  • Company A has three operating divisions.
    Division 1 has centralized financial processing.
    Division 2 has multiple locations each with similar functions and each having unique financial processing systems.
    Division 3 has multiple locations each with similar functions and similar processing systems established by the HQ office of Division 3.
    Division 3 is material to Company A. None of Division 3’s multiple financial processing locations is individually material to Company A or to Division 3. Controls need to be tested for Division 3 for SOX purposes.
    How would you approach controls testing in Division 3? If a tested key control failed at only one of Division 3’s financial processing locations, would that be considered a control deficiency? What if the same control failed at 3 of 10 financial processing locations? Would that be 1 or 3 control deficiencies?
    Would your answer differ if the same fact pattern was applied to Division 2?
    I have my own opinion, but I want to hear your point of view before I reveal my thoughts.

  • Since you say Div. 3’s locations all have similar functions and processing systems, then we would consider it one cycle and they would likely have the same control activities at each location. I would pick a sample of locations to test. If a control failed at more than one location (or 3 out of 10), then we would consider it 1 deficiency (but all 3 locations would share responsibility for the remediation plan).
    For Div. 2, since they have unique financial processing systems, we would likely consider each of those to be separate SOX cycles. For example, if Div. 2 had a warehouse in Texas and a warehouse in Oklahoma and they used totally different inventory management systems, then we might have Sox cycle called ‘Texas Inventory’ and one called ‘Oklahoma Inventory’ and the control activities, narratives, etc. could be different. And in that case you could have deficiencies for each location. Of course, we would also do a scoping exercise and some locations might not warrant being a SOX cycle due to immateriality.

