Book a consultation

Call (607) 555-0142

Email hello@hudsonfrs.com

Service 04: Compliance

Regulatory compliance & internal controls

Controls sized for the business you are now, not the one you were at founding, and not a Fortune 500 framework bolted onto a team of twelve. Documented well enough that they survive the person who designed them leaving.

At a glance

  • Assessment: 4 to 6 weeks
  • Remediation: 1 to 2 quarters typical
  • Frameworks: COSO, SOC 1, SOC 2, SOX readiness
  • Cycles covered: revenue, purchasing, payroll, treasury, close
  • Fee: fixed project fee after scoping
Fit

Who this is for

  • One person can do everything. Set up a vendor, approve the invoice, release the payment and reconcile the bank. Nobody would catch it.
  • Your last audit produced a management letter. With observations you have not remediated, which will reappear this year unless something changes.
  • A customer is asking for a SOC report. Procurement has made it a condition of renewal and you have ninety days.
  • You have doubled in size. The controls were designed for twelve people and you now have sixty, across three locations.
  • Your compliance calendar is one person's inbox. Nobody else knows what is due, to whom, or when.
Outcomes

What good looks like

Controls are not paperwork. A control that exists only in a binder has failed by definition: the test is whether it changes what happens on a Tuesday.

No single point of failure

No individual can both cause a misstatement and conceal it. Where full segregation is impossible, a documented compensating control closes the gap.

The process outlives the person

Written procedures with named roles rather than named individuals, so a resignation is an inconvenience rather than an operational crisis.

Obligations have owners

A single compliance calendar covering tax, payroll, licensing, insurance, registration and reporting: each item with an owner, a lead time and a visible status.

Scope

What's included

Assessment first, always. We will not design controls for a business we have not walked through, because the controls that exist on paper and the controls that operate are rarely the same set.

01

Control environment assessment

Process walkthroughs across the revenue, purchasing, payroll, treasury and financial close cycles, documenting the controls that actually operate, including the informal ones nobody wrote down and the formal ones nobody performs.

02

Segregation of duties matrix

A role-by-function matrix tested against real system access rather than the org chart, identifying every incompatible combination (authorization, custody, record-keeping and reconciliation) and where a compensating control is required.

03

Control design & remediation

Controls designed to the actual size and risk of the business, with the specific system configuration, approval threshold or procedural change needed to implement each one, not a generic framework you will quietly abandon in six weeks.

04

Policy & procedure frameworks

Written policies covering expenditure authority, travel and expense, purchasing, cash handling, journal entry approval, system access and change management, credit and collections, and conflict of interest, in language your team will actually read.

05

Managed compliance calendar

A single register of every recurring obligation (tax, payroll, sales tax, information returns, annual reports, licenses, insurance renewals, registrations and covenant reporting) with owners, lead times and status visible to leadership.

06

SOC 1 & SOC 2 readiness

Gap assessment against the relevant trust services criteria or control objectives, remediation planning, evidence and artefact preparation, and support through the service auditor's examination. We prepare you for the report; an independent firm issues it.

07

SOX readiness

For companies approaching an IPO, held by a private equity sponsor with a portfolio standard, or being acquired by a public filer: building a Section 404-capable control environment and documentation set ahead of the requirement rather than in response to it.

08

Ongoing control testing

Periodic independent testing that the controls still operate as designed, with results reported to leadership or the board. Controls decay quietly, through system changes, staff turnover and workarounds adopted under deadline pressure.

What this does not include

Cybersecurity penetration testing and technical IT security assessment (we assess IT general controls, and will refer you to specialist security firms for the technical work), legal compliance opinions, and issuing the SOC report itself: the service auditor examination must come from an independent firm.

Priorities

Where we look first

You cannot run a forty-control framework with nine people. These are the seven that prevent most of the damage in a small or mid-sized business, in the order we test them.

