SOX and J-SOX Compliance
Internal control assessments, risk management and audits.
Request an initial assessmentSOX and J-SOX require companies listed in the US and Japan, and their subsidiaries, to show that internal controls over financial reporting work.
We provide tailored solutions for compliance with SOX and J-SOX requirements, including internal control assessments, risk management and audits. Our expertise improves transparency, reduces financial risk and strengthens corporate governance.
What it covers
- Scoping and risk assessment
- Documentation of processes and key controls
- IT general controls (access, change, operations)
- Testing of control design and operation
- Remediation plan for deficiencies
- Support during the external audit
Frequently asked questions
SOX and J-SOX Compliance
Does SOX affect us as a company in Albania?
Not directly, but it can through your group. Subsidiaries and significant suppliers of companies that report under SOX or J-SOX usually have to document and test their own controls.
What are IT general controls?
They are the controls over the systems that support financial reporting: who has access, how changes are approved, and how data is protected and recovered. Without them, other controls cannot be relied on.
How does SOX relate to a SOC 1 report?
When part of the financial process is performed by an outside provider, that provider's SOC 1 report is used as evidence for its controls. We cover both sides.
Services
Other services
ESG and Sustainability Reporting
ESG risk assessments, GRI and SASB reporting, and climate strategy.
Learn moreIT Strategy and Service Management
IT strategy, COBIT 2019, ITIL, ISO 20000 and technology adoption advisory.
Learn moreLaw 124 and GDPR Compliance
Data mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.
Learn moreData Protection Officer (DPO)
Outsourced DPO: advice, monitoring and a contact point for the Commissioner.
Learn moreISO 27001 Implementation and Audit
ISMS design, risk management, Annex A controls and certification support.
Learn moreSOC 1, SOC 2 and SOC 3 Reports
Attestation, readiness and training ahead of the engagement.
Learn moreLet's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
