Resources

The regimes we cover, explained.

A plain-language reference for the programs incep2t runs: what each regime requires, who it applies to, and what the work actually involves.

incep2t / resources / SOX

SOX

US · Financial reporting

The Sarbanes-Oxley Act requires US-listed companies to design, test and certify the internal controls over their financial reporting, every year, with management and the external auditor both signing off.

Who it applies to

Any company listed on a US exchange, and often its subsidiaries.

What it involves

Scoping and risk assessment, a risk & control matrix, control testing across the population, deficiency evaluation, and a management assertion filed with the annual report.

ICFR

India / UK / Global · Financial reporting

Internal Controls over Financial Reporting is the equivalent obligation outside the US: the board and management must assess and report on whether financial controls are designed and operating effectively.

Who it applies to

Listed companies in India (Companies Act, Section 143(3)(i)), the UK and other jurisdictions with an equivalent internal-controls mandate.

What it involves

The same core discipline as SOX: process narratives, a control matrix, testing, and a formal management assessment reported to the board and auditor.

ERP transformation

Any regime · Technology change

An ERP implementation or migration rebuilds the systems a company’s controls depend on. If controls and access design aren’t rebuilt alongside the new configuration, the control environment goes stale the day it goes live.

Who it applies to

Any company running an ERP implementation, migration or major upgrade, alongside whichever financial regime it already answers to.

What it involves

Control rationalization against the new design, SoD conflict analysis on new roles and access, ITGC assessment of the new environment, and testing before and through go-live and hypercare.

GDPR

EU / UK · Data protection

The General Data Protection Regulation governs how companies collect, process and protect the personal data of individuals in the EU and UK, with substantial fines for non-compliance.

Who it applies to

Any company processing the personal data of individuals in the EU or UK, regardless of where the company itself is based.

What it involves

A record of processing activities (ROPA), data protection impact assessments (DPIA) for high-risk processing, consent and data-subject-request handling, and a 72-hour breach notification obligation.

DPDP

India · Data protection

The Digital Personal Data Protection Act is India’s data protection law, setting obligations for how personal data is collected, processed and safeguarded, with added duties for organizations classified as Significant Data Fiduciaries.

Who it applies to

Any company processing the personal data of individuals in India, with heightened obligations for Significant Data Fiduciaries.

What it involves

A processing inventory, DPIAs, consent and notice management, a data-subject-request register, and breach obligations tracked to the statute’s own timelines.