Skip to main content
RYSQER
SOX Ready

When auditors walk in,
you're ready.

RYSQER's Internal Control System brings control execution, evidence, reviews and SOX readiness into one system.

See how it works
Control execution overview
Current quarter · All entities
Signed off
82%
+6% vs previous period
In progress
14
due this month
Needs attention
3
overdue items
Control Status
AP-102 Signed off
ITGC-07 Signed off
REV-014 In review
CASH-003 In progress
FIN-021 Overdue
Illustrative RYSQER ICS view · no client data

SOX readiness breaks down in execution.

Your controls may be well documented. But readiness is lost in the day-to-day—when ownership is unclear, recurring execution slips, and evidence, reviews and remediation live in spreadsheets, email threads and disconnected files.

By the time auditors ask, teams are reconstructing what happened instead of showing it.

Built for first-year SOX programs, IPO and US-listing preparation, and teams moving control execution out of spreadsheets and email.

Developed with finance and internal-control teams and already used in live internal-control programs at Nasdaq-listed companies.

How the RYSQER ICS works

1

Set up risks, controls and responsibilities

Identify material financial risks, then define controls with clear owners, reviewers and frequency—only where materiality justifies them.

2

Execute controls and collect evidence

Owners get structured task lists. They execute controls, attach evidence and submit for review—automated reminders make sure nothing slips.

3

Review, test, remediate and report

Reviewers sign off or flag issues and testers document findings. Deficiencies are tracked to closure, and dashboards show control status by entity and period.

Owner task view
Evidence upload · reviewer sign-off · reminders
Due next
2
items require evidence upload
Pending review
1
waiting for sign-off
Task Status
Bank rec (monthly) In progress
Access review (quarterly) Evidence needed
Revenue cutoff (quarterly) In review
Journal approvals (monthly) Signed off
Inventory count (annual) Overdue
Illustrative RYSQER ICS view · no client data

Core capabilities for running SOX controls

Clear ownership and deadlines

Every control has a named owner, a reviewer and a due date. Responsibilities and timelines are explicit, not assumed.

Recurring control execution

Monthly, quarterly and annual controls recur on schedule. Owners receive tasks automatically and reminders chase what's due.

Structured evidence collection

Owners attach the required evidence to each control—files, exports, reports or checklists—kept with the execution record.

Review and sign-off

Reviewers approve or return each control with comments. Every sign-off records who signed off and when.

Testing and deficiency management

Testers document their work, raise deficiencies, and track remediation to closure with severity and assigned owners.

Cross-entity readiness visibility

See status by control, entity and reporting period in one place—so you always know where readiness stands.

Built for the whole control lifecycle

From daily execution to external audit—everyone works in one system with the right access.

Control Owner

Gets a clear task list, uploads evidence, and moves on. Automated reminders mean nothing slips.

Coordinator / SOX Program Owner

Designs the control framework, assigns controls, and monitors execution across every entity and reporting period.

Tester (Internal Audit)

Tests on their schedule, documents findings, and collaborates directly with owners—no email chains.

Auditor (External)

Reviews what's been done, tracks remediation, and downloads everything they need. Evidence is organized and waiting.

Coordinator overview
Cross-entity status · period tracking · exceptions first
On track
3/6
entities on schedule
At risk
1
entity · 3 overdue
Trend
sign-offs improving
Entity Status
Entity A On track
Entity B Watch
Entity C On track
Entity D Watch
Entity E On track
Entity F At risk
Illustrative RYSQER ICS view · no client data
Readiness overview
Current quarter · All entities
On track
Readiness
82%
controls signed off
Overdue
3
controls past due
Deficiencies
3
open, to remediate
Trend
improving vs last period
Readiness by entity
Entity A On track
Entity B Watch
Entity F At risk
Illustrative RYSQER ICS view · no client data

Know where you stand.
Every reporting period.

