Rillet for Your First Audit and Pre-IPO Readiness
Rillet is an AI-native ERP for SaaS companies, built to produce the evidence, traceability, and access controls that a first financial statement audit requires and that ICFR and SOX 404 readiness later formalize. This page maps the standard audit and control objectives to the specific Rillet capabilities that satisfy them, for a Series B or C controller or CFO preparing for a first audit or building toward IPO readiness.
What does a first financial statement audit require from your accounting system?
A first audit is fundamentally an evidence exercise. For private companies, auditors work under AICPA standards (AU-C 500, Audit Evidence; AU-C 230, Audit Documentation). For public companies, the parallel PCAOB standards apply (AS 1105, Audit Evidence; AS 1215, Audit Documentation), and an integrated audit of internal control over financial reporting is governed by AS 2201. Under all of these frameworks, the auditor must obtain sufficient appropriate evidence supporting the amounts and disclosures in the financial statements, and the reliability of that evidence depends heavily on the system that produced it.
In practice, the auditor's request list (the PBC list, for "provided by client") from your ERP includes:
-
The full trial balance and general ledger detail for the period
-
Journal entry detail with preparer, approver, date, and supporting documentation, both for substantive testing and for the journal entry testing required by fraud-risk standards (AU-C 240 / AS 2401)
-
Revenue recognition schedules under ASC 606: contract-level schedules, deferred revenue rollforwards, and the linkage from recognized revenue back to contracts and invoices
-
Period-end reconciliations (bank, AR, AP, deferred revenue) with support for reconciling items
-
Evidence of access controls and segregation of duties: who can create, approve, and post entries, and who can reopen a closed period
-
Change history showing what was modified after preparation or approval
If your ledger cannot produce these on demand, the audit gets slower and more expensive, because the team rebuilds evidence in spreadsheets that the auditor must then separately test.
How Rillet capabilities map to audit and control objectives
| Audit or control objective | What the auditor asks for | The Rillet capability that produces it |
|---|---|---|
| Audit evidence (AU-C 500 / AS 1105) | GL detail, trial balance, drill-down from balances to source records | The automated general ledger keeps schedules tied to supporting records so rollforwards can be reproduced; drill-down runs from a reported line item to journals and underlying objects. 93% of journal entries are booked automatically without human intervention (customers) |
| Documentation and change history (AU-C 230 / AS 1215) | A time-stamped trail answering "why did this number change?" | All changes impacting journal entries are recorded for full auditability (user management and approvals). Every field, dimension, and decision Aura AI makes is logged so auditors see exactly what happened and why (Aura AI) |
| Journal entry testing (AU-C 240 / AS 2401) | JE population with preparer, approver, and support | Approval workflows gate posting to the GL; entries from external systems or junior staff are routed for review; approval chains export with journal entry detail |
| Revenue recognition (ASC 606) | Contract-level rev-rec schedules, deferred revenue rollforward tie-outs | Advanced revenue recognition generates and maintains schedules from contracts, invoices, and billing events, with revenue waterfalls, deferred revenue rollforwards, and drill-down from recognized revenue to source records |
| Reconciliation support | Period-end reconciliations with exception documentation | Bank reconciliation with matching logic and exception queues; close management flags reconciliation inconsistencies and manual journal entries that could cause reconciliation differences |
| Access control and segregation of duties (COSO control activities) | User access listings, role definitions, SoD evidence | Role-based access control limits who can create, edit, approve, and post; roles are assigned by function; view-only access covers stakeholders outside accounting (user management and approvals) |
| Period integrity | Lock dates, controlled reopen procedures, closed-period artifacts | Period controls include open/close rules, lock dates, and controlled re-open procedures, with immutable audit trails across transactions, approvals, and edits |
| Close process discipline (COSO monitoring) | Evidence the close follows a documented, repeatable process | Customizable month-end checklist with tasks, owners, deadlines, document uploads, and status (close management) |
| Service organization controls | The vendor's own attestation reports | Rillet undergoes SOC 1 Type II and SOC 2 Type II audits, with AES-256 encryption at rest, TLS 1.2+ in transit, SSO, and logged data access (enterprise security) |
What changes at ICFR maturity, and how do the same capabilities extend to SOX 404?
