Home / Blog / Roll-forward

How to run a SOX roll-forward without redoing the audit file

There are two January rituals in SOX shops. In one, the team opens a clean copy of last year's file, everything carried forward and reset correctly, and starts walkthrough updates in the first week. In the other, someone spends three weeks copying folders, renaming "FY25" to "FY26" inside two hundred documents, deleting old sign-offs by hand, and discovering in October that a workpaper still contains last year's conclusion — signed off by a reviewer who never noticed the dates.

The difference isn't diligence. It's whether the team has a clear rule for what rolls forward and what resets, and a mechanism that applies the rule consistently instead of relying on two hundred manual edits going right.

The core rule: structure rolls, conclusions don't

Everything in an audit file is one of two kinds of content:

Structure — carry it forward. This is the accumulated knowledge of the audit, and rebuilding it annually is pure waste:

Conclusions and evidence — reset it, completely. Anything that asserts something about a period must start empty:

The rule is easy to state and miserable to execute by hand, because in a folder-based file, structure and conclusions live in the same documents. Every workpaper is simultaneously a template (keep) and a record of last year's testing (reset). Splitting them means editing every file, and every file edited by hand is a file that can be edited wrong.

The four classic roll-forward failures

Ask anyone who's audited a hand-rolled file. These four account for most of the damage:

1. The stale conclusion. A copied workpaper keeps last year's "no exceptions noted, control effective." The tester, working fast, updates the sample and skims the rest. The file now contains a conclusion nobody reached this year. This is the most damaging failure because it's invisible — the workpaper looks complete, which is exactly the problem.

2. The surviving sign-off. Copy operations preserve sign-off fields. A reviewer's initials from last March sit on a workpaper for work that hasn't happened. If your external auditor finds one of these, expect every sign-off in the file to get a harder look — the integrity of the sign-off is the thing they were relying on.

3. The broken cross-reference. Last year's file said "per walkthrough W-7" and "leverages central test T-31." The copy renumbered things, or didn't copy W-7 at all. Every dangling reference is ten minutes of archaeology, multiplied across the file, all season long.

4. The scoping time capsule. The ITGC scope and IT-dependency map roll forward as a frozen document, unreviewed. The business swapped a reporting tool in Q3 of last year; the new file's scope still describes the old one. Structure should roll forward as a starting point for re-validation, not as settled truth — but if re-validating means reverse-engineering a memo, it gets skipped.

What good looks like

A clean roll-forward, whatever tooling you use, has these properties:

Then the human work begins, and it's the right work: update walkthroughs for process changes, re-confirm the IT-dependency map and ITGC scope against current reality, refresh risk assessments, rebalance assignments for team changes, and re-plan sample sizes where risk moved. That's a planning exercise measured in days — and it's the part that actually improves the audit, which is exactly why it deserves the time the copying used to eat.

Interim and roll-forward testing — the other roll-forward

One naming collision worth untangling: rolling forward the file (annual, above) is different from rolling forward interim testing (within a year). If you tested a control through September at interim, year-end needs a roll-forward procedure covering October to December — an update test, not a full re-test.

The same carry/reset logic applies in miniature: the roll-forward test inherits the control, design, and interim reference, but gets its own selection, evidence, and conclusion for the stub period. Files that handle this by editing the interim workpaper in place destroy the interim record in the process; the roll-forward should be a separate test explicitly phased and linked to the interim work it extends.

How SoxDesk does it, briefly

This whole article is essentially the spec for SoxDesk's roll-forward. One action clones an audit into the new year: team, areas, controls, tests, walkthroughs, the IT-dependency and application linkage, account-assertion mappings, leverage relationships, and workpaper content — with every internal cross-reference remapped to the new file. Statuses, sign-offs, samples, findings, evidence, and review notes reset to zero, without exceptions. The prior year stays sealed and archivable. Within a year, tests carry an interim / roll-forward / year-end phase, and a completed interim test spawns its linked roll-forward test in one click.

The mechanism isn't the interesting part; the guarantee is. When resets are structural, the stale conclusion and the surviving sign-off aren't risks you manage — they're states the file can't be in.

If you're rolling forward by hand this year

A closing checklist, tool or no tool:

  1. Archive and lock the prior year first. The copy comes from the archive, never the other way around.
  2. Write the carry/reset split down before touching anything, and have a second person agree to it.
  3. After copying, verify the resets by sampling — open twenty workpapers at random and look for surviving conclusions, dates, and sign-offs. If any of twenty fail, assume the population is contaminated and sweep everything.
  4. Grep (or Ctrl+F across the folder) for the prior year string — "FY25", "2025" — and triage every hit.
  5. Schedule the scoping re-validation as real planned work with an owner and a date, not as a standing intention.

It's the manual version of what the tooling automates — and if step 3 keeps finding survivors, that's the file telling you something about the method.


SoxDesk is an on-premise workflow app for SOX and internal audit teams: one-click roll-forward with structural resets, enforced sign-offs, ITGC linkage — all data on your own network, nothing in anyone's cloud. The 60-day free trial is the full product: soxdesk.com.