Management gets a live view of readiness—overdue controls, incomplete evidence and open deficiencies—by entity and reporting period, without chasing status over email.

Readiness status

Coverage & trend by period

Overdue & at risk

Late controls, missing evidence

Entity progress

Who's on track

Open deficiencies

Findings to remediate

Security and access for internal control environments

EU

Data hosting in Germany

GDPR

Aligned data handling

SSO

Enterprise single sign-on

The RYSQER ICS is delivered as SaaS and hosted in Germany. No local installation or client-side infrastructure is required. Enterprise SSO and role-based access support secure access and separation of duties. Detailed security and data-protection documentation is available on request.

The control catalog is configurable for SOX, COSO or your own framework.

Software first.
Implementation support when you need it.

The RYSQER Internal Control System is the licensed SaaS software at the center of the SOX Ready offer. No local installation or client-side infrastructure is required.

RYSQER can configure and populate the system, structure the control framework, onboard owners, reviewers and testers, and support rollout across entities. Where required, RYSQER can also provide ongoing operational support for the control program.

This combination gives clients one team for software, implementation and practical internal-controls support. Learn more about RYSQER

Software licensing is tailored to your organization, entities and rollout scope.

Initial SOX scoping Control design System configuration Onboarding Rollout across entities Ongoing operational support

The software is the product. Implementation support is optional and provided by Rysqer Consulting GmbH.

Frequently asked questions

What is SOX Ready?

SOX Ready is RYSQER's focused offer for companies implementing and operating SOX controls with the RYSQER Internal Control System. It is not a certification and does not replace an auditor's independent assessment.

Is the RYSQER ICS already in use?

Yes. The software is already used in live internal-control programs at Nasdaq-listed companies and has been developed together with customers and internal-control practitioners.

Who is SOX Ready for?

Finance and internal controls teams running SOX—especially first-year SOX programs, companies preparing for an IPO or US listing, and teams moving control execution out of spreadsheets and email.

Can external auditors access the system?

Yes. External auditors can be given structured, role-based, read-only access where appropriate—so they can review what has been done and download the evidence they need.

How is security handled?

The RYSQER ICS is delivered as SaaS and hosted in Germany. It supports enterprise SSO and role-based access. No local installation or client-side infrastructure is required. Detailed security and data-protection documentation is available on request.

How far can RYSQER support implementation and operation?

RYSQER can configure and populate the system, onboard users, support rollout across entities and provide ongoing operational support where required. The extent of support is tailored to the client's organization and operating model.

Edona Lerchenberger - Senior Manager, Internal Controls & Product at RYSQER

See the RYSQER ICS in action

Book a 30-minute demo with Edona. See the RYSQER Internal Control System in action and discuss how the SOX Ready offer fits your control framework, entities and rollout scope.

Edona Lerchenberger

Senior Manager · Internal Controls & Product

LinkedIn profile
Edona Lerchenberger

Schedule a Demo

30 min with Edona · Your preferred time

Used only to arrange your demo. Deleted after 90 days if no demo is scheduled.

Imprint

Rysqer Consulting GmbH

Bachstr. 6

96215 Lichtenfels

Commercial Register: HRB 6745

Registration court: Coburg

VAT ID: DE347960145

Represented by:

Lennart Wittmann

Managing Director

E-Mail: mail@rysqer.com

Data Protection

Controller: Rysqer Consulting GmbH, Bachstr. 6, 96215 Lichtenfels, mail@rysqer.com

Server logs: IP address, browser, timestamp — legal basis: Art. 6(1)(f) GDPR (legitimate interest in security). Deleted after 7 days.

Demo requests: Name, email, company, and preferred time are stored on EU servers and used solely to arrange your demo — legal basis: Art. 6(1)(b) GDPR. Data is deleted after 90 days if no demo is scheduled.

Your rights: Access, rectification, erasure, restriction, portability, objection (Art. 15–21 GDPR). Complaint to supervisory authority: BayLDA.