Build a SOX program your auditors and audit committee can trust.
RADD’s specialists scope, document, and test internal control over financial reporting for publicly held banks and financial institutions — SOX 302 and 404, PCAOB-aligned, from control design to remediation.
When the external auditors test your controls, gaps become material weaknesses.
Most finance teams at publicly held institutions are stretched — a controller and a small team owning the close, the disclosures, and SOX all at once. Control documentation drifts, key controls go untested, and evidence is scattered.
Where SOX programs break down:
- Control documentation drifts between reporting cycles.
- Key controls go untested.
- Evidence is scattered across teams and systems.
- A simple gap escalates into a significant deficiency.
Then the external audit arrives, a control fails, and a simple gap escalates into a significant deficiency or a material weakness — one that lands in your filings and in front of the audit committee.
You shouldn’t have to run SOX on top of the close.
RADD has sat in your seat. Our consultants have built and tested SOX programs, worked alongside external auditors within the PCAOB framework, and remediated control failures under deadline. We bring that experience to your team — documenting the controls, running the testing, and giving your auditors and audit committee a program they can rely on.
- Built and tested SOX programs from the ground up.
- Worked alongside external auditors inside the PCAOB framework.
- Remediated control failures under deadline.
- Given audit committees a program they can rely on.
The R.A.D.D. Compliance Confidence Framework™
You shouldn’t have to figure out where to start. Our four-step framework turns regulatory uncertainty into a clear path forward — built around your institution’s size, business lines, and risk profile.
Reveal Risks
We uncover the regulatory gaps, operational risks, and audit vulnerabilities specific to your institution through a proactive compliance assessment — before an examiner finds them first.
Align & Analyze
We benchmark your current compliance posture against examiner expectations and board priorities, including emerging risks like crypto, fintech partnerships, IT compliance, and privacy laws (CCPA/GLBA).
Design Your Compliance Roadmap
You get a customized, board-ready roadmap with priorities, timelines, resource recommendations, and predictive strategies to eliminate future findings — not just the ones you already know about.
Deliver & Defend
We execute the roadmap alongside your team — through tailored audit engagements or our RADD Assist subscription — and stand with you in front of examiners, the audit committee, and the board.
Full-scope SOX compliance support.
Consulting & program build
- SOX scoping and risk assessment
- ICFR documentation and narratives
- Risk-and-control matrices (RCM)
- Section 302 and 404 readiness
- Control design evaluation
- Entity-level and IT general controls
- Deficiency evaluation and remediation
- External-auditor coordination
Independent testing & audit
- SOX control testing and walkthroughs
- Operating-effectiveness testing
- Key-control and sample testing
- IT general controls (ITGC) testing
- Management testing support
- Audit committee reporting
- Corrective-action tracking
What “handled” looks like.
It looks like controls that are documented, tested, and evidenced; deficiencies caught and closed before the external audit; and a clean SOX story your auditors and audit committee can stand behind. RADD carries the SOX workload your finance team can’t absorb, quarter after quarter.
Why Clients Rely on RADD LLC
Frequently asked questions
Who is this for?
CFOs, controllers, internal audit leaders, and audit committees at publicly held banks, holding companies, and financial institutions subject to SOX.
Can you help if we’re approaching our first SOX year?
Yes. First-year SOX readiness — scoping, documentation, and initial testing — is core to what we do, and we can start well ahead of your auditor’s timeline.
Do you test controls as well as document them?
Yes — and when independence matters, we scope testing separately from documentation work so your results stay objective.
Do you coordinate with our external auditors?
Yes. We align our documentation and testing to what your external auditors and the PCAOB framework expect, so the reliance work goes smoothly.
Let’s pressure-test your SOX controls before the auditors do.
Book a 30-minute call. We’ll walk through where your SOX risk really sits — and what it takes to close the gaps.