When Internal Controls Break Down at Scale: A Case Study in What No One Warns You About

The controls weren’t wrong when they were written. They became wrong because the company outgrew them. And nobody owned keeping them current.
That’s the internal control failure pattern that shows up most often in growth-stage tech companies preparing for or navigating SOX compliance. Not fraud. Not negligence. Just a framework designed for a company that no longer exists.
Key Takeaways
- Internal controls fail at scale not because they were poorly designed, but because they were designed for a smaller, simpler version of the company
- Cross-functional ownership gaps, not technical errors, are the primary cause of SOX deficiencies at growth-stage tech companies
- A control that lives in one department’s documentation but touches three others is a control that will fail testing
- Remediating a material weakness after audit is 3-5x more resource-intensive than designing the control correctly the first time
- The right internal control framework grows with the company. It doesn’t have to be rebuilt every 18 months
What Are Internal Controls and Why Do They Keep Failing at Growth-Stage Companies?
Internal controls are the documented policies, procedures, and system configurations that ensure financial statements are accurate, complete, and free from material misstatement. For SOX purposes, they’re divided into entity-level controls, process-level controls, and IT general controls. Each layer dependent on the others.
Here’s what the textbook doesn’t tell you: most internal control failures at growth-stage tech companies aren’t design failures. They’re ownership failures. A control gets documented, assigned to one team, and then the company doubles in headcount, changes its ERP, adds a new revenue stream, and hires three new VPs. None of whom were in the room when the original control was written.
The control still exists. It just doesn’t match reality anymore.
The gap between documented controls and actual operations is where auditors find deficiencies. And where companies get blindsided.
Why Does the Standard Advice Keep Missing the Real Problem?
The standard advice on internal controls focuses on documentation quality, COSO framework alignment, and control frequency. All of that matters. But it treats internal controls as a compliance artifact rather than a living operational system.
The COSO Internal Control. Integrated Framework is the recognized standard for evaluating internal control design and effectiveness. It covers five components: control environment, risk assessment, control activities, information and communication, and monitoring. Most SOX consultants can map your controls to COSO. Fewer can tell you why the same controls keep failing in year two and year three.
The real problem is structural. Growth-stage tech companies build controls in functional silos. Finance owns the financial close controls. IT owns the access controls. HR owns the segregation of duties policy. But a journal entry approval workflow touches all three. And when nobody owns the intersection, the intersection breaks.
Consider a typical case: a company completes its first SOX audit as a newly public company, passes with no material weaknesses, and considers the work done. Eighteen months later, they’ve migrated to a new ERP, reorganized their revenue operations team, and promoted two people into roles with conflicting system access. The controls documentation hasn’t been touched. The auditors find three significant deficiencies. The remediation effort takes a full quarter.
That’s not a documentation problem. It’s a maintenance and ownership problem. And it’s almost entirely predictable.
What Does a Control Failure Actually Look Like in Practice?
Most control failures don’t announce themselves. They accumulate quietly until an auditor pulls a sample.
A common scenario: a tech company’s revenue recognition control requires a second reviewer to approve all manual revenue adjustments above a certain threshold. The control is documented, tested, and passes in year one. In year two, the original reviewer gets promoted, the approval workflow is rebuilt in the new system, and the threshold, which was set when average deal size was $50K, no longer captures the adjustments that actually carry material risk because average deal size is now $400K.
The control still runs. It just doesn’t do what it was designed to do.
This is what practitioners in SOX compliance work call a “design gap”. The control exists but its parameters no longer match the risk it was meant to address. Design gaps are harder to catch than operating failures because the control appears to be functioning.
The Cross-Functional Alignment Problem Nobody Talks About
Here’s the contrarian claim worth sitting with: adding more controls doesn’t reduce SOX risk at a growth-stage company. Clarifying who owns each control does.
Over-controlled environments create their own failure mode. When every team has controls assigned to it but no team understands how their controls connect to the others, you get documentation that looks complete and an actual control environment that’s full of gaps. The controls are designed in isolation, owned by one team, and never stress-tested against what happens when two systems talk to each other.
The IT general controls around access management are the clearest example of this. Access provisioning is typically owned by IT. Segregation of duties requirements are set by Finance. The business system configurations are managed by whoever owns the ERP. When a new hire joins the revenue team, all three groups touch the process. And if they’re not coordinating, that new hire ends up with access that violates SOD policy, which IT didn’t know about, which Finance didn’t catch, because nobody owns the intersection.
The control environment is only as strong as the weakest handoff between teams.
The Controls Decay Framework: A Tool for Diagnosing What’s Actually Breaking
Controls decay is the systematic degradation of internal control effectiveness that occurs when organizational change outpaces control maintenance. It’s not a single event. It’s a rate of change problem.
A2Q2 uses a diagnostic approach we call the Controls Decay Framework, which evaluates four decay drivers:
- Organizational change. New hires, departures, role changes, and restructuring that shift who performs or reviews a control
- System change. ERP migrations, integrations, and configuration updates that alter how controls execute
- Process change. New revenue models, M&A activity, or operational changes that introduce risks the original controls weren’t designed to address
- Volume change. Growth in transaction volume or deal complexity that makes previously adequate thresholds immaterial
Use this framework when: you’re 12+ months post-IPO, have completed any system migration, or have grown headcount by more than 30% since your last control design review.
Don’t apply it as a one-time exercise. The value is in running it quarterly. Not as an audit prep activity, but as an operational hygiene check.
