SOX Audit & Compliance
The Sarbanes-Oxley Act of 2002 (SOX) imposes stringent internal control and financial reporting requirements on companies listed on US stock exchanges and their consolidated subsidiaries worldwide. For Indian subsidiaries of US-listed parent companies, SOX compliance is mandatory — requiring documented, tested, and independently audited internal controls over financial reporting (ICFR), CEO and CFO certifications under Sections 302 and 404, and annual external auditor attestation on ICFR effectiveness. We provide comprehensive SOX compliance advisory, ICFR documentation, control testing, and remediation support for Indian operations of US-listed groups.
ICFR Documentation
Documentation of Internal Controls over Financial Reporting — process narratives, risk and control matrices (RCMs), and control descriptions across all significant financial reporting processes (revenue, procure-to-pay, treasury, financial close).
SOX Control Testing
Walkthrough and operating effectiveness testing of key SOX controls — documenting test procedures, sample selection, exceptions identified, and conclusions — in the format required by external auditors conducting the Section 404(b) attestation.
Gap Assessment
Comparison of the company's current internal control environment against SOX best practices and PCAOB auditing standards — identifying design gaps, operating effectiveness failures, and significant deficiencies or material weaknesses requiring remediation.
Section 302 Certification Support
Support for the quarterly and annual Section 302 CEO/CFO certifications — preparing the sub-certification process, disclosure committee operation, and the documentation underlying management's assertions in the certification.
Remediation Advisory
Structured remediation of identified control deficiencies — designing improved controls, implementing system-based preventive controls, strengthening detective controls, and retesting remediated controls to confirm resolution before external audit.
IT General Controls (ITGC)
Documentation and testing of IT General Controls — logical access, change management, computer operations, and data backup — that form the foundation of application control reliance in the SOX ICFR framework.
Key SOX Compliance Areas We Cover
- Financial reporting process documentation — revenue, procure-to-pay, payroll, treasury, close
- Risk and control matrix (RCM) preparation and annual refresh
- Walkthrough interviews and control evidence collection
- Sample-based operating effectiveness testing (IPCM approach)
- IT General Controls testing — logical access, change management, computer operations
- Section 302 and 906 certification sub-process management
- External auditor coordination — PBC list management and query resolution
- Management testing report and remediation tracking
Frequently Asked Questions
What is the difference between a SOX significant deficiency and a material weakness?
Which Indian company operations are subject to SOX compliance?
What is a PCAOB audit standard and why does it matter?
What is the COSO framework and why is it used for SOX?
How often must SOX ICFR be tested?
SOX Compliance That Protects Your US Listing
SOX ICFR documentation, control testing, gap assessment, remediation advisory, and Section 302 certification support for Indian subsidiaries of US-listed companies.
Talk to an Expert