---
# === IDENTITY ===
id: finance/financial-ops/financial-controls-compliance-assessment/2026
canonical_question: "How ready are financial controls — SOX readiness, audit preparedness, segregation of duties?"
aliases:
  - "financial controls maturity assessment"
  - "SOX readiness evaluation"
  - "internal controls audit preparedness"
  - "segregation of duties assessment"
  - "ICFR maturity diagnostic"
entity_type: assessment
domain: finance > financial-ops > Financial Controls & Compliance Assessment
region: global
jurisdiction: global
temporal_scope: 2025-2026

# === VERIFICATION ===
last_verified: 2026-03-10
confidence: 0.86
version: 1.0
first_published: 2026-03-10

# === TEMPORAL VALIDITY ===
temporal_validity:
  status: stable
  last_breaking_change: "PCAOB 2024 inspection findings increased scrutiny on IT general controls and cybersecurity controls in financial reporting"
  next_review: 2026-09-06
  change_sensitivity: low

# === CONSTRAINTS ===
constraints:
  - "Requires access to control documentation, policy manuals, audit reports, and risk registers for reliable scoring"
  - "Most relevant for companies approaching IPO, SOX compliance thresholds, or external audit requirements"
  - "Private companies below $75M revenue are not required to comply with SOX 404(b) but benefit from the framework"
  - "Assessment is diagnostic — it identifies control gaps but does not replace a formal audit or SOX readiness engagement"
  - "Re-run annually or when significant system/process changes occur"

# === SKIP CONDITIONS ===
skip_this_unit_if:
  - condition: "User wants financial metric benchmarks, not controls assessment"
    use_instead: "finance/financial-ops/financial-metrics-benchmarks/2026"
  - condition: "User needs AP/AR process optimization, not controls evaluation"
    use_instead: "finance/financial-ops/accounts-payable-receivable-diagnostic/2026"
  - condition: "User needs IT security controls assessment, not financial controls"
    use_instead: "compliance/cybersecurity-maturity-assessment/2026"

# === AGENT HINTS ===
inputs_needed:
  - key: company_stage
    question: "What stage is the company?"
    type: choice
    options: ["Private (<$75M revenue)", "Private (>$75M, pre-IPO)", "Newly public (first 2 years)", "Mature public company"]
  - key: compliance_requirements
    question: "What compliance requirements apply?"
    type: multi_select
    options: ["SOX 404(a) — management assessment", "SOX 404(b) — auditor attestation", "No SOX requirement (private)", "International (J-SOX, C-SOX, etc.)"]
  - key: assessment_depth
    question: "What depth of assessment is needed?"
    type: choice
    options: ["quick health check (15 min)", "standard assessment (1 hour)", "deep audit (half day)"]
  - key: data_available
    question: "What documentation is available?"
    type: multi_select
    options: ["control matrices", "policy manual", "prior audit reports", "risk registers", "process flowcharts", "IT access logs"]

# === DISTRIBUTION ===
canonical_source: "https://knowledgelib.io/finance/financial-ops/financial-controls-compliance-assessment/2026"
suggested_citation: "Source: knowledgelib.io — AI Knowledge Library (verified 2026-03-10)"

# === RELATED UNITS ===
related_kos:
  leads_to:
    - id: "finance/financial-ops/fpa-maturity-assessment/2026"
      label: "FP&A assessment for companies with weak reporting controls"
    - id: "finance/financial-ops/revenue-operations-assessment/2026"
      label: "RevOps assessment for revenue recognition control weaknesses"
  related_to:
    - id: "finance/financial-ops/accounts-payable-receivable-diagnostic/2026"
      label: "AP/AR diagnostic for transaction-level control testing"
    - id: "finance/financial-ops/financial-metrics-benchmarks/2026"
      label: "Benchmark data for financial reporting metrics"
  depends_on: []
  often_confused_with: []
  alternative_to: []

