Governance, risk and compliance

SmartSuite for the Internal Controls Manager

The Internal Controls Manager owns control design, documentation, consistency and ongoing effectiveness. They maintain standardised control definitions and frequencies, review test results and evidence, approve outcomes, and track control changes and the re-testing they require.

What you own

  • Maintain standardised control definitions, owners and frequencies
  • Review control design for completeness and alignment to risks
  • Review test results, validate evidence and approve outcomes
  • Track control changes and trigger re-testing
  • Evaluate deficiencies and coordinate remediation
  • Support SOX, SOC and other certification cycles
  • Report control health to the Head of Internal Controls

Where the role sits

Each name opens that role's page.

Reports to

Head of Internal Controls

Head of Internal Controls

See the role
Controller

Controller

See the role

Direct reports

Controls Testing Lead

Controls Testing Lead

See the role

Works closely with

SOX Program Manager

SOX Program Manager

See the role
Control Owner

Control Owner

See the role
Internal Auditor

Internal Auditor

See the role
Compliance Manager

Compliance Manager

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

compliance

Touches

contributes or approves

audit, issues-actions, reporting

Depends on

consumes its output

risk, policy

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use the SOX Management suite

Control design oversight

Maintains standardized control definitions and frequencies.

Test review

Reviews results, validates evidence, and approves outcomes.

Change management

Tracks control updates and re-testing requirements.

Suites that serve this role

How SmartSuite supports this role

Compliance management. Maintains control libraries with standardised definitions and frequencies, and tracks control updates and re-testing requirements with version control.

Internal audit. Keeps testing history and evidence repositories traceable for auditors.

Issues and actions. Logs deficiencies with severity, owners and remediation tracked to re-test.

Reporting. Reports control health, testing completion and open deficiencies.

Industry reference

COSO's 2013 framework defines what a well-designed control looks like; PCAOB AS 2201 defines how the external auditor will evaluate it and the SEC's management guidance (2007) how management should assess it. Control changes, re-testing and deficiency aggregation follow those standards.

The same discipline applies beyond SOX. Banks maintain controls under FDICIA and heightened standards; healthcare providers evidence HIPAA safeguards and CMS billing controls; public bodies apply GAO's Green Book; technology companies document controls for SOC 1 and SOC 2, where design and operating effectiveness are tested on the same model.

In their words

Related roles

Head of Internal Controls

Head of Internal Controls

See the role
Controller

Controller

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.