Confidential mandate
Sarbanes–Oxley Entity-Control Architect — Connected Medical Devices
Planned Hiring / New
Sarbanes–Oxley Entity-Control Architect mandate in Minneapolis, United States · Connected Medical Devices
A Minneapolis medical-device issuer commissions a four-month entity-control architecture to strengthen override, risk and committee evidence before its first complete Sarbanes–Oxley management assessment and audit.
The mandate
The issuer has documented transaction controls but still treats entity-level controls as annual policy confirmations. Risk assessment does not consistently drive scoping; whistleblower, Quality and cyber matters enter financial reporting late; delegation changes are not tested for override; and committee evidence records attendance more readily than challenge. Management needs operating controls, not a library of governance descriptions.
The engagement deliverable is a Sarbanes–Oxley Entity-Level Control Architecture and Evidence Manual. It will cover control environment, competence, delegation, fraud and override, risk assessment, information flow, monitoring, deficiency escalation, committee oversight, whistleblower matters and management certification. Each control will have an objective, evidence source, precision, performer, reviewer, exception path and relationship to process-level reliance.
Milestone one at week three provides entity-control inventory, risk and reliance gaps. Week seven concludes milestone two with redesigned controls and evidence standards. At week twelve, milestone three delivers operation through one reporting cycle and adversarial walkthroughs. The accepted architecture, evidence manual, deficiency map and client-run certification rehearsal complete milestone four at week seventeen.
Acceptance requires management to demonstrate every key entity control with contemporaneous evidence; Internal Audit must reperform fifteen unseen cases, including an override allegation and late Quality matter; and external-audit coordination must confirm evidence accessibility without pre-agreeing reliance. The Accounting Officer signs after control owners complete an accelerated certification and executive-turnover scenario without consultants.
The client will provide governance documents, delegations, risk assessments, committee packs, whistleblower and compliance protocols, deficiency history, certifications, organisation and incentive data, control matrices and access to responsible executives. Client management operates and concludes on controls. The assignment excludes audit or attestation, legal advice, investigations, Quality remediation, process-control redesign and production system implementation.
Why this is external work
Existing teams are skilled at transaction controls but have normalised broad entity-control descriptions that are difficult to test. Internal Audit must later evaluate the design independently. External architecture adds experienced challenge and practical evidence standards without performing management controls, investigating allegations or predetermining auditor reliance.
What you will own
- Map entity-level objectives across integrity, competence, authority, risk assessment, information, monitoring, escalation and board oversight.
- Define evidence and precision for delegation, incentive review, fraud risk, override monitoring, certification and committee challenge.
- Connect product Quality, cyber, compliance, legal and whistleblower matters to timely financial-reporting risk assessment.
- Exercise executive turnover, override allegation, late deficiency, incentive conflict, acquisition change and committee information failure.
- Establish severity and escalation logic linking entity weaknesses to process reliance, compensating controls and certification.
- Design sustainable performer and reviewer capacity without converting annual questionnaires into unsupported control evidence.
- Transfer the manual through a client-run accelerated certification and Internal Audit reperformance before acceptance.
Candidate qualifications
- Led Sarbanes–Oxley entity-level control design for a newly scoped public medical-device, life-science or regulated manufacturer.
- Converted governance, risk, culture and oversight principles into controls with testable precision and contemporaneous evidence.
- Connected Quality, cyber, compliance, whistleblower and legal matters to financial-reporting risk and deficiency evaluation.
- Challenged management override and executive incentive risk without assuming investigative, legal or audit authority.
- Worked with Audit Committees, Internal Audit and external auditors while protecting management ownership and assurance independence.
- Delivered entity-control frameworks that operating owners sustained through certification after consultants withdrew.
Non-negotiables
- The named architect must lead Minneapolis executive walkthroughs and the accelerated certification acceptance exercise.
- No current relationship may compromise independence from the external auditor, control adviser or whistleblower provider.
- Management performs and concludes on controls; Internal Audit and external auditors retain independent roles.
- Attestation, investigation, legal advice, Quality remediation and process-control implementation are expressly excluded.
- 49 words maximum. Describe an entity-level control that looked strong on paper but lacked enough precision to operate.
- 49 words maximum. How did you connect a non-finance allegation to financial-reporting risk without conducting the investigation?
- 49 words maximum. Which client evidence is essential before testing management-override monitoring?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.