# === SOURCES ===
sources:
  - id: src1
    title: "SOX Compliance Assessments 101: An Essential Guide"
    author: Armanino
    url: https://www.armanino.com/articles/sox-compliance-assessment-guide/
    type: industry_report
    published: 2025-06-01
    reliability: authoritative
  - id: src2
    title: "COSO Internal Control — Integrated Framework"
    author: COSO / AICPA
    url: https://www.coso.org/guidance-on-ic
    type: official_docs
    published: 2025-01-01
    reliability: authoritative
  - id: src3
    title: "Segregation of Duties for SOX Compliance"
    author: SecurEnds
    url: https://www.securends.com/blog/segregation-of-duties-for-sox-compliance/
    type: industry_report
    published: 2025-04-01
    reliability: high
  - id: src4
    title: "SOX Controls: Common Types, Examples & Implementation"
    author: Exabeam
    url: https://www.exabeam.com/explainers/sox-compliance/sox-controls-common-types-examples-implementation-practices/
    type: industry_report
    published: 2025-05-01
    reliability: high
  - id: src5
    title: "SOX Compliance Checklist: Essential Steps for Financial Teams"
    author: MindBridge
    url: https://www.mindbridge.ai/blog/sox-compliance-checklist-essential-steps-for-financial-teams/
    type: industry_report
    published: 2025-07-01
    reliability: high
  - id: src6
    title: "COSO Framework Fundamentals"
    author: AuditBoard
    url: https://auditboard.com/blog/coso-framework-fundamentals
    type: industry_report
    published: 2025-03-01
    reliability: high
---

# Financial Controls & Compliance Assessment

## Purpose

This assessment evaluates the maturity of a company's internal financial controls across five critical dimensions: control environment and governance, segregation of duties, financial close and reporting controls, IT general controls, and audit readiness. The output is a composite maturity score (1-5) aligned with the COSO framework that identifies control gaps before auditors do. Use this when preparing for an IPO, evaluating SOX readiness, onboarding a new controller, or diagnosing why audit findings keep recurring. [src2]

## Constraints
<!-- Agents: read before running this assessment with a user. -->

- Requires access to control documentation, policy manuals, and prior audit reports for reliable scoring
- Most relevant for companies approaching IPO or SOX compliance thresholds — private companies benefit from the framework but are not required to comply
- SOX 404(b) auditor attestation is required for accelerated filers ($75M+ public float); smaller reporting companies need only 404(a) management assessment
- Assessment is diagnostic — it identifies control gaps but does not replace a formal SOX readiness engagement with an auditing firm
- Re-run annually or whenever significant system migrations, ERP changes, or organizational restructures occur

## Assessment Dimensions

### Dimension 1: Control Environment & Governance

**What this measures**: The foundation of internal controls — tone at the top, organizational structure, policies, and risk assessment processes aligned with COSO Component 1.

| Score | Level | Description | Evidence |
|-------|-------|-------------|----------|
| 1 | Ad hoc | No formal control policies; roles and responsibilities unclear; no risk assessment process | No written policies; no org chart for finance; no documented risk assessment |
| 2 | Emerging | Basic policies exist but are outdated or incomplete; ethics/compliance training sporadic; informal risk identification | Some policies documented; last update >2 years ago; annual compliance training; informal risk discussions |
| 3 | Defined | Comprehensive policy manual updated annually; formal risk assessment process; code of conduct enforced; whistleblower hotline | Policy manual current; annual risk assessment; code of conduct signed; hotline active |
| 4 | Managed | Risk-based control framework aligned to COSO; continuous policy monitoring; risk appetite formally defined; board oversight active | COSO-aligned framework; quarterly risk reviews; risk appetite statement; audit committee engaged |
| 5 | Optimized | Integrated GRC platform; continuous control monitoring; risk-aware culture embedded; leading indicator risk identification | GRC platform deployed; continuous monitoring; culture surveys; predictive risk analytics |

**Red flags**: No written finance policies; CEO/CFO override controls routinely; no whistleblower mechanism exists; risk assessment done only when auditors require it. [src2]
**Quick diagnostic question**: "When was your financial policy manual last updated, and do you have a formal risk assessment process?"

### Dimension 2: Segregation of Duties

**What this measures**: Whether duties are divided appropriately to prevent any single person from having control over an entire financial process — a fundamental fraud prevention mechanism.

| Score | Level | Description | Evidence |
|-------|-------|-------------|----------|
| 1 | Ad hoc | One person handles end-to-end financial processes (initiate, approve, record, reconcile); no SoD awareness | Same person creates vendors and approves payments; no SoD matrix; founder signs everything |
| 2 | Emerging | SoD concerns identified but not systematically addressed; some dual controls exist; compensating controls informal | Some processes have dual approval; SoD violations known but not remediated; spreadsheet tracking |
| 3 | Defined | Formal SoD matrix documented; key process conflicts identified and remediated; compensating controls documented | SoD matrix exists; conflicts mapped; compensating controls documented; quarterly review |
| 4 | Managed | Automated SoD enforcement in ERP/financial systems; continuous monitoring for violations; exceptions tracked and approved | System-enforced SoD; automated violation alerts; exception management workflow; annual certification |
| 5 | Optimized | Real-time SoD monitoring across all systems; predictive conflict detection; cross-application SoD analysis | Real-time monitoring; cross-system SoD analytics; predictive conflict detection; zero unresolved violations |

**Red flags**: Same person creates vendors and processes payments; no SoD matrix exists; system access reviews not performed; compensating controls are undocumented. [src3]
**Quick diagnostic question**: "Can a single person create a vendor, enter an invoice, and approve payment without any second approval?"

