- 04Control identification & RCM build
- 06Control documentation
- 07Walkthroughs (test of design)
- 08Sample selection
- 09Testing (operating effectiveness)
IT track
- 05IT scoping
- —ITGC testing by your IT audit function or a specialist provider
Both tracks feed deficiency evaluation.
Conclude
- 10Deficiency evaluation
- 11Remediation
- 12Management assessment
- 13Reporting & external audit support
Stages
Each stage
01Planning & scoping
Determine filer status and materiality, identify significant accounts and disclosures, map them to processes and locations, and document the scoping rationale.
02Entity-level controls
Assess the control environment, oversight, risk assessment and period-end financial reporting process.
03Risk assessment
For each in-scope process, identify what could go wrong and map risks to relevant financial statement assertions.
04Control identification & RCM build
Identify the key control for each risk and document its attributes: owner, type, nature, frequency and evidence.
05IT scoping
Identify in-scope systems and the IT general controls they depend on. (Ditton does not perform ITGC testing; that sits with your IT audit function or a specialist provider.)
06Control documentation
Process narratives, test procedures and walkthrough packages.
07Walkthroughs (test of design)
Trace transactions end to end; confirm controls exist and are designed to address the risk.
08Sample selection
Define populations and select samples with documented rationale.
09Testing (operating effectiveness)
Execute tests, evaluate evidence, document conclusions and exceptions.
10Deficiency evaluation
Classify exceptions as control deficiencies, significant deficiencies or material weaknesses, considering aggregation and compensating controls.
11Remediation
Root cause, action, owner, target date, and validation through re-testing.
12Management assessment
Management concludes on ICFR effectiveness, supporting the Section 302 certifications and the Section 404(a) management report.
13Reporting & external audit support
Support auditor fieldwork where applicable, respond to requests, archive workpapers.