Build a SOX program your auditors and audit committee can trust.

RADD’s specialists scope, document, and test internal control over financial reporting for publicly held banks and financial institutions — SOX 302 and 404, PCAOB-aligned, from control design to remediation.

When the external auditors test your controls, gaps become material weaknesses.

Most finance teams at publicly held institutions are stretched — a controller and a small team owning the close, the disclosures, and SOX all at once. Control documentation drifts, key controls go untested, and evidence is scattered.

Then the external audit arrives, a control fails, and a simple gap escalates into a significant deficiency or a material weakness — one that lands in your filings and in front of the audit committee.

You shouldn’t have to run SOX on top of the close.

RADD has sat in your seat. Our consultants have built and tested SOX programs, worked alongside external auditors within the PCAOB framework, and remediated control failures under deadline. We bring that experience to your team — documenting the controls, running the testing, and giving your auditors and audit committee a program they can rely on.

A clear path to a defensible SOX program.

Step 1

Assess

We scope your SOX program against the risks that matter — mapping significant accounts and processes, evaluating control design, and identifying where documentation or testing falls short.

Step 2

Build

We build the control documentation, narratives, and testing framework that hold up — risk-and-control matrices, process walkthroughs, and evidence your external auditors can rely on.

Step 3

Defend

When testing turns up an exception, we’re there — evaluating deficiencies, driving remediation, and coordinating with your external auditors so issues get resolved, not reported.

Full-scope SOX compliance support.

Consulting & program build

Independent testing & audit

What “handled” looks like.

It looks like controls that are documented, tested, and evidenced; deficiencies caught and closed before the external audit; and a clean SOX story your auditors and audit committee can stand behind. RADD carries the SOX workload your finance team can’t absorb, quarter after quarter.

Frequently asked questions

CFOs, controllers, internal audit leaders, and audit committees at publicly held banks, holding companies, and financial institutions subject to SOX.

Yes. First-year SOX readiness — scoping, documentation, and initial testing — is core to what we do, and we can start well ahead of your auditor’s timeline.

Yes — and when independence matters, we scope testing separately from documentation work so your results stay objective.

Yes. We align our documentation and testing to what your external auditors and the PCAOB framework expect, so the reliance work goes smoothly.

Let’s pressure-test your SOX controls before the auditors do.

Book a 30-minute call. We’ll walk through where your SOX risk really sits — and what it takes to close the gaps.