The 23 controls
For growth groups that do not yet need full SOX-style ICFR but want a defensible control environment — pre-IPO, ahead of a Series-C audit, or in advance of investor due diligence — there is a defensible floor. We call it the 23. Every control is observable, testable, and tied to a specific financial-statement assertion.
Revenue (6 controls)
- Order-to-cash three-way match
- Credit-limit approval threshold
- Revenue recognition cut-off review
- Customer master-data segregation
- Sales-return authorisation
- Period-end revenue reconciliation
Procure-to-pay (6 controls)
- Purchase-order approval matrix
- Goods-receipt-to-invoice match
- Vendor master-data dual control
- Payment-run authorisation
- Accrual cut-off review
- Quarterly vendor reconciliation
Close (5 controls)
- Journal-entry review threshold
- Balance-sheet reconciliation sign-off
- Intercompany matching
- Period-end accrual checklist
- Management review of the trial balance
Access and IT (3 controls)
- User-access review (quarterly)
- Privileged-access logging
- Change-management approval for financial systems
Treasury and tax (3 controls)
- Bank-reconciliation review
- Tax-position memo for each material judgement
- Cash-flow forecast variance review
What the 23 are not
They are not a SOX framework. They are not a substitute for ICFR for a listed entity. They are the floor that lets management sign a meaningful control representation, lets an auditor rely on controls rather than testing everything substantively, and lets an investor diligence team finish in two weeks rather than six.
