Governance, risk and compliance

SmartSuite for the Head of Internal Controls

The Head of Internal Controls owns the internal control framework across the organisation: the control library, design standards, the testing programme and the certification that controls operate. They lead SOX and non-financial control programmes and report control effectiveness to the CFO and audit committee.

What you own

  • Own the internal control framework and control library
  • Set control design, documentation and testing standards
  • Lead the SOX programme and other control certification programmes
  • Oversee deficiency evaluation, aggregation and remediation
  • Coordinate with internal and external audit on reliance and testing
  • Report control effectiveness to the CFO and audit committee

Where the role sits

Each name opens that role's page.

Reports to

Chief Financial Officer

Chief Financial Officer

See the role
Chief Audit Executive

Chief Audit Executive

See the role

Direct reports

Internal Controls Manager

Internal Controls Manager

See the role
SOX Program Manager

SOX Program Manager

See the role
Controls Testing Lead

Controls Testing Lead

See the role

Works closely with

Controller

Controller

See the role
Audit Director

Audit Director

See the role
External Auditor

External Auditor

See the role
Compliance Director

Compliance Director

See the role
Chief Risk Officer

Chief Risk Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

compliance

Touches

contributes or approves

audit, issues-actions, reporting, risk

Depends on

consumes its output

policy

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

No items found.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Maintains the control library with design standards, frequencies and framework mappings as the single source for every control programme.

Internal audit. Shares control status, testing history and evidence with internal and external auditors for reliance.

Issues and actions. Evaluates and aggregates deficiencies with remediation tracked to re-test.

Reporting. Reports control effectiveness and certification readiness to the CFO and audit committee.

Industry reference

COSO's Internal Control Integrated Framework (2013) is the structure; SOX Sections 302 and 404 and PCAOB AS 2201 make it a certified, audited duty for US registrants. The UK Corporate Governance Code (2024) adds a board declaration on material controls from 2026, and Japan's J-SOX imposes a similar regime.

Banks above the FDICIA thresholds (12 CFR 363) report on internal control over financial reporting to their regulator. US federal agencies follow OMB Circular A-123 and GAO's Green Book; recipients of federal awards, including universities and health systems, must maintain internal control under the Uniform Guidance (2 CFR 200.303). Technology companies often extend the framework to SOC 1 reports.

In their words

Related roles

Chief Financial Officer

Chief Financial Officer

See the role
Chief Audit Executive

Chief Audit Executive

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.