Skip to main content

Elevate

Case Study | Consolidated Water

Serving as the IT Internal Audit Function for a Public Company SOX Program

This SOX compliance case study documents how Consolidated Water Co. Ltd. (NASDAQ: CWCO) has relied on Elevate Consult as its IT internal audit function for more than 15 years, with ITGC and application control testing supporting its annual ICFR attestation.

C A S E   S T U D Y

Scaling AI Governance with Confidence

C L I E N T

Consolidated Water Co. Ltd. (NASDAQ: CWCO) – Coral Springs, FL

INDUSTRY

Water Solutions / Seawater Desalination

SERVICES PROVIDE

SOX Compliance (IT), IT Internal Audit

ENGAGEMENT
April 2025 to February 2026 (relationship of more than 15 years)
“Elevate has provided our company, Consolidated Water Co. Ltd., with more than 15 years of outstanding service. They have served in an internal auditor capacity and have proven to be highly valuable in ensuring that we have met and continue to meet the financial reporting control requirements for public companies under the Sarbanes-Oxley Act.”
VP of Finance, Consolidated Water Co. Ltd.

Client Profile

Consolidated Water Co. Ltd. (NASDAQ: CWCO) is a publicly traded water solutions company that develops and operates seawater desalination and water treatment and distribution systems, with U.S. operations based in Coral Springs, Florida. As an SEC-registered public company, Consolidated Water is subject to the internal control over financial reporting (ICFR) requirements of the Sarbanes-Oxley Act (SOX), which require management to assess, and the external auditor to attest to, the effectiveness of controls over financial reporting. 

A significant portion of SOX scope at a public company is IT-dependent: the IT general controls (ITGCs) and application controls supporting the systems key to the financial reporting process must be tested each cycle. Consolidated Water has relied on Elevate Consult in an internal audit capacity for more than 15 years to support its SOX program, including the IT controls testing that underpins its annual ICFR attestation.

The Challenge

The company needed support managing and executing IT-dependent SOX control testing while coordinating internal resources, evidence requests, external auditor inquiries, and reporting-cycle deadlines. The engagement required more than completing ITGC and application control testing. It also required active project management across company personnel, control owners, internal audit stakeholders, and the external auditor to keep testing organized, evidence moving, and open items visible. Three connected challenges shaped the work:

Coordinating internal resources and evidence collection.

The systems supporting financial reporting required ITGC and application control testing across areas such as access, change management, operations, and automated/application controls. The company needed assistance coordinating with internal resources to obtain complete and timely evidence for testing.

Managing external auditor requests and follow-up inquiries.

Because the work supported external audit reliance, testing workpapers needed to be organized, clearly documented, and responsive to external auditor expectations. The engagement required ongoing coordination to address external auditor questions and provide timely follow-up where additional explanation or support was requested.

Maintaining testing structure, risk alignment, and budget discipline.

The SOX program required testing to remain aligned with the risk and controls matrix, while also incorporating relevant cybersecurity testing results into the updated risk assessment. The company needed the work managed efficiently, with observations clearly communicated and remediation support provided where control gaps surfaced.

As the company’s long-standing internal audit partner for IT, the engagement also required continuity and institutional knowledge of the company’s systems, control owners, and SOX control environment across reporting cycles. 

The Solution

Elevate Consult served as the IT internal audit function supporting Consolidated Water’s SOX compliance program, performing the IT controls testing and documentation required for the company’s annual ICFR attestation. Work was led by Elevate professionals holding CISA and CRISC credentials with deep SOX IT audit experience.

 

Risk and Controls Matrix

Maintained and updated the risk and controls matrix mapping financial reporting risks to the IT general controls and application controls in SOX scope 

Confirmed the systems key to the financial reporting process and their in-scope controls 

ITGC and Application Controls Testing

Tested IT general controls across the in-scope systems, with working papers prepared for external auditor reliance 

Tested application controls supporting the financial reporting process, documented in external auditor working papers 

Prepared workpapers to the external auditor’s documentation and sampling expectations 

Cybersecurity Testing and Risk Assessment

Performed cybersecurity testing and incorporated the results into an updated risk assessment 

Reflected IT and security risks in the SOX control environment and the risk and controls matrix 

The Outcome

Organized and efficiently executed SOX IT control testing that supported external audit reliance and strengthened confidence in the internal audit process.

The company’s IT-dependent SOX controls were tested and documented for the reporting cycle, including ITGC and application control testing. The engagement team proactively managed the project, maintained clear organization across the testing workpapers, and supported timely responses to external audit inquiries. 

The company gained confidence that the work was performed in a structured, efficient, and well-managed manner. Observations and recommendations were communicated to management, with remediation support provided where control gaps surfaced. The engagement continued a long-standing relationship in which Elevate has supported the company’s SOX program in an internal audit capacity for more than 15 years. 

Tested and documented ITGC and application controls supporting SOX compliance 

Supported external audit reliance through organized testing workpapers and responsive follow-up 

Proactively managed testing status, workpaper organization, and external audit coordination 

Communicated observations and recommendations accepted by the company 

Incorporated cybersecurity testing results into an updated risk assessment 

Provided remediation support where control gaps surfaced 

Services Provided

IT Internal Audit for SOX Compliance 

External Auditor Working Paper Preparation 

Risk and Controls Matrix Development and Maintenance 

Cybersecurity Testing and Risk Assessment 

IT General Controls (ITGC) Testing 

Remediation Support 

Application Controls Testing 

Why Elevate Consult

Audits don’t reward good intentions. They reward evidence. Elevate Consult is a B2B advisory firm specialized in cybersecurity, GRC, and AI governance, with professionals holding CISA, CRISC, and CPA credentials, alongside ISO 27001 and ISO 42001 Lead Auditors, SOC 2 specialists, SWIFT CSP Certified Assessors, and CMMC Certified Assessors on staff. Elevate supports SOX IT compliance as an internal audit partner, delivering ITGC and application control testing and documentation that external auditors can rely on, on the external audit timeline. 

Frameworks Elevate supports: SOX (IT controls, ITGC and application controls), Internal Audit (IIA Global Internal Audit Standards), SOC 2, ISO 27001 (ISMS), ISO 27701 (PIMS), ISO 42001 (AIMS), NIST AI RMF, EU AI Act readiness, GDPR, CPRA/CCPA, CMMC, FedRAMP, SWIFT CSP, FedLine SSAP, CMS EDE

FAQ

How did Consolidated Water support its SOX IT controls testing?

Consolidated Water Co. Ltd. engaged Elevate Consult as its IT internal audit function for SOX, performing IT general controls and application controls testing, maintaining the risk and controls matrix, incorporating cybersecurity testing into an updated risk assessment, and providing remediation support, with workpapers prepared for external auditor reliance.

What are ITGCs and application controls in a SOX audit?

IT general controls (ITGCs) are controls over the IT environment supporting financial reporting systems, covering areas such as access, change management, and operations. Application controls are controls within the applications that process financial transactions. For Consolidated Water, Elevate Consult tested both and documented them in working papers prepared for external auditor reliance.

Can a firm serve as a company's IT internal audit function for SOX?

Yes. Consolidated Water Co. Ltd. has relied on Elevate Consult in an internal audit capacity for more than 15 years to support its SOX program, including the IT general controls and application controls testing that underpins its annual internal control over financial reporting attestation.

Ready to scope your SOX IT controls support?

Audits don’t reward good intentions. They reward evidence.

Prefer to start on your own? Get the Free AI Governance Training