Data subject access request: one month, everything you hold, no charge
A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.
Sarbanes-Oxley is short. What consumes a finance team is proving that controls operated all year — and proving it with records made at the time.
SOX compliance is the work a public company does to satisfy the Sarbanes-Oxley Act: management asserts that internal control over financial reporting is effective, and — above a size threshold — the external auditor attests to that assertion. The law is short. The programme built to satisfy it is not.
The distinction that decides how expensive a year becomes is between having controls and being able to evidence them. A control that operated every month but left no dated artefact is, for SOX purposes, a control that cannot be tested — and a control that cannot be tested is a deficiency waiting to be written up.
In practice most findings are not clever. Reviews performed without any record of what was reviewed. Access that was never removed when someone changed role. Journals posted and approved by the same person. Spreadsheets central to a number, with no version control and no check on their formulas. Controls that were redesigned mid-year with nobody updating the documentation.
The common thread is that each is a documentation failure at least as much as a control failure. The work happened, or mostly happened; what is missing is the record proving it happened when the tester needs it to have happened.
Evidence created after the fact rarely survives contact with a tester, because it is dated after the fact. Design each control so the artefact is produced when the control runs — an approval that records who and when, a reconciliation that is signed on completion, an access review with the list attached.
Ettex is not a SOX platform and does not test controls — that work belongs to people. What Ettex Records holds is the evidence layer: the process documentation with its version history, the reviews and their sign-offs, the artefacts each control produced, filed against the control rather than in an inbox. When the tester asks for the June approval, it is retrieved rather than reconstructed. The internal controls themselves still have to be designed and operated by the business.
SOX programmes tend to grow: more controls, more testing, more documentation, without anyone asking whether the added control addresses a real risk to the financial statements. A programme with three hundred key controls in a mid-cap company is usually not more assured than one with eighty — it is more expensive and less well performed.
Companies with securities registered in the United States, including many foreign private issuers. Requirements differ by filer status: smaller reporting companies and non-accelerated filers face management assertion without an auditor attestation on ICFR.
Section 302 requires officers to certify the accuracy of each periodic report and the effectiveness of disclosure controls. Section 404 requires an annual management assessment of internal control over financial reporting, with auditor attestation for larger filers.
A deficiency, or combination of deficiencies, such that there is a reasonable possibility a material misstatement would not be prevented or detected on a timely basis. It is a severity conclusion, not a category of error.
Not legally, but companies preparing for an IPO or an acquisition by a public company build the programme in advance, because the first year of readiness is the longest one.
A DSAR is not a support ticket. The clock starts on receipt, the scope is everything, and the exemptions are narrower than most teams assume.
The SoA lists every Annex A control, whether you apply it, and why. It is the map between your risk assessment and everything else in the certificate.
Access accumulates. A user access review is the periodic check that every permission still has a reason — and the record proving someone looked.