SOX & ICFR Advisory
Management owns ICFR. We help make it defensible.
RCM development, remediation, 404(a) readiness and SOX programme build for US-listed, pre-IPO and UK-listed companies.
Regulatory context
The assurance layer is thinning on both sides of the Atlantic.
In the US, the SEC has proposed raising the large accelerated filer threshold to $2 billion in public float. On the SEC’s own estimate, 80.8% of reporting companies would become non-accelerated filers and fall outside the Section 404(b) auditor attestation. Management’s obligation to assess ICFR under Section 404(a) does not change. The proposal is not final.
In the UK, Provision 29 of the UK Corporate Governance Code requires boards to declare whether material controls were effective at the balance sheet date, for financial years beginning on or after 1 January 2026. The FRC has stated that the financial statement audit opinion does not cover that declaration.
Fewer auditors testing. The same responsibility to conclude.
Where this leaves managementCurrent as at 23 September 2026.
14 financial reporting process areas
End-to-end SOX lifecycle methodology
Published 2026 practitioner handbook
See what we produceServices
Where we start
You disclosed a material weakness
You need to conclude on ICFR without an auditor testing it
Your risk and control matrix won’t survive scrutiny
You’re building a SOX programme for the first time
Your board has to declare on material controls
How we work
Why Ditton
Practitioner-built.
Methodology and materials developed from inside real SOX programmes — not generic GRC implementation.
Fixed-scope.
Clear deliverables, clear boundaries and clear commercial terms before work begins.
Evidence-first.
Every engagement is designed around what management needs to support its ICFR conclusion.
No software to buy. No multi-year transformation programme.
Deliverables
What the work looks like
The artefacts a Ditton engagement produces, and why each one exists.
Risk and Control Matrix extract
The backbone of the programme: each risk mapped to its assertions, the key control that addresses it, and the attributes needed to test it.
Deficiency evaluation memo
Documents the severity assessment of a control exception, including aggregation and compensating controls, and the basis for classification.
Audit committee reporting extract
Summarises ICFR status and deficiencies in the form an audit committee needs to exercise oversight.
Methodology
The SOX lifecycle, end to end
A 13-stage lifecycle from scoping to the management assessment, with business process and IT workstreams running in parallel.
Plan
- 01Planning & scoping
- 02Entity-level controls
Business process track
- 03Risk assessment
- 04Control identification & RCM build
- 06Control documentation
- 07Walkthroughs (test of design)
- 08Sample selection
- 09Testing (operating effectiveness)
IT track
- 05IT scoping
- —ITGC testing by your IT audit function or a specialist provider
Both tracks feed deficiency evaluation.
Conclude
- 10Deficiency evaluation
- 11Remediation
- 12Management assessment
- 13Reporting & external audit support
Library & Books
The same material our engagements are built from.
RCM Library
Practitioner-built RACMs covering the core financial reporting processes of a SOX programme, released process by process.
SOX Execution Kit
An Excel workbook linking controls, tests, deficiencies and remediation through shared IDs.
The SOX Compliance Handbook, 2026 Edition
Book 1 of The SOX Lifecycle Series.