The Internal Controls Assessment module supports the SOX-style quarterly attestation cycle. 36-control seeded template, control owner certification, deficiency register, and audit-ready quarterly attestation report.
Internal Control Framework, IT General Controls, and the four major financial cycles (O2C, P2P, H2R, R2R).
Control / Evidence / Task ownership separation — same model as SOC 2 Readiness for cross-program efficiency.
Severity-graded (Deficiency / Significant Deficiency / Material Weakness) with remediation tracking auditors look for.
Generated at cycle close with control-by-control status, deficiency summary, and trend comparison.
All five integrated components — control environment, risk assessment, control activities, information & communication, monitoring — structured the way an external auditor expects to review them.
The four ITGC categories auditors always test: access management, change management, computer operations and program development.
Order-to-Cash, Procure-to-Pay, Hire-to-Retire and Record-to-Report — the cycles where entity-level and process-level controls actually live.
A fresh attestation instance each quarter from the same template, with prior-quarter carry-forward — built around the natural rhythm of a SOX program.
A platform-global Internal Control Self-Attestation template covering COSO, ITGC and the major financial cycles, ready to run on day one.
Each owner certifies design and operating effectiveness with a digital signature per cycle — signed attestations retained as evidence.
Deficiencies tracked with severity — Deficiency, Significant Deficiency, Material Weakness — remediation owner and status.
The same Control / Evidence / Task model as SOC 2 readiness, so internal controls and SOC 2 share the underlying machinery.
Each control maps to the corresponding SOC 2 TSC and ISO 27001 Annex A control — evidence collected for SOX is reused across frameworks.
A quarterly attestation report and deficiency register export as a branded PDF — the artefacts the Audit Committee and external auditors ask for.
Verisq's Internal Controls Assessment is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.