### Dimension 3: Financial Close & Reporting Controls

**What this measures**: The controls around the financial close process, including account reconciliations, journal entry controls, and financial statement preparation.

| Score | Level | Description | Evidence |
|-------|-------|-------------|----------|
| 1 | Ad hoc | No formal close process; reconciliations sporadic; journal entries unreviewed; close takes 20+ business days | No close checklist; reconciliations done only for audit; JEs posted without review; 20+ day close |
| 2 | Emerging | Basic close checklist exists; key reconciliations performed monthly; some JE review; close takes 15-20 days | Close checklist exists; bank and AR/AP recs monthly; JE review for material entries; 15-20 day close |
| 3 | Defined | Documented close calendar; all balance sheet accounts reconciled monthly; JE controls enforced; 10-15 day close | Close calendar; full BS reconciliation; JE approval workflow; three-way match; 10-15 day close |
| 4 | Managed | Automated close management; continuous reconciliation; automated JE controls; 5-10 day close; sub-certifications | Close management tool; automated recs; JE limits enforced; sub-certs from BU controllers; 5-10 day close |
| 5 | Optimized | Continuous close capability; real-time reconciliation; AI-assisted anomaly detection; close under 5 days | Continuous close; real-time matching; AI anomaly detection; virtual close capability; <5 day close |

**Red flags**: Monthly close takes more than 15 business days; balance sheet accounts not reconciled monthly; journal entries above $50K posted without review. [src5]
**Quick diagnostic question**: "How many business days does your monthly close take, and are all balance sheet accounts reconciled monthly?"

### Dimension 4: IT General Controls (ITGCs)

**What this measures**: The controls over IT systems that support financial reporting — access management, change management, data backup, and system operations.

| Score | Level | Description | Evidence |
|-------|-------|-------------|----------|
| 1 | Ad hoc | No formal access management; shared passwords; no change management; no system logs | Shared admin accounts; no access reviews; changes deployed without testing; no audit trail |
| 2 | Emerging | Basic access controls exist; passwords individual but not reviewed; change management informal; some logging | Individual accounts; no periodic access review; informal change process; basic logging |
| 3 | Defined | Formal access provisioning and quarterly reviews; documented change management; automated backups; audit logging enabled | Quarterly access reviews; change tickets required; automated backups; SOC-reviewed systems |
| 4 | Managed | Role-based access controls; automated provisioning/deprovisioning; formal SDLC; comprehensive audit trails | RBAC enforced; automated onboard/offboard; SDLC with UAT; complete audit trail; DR tested |
| 5 | Optimized | Zero-trust access model; continuous access monitoring; automated change validation; real-time security analytics | Zero-trust architecture; continuous monitoring; automated validation; security analytics; SOC 2 Type II |

**Red flags**: Shared admin passwords exist; terminated employees retain access for more than 24 hours; no change management process; system logs not retained or reviewed. [src4]
**Quick diagnostic question**: "How quickly is system access revoked when an employee leaves, and do you perform quarterly access reviews?"

### Dimension 5: Audit Readiness

**What this measures**: The organization's preparedness for internal or external audit — documentation, evidence retention, self-assessment, and remediation processes.

| Score | Level | Description | Evidence |
|-------|-------|-------------|----------|
| 1 | Ad hoc | No audit preparation; evidence gathered reactively; prior audit findings not tracked; no internal audit function | Audit prep is firefighting; prior findings not tracked; evidence pulled during audit; no internal audit |
| 2 | Emerging | Basic audit preparation 2-4 weeks before audit; prior findings partially addressed; documentation gaps exist | Pre-audit prep occurs; some findings remediated; documentation incomplete; no PBC list maintained |
| 3 | Defined | Year-round audit readiness; PBC list maintained; prior findings fully remediated; control self-assessments performed | PBC list current; findings tracked to remediation; annual control self-assessment; evidence retained |
| 4 | Managed | Continuous audit readiness; automated evidence collection; internal audit function; remediation tracked with SLAs | Automated evidence; internal audit team; finding remediation SLAs; management testing program |
| 5 | Optimized | Audit-ready continuously; AI-assisted control testing; predictive issue identification; zero repeat findings | AI-assisted testing; zero repeat findings; predictive analytics; continuous assurance platform |

**Red flags**: Prior audit findings recur year after year; evidence is scrambled together during audit; no internal audit function exists at a company with $50M+ revenue; material weaknesses reported. [src1]
**Quick diagnostic question**: "How many of last year's audit findings have been fully remediated, and do you maintain a year-round PBC list?"

