Entity level controls (ELCs) are often difficult to identify and even more difficult to assess. Soft controls are similar to entity level controls. They do not lend themselves to normal validation processes. Assessors must often utilize interviews, questionnaires and observations or other unique methods.
Other courses have looked at top-down risk assessment (RA) and discussed ELCs and some methods for assessment. This course delves further into understanding approaches to assessing the design and operating effectiveness of ELCs and soft controls. We cover methods and alternatives to measuring and assessing ELCs and soft controls.
Information within this course comes from readily available public domain documents and is utilized by the trainer as a supplement for relaying the course content.
Note: The concepts outlined in this course are up to date and relevant in regards to the Sarbanes-Oxley legislation. Although there have not been any changes in the legislative concepts of the law since it’s release in 2002, some aspects of executing the work have evolved. This speaker is preparing a series of courses titled “Sarbanes-Oxley 20 years later”. Those courses can be found individually on the platform and would be beneficial for anyone involved with compliance.
NOTE: The Instructor has created 5 new segments on Sarbanes-Oxley Update - 20 Years Later:
Sarbanes-Oxley Update - 20 Years Later: Accounting Risk Assessment Considerations
Sarbanes-Oxley Update - 20 Years Later: Sourcing Emerging Risks Part 1
Sarbanes-Oxley Update - 20 Years Later: Evaluating Testing Processes
Sarbanes-Oxley Update - 20 Years Later: Sourcing Emerging Risks Part 2
Sarbanes-Oxley Update - 20 Years Later: Examining Fraud Risks
Prerequisites
No Advanced Preparation or Prerequisites are needed for this course.
Learning Objective
- Explore Hard vs. Soft entity level controls (ELCs)
- Recognize challenges of evaluating soft controls
- Explore Methods for assessing soft controls and determining effectiveness
- Committee of Sponsoring Organizations (COSO)
- Maturity Model
- Cause and effect analysis
- Questionnaires and surveys
- Discover how to link soft controls to COSO principles and financial statement assertions
Last updated/reviewed: July 24, 2025
(170) Reviews
(131 rating)Lots of new information on big datas role with fraud detection.
Have to say that this is a good, exhaustive and updated trainning on COSO and anyone can take a nice understanding of the whole picture
A good primer for people moving into a leadership position.
Concise and direct course on the sections 806,902 qnd 906. Direct with great examples of how the sections work
Great presentation to understand the importance of HR within the budgeting and planning process of a Company.
Really great course. Professionally communicated and in an interesting way that provides insight as to the nature of the inner workings of the SEC and public companies in more ways than just accounting.
Great summarized course to understand the basics of a Board of Directors structure
Ethical issues are sometimes downrated, what is not correct. Great presentation.
I like to read the slide decks in the pdf format. The pdfs for this course were not sufficient to learn the content.
Very good teacher and very interesting content. I addressed many relevant topics and give a broad overview on fraud schemes and controls. I like that it illustrates the content with statistics.
This course is a very good material for beginners, but also experienced professionals. It is clearly and accessibly structured with key points brought to attention of the students.
clear course, well structured and explained. It helps a lot to understanding the evolution and how some current practices went live.
Well explained and excellent slides for future use. Well explained and excellent slides for future use.
It's hard to distill the entire history of ethical thought down into a 2 hour business course, but I give credit to the instructor for making the effort.
What a fantastic course! This course was chock full of great tips and general ideas. Definitely a ton of "a ha" kind of moments and very helpful for those of us at the middle management level who would like to try to convince the Executive level that moving even at least to data mining would be helpful. Also, really appreciated the presenter's use of helpful visuals as well.
very good presentation and helpful and I agree that it will further help me in my work and upgrade my skills and knowledge
Enjoyed this course and the additional insights from the instructor. Very clear and concise concepts. Would highly recommend to organizations or individuals needing more insight to the "SOX World".
I have enjoyed so much this course, which I considered have an invaluable materials and knowledge to use as a permanent reference and to apply in SOX audit duties regularly. Thanks to Lynn for this magnificent and outstanding course because it will help me to achieve my professional goals in my Auditor career :)
Very informative course and great experience provided to learners
I enjoyed getting to now some of the automation areas that are being seen across SOX compliant companies.
The course is well organized and easy to understand!
I found the slides to be very interesting. Ms. Louis made the slides very engaging.
Great course on ethical and regulatory considerations for remote employees. This will interest you!
