NI 52-109  ·  SOX 404  ·  COSO 2013

One stop. Full accountability.

OSA — short for One Stop Accountability — is a single system of record for your entire internal controls program. It automates the identification, mitigation, and evaluation of financial reporting risks — risk assessment, control testing, gap remediation, management reporting, and process owner certifications — mapped directly to your financial statements and built on the COSO 2013 risk management framework, so organizations can optimize the efficiency of their financial reporting processes and meet NI 52-109 (Canada) and SOX 404 (U.S.) requirements without the manual, spreadsheet-driven labor most teams rely on today.

2013
Founder's advisory
practice began
20+
Organizations successfully
advised on internal controls
audit compliance
COSO
2013 Framework fully
referenced for regulatory
requirements

Why OSA

Within the competitive landscape of compliance software, OSA aims to deliver the highest quality service at the lowest price. High quality — built on significant experience and a historically consistent record of positive outcomes for clients' internal controls systems. Low cost — competitively priced subscription fees, made possible by the deliberately small size of the OSA service organization. Built for growing and newly public issuers who don't need (or want to pay for) Fortune-500-scale GRC software.

Product Overview

Risk management framework compliance

Executives certify with comfort that the evaluation is designed to comply with the five components and 17 principles of the COSO 2013 Framework.

Centralized evaluation management

Risk assessments, controls, test evidence, and remediation are collected in a single system — not scattered on the network, across spreadsheets and inboxes.

Executive regulatory support

Process owners certify on the effectiveness of controls and remediation efforts to close gaps. Certification review comments and change indicators are captured in workflows to ensure documentation is up to date and relevant.

Increased quality and reduced compliance costs

Automation replaces manual coordination and communication across process owners, testers, and reviewers. Automated dashboard reporting provides real-time evaluation status visibility to management and stakeholders.

Audit preparation and transparency

Versioning provides an evidence trail of all changes; sign-offs are timestamped and traceable for internal and external audit. Attach policies and test sheets for complete analysis.

Clear and purposeful user experience

The certification process highlights the cause-and-effect relationship between risk and controls, presented in basic terms to process and control owners to ensure internal control accountabilities are understood and stewarded effectively.

Ease of system implementation

Cloud SaaS on the AWS platform with no integrations to your existing systems. AWS data is encrypted, and processes are compliant with SOC 1/2/3 and ISO 27001 certified infrastructure requirements.

Consulting services flexibility

Clients can choose to have the evaluation performed by OSA's experienced external consultants, or we can train your internal resources to perform the evaluation in-house.

Thoughtful AI adoption

An AI Agent is being developed for the next version of the OSA application, with caution in mind to ensure sufficient human judgement is involved in reaching appropriate conclusions about the effectiveness of internal controls. The current pace of AI agent introduction can seem overwhelming, so OSA's development is careful to ensure utility and benefit is derived rationally, rather than overwhelming the user with misaligned AI capabilities. OSA is built and maintained by a licensed CPA with two decades of practical experience — not just an algorithm.

Key Features & Benefits

One platform for the entire ICFR lifecycle

Each system capability is strategically designed so the evaluation delivers a user-friendly experience while ensuring the application content is relevant to optimizing organizational processes and meeting regulatory compliance requirements.

Request a Demo

See OSA on your own control set

Tell us about your organization and your ICFR requirements — we'll follow up to schedule an introductory meeting to discuss how OSA can optimize your internal controls.

Company representative contact
Company size
Opens a pre-filled email to send to our team — no data is stored.

Request drafted

Your email client should now have a pre-filled message with your demo request. Send it over and we'll be in touch to schedule a demo.

Qualifications, Experience & Security

Led by a Founder with two decades in the profession

OSA's Founder is a Chartered Professional Accountant (CPA) with 20 years of experience in financial reporting, internal audit, and internal control over financial reporting. Since 2013, they have advised and serviced more than 20 organizations on SOX 404 and NI 52-109 compliance programs — work that directly informed the "one stop" philosophy behind the OSA platform's design.

We value a strong cybersecurity posture, and as a service provider we are working to assure you that OSA's IT governance controls — including user access and change management — are aligned with industry security standards. OSA is currently undergoing a SOC 2 examination to formally validate the platform's controls.

20
Years as a CPA
20+
Organizations serviced since 2013

Resources

Grounded in the framework you already report to

A starting set of resources — to be expanded with product-specific guides and client case studies over time.

COSO Governance

COSO is a joint initiative of five private-sector professional associations, each represented on its board. OSA's control structure is built around the framework these organizations jointly govern.

Source: coso.org/governance

The Five Components and 17 Principles of the COSO Framework

Executive Summary →

Control Environment

  1. Sets the tone through integrity and ethical values across the organization
  2. Board oversight is independent of management and exercises effective governance
  3. Management establishes structures, reporting lines, and authorities
  4. Attracts, develops, and retains competent people
  5. Holds individuals accountable for their internal control responsibilities

Risk Assessment

  1. Specifies clear objectives so risks can be identified and assessed
  2. Identifies and analyzes risks to achieving those objectives
  3. Considers the potential for fraud when assessing risk
  4. Identifies and evaluates changes that could significantly affect internal control

Control Activities

  1. Selects and develops control activities that mitigate risk to acceptable levels
  2. Selects and develops general controls over technology
  3. Deploys controls through policies and procedures, and puts them into action

Information & Communication

  1. Uses relevant, quality information to support internal control
  2. Communicates internally, including objectives and responsibilities for internal control
  3. Communicates with external parties about matters affecting internal control

Monitoring Activities

  1. Conducts ongoing and/or separate evaluations of internal control
  2. Evaluates and communicates deficiencies to those responsible for corrective action

Product Walkthrough

A guided video tour of risk assessment, testing, remediation, and certification inside OSA.

Downloadable Resources

Product brief and an ICFR readiness checklist for teams preparing their first SOX 404 or NI 52-109 cycle.

Case Studies

Placeholder formats below — to be replaced with named engagements as client consent and the SOC 2 report are finalized.

Contact

Questions before you request a demo?

Reach out directly and a member of the team will respond.

Email Us →