WeConsulting.

Join us.

Two different routes in, depending on how you want to work with us.

All Join us

AssuranceService

Internal Controls over Financial Reporting

Internal Controls over Financial Reporting (ICFR) Services are designed to help organizations ensure the accuracy and reliability of their financial statements through controls that are documented, tested and demonstrably operating.

Overview

ICFR work goes wrong in a predictable way: an enormous documentation exercise that produces hundreds of controls, most of which nobody can test efficiently and several of which do not actually address a real misstatement risk.

We start at the other end, from the financial statement line items and the assertions that could be materially misstated, and work back to the smallest set of controls that genuinely mitigates them. The result is a control set that is defensible to auditors and sustainable for the finance team that has to operate it every month.

What this covers

  • 01

    Scoping and risk assessment

    Materiality, significant accounts and disclosures, and the assertions at risk, documented so that the scope of the exercise can be justified rather than assumed.

  • 02

    Process and control documentation

    Narratives, flowcharts and risk-and-control matrices for each significant cycle, at a level of detail that supports testing.

  • 03

    Design and operating effectiveness testing

    Walkthroughs, sample-based testing and evaluation of deficiencies, with clear classification between deficiency, significant deficiency and material weakness.

  • 04

    Entity-level and IT general controls

    The control environment, management review controls, and the ITGC layer over access, change and operations that everything else depends on.

  • 05

    Remediation support

    Redesign of failed controls, including practical decisions about automation, and re-testing once implemented.

  • 06

    Sustainability and handover

    Control ownership, evidence standards and an annual testing calendar that the business can run itself.

How we can help

What a full engagement typically produces. Scope is agreed up front and adjusted to what your organisation actually needs.

  • ICFR scoping and materiality memorandum
  • Process narratives and flowcharts
  • Risk and control matrices by cycle
  • Test plans and completed testing files
  • Deficiency log with severity assessment
  • Remediation plan and re-test results
  • Entity-level control assessment
  • Management's assessment and supporting evidence pack

Standards and frameworks

Work is delivered against recognised standards so that findings are defensible to your auditors, your board and your regulator.

COSO Internal Control — Integrated FrameworkIFRS Accounting StandardsISA 315SOX 404 methodologyCOBIT (IT general controls)

Questions we get asked

We are not SOX-registered. Is ICFR still relevant?
Yes. The discipline is about reliable financial reporting, not about a specific statute. Boards, lenders, investors and prospective acquirers all place weight on it, and external auditors reduce substantive testing where controls can be relied upon.
How many controls should we expect to end up with?
Fewer than most organisations start with. A mid-sized entity is usually well served by a control set in the low hundreds. If the number is climbing past that, the scoping is generally the problem.

Talk to us about internal controls over financial reporting.

Tell us what you are trying to resolve. We will tell you honestly whether we are the right firm for it.