SOX Programme Build
Building a SOX programme for the first time is a sequencing problem before it is a documentation problem.
Ditton sequences the build across the full SOX lifecycle, from scoping to the management assessment, so each stage has what it needs from the one before.
The sequence
What usually has to happen
Plan
- 01Planning & scoping
- 02Entity-level controls
Business process track
- 03Risk assessment
- 04Control identification & RCM build
- 06Control documentation
- 07Walkthroughs (test of design)
- 08Sample selection
- 09Testing (operating effectiveness)
IT track
- 05IT scoping
- —ITGC testing by your IT audit function or a specialist provider
Both tracks feed deficiency evaluation.
Conclude
- 10Deficiency evaluation
- 11Remediation
- 12Management assessment
- 13Reporting & external audit support
Deliverables
What Ditton delivers
- Risk and Control Matrix extractThe backbone of the programme: each risk mapped to its assertions, the key control that addresses it, and the attributes needed to test it.
- Walkthrough narrativeTraces a transaction end to end to confirm controls exist where documented and are placed to address the stated risk.
- Testing workpaperRecords the population, sample, attributes tested, evidence examined and conclusion on a control’s operating effectiveness.
- Deficiency evaluation memoDocuments the severity assessment of a control exception, including aggregation and compensating controls, and the basis for classification.
- Remediation trackerTracks each deficiency from root cause through remediation to validated closure, with owners and target dates.
- Programme status reportGives management a single view of programme progress, testing status, open deficiencies and risks to the timetable.
Engagement
How to start
Fixed-fee entry point
404(a) Management Assessment Readiness Review
A review of what is already in place against the lifecycle, with written findings and a defined scope for the build.
Fixed fee — confirmed at scopingFixed-fee entry point
Auditor Transition ICFR Review
For companies that have changed auditor.
- Scoping
- Key controls
- Entity-level controls
- Significant processes
- Evidence expectations
- Open deficiencies and remediation
- Reviewed before first-year planning
Scoped programme
SOX Programme Build
Scoped from a Readiness Review or scoping call: building the programme stage by stage across the lifecycle.
Scoped engagement — quoted after a scoping callDownload
Engagement Scope Note
How a Ditton engagement is scoped: deliverables, boundaries and commercial terms, agreed before work begins.