## Scoring & Interpretation

### Overall Score Calculation

All five dimensions are weighted equally. For private companies not subject to SOX, Dimension 4 (ITGCs) can be de-weighted to 0.5x.

```
Overall Score = (Control Environment + SoD + Close Controls + ITGCs + Audit Readiness) / 5
Private company variant = (Control Env + SoD + Close Controls + ITGCs × 0.5 + Audit Readiness) / 4.5
```

### Score Interpretation

| Overall Score | Maturity Level | Interpretation | Recommended Next Step |
|---------------|---------------|----------------|----------------------|
| 1.0 - 1.9 | Critical | Major control deficiencies exist — material weakness likely if audited | Engage external advisor for urgent control remediation; not ready for any audit |
| 2.0 - 2.9 | Developing | Significant gaps in controls; suitable for private companies but not for public reporting | Document key controls, implement SoD matrix, formalize close process |
| 3.0 - 3.9 | Competent | Controls adequate for most private companies; pre-IPO readiness requires 6-12 months of improvement | Automate control testing, implement GRC tool, build internal audit capability |
| 4.0 - 4.5 | Advanced | SOX-compliant control environment; suitable for public company reporting | Optimize with continuous monitoring and AI-assisted testing |
| 4.6 - 5.0 | Best-in-class | Leading control environment; audit is a formality, not a risk | Maintain through continuous improvement and benchmark externally |

### Dimension-Level Action Routing

| Weak Dimension (Score < 3) | Fetch This Card |
|----------------------------|-----------------|
| Control Environment | Review financial-metrics-benchmarks for governance KPI targets |
| Segregation of Duties | Review accounts-payable-receivable-diagnostic for transaction controls |
| Financial Close | Review fpa-maturity-assessment for reporting process improvement |
| IT General Controls | Review revenue-operations-assessment for system integration controls |
| Audit Readiness | Review financial-controls-compliance-assessment remediation guidance |

## Benchmarks by Segment

| Segment | Expected Average Score | "Good" Threshold | "Alarm" Threshold |
|---------|----------------------|-------------------|-------------------|
| Private (<$75M revenue) | 2.0 - 2.5 | > 3.0 | < 1.5 |
| Private (>$75M, pre-IPO) | 2.5 - 3.0 | > 3.5 | < 2.0 |
| Newly Public (first 2 years) | 3.0 - 3.5 | > 4.0 | < 2.5 |
| Mature Public Company | 3.5 - 4.5 | > 4.0 | < 3.0 |

[src1, src6]

## Common Pitfalls in Assessment

- **Documentation vs. execution gap**: Having a policy manual does not mean controls are operating effectively. Auditors test both design and operating effectiveness — assess whether controls are actually performed, not just documented. [src1]
- **IT control underestimation**: Companies consistently under-invest in IT general controls, leading to the most common audit findings. PCAOB inspections in 2024 flagged ITGCs as the top deficiency area across all firm sizes. [src4]
- **Compensating control over-reliance**: Using compensating controls for SoD violations is acceptable short-term but should not become permanent. More than 5 compensating controls for SoD suggests the system configuration needs fixing. [src3]
- **Audit readiness timing**: Starting SOX readiness 6 months before IPO is too late. Best practice is 12-18 months of pre-readiness plus a full year of operating effectiveness before the first 404 filing.

## When This Matters

Fetch when a user asks about SOX readiness, internal control assessment, audit preparedness, segregation of duties evaluation, IPO readiness from a controls perspective, or diagnosing why audit findings keep recurring.

## Related Units

- [FP&A Maturity Assessment](/finance/financial-ops/fpa-maturity-assessment/2026)
- [Revenue Operations Assessment](/finance/financial-ops/revenue-operations-assessment/2026)
- [Accounts Payable & Receivable Diagnostic](/finance/financial-ops/accounts-payable-receivable-diagnostic/2026)
- [Financial Metrics Benchmarks](/finance/financial-ops/financial-metrics-benchmarks/2026)
