IT Audit & ITGC
Access, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGC
Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.
Usually 120 to 250 key controls including ITGCs, for a mid-market company with one ERP, one primary revenue stream and a single significant location. A SOX 404 compliance consultant in Los Angeles who arrives at 600 or more for that complexity is describing a mis-scoped programme, not an unusually rigorous one.
Section 404 requires management to assess the effectiveness of internal control over financial reporting. It does not require documenting every process in the company, which is why scoping, rather than testing, is where the money is won or lost: the gap between good and bad scoping is roughly a factor of three in annual cost, permanently.
Companies engage a SOX 404 compliance consultant in Los Angeles at one of two moments: shortly after becoming a public filer and realising that Section 404 is a programme rather than a project, or two years in, when the programme has grown to eleven hundred controls and nobody can remember why most of them exist.
Both problems have the same root cause: scoping. The eleven-hundred-control programme was not built by someone being unusually careful. It was built by someone who never drew a boundary, followed by three years of people adding controls that nobody felt authorised to remove.
The scoping exercise determines which accounts are material, which processes feed them, which locations are significant, and which controls actually address a risk of material misstatement. Everything downstream inherits those decisions.
The failure pattern is consistent and expensive. A first-year programme is built by documenting every process anyone can describe, mapping a control to each step, and calling the result a control matrix. It produces hundreds of controls that address no material risk, each of which must then be tested annually, evidenced, and remediated when it fails. Nobody ever removes them, because removing a control feels like reducing rigour.
Proper scoping works in the opposite direction, from the financial statements backwards. Which balances are quantitatively or qualitatively material. What could go wrong in each. Which controls, if they operated, would prevent or detect that. Everything else is a business process, not a SOX control, and should be managed as one.
Every automated control, every system-generated report used in a control, and every calculation performed by the ERP depends on the general IT controls underneath it. If access management, change management and IT operations are not effective, the application controls sitting on top cannot be relied upon, and the deficiency is pervasive rather than isolated, which is how a single access-review failure becomes a material weakness.
This is the area where finance-led SOX programmes most often come apart, because it requires someone who can read an access listing, understand a change ticket, and evaluate whether a privileged account should exist. Holding CISA alongside the CPA licence is the practical reason this practice handles both halves rather than subcontracting one. The dedicated detail is on the IT audit and ITGC page.
A newly public company (whether through IPO, direct listing or de-SPAC) faces a compressed timeline in which the finance team is simultaneously learning to file 10-Qs. The realistic sequence over the first year is: scope in the first quarter, document and design in the second, remediate through the third, and test in the fourth so that management's assessment rests on controls that have actually operated.
The decision that most affects year two is how much of the programme lives in a tool versus in spreadsheets, and how much of the testing the company can perform itself. A programme designed so that the consultant must return annually to run it is a programme designed badly.
When a control fails, three questions follow: what is the magnitude of potential misstatement, what is the likelihood, and does a compensating control catch it. The answers determine whether the failure is a deficiency, a significant deficiency, or a material weakness, and the last of those requires disclosure and moves markets.
This is where experience is not substitutable. The evaluation is a judgment made under pressure, usually late in the year, usually with the external auditor holding a different preliminary view. Having sat on the auditor's side of that conversation for twenty years changes how it is prepared for: with the analysis documented before the discussion rather than assembled during it.
For companies already two or three years in, the more common engagement is rationalisation. The pattern is recognisable, control counts that only ever increase, testing that consumes the fourth quarter, and a matrix containing controls that duplicate one another or that address risks that ceased to exist when a system was replaced.
Rationalisation works through the same backwards logic as initial scoping, and typically removes 30 to 50% of controls from an unrationalised programme without reducing coverage of material risk. The constraint is rarely analytical. It is that removing controls requires a documented rationale the external auditor will accept, and writing that rationale is the actual work.
Work backwards from the financial statements to material accounts, relevant assertions, significant processes and locations. Everything downstream depends on this being done properly.
Narratives, flowcharts and a risk and control matrix, including ITGCs. Gaps in control design are identified here, when they are cheap to fix.
Design and implement the missing controls, then let them operate long enough to be tested. Controls that have never operated cannot support an assessment.
Execute testing, evaluate exceptions, aggregate deficiencies, and prepare management’s assessment, with the external auditor’s likely position anticipated rather than discovered.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
There is no correct number, but there is a useful sanity check. A mid-market company with one ERP, one primary revenue stream and a single significant location can usually be covered by something in the range of 120 to 250 key controls including ITGCs.
Programmes at 600, 900 or 1,200 controls at that complexity are almost always mis-scoped rather than unusually rigorous. Each excess control carries an annual cost in testing, evidence and remediation, and none of them reduce the risk of material misstatement.
Management's assessment under 404(a) is generally first required in the second annual report following the IPO. The auditor attestation under 404(b) depends on filer status, and emerging growth companies and smaller reporting companies have exemptions and phase-ins that can defer it considerably.
The trap is treating the deferral as time available. Controls must have operated before they can be tested, so a company that starts designing in the year the assessment is due has no operating history to test against, and remediation collides with the filing deadline. Starting in the first year is materially cheaper than starting in the second.
Both are control deficiencies; they differ in severity. A significant deficiency is less severe than a material weakness but important enough to merit attention by those responsible for financial reporting oversight. A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis.
The practical distinction is disclosure. A material weakness must be disclosed, and it affects the auditor's opinion on ICFR. Two points are frequently missed: deficiencies aggregate, so several individually minor issues in the same process can combine into a material weakness; and an ITGC failure is often pervasive rather than isolated, because everything relying on that system inherits the problem.
For management's own testing programme, yes; this work is performed on behalf of management, which is expected to design and assess its own controls. That is a different role from the external auditor's.
Where independence does bite is if this practice were also performing your financial statement audit or ICFR attestation. It cannot do both, and which side applies is agreed before the engagement begins. The audit and attestation page sets out the same rule from the other direction.
Common, and usually resolvable, but the resolution depends on documentation rather than argument. The auditor's position is typically that a process or location you excluded could produce a material misstatement, and the answer is a quantitative and qualitative analysis showing why it could not.
Where the analysis was written at the time of scoping, these conversations are short. Where it is reconstructed afterwards, the auditor tends to prevail regardless of the merits, because contemporaneous rationale is what makes a scoping decision defensible.
Access, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGCAudits, reviews, compilations, agreed-upon procedures and benefit plan audits, work that only a licensed CPA firm can issue.
Audit & attestationWhere the business can fail, whether the control that should catch it works, and what to fix first.
Risk & controlsThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp