Most comp teams catch the gap before payroll runs. The problem isn't the error — it's that the fix leaves no trail.
She caught the gap on Tuesday.
HRIS said terminated. The incentive compensation system — ICM — still had the rep active. She found it during her weekly reconciliation, updated the record, flagged it to her manager, moved on. The comp cycle ran clean. Nobody got an errant payment. The control worked exactly as designed.
Three months later, the auditor arrived.
He asked for the working paper on comp controls for the quarter. She searched her email. She checked her spreadsheet. She found her own note — a single line in a tab labeled "issues" — but no timestamp, no closed state, no cross-system verification. She spent the next two days reconstructing what happened from memory, a Slack thread, and a spreadsheet that had been overwritten twice since March.
The auditor was patient. The room was not.
This is not a story about failure. The control worked. The comp analyst found the gap, closed it, and prevented an errant payment. That is the definition of a functioning control. The problem is that a functioning manual control disappears the moment it completes. The fix lives in the analyst's memory, in a Slack thread, in a spreadsheet only she can find. It is structurally undocumentable — not because no one tried, but because manual reconciliation was never designed to produce evidence.
That Tuesday event is not an exception. Comp teams at growth-stage companies handle dozens of these events per year. A termination that didn't propagate. A promotion that left the old quota active. A territory reassignment that ICM never received. Each one caught. Each one corrected. Each one gone — leaving no record that the detection happened, no record of the gap itself, no record of the resolution.
The control works every time. The proof disappears every time.
This distinction matters more than most comp teams realize. An auditor is not looking for evidence that your systems are perfect. They know they are not. They are looking for evidence that you caught the disagreements, that you have a mechanism to do so systematically, and that you can demonstrate — with documentation — that mechanism operated throughout the reporting period. Not on the day of testing. Not in a post-hoc reconstruction. Throughout.
Manual reconciliation can deliver the first part. It cannot deliver the third.
This is not an informal standard. PCAOB Auditing Standard AS 2201 — the standard governing integrated audits of internal control over financial reporting — makes the distinction explicit. Paragraph .47 classifies manual controls as inherently higher risk than automated controls. Higher risk means more evidence required. More evidence means larger samples, more analyst hours, and more reconstruction work at audit time. The auditor is not being difficult. They are following a standard that treats your manual reconciliation process as a higher-risk control by definition — regardless of how well it actually works.
SOX Section 404 requires internal controls over financial reporting to meet three standards. Most RevOps and comp teams are familiar with the first. Almost none can demonstrate the third.
Most RevOps and comp teams are familiar with the first standard. Almost none can demonstrate the third.
The auditor is not looking for evidence that your systems are perfect. They are looking for evidence that you caught the disagreements, that you have a mechanism to do so systematically, and that you can demonstrate — with documentation — that mechanism operated throughout the reporting period.
— PCAOB AS 2201, operating effectiveness standard
The auditor traces five questions for every event in the sample:
Questions 2 through 5 require a timestamped record that existed at the time of the event — not a reconstruction assembled after the fact. Manual reconciliation is structurally incapable of producing that record for every event, at scale, throughout a full quarter.
See if your org has this pattern right now.
Scan my data →The auditor does not fail you because the error happened. The auditor flags you because the documentation doesn't exist to prove you caught it, traced it, and closed it. That failure note goes into the management letter. The CFO reads it. The audit committee asks why.
There is a second exposure most comp teams don't consider. ASC 340-40 governs the capitalization of incremental costs to obtain contracts — which includes sales commissions. If a commission was calculated on incorrect plan terms, capitalized, and later reversed, but no documentation exists of the detection and resolution, the capitalized amount may be in question. This is not a hypothetical. This is the kind of item that surfaces in restatement conversations.
The audit scramble has a number. KPMG's 2025 SOX Survey found that average testing hours per control rose to 16 hours in FY2024 — up from 12 hours in FY2022, a 33% increase in three years. Comp controls are among the most labor-intensive because they span multiple systems and require the auditor to trace events across HRIS, ICM, and payroll independently. Internal audit teams running SOX 404 comp controls testing spend an estimated 40 to 80 hours per audit cycle on reconstruction alone — pulling emails, locating spreadsheets, interviewing analysts, assembling a narrative the auditor will test against a standard no one wrote down explicitly.
