Internal Control Frameworks: ICS, SOX and ISAE 3402

Home / Services / Internal Control

We don’t just build controls. We make sure frameworks like ICS and SOX rest on solid organisational, process and IT foundations. And we help you get those built too.

How an implementation runs

From scoping to an audit-ready state.


PHASE 1

Scope & design

  1. Scoping: financial and IT
  2. Business process definitions and full documentation (flowcharts and narratives)
  3. Significant risk definitions for the risk-control matrix
  4. Control design drafting: entity level, IT general and process controls

PHASE 2

Validate & implement

  1. Control design validation and dry-runs
  2. Control design remediation
  3. Implementation of the risk-control matrix
  4. Control performance support and evidence assessments
  5. Pre-audit assessments

PHASE 3

Make it last

  1. Reshaping IT and non-IT elements of organisation and process structure
  2. Annual internal control cycle: manuals, trainings, communication
  3. Making your IT ecosystem compatible with internal control requirements
  4. Liaison with Internal and External Audit (e.g. reliance agreement)

Done before, at scale

15+ yrs

Group Head ICS of a global building-materials group, 50 operating entities.

5 yrs

SOX from scratch for a US-listed company across Germany, the Netherlands and the US.

~40

Process controls implemented at 10 entities across Asia, Latin America and Africa, boosting global compliance.

1–3

Systems in scope. Ideally one, never more than three financially relevant systems in your Internal Control scope.