Control Implementation for New Public Company.

Overview

  • Behunin & Associates supports the design and implementation of IT controls for an $8B revenue newly public company.
  • Address control deficiencies, documentation gaps, and segregation-of-duties concerns.

Before this project began the company had extensive control deficiencies across a wide number of applications

Our global healthcare client is a large organization with $8B in revenue that went public two years ago. Their SOX environment is complex and includes more than 50 applications. The company is managing an evolving technology environment in which new applications must meet SOX requirements, and existing systems need stronger controls, clearer documentation, or targeted remediation. Behunin & Associates supports this work by helping the organization identify control gaps, design practical solutions, and document how systems, reports, interfaces, and control activities support financial reporting.

What does the engagement cover?

We began by reviewing the IT general controls already in place and understanding which applications fall within the SOX scope. The team assessed the relationship between risks and existing controls, then identified areas where coverage was incomplete or responsibilities were unclear.

The ongoing work engagement includes user access, segregation of duties, change management, computer operations, automated and configuration controls, SOC 1 reviews, and systems development life cycle considerations. For existing applications, B&A also supports deficiency remediation and improvements to control quality.

How do we work with control owners?

B&A interviews application owners and control owners to understand how each process operates, what evidence is retained, and whether the control addresses the intended risk. Where gaps exist, the team helps design and implement controls that are practical for the business to operate and suitable for audit testing.

The engagement also includes validating control narratives, updating documentation where necessary, and supporting discussions with internal and external auditors about control design, scope, and evidence.

What documentation is developed?

We help identify and document IT general and application controls, system interfaces, and other IT dependencies that affect financial reporting. This includes mapping how information moves between systems, identifying reports used in financial processes, and clarifying which controls support the completeness and accuracy of that information.

What value does our work bring to the client?

This ongoing engagement gives our client a more consistent approach to managing IT controls across its SOX environment. Control owners have clearer responsibilities, documentation more accurately reflects actual processes, and identified gaps are addressed through targeted implementation or remediation.

Behunin & Associates helps organizations build practical IT controls that align with system risks and support long-term SOX compliance. Contact us to discuss control implementation, remediation, or readiness support for your technology environment.

← All Client Successes