SOX Compliance for Indian Subsidiaries of US-Listed Companies: A Practical Guide for Controllers and Risk Teams

SOX Compliance for Indian Subsidiaries of US-Listed Companies: A Practical Guide for Controllers and Risk Teams

Follow Us:

If your company is the Indian subsidiary of a US-listed company, your finance and risk teams may play an important role in supporting the group’s SOX compliance program. Where the subsidiary is determined to be in scope based on the parent company’s risk assessment, management is expected to establish, operate, and document effective internal controls over financial reporting. Where an Indian subsidiary is within SOX scope, Controllers, CFOs, and risk teams in India are expected to design internal controls over financial reporting, test those controls, and produce documented evidence that stands up to PCAOB-registered external auditor scrutiny. Yet a significant number of Indian finance teams carry this obligation without a formal SOX program, a maintained Risk and Control Matrix, or a clear testing plan. This guide explains how Indian subsidiaries can support their parent company’s SOX compliance obligations, how to scope and build a compliant controls environment, and the practical steps your team can take to achieve and maintain audit readiness.

What Is SOX and Why Does It Apply to Indian Subsidiaries?

The Sarbanes-Oxley Act is a US federal law passed in 2002 following major corporate accounting failures. It requires US-listed companies to maintain effective internal control over financial reporting across their consolidated operations. As a result, subsidiaries that contribute to the consolidated financial statements may be brought into the parent’s SOX compliance program. The law is administered by the SEC, while the Public Company Accounting Oversight Board (PCAOB) establishes auditing standards and oversees registered public accounting firms that audit US-listed companies.

The critical point for Indian finance teams is this: SOX applies to the full consolidated entity, not just the US parent. Under Exchange Act Rules 13a-15 and 15d-15, the CEO and CFO of the US parent must certify the design and operating effectiveness of internal controls across all financially significant subsidiaries. Where the Indian subsidiary is within the parent’s SOX scope, its controls contribute directly to the overall management assessment and certification.

Whether your subsidiary falls into active SOX scope depends on a materiality assessment. If your Indian entity contributes meaningfully to consolidated revenue, total assets, or key financial reporting processes such as revenue recognition or intercompany settlements, it will be identified as an in-scope component requiring management testing and potentially subject to walkthroughs, control testing, or additional procedures performed by the parent company’s internal audit function or external auditors, depending on the audit strategy.

What Are the Key SOX Sections Every Indian Controller Must Understand?

Three sections of the Sarbanes-Oxley Act carry direct implications for Indian finance and risk teams.

Section 302 requires the US parent’s CEO and CFO to certify, on a quarterly and annual basis, that financial statements are accurate and that all significant deficiencies and material weaknesses in internal controls have been disclosed. Consequently, control deficiencies identified within an in-scope Indian subsidiary should be promptly communicated to the parent company’s SOX or corporate finance team for evaluation and appropriate reporting.

Section 404 is the most resource-intensive requirement for Indian teams. Under Section 404(a), management must assess the effectiveness of internal controls over financial reporting as of each fiscal year-end. For issuers subject to Section 404(b), external auditors independently attest to management’s assessment. As a result, controls operating within in-scope Indian subsidiaries are commonly documented, tested, and evaluated as part of the parent’s overall SOX compliance program. Testing is generally performed by management, internal audit, or external advisors, while external auditors independently evaluate selected controls in accordance with PCAOB Auditing Standard AS 2201 as part of the audit of the group’s consolidated ICFR.

Section 906 establishes criminal penalties for CEOs and CFOs who knowingly or willfully certify materially false financial reports. Although these certifications are made by the executives of the US-listed parent company, accurate financial reporting and effective internal controls across in-scope subsidiaries are essential to supporting those certifications. In addition, SOX includes whistleblower protections that encourage employees to report suspected financial misconduct through appropriate channels, such as the parent company’s ethics hotline or audit committee, without fear of retaliation.

How Should Indian Teams Scope a SOX Compliance Program?

Scoping is the process of determining which entities, locations, financial statement accounts, disclosures, business processes, and controls should be included within the parent’s SOX compliance program. It follows a top-down, risk-based approach that considers materiality, financial reporting risks, and the likelihood of material misstatement. Once the scope is established, internal controls are designed and evaluated using the COSO 2013 Internal Control – Integrated Framework, which is built around five components: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.

The process typically begins by identifying significant accounts and disclosures. These are the financial statement line items that, if misstated, could materially affect the consolidated financials of the US parent. For most Indian subsidiaries, common starting points include revenue recognition, accounts payable, payroll, intercompany balances, and tax provisions.

From significant accounts, identify the underlying business processes. Then map the controls within those processes into two categories:

  • Entity-level controls, which cover the overall control environment, tone at the top, audit committee oversight, fraud risk management, and period-end financial reporting procedures
  • Process-level controls, which cover specific transaction cycles such as order-to-cash, procure-to-pay, and record-to-report

In addition to business process scoping, organizations should also identify the IT applications that support financial reporting. This includes ERP systems, financial consolidation tools, payroll applications, revenue and billing systems, and other applications that process or store financially significant data. Applications identified as in scope are typically subject to IT General Controls (ITGCs), including user access management, change management, and IT operations controls, to help ensure the reliability and integrity of financial reporting.

Although materiality thresholds are set at the group level, Indian controllers need to understand how their entity’s numbers feed into those calculations and which processes carry the highest inherent risk of misstatement.

Pierag’s Risk Advisory team supports Indian subsidiaries in conducting structured SOX scoping exercises and gap assessments that identify which processes need active controls and where the highest-risk gaps exist.

How Do You Build Internal Controls Over Financial Reporting (ICFR) in India?

Internal Controls over Financial Reporting, or ICFR, refers to the policies, procedures, and control activities designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements in accordance with the applicable financial reporting framework.

For each significant process identified during scoping, Indian finance and risk teams should complete five steps:

  1. Document the process through a written narrative or process flowchart
  2. Identify the risks that could cause a material misstatement in that process
  3. Map the controls that address each risk in a Risk and Control Matrix (RCM)
  4. Classify controls as preventive or detective and as manual or automated
  5. Assign control ownership to named individuals within the finance or operations team

Segregation of duties (SOD) requires particular attention in Indian subsidiaries. Many Indian finance teams operate with lean headcount, where the same person initiates, approves, and records transactions. Where true segregation cannot be achieved, compensating controls must be documented and tested. Leaving segregation of duties conflicts unaddressed and undocumented is one of the more common causes of significant deficiency findings in Indian subsidiary audits.

In addition to documenting controls, management should identify any reports, spreadsheets, or system-generated data relied upon to perform key controls. Under SOX, Information Produced by the Entity (IPE) used in control execution should be evaluated for completeness and accuracy through appropriate validation procedures. This is particularly important for reports extracted from ERP systems, manually prepared reconciliations, and spreadsheet-based calculations.

Why Are IT General Controls a Financial Reporting Risk for Indian Teams?

IT General Controls (ITGCs) are the foundational controls that support the reliability, security, and integrity of financial systems and the data they process. Effective ITGCs help ensure that automated application controls operate as intended and that system-generated reports and information used in financial reporting can be relied upon. Where relevant ITGCs are ineffective, management may not be able to rely on automated controls or Information Produced by the Entity (IPE), potentially increasing financial reporting risk and the extent of manual testing required.

SOX ITGC testing covers three primary domains:

  • Access management: Who has access to financial systems, how access is provisioned and removed, and whether privileged access is appropriately restricted to authorized personnel
  • Change management: How changes to applications, system configurations, and financial data are authorized, tested, and deployed into production
  • Computer operations: How automated batch jobs, financial close processes, and data interfaces are monitored and managed

Where Indian subsidiaries operate in-scope applications such as SAP, Oracle, Microsoft Dynamics, NetSuite, or other ERP platforms, management should ensure that relevant ITGCs are appropriately designed, implemented, and operating effectively throughout the reporting period. Effective ITGCs provide the foundation for management’s reliance on automated controls and system-generated information used in financial reporting.

Although ITGCs are typically owned by the IT function, finance and controllership teams should understand their impact because deficiencies in ITGCs can affect management’s ability to rely on automated controls, system-generated reports, and other evidence used to support financial reporting.

PCAOB inspection reports have frequently highlighted deficiencies in the evaluation and testing of IT General Controls, reinforcing the importance of a robust IT control environment as part of an effective SOX compliance program.

Common SOX Challenges for Indian Subsidiaries

Implementing and maintaining a SOX compliance program can be challenging, particularly for Indian subsidiaries that support global finance operations. While each organization has unique risks, several themes consistently emerge across first-year implementations and ongoing compliance programs.

Common challenges include:

  • Limited finance resources, where lean teams struggle to balance SOX documentation, testing, and remediation alongside month-end and year-end close activities.
  • Incomplete or outdated process documentation, including missing process narratives, flowcharts, and Risk and Control Matrices (RCMs).
  • Segregation of Duties (SoD) conflicts, particularly in smaller finance teams where individuals perform multiple incompatible activities without documented compensating controls.
  • Weak IT General Controls (ITGCs) over in-scope applications, including deficiencies in user access management, change management, and system operations.
  • Poor evidence retention, making it difficult to demonstrate that controls operated effectively throughout the year.
  • Coordination challenges between Indian teams and the US parent company’s finance, internal audit, and external auditors, particularly around testing timelines, documentation standards, and remediation activities.

Organizations that address these challenges proactively through clear governance, well-defined control ownership, timely testing, and ongoing monitoring are generally better positioned to support the parent company’s SOX compliance program and reduce audit issues.

What Happens When SOX Control Deficiencies Are Identified?

When control testing reveals a gap, the severity classification determines what happens next. SOX defines three levels:

  • Control deficiency: A design or operating gap that is unlikely on its own to result in a material misstatement
  • Significant deficiency: A deficiency, or combination of deficiencies, that is less severe than a material weakness but important enough to warrant formal communication to the audit committee or those charged with governance.
  • Material weakness: A deficiency where there is a reasonable possibility that a material misstatement in financial statements would not be prevented or detected and corrected on a timely basis

A material weakness identified in an Indian subsidiary must be disclosed publicly in the US parent company’s annual 10-K filing. This is visible to investors, analysts, and regulators. It can affect the parent company’s credit ratings, share price, and access to capital markets.

Understanding this escalation path is what should drive remediation prioritization in Indian risk teams. Not every gap requires the same urgency, but misclassifying a significant deficiency as a lower-severity control deficiency carries real disclosure risk.

How Should Indian Teams Prepare for PCAOB External Auditor Testing?

As part of the audit of the US-listed parent company’s Internal Control over Financial Reporting (ICFR), the PCAOB-registered external auditor may perform procedures over the controls operating within in-scope Indian subsidiaries. Depending on the audit strategy and the significance of the subsidiary, these procedures may include walkthroughs, inspection of control documentation, reperformance of selected controls, evaluation of management testing, and assessment of remediation activities. PCAOB AS 2201 expressly permits external auditors to use the work of others, including management and internal audit, where that work meets the auditor’s standards for competence, objectivity, and quality. Where auditors choose to rely on management testing, they expect the same rigor, documentation quality, and methodology they would apply themselves. Well-executed management testing can improve audit efficiency and reduce duplication of effort during the external audit.

Practical steps to prepare:

  • Complete management testing before the auditor’s scheduled fieldwork window
  • Retain organized, complete evidence for every control tested, including population data, sample selection rationale, tester conclusions, and reviewer sign-off
  • Conduct and document walkthroughs for every significant process before the audit begins
  • Validate the completeness and accuracy of Information Produced by the Entity (IPE), including system-generated reports and spreadsheets relied upon in the execution of key controls.

Remediate identified control deficiencies promptly and retain evidence demonstrating that corrective actions have been implemented and successfully re-tested. Indian controllers should also maintain close coordination with the US parent’s internal audit function, which typically acts as a liaison between the subsidiary and the external audit team. Where the internal audit function co-sources or outsources SOX testing to a risk advisory firm, Indian finance teams should understand how that work is documented and how it will be presented to the external auditor.

SOX Compliance Checklist for Indian Subsidiaries

Indian subsidiaries supporting the SOX compliance program of a US-listed parent company should periodically assess whether the key elements of their internal control framework are in place. The following checklist can serve as a practical reference to evaluate readiness and identify areas requiring attention.

  • Confirm whether the Indian subsidiary is within the parent’s SOX scope based on materiality and risk assessment.
  • Identify significant financial statement accounts, disclosures, and the underlying business processes.
  • Document process narratives, flowcharts, and Risk and Control Matrices (RCMs) for all in-scope processes.
  • Design and implement appropriate entity-level and process-level controls.
  • Identify in-scope IT applications and evaluate the design and operating effectiveness of IT General Controls (ITGCs).
  • Validate the completeness and accuracy of Information Produced by the Entity (IPE) used in key controls.
  • Perform walkthroughs to confirm that documented controls reflect actual operating practices.
  • Execute SOX management testing and retain complete, audit-ready evidence for each key control.
  • Evaluate identified control deficiencies, implement remediation plans, and re-test controls where necessary.
  • Coordinate regularly with the US parent company’s SOX, finance, internal audit, and external audit teams to support timely reporting and audit readiness.