It is a very lengthy topic. I like it but it would be better if can have more detail of each subsection. Feel like it is not enough and wish to have more examples.
I have completed the course and have no further comments.
The course is very informative and provides illustrative samples of fraud. It would be beneficial if the course would also provide the summary of results indicating the correct/incorrect answers.
The title is misleading, I thought the instructor was going to talk more about the concern of the CFO in running the organization, new technology adoption etc.
Thanks for the very comprehensive course in understanding expectations under SOX standards.
I liked how the course detailed and explained the traits and skills areas.
The course material explain the full scope of the IT and its relation to controls
I like how the instructor works through simple, real examples of the close process. Good refresher.
not sure I agree with this question and answer: Question: Which of the following is not a disclosure control procedure?
Interesting class. The final exam comes more from the class than the handouts, would like to see all material in a hand out for reference after the class.
Content and material was very sloppy. Overall the instructor was incredibly knowledgeable, however one of the key concepts of Mgmt Accounting is the usefulness and presentation of information and yet the information presented was poorly presented.
Good overview of professional ethics for New York CPAs.
Very nice summary Very nice summary Very nice summary Very nice summary
Interesting and informative course with relevant information to understand the controllership function. Easy to follow and understand.
The material provided are very brief. Kindly provide more explanatory material, most of the content that are provided here are from CIA and Gleim is more straight forward. It should be good to have the same standard.
Great overview of the COSO and internal control processes/procedures
A very clear explanations, covering all topics. I really love the session. Perhaps can get a more exciting slides or link share for reference. Overall, good. thank you!
Amazing course! Very solid material to provide a broad understanding of how Fraud is managed according with SOX.
I liked the course because it introduces you to a short history of the regulations and how they developed over time.
This course provides some great information. The topics covered are very helpful as well.
I am a CPA, but have been performing non financial audits for the past decade. This course was a great refresher.
Jim has a great teaching style making it easy to grasp the key concepts for this course. This was a very good refresher for me. Thank you Jim!
its a great course with full of information! i find it useful for me to detect a fraud next time
I am very happy with the training I received in these modules. I also very much appreciate all the templates and documentation provided in the last module. I know that I will be referring back to this material often in the future.
Enjoyed the course which Is exactly what I was seeking to begin educating myself about SOX and how SOX relates to EA/IA. Thanks for sharing your knowledge and expertise, Lynn!
Great exposure to Fraud Risk Management Strategy. Fraud Risk Monitoring is crucial in today's business environment. Professionals from business and accounting background could make use of the information for professional certification studies and on-job applications. I would definitely keep the notes for future reference.
Training was a little longer than others but very informative. It made it very clear to understand the difference between a soc 1, 2 (type 1 and 2 report), 3 and the cybersecurity report.
This excellent course helps and encourages to use healthy scepticism to detect cash related fraud cases.
Material was a little hard to understand and retain. I would have liked more clarification
This was an excellent course because it provided tactical ways to implement the information provided.
The course is very useful for those risk management professionals who need to rethink their organizational planning efforts.
A helpful, tangible approach on the topic. Judgment and specific company factors play into a conclusion/position. The information within this webinar will be useful.
An excellent course on SOX Section 404! Perhaps a little discussion about what is meant by acceptable level" of risk and who determines it will surely be appreciated by those taking this course
This is a really good informative course--thanks for putting it together.
Excellent course, the material and trainer were really clear even for those new in SOX world.
I learned a lot from this course and will highly recommend it!
The training videos was good and understandable. The PPT presented was clear .
These tools will provide assistance in the development and execution of SOX compliance procedures.
ExcelLent :) Well-structured and easy to study Text Based Course. Very useful supporting materials. Interesting info.
Dislike: The writing of the exam questions aren't as well written as the rest of the courses.
This a trending topic in current industries and gaining more focus for its use cases and utilization. The course provided a good introduction to this topic.
It was very well structured, well-paced and easy to follow training course. Structuring the course in segments as well as offering a continuous play option is perfect for any learning style. The examples given were good.
This is an excellent SOX topic that I have not previously seen covered before.
The learning activity was engaging and appropriate. It met my expectations.
Like in other webinars Lynn has, I loved how she goes deep in every slide using examples and/or making great observations for when you are in the process of RA. With that, you can see she is very knowledged in the subject she is teaching about.
