Continuous SOX Controls Monitoring — Not Once-A-Quarter Sampling.
Most SOX testing still reviews 25 to 60 transactions a quarter and lets the rest of the population go unseen. VeraStream runs the same eight production detectors against every transaction your business posts — policy, duplicate, anomaly, and vendor risk — so a control failure is surfaced the day it lands, not three months later.
Why quarterly sampling is no longer enough
Three gaps your current SOX 404 testing already has
Quarterly sampling leaves a blind spot
Standard sampling-based tests of internal controls over financial reporting — per AICPA AU-C 530 and PCAOB AS 2315 — typically test 25 to 60 items regardless of population size. The vast majority of the population is never reviewed by a human, so a single fraudulent or off-policy transaction has only a small chance of landing inside the sample.
Source: AICPA AU-C 530 / PCAOB AS 2315
Manual walkthroughs absorb internal audit capacity
Protiviti’s Internal Audit Capabilities and Needs Report consistently finds that process-level walkthroughs and control re-performance consume a large, persistent share of internal audit hours — and that’s hours your team is not spending on higher-judgment substantive testing of your ICFR.
Source: Protiviti Internal Audit Capabilities and Needs Report
A material-weakness disclosure is expensive
Public companies that disclose a material weakness in ICFR under SOX 404(b) typically face multi-million-dollar remediation, restatement, and lost-market-cap costs — and an extended period of elevated control risk while controls are re-papered and re-tested.
Detector → SOX control objective mapping
How VeraStream maps to the control objectives your ICFR assessment tests
Eight production detectors, run continuously against every transaction. The same logic that surfaces a control failure mid-cycle also produces the workpaper — the receipt, the rule that tripped, the override applied. Test it on your own ledger at /audit or browse /pricing to see what continuous ICFR monitoring costs at your spend level.
| Detector | SOX Control Objective | Sample Finding |
|---|---|---|
evaluatePolicy | Segregation of duties / approval-matrix gap — invoice bypasses required approver chain | Travel to a banker posted with no manager-of-record sign-off — held until approved. |
findDuplicateInvoices | Completeness & accuracy of disbursements — same vendor paid twice under typosquatted IDs | Same vendor, same amount, two invoice numbers within 48 hours — payments held for review. |
detectExpenseAnomalies | Existence & occurrence — one cardholder, two closenames, same weekend | Same employee, same merchant category, weekend booking — flagged for confirmation alongside an unrelated meal entry. |
detectVendorRisk | Authorization of new vendors — typosquat / unapproved payee / shell-vendor heuristic | New vendor whose name is a near-miss of an approved master-data vendor — typosquat risk held for approval. |
detectThresholdGaming | Threshold-evasion / sub-approval structuring — payments split below approval tier | $18,400 × 2 to the same vendor within 3 hours — each below the $25,000 approver threshold, flagged as threshold gaming. |
detectRoundDollar | Round-dollar disbursements / script patterns — first-seen vendors under 30 days | $50,000 wire to a vendor first-seen 11 days prior — no cents, same memo template as the prior batch — flagged as round-dollar. |
detectGhostEmployee | Ghost-employee / SOD weakness — new vendor on a new approver in the same week as a master-data change | A new vendor was added to the master and a new approver was granted sign-off rights within the same 48-hour window — flagged as ghost employee. |
detectDuplicatePayment | Same vendor paid twice in a short window — recurring SaaS/rent and refund reversals auto-suppressed | Two $25,000 wires to Northwind Industrial on consecutive days — flagged as exact duplicate cluster. |
Frequently asked
Common questions from SOX and internal-audit teams
What the agent does for continuous SOX internal controls monitoring and ICFR testing — plain HTML answers, no JavaScript required to read.
How does continuous SOX internal controls monitoring work?
The same eight production detectors — evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — run on every transaction. The ICFR tests run against every transaction your business posts, not a 25-to-60-item quarterly sample. A control failure surfaces the day the second payment queues — the same workpaper (receipt, rule, override) is produced at the moment of flag, so your internal audit team can address the finding before the period closes rather than after.
How does this fit SOX 404(b) and the ICFR assessment?
VeraStream runs the exact same control logic on every transaction instead of the conventional 25-to-60-item quarterly sample. Every flagged transaction ships with a timestamped workpaper (the receipt, the rule that tripped, the override applied) that maps to the control objectives your Section 404(b) assessment tests — your external auditor keeps the sign-off, you keep the steady-state assurance. The same eight production detectors — evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — run on every transaction.
Which ERPs and card feeds do you connect to for SOX controls monitoring?
Live deploys use pre-built connectors to NetSuite, SAP, Oracle, Coupa, Concur, Expensify, Brex, and Ramp. New payments and invoice postings stream into the ICFR audit in real time. The same eight production detectors — evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee — run on every transaction. If your ERP is a different platform, the /audit page lets you drop a CSV of the ledger and see the same detectors run in the browser — no integration required. For the connector target list and the progressive tier-by-tier rollout of each one, see /integrations.
What does the workpaper for a flagged SOX control look like?
Every flag ships a workpaper: the receipt (the original transaction, the duplicate or anomaly that triggered the flag, the payment that was held), the rule that tripped (the detector name and the threshold or heuristic that fired — one of evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee), and any override applied. Sized to PCAOB AS 2315 — your external auditor receives the same evidence package they would demand from a manual control test, but produced continuously rather than once a quarter.
How long does a baseline ICFR scan take — and what does it cost?
A baseline scan against a full ledger returns flagged findings in under 90 seconds in the browser. A monitored live deployment — connectors to the ERP and card feed, evaluatePolicy, findDuplicateInvoices, detectExpenseAnomalies, detectVendorRisk, detectThresholdGaming, detectRoundDollar, detectDuplicatePayment, detectGhostEmployee running continuously, with weekly finding roll-ups — typically launches within two weeks of data access. Use /pricing to see what continuous ICFR monitoring costs at your spend level.
Test it on your own ledger
Stop testing 25 transactions a quarter
Drop a CSV in the in-browser audit, or book a walkthrough and run VeraStream against your actual SOX-relevant spend — no quarterly sampling, every control failure surfaced before the period closes.