What’s the Honest Comparison: Building Controls Internally vs. Working With a Specialized Partner?
| Scenario | Internal Build | Working With A2Q2 |
| Control design timeline | 6-12 months for first-time SOX | 8-16 weeks with experienced guidance |
| Cross-functional alignment | Often siloed by department | Orchestrated across accounting, IT, HR, legal |
| Auditor readiness | Uncertain until tested | Designed with auditor expectations built in |
| Scalability | Rebuilt as company grows | Framework designed to scale with the company |
| Cost of a missed deficiency | Remediation + restatement risk + audit fees | Avoided through proactive design |
| Team bandwidth impact | High. Internal teams carry the full load | Shared. A2Q2 acts as an extension of your team |
The honest tradeoff isn’t cost. It’s risk timing. Building internally is slower and the deficiencies surface at the worst possible moment. During audit. Working with a firm that’s done this specific work for growth-stage tech companies means the gaps get found during design, not testing.
Who Is This Approach Not Right For?
If your company is pre-revenue, pre-Series B, or more than three years away from a public offering, a full SOX-grade internal control framework is premature. The overhead won’t match the risk.
This work is also not a fit if your organization isn’t ready to commit cross-functional ownership. A2Q2 can design the controls blueprint and train every team that touches it. But if Finance, IT, and HR won’t coordinate on execution, the controls will decay on the same timeline as before. The framework requires the organization to actually use it.
And if you’re looking for a firm that will hand you a template and disappear, A2Q2 isn’t that. The value of their approach is in the ongoing calibration. The quarterly check-ins, the system change reviews, the handoff protocols that keep controls current as the company evolves.
Frequently Asked Questions
How do I know if my internal controls are actually failing or just need better documentation? If your controls are documented but your auditors keep finding operating deficiencies, the documentation isn’t the problem. The execution is. If your auditors are finding design gaps, the controls were never built to address the actual risk. Those are two different problems requiring different fixes, and conflating them is one of the most common ways companies waste remediation time.
When should a growth-stage tech company start building SOX-compliant internal controls? Most practitioners recommend starting the readiness process 18-24 months before your expected IPO date. That gives you time to design, implement, and run controls through at least one full cycle before external auditors test them. Starting at 12 months is possible but leaves almost no room for remediation if gaps surface.
What’s the difference between a significant deficiency and a material weakness? A significant deficiency is a control gap that’s less severe than a material weakness but still important enough to warrant attention from those responsible for financial oversight. A material weakness means there’s a reasonable possibility that a material misstatement in your financial statements won’t be prevented or detected. Material weaknesses disclosed publicly can damage stock price, delay filings, and trigger SEC scrutiny. The stakes are meaningfully different.
Why do IT general controls matter so much for SOX? IT general controls. Covering access management, change management, computer operations, and system development. Are the foundation that financial controls sit on. If the system producing your financial data can be accessed or changed without proper controls, every financial control that relies on that system is compromised. Auditors test ITGCs specifically because a failure there can invalidate the entire control environment.
Can we use our existing ERP controls as SOX controls? Sometimes, but not automatically. ERP systems like NetSuite, Workday, or SAP have configurable controls built in. But whether those configurations meet SOX requirements depends on how they’re set up, who has access to change them, and whether they’re tested and documented appropriately. The system having a feature isn’t the same as the control being effective. You can explore how ERP configuration intersects with SOX requirements to understand where the gaps typically appear.
What happens if we find a control gap during our own testing before the auditors do? Finding it yourself is always better than the auditors finding it. Self-identified deficiencies give you time to remediate, document the remediation, and demonstrate to auditors that your monitoring controls are working. The SEC and PCAOB view self-identification as a positive signal about your control environment’s maturity. The worst outcome is a gap that you missed and the auditors caught. Because that raises questions about your monitoring controls, not just the specific deficiency.
How does A2Q2 approach companies that already have some SOX controls in place but aren’t sure if they’re adequate? A2Q2 starts with a diagnostic review. Mapping existing controls against current operations, identifying decay points, and flagging cross-functional ownership gaps. The goal isn’t to rebuild everything; it’s to find what’s actually at risk and fix that specifically. Companies that have been through one or two audit cycles often have a solid foundation with predictable gaps. The work is calibration, not reconstruction.
You’ve Read the Case Study. Now What?
If you recognize your company in any of these scenarios. Controls that haven’t been updated since your last system migration, cross-functional handoffs that nobody formally owns, a SOX documentation library that’s technically complete but operationally disconnected. The next step isn’t another internal review.
It’s a conversation with a team that’s built these frameworks for growth-stage tech companies specifically, not adapted an enterprise model down to your size.
A2Q2 has 18+ years of hands-on SOX implementation experience, built specifically for companies at your stage. If you’re heading into your first or second audit cycle and you’re not fully confident in what your auditors are going to find, reach out to A2Q2 to schedule a controls diagnostic. You’ll leave the conversation knowing exactly where your gaps are. And what it actually takes to close them.
About the Author
A2Q2 is a specialized consulting firm focused on SOX compliance and IPO preparation for growth-stage technology companies. With 18+ years of hands-on Sarbanes-Oxley experience, they help CFOs, Controllers, and cross-functional finance teams design and implement scalable internal control frameworks. Without the bureaucracy that slows companies down at the worst possible time. A2Q2 works with companies ranging from pre-IPO through their first several years as a public company, serving as an integrated extension of the finance and accounting team.
Leave a Reply