The Course was very engaging and provided great examples of real life. The instructor is very enthusiastic and content is to the point.
Great! Thank you for another useful and interesting course. Awesome summary.
The course is very informative and covers all necessary topics that are needed to be proficient in the Sarbanes Oxley. I highly recommend this course to individuals who wants to learn and understand SOX.
Very good test, I am now SUPER good at ethics need more words to hit 50
Very informative course. I recommend to anyone, don't have anything else to comment on.
This was very helpful and I will definitely save these training materials if our department is ever called on to conduct an audit of the network. Currently we also have an Information Security team that is a second line of defense to our Internal Audit team.
Great course! A very thorough review of internal controls that was easy to understand.
Did not understand the section on controversy around Pitt & Webster. Seemed somewhat irrelevant
the course was very insightful and its very applicable to my technology area of practice
A good course on ITGC. It has helped me refresh and reinforce my understanding of the topic
I would have liked a deeper dive on the SOX Testing Process and IT sections. IT was very general and didn't give a lot of specifics or depth. The control testing didn't even mention IPE. Would have liked more guidance on testing specifics. The background, explanation of legislation, auditing standards, COSO, etc were very beneficial.
Objectives Met, Appropriate requirements, Activties completed
This is an excellent course from Lynn Fountain! The real-life scenarios and current event considerations bring life to the topic.
I enjoyed the examples given in this course. These examples helped to bring all of the concepts that I am learning in the certification together!
Great deal of practical solutions to enhancing executive presence. Solid examples by the instructors.
Very meaningful and informative course gives a very good understanding on standard evolution.
Great overview of COSO 2013 and how management is responsible for their internal controls.
Good refresher course to understand the concept of SOX
I am with a new company implementing a SOX program. While I had experience in SOX previous to this class, these lectures have provided new information, a great foundation, and good real world examples. I will likely be returning to the classes and handouts on a routine basis for guidance.
Very good course, Its good to have a one presentation rather than many
Very Informative. Comprehensive learning. Extensive material provided.
Excellent articulation of COSO 2013 principles that have provided better practical linkage. Only one improvement recommended is to include some more specific examples
Best point: understanding SEC vs PCAOB and AS2 to AS5
Thank you for another great course that introduced the connection of COSO 2013 and fraud.
KPI section could be more informative in measuring how effective your profile is.
The tools (resources, downloadable material) in this are incredibly valuable - a great conclusion for this certification program.
This was an excellent and engaging course. It gave a simple, but wholistic introduction to the Sarbanes Oxley Act. Looking forward to watching the remaining courses in the certification.
Overall a great reminder of how to be successful as we all continue to work from home more frequently
Your courses have all been so wonderful, so informational, and so thorough--in short, greatly appreciated by me! Thank you for sharing your expertise, your wealth of knowledge, your inclusion of examples! I have greatly enjoyed reading and listening to all of your lectures thus far.
Great course and very well prepared and explained.
Good review of various types of audit reports that can be issued. However, this course did not cover the dating of the report or the auditor's responsibilities for reporting of subsequent events.
A lot to digest! Terms are essential in understanding concepts.
LOTS of good information! So much actually that I am sure that I need to come back to these slides many times to really understand this thoroughly. There are so many things to be taken into consideration. Good templates and examples.
Gave a good overview of SOX related to ITGC. Would have like to gone into more detail on application controls. Overall, good course.
great course, easy to read and follow along the way the text is written
It was very interesting to get perspective from someone who has worked in both external and internal audit. This was a great refresher on what goes into consideration when issuing an audit opinion.
Overall course contained very good information and history behind the "why?" we do all the work we do
Thank you so much for this amazing course where I had the opportunity to learn so many interesting things that I will be able to apply in my daily routine.
Well detailed and properly explained concepts on fraud risk assessment. This is a good introduction into Fraud risk assessment and sets the expectations for beginners
i felt that the instructor gave her best effort to capture the new concepts of the standard.
Very helpful, however, too much theoretical information, years, reports
The presenter provides plenty of relevant insights on fraud evaluations in a very clear and concise manner
Excellent course with a strong presenter. A course for anyone who wants to understand and develop stronger more compelling presentations and how to deliver them.
This course is helpful to brainstorm improvement of internal control by providing useful information of fraud concealment method, data analytics technique and other action to detect fraud.
Thanks for this in-depth course. The course material is rich and the delivery, very excellent.
This was a good course. well delivered. Good job .
