SOC, SOX and US filings, run from India
We support US-facing compliance end to end: SOC 1 and SOC 2 readiness and evidence management, SOX scoping and control testing under COSO, and preparation of US federal and state returns. We work as the offshore engagement team for technology companies and for CPA firms that need capacity.
A SOC 2 report is now the price of entry for selling software to any serious US buyer, and a SOX programme consumes a controller's entire year. Both are mostly disciplined evidence work — which is exactly the kind of work a well-run offshore team should be doing.
SOC services
These services help a company build trust with its clients by validating the controls behind security, availability, processing integrity, confidentiality and privacy.
Most first-time SOC failures are not control failures. They are evidence failures — the control existed, but nobody could produce nine months of proof that it ran every time.
- SOC readiness assessments. Evaluating your current control environment against the SOC frameworks to identify gaps before the formal audit
- Assistance with SOC 2 examination and reporting. Supporting the audit of operations and compliance controls against the Trust Services Criteria — security, availability, processing integrity, confidentiality and privacy
- SOC 3 reporting. A high-level, publicly disclosable version of the SOC 2 report, without the confidential detail
- Remediation support. Designing and implementing the controls that readiness testing shows are missing
SOX compliance services
These services keep publicly traded companies — and private companies preparing for an IPO — reporting accurately, through internal controls that are documented, tested and defensible.
We handle the parts of a SOX programme that scale badly with headcount, working under your control owners and to your external auditor's expectations.
- SOX readiness. Designing a brand-new SOX compliance programme for a private company going public
- Scoping and risk assessment. Determining which financial systems, applications and business units are material to financial reporting
- Control documentation. Creating and updating risk control matrices, process flowcharts and narratives
- Testing of operating effectiveness. Executing transaction and control testing to confirm that policies are consistently followed
- Deficiency management. Evaluating control failures — deficiencies, significant deficiencies and material weaknesses — and advising on remediation plans
- Liaising with external auditors. Managing the relationship and the data sharing, to reduce audit friction
ITGC services
Information Technology General Controls are the foundation under both SOC and SOX. If access, change and operations controls are weak, nothing built on top of them can be relied on.
- Access control management. Auditing user provisioning, termination, privileged access and periodic user access reviews
- Change management review. Testing controls around software development, configuration, source code modification and emergency changes
- IT operations oversight. Assessing backup management, job scheduling, incident response and problem management procedures
- Physical and environmental security. Reviewing data centre controls, badge access and environmental monitoring
- Network and security infrastructure assessment. Reviewing firewalls, vulnerability management and patch management practices
US return filing and accounting support
We prepare and review US federal and state filings, and run day-to-day US GAAP bookkeeping and close, either directly for a company or white-labelled for a CPA firm that needs capacity through busy season.
- Form 1120, 1120-S and 1065 preparation and review support
- State income, franchise and sales tax filings, and multi-state apportionment
- US GAAP bookkeeping, month-end close and reconciliations
- 1099 and W-2 season support, and fixed asset and depreciation schedules
- White-label engagement support for CPA and accounting firms
What you get
- SOC readiness and gap analysis
- Policy and control documentation set
- SOC 2 examination and SOC 3 reporting support
- SOX RCM, testing and remediation tracking
- ITGC testing across access, change and operations
- US federal and state return preparation
- Dedicated offshore team
Technology and services clients
The pattern is consistent: the first SOC 2 cycle takes six to nine months and consumes a founder's attention; the second takes weeks, because evidence is being collected continuously rather than reconstructed. The work is in building that second state early.
Questions we get asked
What is the difference between SOC 1, SOC 2 Type 1 and Type 2?
SOC 1 covers controls relevant to a client's financial reporting. SOC 2 covers the Trust Service Criteria — security, availability, processing integrity, confidentiality and privacy. Type 1 tests whether controls are designed correctly at a point in time; Type 2 tests whether they actually operated over a period, typically three to twelve months. Enterprise buyers almost always want Type 2.
Can you issue the SOC 2 report?
No, and nobody who prepares you should. The report must be issued by an independent licensed CPA firm. Our role is readiness, remediation, documentation, evidence management and support through fieldwork, which is where the work and the cost actually sit. We coordinate with your chosen audit firm.
How long does SOC 2 readiness take?
Six to twelve weeks to become audit-ready for a Type 1 in a company with reasonable engineering hygiene. A Type 2 then needs an observation window of three months at minimum, more commonly six to twelve, during which the controls have to demonstrably run.
Do you work with US CPA firms as a back office?
Yes. A meaningful part of this practice is white-label support for CPA firms during busy season — preparation and review of returns, bookkeeping and close, worked in the firm's own systems under an NDA and to the firm's templates and standards.
How do you handle data security for US client data?
Work happens in your environment wherever possible. Where it cannot, access is role-based and logged, records are not stored on local machines, and client data is never submitted to AI systems that train public models. We will sign your NDA, DPA and security addendum.
Often needed alongside this
Internal Audit & Assurance
Internal audit tests whether your controls actually work — not whether the accounts balance. We run internal audits, stock and receivable verification…
Read moreBusiness Software
We build and support two products for Indian MSMEs. Nakad handles POS billing, invoicing, customer credit limits and automated collection follow-up on…
Read moreSOPs & Process Consulting
Process consulting replaces people-dependence with system-dependence. We document how purchase, stores, payroll, sales and accounts actually work, red…
Read moreStart with a free 30-minute review of your numbers
Send us the last two years' balance sheets and the pain point that is bothering you most. We come back with things you can fix in the next quarter — no obligation, no sales deck.