The Trust Operations Platform — demonstrate the compliance diligence your stakeholders expect, beyond SOC 2. See how it works →
Platform · ICA · SOX-style

SOX-style attestation, quarterly cadence built in.

The Internal Controls Assessment module supports the SOX-style quarterly attestation cycle. 36-control seeded template, control owner certification, deficiency register, and audit-ready quarterly attestation report.

Capabilities

Internal Controls Assessment — what's in the box.

+

COSO + ITGC + financial cycles

Internal Control Framework, IT General Controls, and the four major financial cycles (O2C, P2P, H2R, R2R).

+

Three-tier ownership

Control / Evidence / Task ownership separation — same model as SOC 2 Readiness for cross-program efficiency.

+

Deficiency register

Severity-graded (Deficiency / Significant Deficiency / Material Weakness) with remediation tracking auditors look for.

+

Quarterly attestation report

Generated at cycle close with control-by-control status, deficiency summary, and trend comparison.

Scope & taxonomy

SOX-grade, quarter after quarter.

+

COSO framework

All five integrated components — control environment, risk assessment, control activities, information & communication, monitoring — structured the way an external auditor expects to review them.

+

IT General Controls

The four ITGC categories auditors always test: access management, change management, computer operations and program development.

+

Financial cycles

Order-to-Cash, Procure-to-Pay, Hire-to-Retire and Record-to-Report — the cycles where entity-level and process-level controls actually live.

+

Quarterly cadence

A fresh attestation instance each quarter from the same template, with prior-quarter carry-forward — built around the natural rhythm of a SOX program.

Capabilities

Attestation, deficiencies, evidence — in one place.

+

36-control seeded template

A platform-global Internal Control Self-Attestation template covering COSO, ITGC and the major financial cycles, ready to run on day one.

+

Control-owner certification

Each owner certifies design and operating effectiveness with a digital signature per cycle — signed attestations retained as evidence.

+

Exception register

Deficiencies tracked with severity — Deficiency, Significant Deficiency, Material Weakness — remediation owner and status.

+

Three-tier ownership

The same Control / Evidence / Task model as SOC 2 readiness, so internal controls and SOC 2 share the underlying machinery.

+

Cross-mapped evidence

Each control maps to the corresponding SOC 2 TSC and ISO 27001 Annex A control — evidence collected for SOX is reused across frameworks.

+

Audit-ready output

A quarterly attestation report and deficiency register export as a branded PDF — the artefacts the Audit Committee and external auditors ask for.

Stop running this in spreadsheets.

Verisq's Internal Controls Assessment is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.

See pricing Back to home