This was a very confusing one. I finally passed when I answered one question which seemed again what the material and I understood. It was question six. I disagree that it should be answer A. A going concern is considered when a company has issues about going a year from the opinion letter date.
Great addition to illumeo. Really helps keep up with the Ethics requirement in a timely manner.
This entire section is new to me and is very technical. This would be helpful if you need to understand the basics of XBRL.
Excellent full package on SOX and COSO principles with key template to implement process in the organization.
This course was well developed and well presented. Good coverage of the subject.
Great course of audit committee effectiveness in the aftermath of 2007
Good review course. This was a solid refresher for something I have been away from for some time.
Overall great course! I do not have any feedback on how to improve the quality of this course. I thought for an intro course to Yellow Book, the basics were covered effectively.
This course provided a good high level overview of how to conduct a risk assessment for SOX.
The final module in this marathon of a course - 17 courses yet it was very well delivered and comprehensive. Job well done as I learnt a lot.
Provides a good insight into section 404 requirements
The explanation is very clear, straight to the point.
Very good and simplified course. It serves as a good refresher for people practicing SOX and ICFR only daily basis but serves as a good basis for people just starting to learn SOX.
outdated with 2013 data - don't think FCPA enforcement has increased under Trump
Everything is making sense but I guess what I'm struggling with is how to identify the "differences" between ASC 606 vs previous version. I felt like all the things that you said existed before. I was wondering if there is a summary/table available where I can clearly see the difference in transaction treatment between ASC 606 and the old version.
good review, nice to be back to this online trainings
Very well presented. Easy to understand and follow.
This SOX 404 section possess good controls information.
This course helped me strengthen my understanding of IA fundamentals.
Overall good learning material. the XBRL vs SOX was really good learning in a way that shows link between them.
An important aspect that companies forget to look at because cyber attacks are seldomly experienced by them. Great refresher on how to react to cyber attacks
Simple and very usefulThe simplicity was surprising yet we overlook most of the tasks involved here
This course clearly identifies the different variations of delegating work in the organization, based on the individuals.
Awesome course, covers the process for ensuring that SOX controls are documented and tested as necessary. Materiality piece was great as well.
I thought the questions were less aligned to the information in the slide deck as they have been in other courses.
This course provides a detailed materials on preventing and detecting fraud.
excellent walk through of the evolution of the AS supported by personal experience of the spaeker
I have been working in the SOX/404 area of my internal audit department for a number of years and knew a lot of this at a certain (and varying) level/s - this course showed me where I need to focus more and filled in more gaps than I knew I had!
This course was excellent and provided important information that I will utilize in the future.
Excellent overview about temporary differences, very useful examples and exercises
This class should be broken out into two classes. This is a lot of information for one class.
Good, clear explanation of control activities with a more in-depth look at each principle and POF. The concepts are easy to understand with great examples provided.
this was alot of work but the slides and seminars made it much easier
This course provides a good overall view of what composes ethics and what influences it within an organization
Great course specially regarding the differences between application controls and general controls.
Great review of preparing indirect cash flow statement.
Great refresher on basic accounting topics. The materials were easy to follow, and navigate.
I was not familiar with XBRL, so this course was very helpful.
This course is full of a lot of technical information. At times I found it hard to follow, but still finished having learned enough to have a reasonable understanding of the topic.
Good insight in personalities and leadership. Excellent explanations of human behavior
This is a great overview of XBRL - I found it very technical having not covered the topic before but still managed to understand enough to pass the test. Lynn's presentation was clear and demonstrated her expertise in this area.
Great information! Easy to understand and overall meaningful content....
Very insightful and great suggestions for creating a mutually beneficial relationship between leader and subordinates.
This is the only course I have ever done on Illumeo that does not have a continuous playback option. The lack of this option combined with the bifurcation of the slides and the examples into a separate documents makes this course harder to follow that most other courses.
Good information, easy to understand. Overall enjoyed the whole course.
Interesting real life cases.
Short albeit good review of T&E expenses.
Some more error rectification technique may be included in this course.
Very informative
Excellent - gave me a good understanding of SOX by providing the history and timeline of the changes.
I liked the course it was very informative.
Good introductory course to the topic
Excellent course
Good details
excellent refresher
This is a great synopsis of the IPO process, including the key regulatory considerations and planning elements. I highly recommend this course.
Ask the instructor a question about this lesson