Maintaining this checklist throughout the reporting year can help Indian finance and risk teams strengthen their control environment, support management’s SOX assessment, and improve readiness for external auditor review.

SOX compliance is not just a regulatory obligation for US-listed companies—it is a continuous process of building and maintaining a robust internal control environment across global operations. For Indian subsidiaries, success depends on effective scoping, well-designed controls, disciplined testing, timely remediation, and close coordination with the US parent company. By adopting a structured approach, finance and risk teams can strengthen financial reporting, support management’s SOX assessment, and improve readiness for external auditor review.

Frequently Asked Questions

Does SOX compliance apply to Indian subsidiaries of US-listed companies?

Yes. If the US parent company is listed on a US stock exchange and files annual reports with the SEC, SOX applies to the entire consolidated entity, including Indian subsidiaries. The CEO and CFO of the US parent must certify the effectiveness of internal controls across all significant components under Sections 302 and 404. Whether your specific Indian entity is in active scope depends on a materiality assessment, but subsidiaries that represent significant portions of consolidated revenue, total assets, or key financial reporting processes are typically included and subject to management testing and, where applicable, external auditor procedures.

What is ICFR, and what does it require from Indian controllers?

Internal Controls over Financial Reporting (ICFR) refers to the processes and controls maintained to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements in accordance with the applicable financial reporting framework. Under Section 404, management must assess ICFR effectiveness annually. For Indian controllers, this means designing controls across significant financial processes, documenting them in a Risk and Control Matrix, conducting walkthroughs, testing controls throughout the year, and retaining evidence that is audit-ready. For issuers subject to Section 404(b), the PCAOB-registered external auditor also audits management’s assessment of ICFR and may rely on management testing where it is appropriately planned, executed, documented, and supported by sufficient evidence.

What is a material weakness and why does it matter for Indian subsidiaries?

A material weakness is a deficiency in internal control where there is a reasonable possibility that a material misstatement in the financial statements would not be prevented or detected on a timely basis. If a material weakness is identified in an Indian subsidiary, it must be publicly disclosed in the US parent company’s 10-K filing with the SEC. This disclosure is visible to investors and financial markets and can affect the parent company’s stock price, credit ratings, and ability to raise capital. Indian risk teams must understand the three severity levels, control deficiency, significant deficiency, and material weakness, so they can prioritize remediation and make accurate escalation decisions.

How should Indian finance teams approach IT General Controls for SOX?

IT General Controls (ITGCs) support the reliability of IT applications used in financial reporting. For in-scope systems, ITGC testing typically covers logical access management, program change management, and computer operations. Indian finance teams should work closely with IT to ensure these controls are appropriately designed, documented, tested, and monitored. Weak ITGCs may affect management’s ability to rely on automated controls and system-generated reports, increasing financial reporting and audit risk.

When should an Indian subsidiary engage a risk advisory firm for SOX support?

An Indian subsidiary should consider engaging a risk advisory firm when it is brought into SOX scope for the first time, needs to remediate control deficiencies, lacks the internal capacity to perform SOX documentation and testing, or is preparing for external auditor review. A risk advisory firm can assist with SOX scoping, gap assessments, Risk and Control Matrix (RCM) development, management testing, remediation, and audit readiness.

Recent Posts
From 200 Hours to 40: Automating Incentive Calculations at a Top 10 US CPA Firm
From 200 Hours to 40: Automating Incentive Calculations at a Top 10 US CPA Firm
The problem wasn't the maths Every month, a Top 10 US CPA firm spent more than 200 hours calculating sales...
The Maturity Trap:<br>Why Finance AI Stalls Before It Scales
The Maturity Trap:
Why Finance AI Stalls Before It Scales
Finance leaders no longer need convincing that AI matters. According to a study conducted by leading consulting firm, nearly nine...
BRSR Core Assurance: What the New Requirements Mean for Companies Under SEBI’s ESG Guidelines
BRSR Core Assurance: What the New Requirements Mean for Companies Under SEBI’s ESG Guidelines
How Did ESG Reporting in India Reach This Point? India's ESG reporting journey has been defined by progressive regulatory intent....