System and data scope
Identify applications, integrations, spreadsheets, databases, infrastructure, service providers, and manual processes that can affect financial reporting. Record owners and dependencies before testing controls.
North Star helps Canadian organizations document, test, and improve the technology controls that support reliable financial reporting. The work is designed around accountable owners and usable evidence—not a claim that an IT provider can certify an issuer.
Canadian searchers often use “Canadian SOX” as shorthand when looking for controls related to financial reporting. The applicable Canadian instrument is National Instrument 52-109, Certification of Disclosure in Issuers' Annual and Interim Filings. The instrument and its companion policy address issuer certification, disclosure controls and procedures, and internal control over financial reporting. Applicability and management's obligations should be confirmed with securities counsel and the organization's auditors.
Identify applications, integrations, spreadsheets, databases, infrastructure, service providers, and manual processes that can affect financial reporting. Record owners and dependencies before testing controls.
Review user provisioning, role design, privileged access, segregation concerns, MFA, shared accounts, periodic access reviews, emergency access, and timely removal when duties change.
Document requests, approvals, development, testing, migration, emergency changes, and evidence. The process should cover configuration, code, integrations, reports, and infrastructure that can affect relevant data.
Assess scheduled jobs, interfaces, monitoring, incident handling, backups, restoration, vulnerability remediation, and capacity. Exceptions need owners, impact assessment, and evidence of resolution.
Map vendors to control objectives, contracts, service reports, complementary user controls, subservice organizations, data access, incident notification, and exit procedures.
Define what demonstrates operation, where evidence is retained, who reviews it, how exceptions are evaluated, and how remediation is tracked through retesting and closure.
North Star begins by agreeing on scope with management, finance, IT, legal counsel, and auditors as appropriate. We document the current environment and map technology activities to the control objectives supplied by the organization. We can then help close technical gaps, produce operating procedures, assign evidence owners, and establish a review calendar.
Deliverables may include an IT system inventory, risk and control matrix, access and change-management procedures, evidence index, vendor responsibility register, backup and recovery test results, exception log, remediation plan, and status reporting. Work can be completed remotely across Canada. Physical work is quoted separately and scheduled honestly from Prince George or Grande Prairie.
North Star does not provide legal opinions, financial-statement audit services, issuer certification, or independent assurance. Management, legal counsel, and the organization's auditors determine applicability, materiality, testing reliance, and reporting conclusions. Our role is technical assessment, implementation, documentation, evidence support, and ongoing operation within an agreed scope.
Use the SOC 2 page for service-organization trust criteria and readiness work; it is not the owner for Canadian SOX searches.
Use the managed compliance page for recurring evidence collection, review calendars, ownership, and remediation follow-through.
Use the cybersecurity hub for security risk assessment and controls that are broader than financial-reporting scope.
Bring the reporting scope, systems, service providers, existing controls, known exceptions, and deadlines. North Star will define a practical technical work plan.
Request an assessment