Across 14 process areas
Operating effectiveness tested
1 significant · 2 control
Subject to sig. def. remediation
Control scoping, design assessment, operating effectiveness testing, deficiency classification, and management opinion — all traceable from regulatory requirement to test evidence.
Define the ICFR scope by financial statement cycle and assertion — with COSO-aligned control descriptions, owner assignments, and a full audit trail of scope decisions.
Test whether each key control is designed to achieve its objective and whether it operated effectively throughout the period — with structured workpapers and evidence requirements for every test.
Classify deficiencies as control deficiency, significant deficiency, or material weakness — and produce the management assessment that satisfies your regulatory and external auditor requirements.
Design effectiveness, operating effectiveness, deficiency management, and management opinion — with the audit trail that makes every conclusion defensible.
Define in-scope key controls by financial statement assertion, COSO principle, and risk of material misstatement — with entity-level and process-level controls maintained in a structured matrix.
Document and assess whether each control is designed to prevent or detect material misstatements — with walkthroughs, process documentation, and design assessment conclusions retained as workpapers.
Execute test programmes with statistically or risk-based sample sizes, record results at the item level, and flag exceptions automatically for deficiency assessment — for both management and external auditor reliance.
Classify each control failure as a control deficiency, significant deficiency, or material weakness — with the severity assessment documented and escalated to management and the audit committee.
Produce the management assessment on ICFR effectiveness — aligned to ADAA ICFR requirements, SOX Section 404, and CMA Corporate Governance standards — with full evidence traceability.
Compile the complete workpaper package — test results, sample documentation, deficiency assessments — in the format required for external auditor reliance, reducing duplication and audit costs.
Three screens — the controls testing register your ICFR team executes from, the workpaper your testers document in, and the assurance dashboard your audit committee relies on.
Every in-scope control — its COSO mapping, test method, sample size, test result, and deficiency classification — in one view for the ICFR programme lead.
The detailed test record for a significant deficiency — test steps, sample items, exception documentation, and deficiency assessment conclusion — all in one defensible workpaper.
The view your audit committee receives — ICFR opinion, deficiency pipeline, testing completion by process area, and trend year over year.
Identify key controls by financial statement assertion and material misstatement risk — aligned to COSO principles and in-scope for your regulatory requirements.
Perform walkthroughs and documentation review for each key control — concluding on whether it is designed to prevent or detect material misstatement.
Execute structured test procedures with risk-based or statistical samples — documenting results at the item level and flagging exceptions for immediate deficiency assessment.
Assess each exception and classify as a control deficiency, significant deficiency, or material weakness — with severity rationale documented and escalated.
Produce the management assessment of ICFR effectiveness — with full evidence traceability from testing to opinion — ready for regulatory submission and external auditor reliance.
Full traceability from financial statement assertion to test evidence to opinion — no gaps
COSO 2013-aligned control matrix with entity-level and process-level controls managed together
Test workpapers that satisfy both management assessment requirements and external auditor reliance standards
Deficiency classification and escalation built in — material weakness never surprises the audit committee
ADAA ICFR, SOX 404, and CMA CG requirements pre-mapped — no custom configuration required
© 2026 Falconry360 . All rights reserved.