Back to all briefings
/ GOVERNANCE 08 Apr 2026 · 7 min read

SOX-lite for growth groups: the controls that actually matter.

The 23 controls we install on day one. Everything else is optional and most of it is overhead.

The 23 controls

For growth groups that do not yet need full SOX-style ICFR but want a defensible control environment — pre-IPO, ahead of a Series-C audit, or in advance of investor due diligence — there is a defensible floor. We call it the 23. Every control is observable, testable, and tied to a specific financial-statement assertion.

Revenue (6 controls)

  • Order-to-cash three-way match
  • Credit-limit approval threshold
  • Revenue recognition cut-off review
  • Customer master-data segregation
  • Sales-return authorisation
  • Period-end revenue reconciliation

Procure-to-pay (6 controls)

  • Purchase-order approval matrix
  • Goods-receipt-to-invoice match
  • Vendor master-data dual control
  • Payment-run authorisation
  • Accrual cut-off review
  • Quarterly vendor reconciliation

Close (5 controls)

  • Journal-entry review threshold
  • Balance-sheet reconciliation sign-off
  • Intercompany matching
  • Period-end accrual checklist
  • Management review of the trial balance

Access and IT (3 controls)

  • User-access review (quarterly)
  • Privileged-access logging
  • Change-management approval for financial systems

Treasury and tax (3 controls)

  • Bank-reconciliation review
  • Tax-position memo for each material judgement
  • Cash-flow forecast variance review

What the 23 are not

They are not a SOX framework. They are not a substitute for ICFR for a listed entity. They are the floor that lets management sign a meaningful control representation, lets an auditor rely on controls rather than testing everything substantively, and lets an investor diligence team finish in two weeks rather than six.

/ FW GLOBAL CONSULTING

If this briefing raises a question on your file, we are glad to take it on a call.