SmartSuite for the Internal Controls Manager
The Internal Controls Manager owns control design, documentation, consistency and ongoing effectiveness. They maintain standardised control definitions and frequencies, review test results and evidence, approve outcomes, and track control changes and the re-testing they require.
What you own
- Maintain standardised control definitions, owners and frequencies
- Review control design for completeness and alignment to risks
- Review test results, validate evidence and approve outcomes
- Track control changes and trigger re-testing
- Evaluate deficiencies and coordinate remediation
- Support SOX, SOC and other certification cycles
- Report control health to the Head of Internal Controls
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use the SOX Management suite
Control design oversight
Maintains standardized control definitions and frequencies.
Test review
Reviews results, validates evidence, and approves outcomes.
Change management
Tracks control updates and re-testing requirements.
Suites that serve this role
Products this role uses most
How SmartSuite supports this role
Compliance management. Maintains control libraries with standardised definitions and frequencies, and tracks control updates and re-testing requirements with version control.
Internal audit. Keeps testing history and evidence repositories traceable for auditors.
Issues and actions. Logs deficiencies with severity, owners and remediation tracked to re-test.
Reporting. Reports control health, testing completion and open deficiencies.
Industry reference
COSO's 2013 framework defines what a well-designed control looks like; PCAOB AS 2201 defines how the external auditor will evaluate it and the SEC's management guidance (2007) how management should assess it. Control changes, re-testing and deficiency aggregation follow those standards.
The same discipline applies beyond SOX. Banks maintain controls under FDICIA and heightened standards; healthcare providers evidence HIPAA safeguards and CMS billing controls; public bodies apply GAO's Green Book; technology companies document controls for SOC 1 and SOC 2, where design and operating effectiveness are tested on the same model.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.