The flip side is equally documented. Gartner found that organizations automating at least 25% of their internal controls paid 27% lower audit fees on average — and for companies with fewer than 50 controls, the effect reached 52% lower fees when more than a quarter of controls were automated. That's not a rounding error. That's a headcount. Automated controls require less auditor time to test, less client time to support, and less reconstruction work to assemble. The documentation exists before the auditor arrives. The auditor's hours drop. So does the bill.
For a company paying $180,000 to $485,000 annually in manual commission controls testing — the current range for Big Four engagements covering this scope — a 27% reduction is $49,000 to $131,000 per year. That math belongs in the conversation your CFO has about whether controls automation is a compliance cost or a finance decision.
If you want to see what a drift log looks like as a working paper, run a free scan. The evidence structure is the same — just scoped to your data.
The comp analyst still finds the gap. The human is still in the loop. The reconciliation process does not change. OrgDrift is not replacing the analyst's judgment. It is recording her work.
Here is what a single event looks like when it is logged rather than fixed and forgotten:
Event detected: 2026-01-14 09:42 UTC
Systems in disagreement:
HRIS → status: terminated (effective 2026-01-10)
ICM → status: active (last updated 2025-11-03)
Category: Termination propagation
Severity: High
Assigned to: [comp analyst] 09:42 UTC
Resolution: ICM record updated, plan deactivated
Closed: 2026-01-14 11:07 UTC
Comp impact: None — caught before cycle
However many events your quarter produced — a dozen after a quiet period, forty after a reorg, more if territory changes ran late — all automatically organized. All timestamped. All traceable to specific systems, specific fields, specific resolution actions.
The audit sample pull becomes: export the drift log for Q3.
Every event. Every gap. Every resolution. Every timestamp. Every name. Most of that time is reconstruction. Documentation that should have been built during the quarter gets built in the two weeks before the auditor arrives.
When the log exists, audit prep for comp controls becomes an export. Analyst stress at audit time — eliminated. CFO Section 302 certification — supported by documented evidence, not verbal assurance.
For PE Operating Partners: "We have a full audit trail across all portfolio companies showing every comp control event, resolution, and timestamp" is a different due diligence conversation than "we have a good team."
I ran global sales compensation at CyberArk. I have been in both of these rooms.
The first room is the audit scramble room. The auditor asks for the working paper on comp controls. The team spends two days pulling emails, locating spreadsheets, interviewing analysts, reconstructing a narrative that may or may not hold together when tested against what the systems actually show. The auditor is patient. The Controller is in the back of the room watching hours turn into days. The CFO gets a summary later. The summary does not mention how the documentation was assembled.
I know what that room costs — not in audit findings, but in trust. Nobody in that room is incompetent. The comp team did their job. The controls worked. The cost is that a functioning control looks indistinguishable from a missing control when the documentation doesn't exist to tell them apart.
The second room is where OrgDrift was born.
A SOX director was reviewing an automated reconciliation log I had built — a manual precursor to what OrgDrift does today. She went quiet. Not to critique it. Not to request additional documentation. She stopped to recognize it.
"This is what I've been asking for."
Not a better process. A process that proves itself.
Every timestamped entry was a working paper. Every closed event was evidence of operating effectiveness. Every quarter was audit-ready, not because the team prepared for it, but because the documentation was built into the operational workflow from day one. The control didn't just work. It proved it worked. Automatically.
That second room is the entire product.
OrgDrift is building the operational process that makes comp controls not just effective, but provably effective.
Detect the event: automatically, across HRIS and ICM, at the moment of system disagreement. Verify the fix: close the event with a timestamped resolution record attached to a specific analyst action. Prevent the exposure: eliminate the audit reconstruction entirely, because the working paper builds itself throughout the quarter.
This is what OrgDrift Verify delivers today — a standing record that every reorg, departure, and role change was verified. Remediate (roadmap) will layer the tag/triage/sign-off workflow on top, so control owners across teams can close findings in one place with an audit trail. Together they turn SOX comp-control prep from a three-day reconstruction into a 20-minute review.
Drop in a CSV export from your HRIS, CRM, or comp system. Get your ODIS in minutes. Your data never leaves your browser.
Scan my data →No IT ticket. No OAuth. No data upload to any server.
Get Drift Notes
Short, sharp field notes on data propagation, control risk, and audit pain.
The verification layer between your systems and your auditors.
“Your org changed. Nobody told your data.”
Every record sealed with a tamper-evident hash
Your data never leaves your browser
Enterprise compliance certification in progress