Internal Control Advisory — ICFR and SOX Readiness
COSO-Based Control Design, Documentation and Testing — in English and Korean
We help companies design, document and test internal control over financial reporting, so management can stand behind its numbers before a parent company, an auditor, a lender or a buyer starts asking.
Most companies that call us about internal controls fall into one of three groups: US subsidiaries whose Korean parent must evaluate controls across the group, companies preparing for an IPO or new to SEC reporting, and private businesses whose lender, investors or buyer want proof that the books can be relied on. SW Accounting & Consulting Corp is a Los Angeles-based CPA firm serving clients across the United States, with much of our work in California. Every engagement is led personally by CEO Sangwon Youn (US CPA, California; KICPA) from the first consultation through delivery, with a team of associate CPAs supporting the day-to-day work. We work in English and Korean.
Do we need internal control work — and why now?
You need it when someone outside management is about to rely on your financial statements and will ask how you know they are right.
For a US subsidiary of a Korean listed group, that someone is the parent. Korea’s internal control regime for listed companies (내부회계관리제도), set under the Act on External Audit of Stock Companies, is being extended from the parent’s standalone books to the consolidated group, phased in by company size. Once a group is in scope, significant subsidiaries — often including the US operation — are pulled into the parent’s documentation, testing and external audit of internal control.
Before an IPO, the trigger is the Sarbanes-Oxley Act. For a private company it is usually commercial: a lender’s reporting covenants, an investor’s due diligence, a buyer’s quality of earnings team, or an owner who realizes that one bookkeeper controls the checkbook, the vendor list and the bank reconciliation. A month-end close where numbers keep changing after they are reported is the most common warning sign.
Which Sarbanes-Oxley requirements apply to us?
Every SEC reporting company needs management’s own annual assessment under Section 404(a); only accelerated and large accelerated filers also need an auditor’s attestation under Section 404(b).
Under Section 404 of the Sarbanes-Oxley Act and Item 308 of Regulation S-K, management must assess whether internal control over financial reporting was effective at fiscal year-end. A newly public company can omit the assessment from its first annual report, so the first one usually appears in the second — which means the controls have to be operating well before that year-end.
Section 404(b) adds an attestation by the independent auditor under PCAOB AS 2201. Non-accelerated filers are exempt by statute, and emerging growth companies are exempt while they keep that status, which can last until the end of the fiscal year following the fifth anniversary of the IPO. The SEC has proposed redrawing filer categories in a way that would widen the exemption (see our summary of the proposed filer status overhaul), so confirm where that rulemaking stands when you plan. Either way, management still assesses its controls and officers still certify the financial statements.
What framework do you work from?
The COSO 2013 Internal Control — Integrated Framework: five components and 17 principles, scaled to the size of your business.
The COSO framework is the one most US public companies use for their 404 assessment. Its five components — control environment, risk assessment, control activities, information and communication, and monitoring activities — break down into 17 principles, and an effective system needs each one present and functioning. That reaches well beyond transaction checks, to tone at the top and to how management notices when a control stops working.
Because COSO is principles-based, a company with a small finance team can meet all 17 principles with fewer, simpler controls and more direct involvement from senior management. We scale the documentation to what your auditor, parent or lender actually needs to see.
What do we actually receive?
A scoped, documented control set — risk assessment, process narratives and flowcharts, and a risk-and-control matrix — with IT controls and segregation of duties sized to your team.
We start with risk assessment and scoping: which accounts and disclosures are significant, which entities and processes feed them, and what could go wrong. Each in-scope process — typically revenue, purchasing and payables, payroll, inventory where it matters, treasury and the financial close — is documented in narratives and flowcharts, then rolled into a risk-and-control matrix that ties each risk to its control, owner, frequency and evidence.
IT general controls are handled at a practical level: who can access the accounting system and how that access is approved and removed, how system and report changes are controlled, and whether backups and automated jobs run. For a company on a cloud accounting package or a mid-market ERP, that usually means a handful of well-designed controls, not an enterprise IT program. For businesses covered by California’s cybersecurity audit rule, the access work overlaps, though the two reviews have different objectives.
For small teams, we map the segregation-of-duties conflicts that matter — one person creating vendors and releasing payments, or posting entries and reconciling the bank — and design compensating controls where splitting duties is not realistic: owner review of bank activity, approval of vendor and bank-detail changes, and independent review of reconciliations. In owner-managed businesses, this is where fraud exposure is most often reduced.
How are controls tested, and what happens when one fails?
We walk through each key control to confirm its design, test samples to confirm it operated, and grade any failure by how seriously it could misstate the financial statements.
A design walkthrough follows one transaction end to end to confirm that the documented control would catch the error it targets. Operating-effectiveness testing then samples the period and checks the evidence — the approval, the review and its follow-up, the signed-off reconciliation. A control that cannot be evidenced is treated as not performed, which is how an auditor will treat it too.
Exceptions are graded as control deficiencies, significant deficiencies or material weaknesses, using the severity concepts the SEC and PCAOB apply. Each one gets a remediation plan with an owner, a corrective action and a retest, so management can show the fix worked. Before a first 404 assessment, a dry-run year of this testing is the most reliable way to find problems while there is still time to fix them.
How does this work for a US subsidiary reporting to a Korean parent?
We document in English for your US team and auditors, prepare Korean versions for the parent’s internal control team, and build the work around the parent’s framework and calendar.
Korean groups usually send subsidiaries a control template — a risk-and-control matrix, test scripts and evidence requests — built on Korea’s own internal control framework, which follows the same COSO structure. We map your actual US processes into it rather than creating a parallel set of documentation, and we flag where a parent control assumes a system, staffing level or approval chain the US entity does not have.
Timing matters as much as content. The parent’s internal control team and its auditor set the calendar, so the first questions are when your entity comes into scope and which accounts the parent treats as significant. Your controls feed the same numbers as your monthly Korean IFRS reporting package, so we tie close, intercompany and reporting-package controls together. For a newer entity, see our guide to setting up a US subsidiary for a Korean company.
How is this different from an audit?
We help you design, document and test your controls; your external auditor stays independent and reaches its own conclusions.
This is an advisory engagement. It does not produce an audit opinion or an attestation report on your controls, and management remains responsible for its controls and its assessment of them. Our work gives management a documented basis for that assessment and gives your auditor organized evidence; the auditor decides independently how far, if at all, to use it.
Independence rules limit how far a financial statement auditor can go in designing or operating its client’s controls, which is one reason companies bring in a separate adviser. If you already have an internal audit function, in-house or outsourced, we work alongside it where it needs more capacity.