The seven priority internal controls and the exposure each addresses
# Control Exposure it closes
01Independent bank reconciliation reviewWhoever reconciles the bank should not also authorize payments. An owner or board member reviewing the completed reconciliation catches most diversion.
02Vendor master change controlAdding or amending a vendor (especially bank details) requires a second approver. This is the single most exploited weakness in payment fraud.
03Dual authorization above a thresholdPayments over an agreed amount need two approvals. Set the threshold where it bites without paralysing operations.
04Purchase approval before commitmentApproval at the point of order rather than at the point of invoice. Approving an invoice for goods already received is not a control.
05Payroll change reviewNew starters, leavers and pay rate changes reviewed against HR records by someone outside payroll. Ghost employees survive precisely where this is absent.
06Journal entry reviewManual journals above a threshold, and all journals posted after close, reviewed and approved. Most financial statement manipulation happens through manual journals.
07System access reviewQuarterly review of who has access to what, with prompt removal on departure. Access accumulates over careers and is almost never revoked.

The full reasoning behind each is set out in Internal Controls for Small Businesses: The Seven That Actually Matter.

Engagement

How the engagement runs

Assessment is a fixed-fee project. Remediation and ongoing testing can be a project or a retainer, depending on whether you have the internal capacity to execute the plan yourselves.

Stage 01

Assess

Walkthroughs of every significant cycle, system access extraction, and documentation of what actually operates, producing a findings report ranking gaps by likelihood and impact.

Stage 02

Design

A remediation plan with a specific control, an owner and a date for each gap, sequenced so the highest-exposure items are closed first rather than the easiest ones.

Stage 03

Execute

Policies written, system approvals configured, thresholds set, roles reassigned and the team trained on what changed and why. Adoption is the hard part, and it is included.

Stage 04

Monitor

Periodic independent testing that controls still operate as designed, reported to leadership or the board, with re-testing of anything previously found deficient.

Sectors

Where compliance is heaviest

Some sectors carry regulatory obligations that dwarf the ordinary financial control set. These are the ones where the compliance calendar does most of the work.

Questions

Compliance & controls FAQ

It means no single person controls a transaction end to end. The four incompatible functions are authorization, custody of assets, record-keeping and reconciliation.

When one person can set up a vendor, approve an invoice, release the payment and reconcile the bank account, there is no point at which an error or a diversion would be caught by the process itself: detection depends entirely on someone happening to look. It is the most common control gap we find in businesses under fifty employees, and the one most frequently cited in occupational fraud cases.

Not completely, and pretending otherwise produces a control matrix nobody follows, which is worse than admitting the constraint.

In a small team the answer is compensating controls: an owner or board member reviews the bank statement independently of whoever reconciles it; new vendors need a second approval; payments above a threshold need dual authorization; someone outside accounting reviews the monthly close. The objective is that no single person can both cause and conceal a misstatement. That is achievable at nine people even when full segregation is not.

SOC 1 reports on controls relevant to a client's financial reporting: what a payroll processor or claims administrator provides so their clients' auditors can rely on their processing. SOC 2 reports on security, availability, processing integrity, confidentiality and privacy, and is what a SaaS or technology vendor is usually asked for in procurement.

Each comes as Type I, testing design at a point in time, or Type II, testing operating effectiveness over a period of usually six to twelve months. Most enterprise buyers want Type II, so plan for the observation window rather than assuming it can be produced in a fortnight.

Section 404 internal control reporting applies to SEC registrants, so a private company is not directly subject to it.

It becomes relevant in three situations: you are preparing for an IPO and need a control environment that will withstand scrutiny; a private equity sponsor requires SOX-equivalent controls as a portfolio standard; or you are being acquired by a public company and will be folded into their framework. In all three, the work is far cheaper done ahead of the requirement than in response to it.

For a business under 100 employees, four to six weeks: process walkthroughs across the revenue, purchasing, payroll, treasury and close cycles; documentation of the controls that actually operate rather than those written down; a segregation of duties matrix tested against real system access; and a findings report ranking gaps by likelihood and impact with a remediation plan.

Remediation itself typically runs a further one to two quarters, depending on how much of it is system change rather than process change. System change is slower but sticks; process change is faster but decays without testing.

Related services

Audit & Assurance

Control weaknesses are what produce management letter comments. Closing them beforehand is materially cheaper than being told about them afterward.

Explore

Accounting & Bookkeeping

A reliable close depends on controls that work. Most close failures we investigate trace back to a control gap rather than an accounting error.

Explore
Next step

Ask one uncomfortable question

Could one person in your business set up a vendor, approve an invoice, release the payment and reconcile the bank? If the answer is yes (or you are not certain), that is the conversation to have.