12 requirements evaluated: 6 supported, 6 partial.
Supported
Requirement evaluated: The platform must support the full internal audit lifecycle beyond SOX, including annual audit planning (risk assessment, audit universe, resource scheduling), fieldwork execution with structured workpapers, and issue tracking through resolution. Workpapers must support version locking and reviewer sign-off to meet documentation standards appropriate for a newly public company establishing its internal audit function.
For a newly public company standing up its internal audit function from spreadsheets, Diligent's Audit Management module (part of the One Platform, formerly HighBond) covers the full internal audit lifecycle in a structured sequence. At the planning stage, the Audit app lets the team define and maintain an audit universe of auditable entities, then score and prioritize those entities through a formal risk assessment; the risk assessment results link directly to an annual audit plan with timeline and scope management for each engagement. Resource utilization is tracked visually across the organization within the platform, supporting capacity-based scheduling. …
Limitations: The sign-off chain is configurable up to five levels, which is unlikely to constrain a newly public company but would be a ceiling for larger, more complex review hierarchies. …
Partial
Requirement evaluated: The platform must enforce role-based access controls that segregate permissions between control owners (who can only respond to evidence requests and view their assigned controls), internal auditors (who can execute tests and document workpapers), and audit leadership and external auditor read-only roles (who can review but not modify completed workpapers or locked test results). This is required for a post-IPO SOX 404 environment where external auditors will review the platform's evidence and documentation.
For a post-IPO SOX 404 program, Diligent One Platform (formerly HighBond) enforces RBAC through a layered model combining org-level privileges set in Launchpad with project-level roles assigned per engagement. Control owners are mapped to the Contributor User role: <cite index="62-1,62-2,62-3">users assigned the Contributor User role only have access to items they have been assigned, and depending on their part in the project (Control Owner, Action Owner, Issue Owner, etc.) they can have edit, read-only, or no access to individual items</cite> — meaning a control owner cannot browse the full control universe. …
Limitations: The most material gap for this buyer's four-persona SOX requirement is that audit leadership and external auditors share the same Oversight Reviewer role with no separately named, distinct role to enforce governance separation between an internal leadership reviewer and an external party — there is no dedicated 'extern …
Supported
Requirement evaluated: The platform must support structured scheduling, documentation, and sign-off for control walkthroughs and design-effectiveness testing, replacing the buyer's current manual, email-based process. Each test must be linkable to a specific control in the RCM, must support attachment of evidence, and must enforce a reviewer/approver workflow so that no test is considered complete without documented sign-off.
For a post-IPO SOX team currently managing walkthroughs and testing in spreadsheets and email, Diligent One Platform (formerly HighBond) provides a dedicated Internal Control workflow within its Projects module that creates a structured, linked record for every control. <cite index="17-12">For each control defined in a project, a test plan, walkthrough, and testing round are automatically created</cite>, so walkthroughs (design effectiveness) and test plans (operating effectiveness) are distinct objects tied to the specific control in the framework, replacing free-text email references. …
Limitations: A Professional Manager role can override a completed sign-off post-hoc, which should be documented in the buyer's SOX procedures to maintain audit trail integrity. …
Supported
Requirement evaluated: The platform must provide a deficiency tracking and remediation workflow that captures control deficiencies identified during testing, classifies them by severity (control deficiency, significant deficiency, material weakness), assigns remediation owners, sets due dates, sends automated reminders, and tracks remediation closure with supporting evidence. This replaces the buyer's current manual follow-up process and must produce a roll-up view of open deficiencies suitable for audit committee reporting.
For a newly public company replacing manual spreadsheet follow-up, Diligent One Platform's Projects app provides a structured issues-and-actions module that captures deficiencies identified during SOX control testing directly in workpapers, links them to the originating control and project, assigns remediation owners with defined action plans and due dates, and sends automated email notifications to owners on assignment plus configurable recurring reminders until closure. The Follow-up and Remediation tab allows owners to submit management responses and remediation plans; auditors then retest and record findings on a dedicated Retest Information subtab before marking items resolved. …
Limitations: The severity field is configurable rather than arriving pre-populated with an enforced SOX-specific three-tier picklist (control deficiency, significant deficiency, material weakness); the buyer must configure and enforce these field values during implementation to ensure consistent classification for roll-up reporting …
Showing the 4 most recent of 12. The rest are in the comparisons listed below.