SOX & ICFR Advisory

Management owns ICFR. We help make it defensible.

RCM development, remediation, 404(a) readiness and SOX programme build for US-listed, pre-IPO and UK-listed companies.

Regulatory context

The assurance layer is thinning on both sides of the Atlantic.

In the US, the SEC has proposed raising the large accelerated filer threshold to $2 billion in public float. On the SEC’s own estimate, 80.8% of reporting companies would become non-accelerated filers and fall outside the Section 404(b) auditor attestation. Management’s obligation to assess ICFR under Section 404(a) does not change. The proposal is not final.

In the UK, Provision 29 of the UK Corporate Governance Code requires boards to declare whether material controls were effective at the balance sheet date, for financial years beginning on or after 1 January 2026. The FRC has stated that the financial statement audit opinion does not cover that declaration.

Fewer auditors testing. The same responsibility to conclude.

Where this leaves management

Current as at 23 September 2026.

14 financial reporting process areas

End-to-end SOX lifecycle methodology

Published 2026 practitioner handbook

See what we produce

How we work

Why Ditton

Practitioner-built.

Methodology and materials developed from inside real SOX programmes — not generic GRC implementation.

Fixed-scope.

Clear deliverables, clear boundaries and clear commercial terms before work begins.

Evidence-first.

Every engagement is designed around what management needs to support its ICFR conclusion.

No software to buy. No multi-year transformation programme.

Methodology

The SOX lifecycle, end to end

A 13-stage lifecycle from scoping to the management assessment, with business process and IT workstreams running in parallel.

See each stage

Plan

  1. 01Planning & scoping
  2. 02Entity-level controls

Business process track

  1. 03Risk assessment
  2. 04Control identification & RCM build
  3. 06Control documentation
  4. 07Walkthroughs (test of design)
  5. 08Sample selection
  6. 09Testing (operating effectiveness)

IT track

  1. 05IT scoping
  2. —ITGC testing by your IT audit function or a specialist provider

Both tracks feed deficiency evaluation.

Conclude

  1. 10Deficiency evaluation
  2. 11Remediation
  3. 12Management assessment
  4. 13Reporting & external audit support

Have an ICFR issue to discuss?

Start a conversation