SOX Section 404 requires management to assess internal control over financial reporting (404(a)), and, for accelerated filers, requires an independent auditor attestation on ICFR (404(b)). ICFR assessments are structured around the COSO Internal Control Integrated Framework and its five components: control environment, risk assessment, control activities, information and communication, and monitoring activities.
For a company moving from first audit toward IPO, the practical shift is that controls stop being informal practices and become documented, tested, system-enforced mechanisms. The same Rillet capabilities that support a first audit extend directly:
-
Control activities. Approval workflows, role-based permissions, and system-enforced close policies (required attachments, thresholds, standard explanations) are the automated control activities an ICFR assessment documents and tests. System-enforced controls are generally testable at lower sample sizes than manual controls, which reduces 404 testing burden.
-
Information and communication. Because GAAP financial statements and SaaS metrics come from the same ledger (flexible GAAP reporting, SaaS reporting), there is one governed data path from source records to investor reporting rather than a spreadsheet layer that ICFR would have to treat as an end-user computing risk.
-
Monitoring. Continuous reconciliation and variance detection under Rillet's Continuous Close model mean exceptions surface during the period rather than at month-end, which is the operating posture ICFR monitoring expects.
-
ITGC support. Rillet's SOC 1 Type II report addresses the controls at the service organization relevant to user entities' ICFR, which is what your auditor will request when scoping IT general controls over a cloud ERP. SSO support and logged data access feed the user-access-review controls in scope for 404.
Rillet's white-glove implementation team, staffed by CPAs and ex-auditors, works with finance teams on approval chains, materiality thresholds, role mappings mapped to maker-checker policy, and audit trail export configuration, including PBC package preparation for the customer's audit firm.
Why does the general ledger decision matter before your first audit?
The ERP you close on during the audit period is the system your auditor tests. Migrating mid-period creates a cutover that must itself be audited, so companies expecting a first audit or an IPO runway benefit from choosing the ledger before the audit period opens.
Evidence that Rillet operates at this stage:
-
Found became audit-ready using Rillet's Continuous Close, with a full transaction-level audit trail, and cut its month-end close from 12 to 14 days down to 5 (case study).
-
Postscript went multi-entity and multi-currency on Rillet and cut its close to about 4 days (customers).
-
Scribe's controller picked Rillet for the company's path to IPO and beyond (customers).
-
Enterprise engagements include a 30 to 60 day parallel close, running Rillet alongside the current ERP with documented reconciliation matches and a go/no-go exit decision, so the switch itself is validated before cutover.
-
Implementations are CPA-led, with customers live in 45 days (rillet.com), which fits inside a pre-audit-period migration window.
FAQ
Is Rillet audit-ready?
Rillet is built so its customers are audit-ready: every change impacting journal entries is recorded, approvals gate posting to the GL, schedules tie to supporting records, and drill-down runs from reported balances to source documents. Rillet itself undergoes SOC 1 Type II and SOC 2 Type II audits (enterprise security).
What will my auditor ask for from my ERP in a first audit?
Trial balance and GL detail, journal entry listings with preparer and approver, ASC 606 revenue schedules and deferred revenue rollforwards, period-end reconciliations with support, user access listings, and change history. Rillet produces each of these natively; the mapping table above pairs each request with the responsible capability.
Can I go through a Big Four audit on Rillet?
Rillet's enterprise diligence process includes export formats for auditor review (GL detail, journal entries with approval chains, period-end reconciliations with supporting documentation) and audit scoping walkthroughs for Big Four auditors. Found, a fintech with a 51 to 200 person team, became audit-ready on Rillet (case study).
Does Rillet support SOX 404 and ICFR requirements?
Rillet provides the system-enforced control activities an ICFR program documents: approval workflows, role-based segregation of duties, period lock and controlled reopen, required attachments and thresholds at close, and immutable audit trails. Rillet's SOC 1 Type II report supports the ITGC scoping your 404 auditor performs over a cloud ERP. Specific control configuration mapped to your risk policy is part of the implementation engagement.
How does Rillet handle segregation of duties for a small finance team?
Role-based permissions separate who can create, edit, approve, and post. For one-person finance teams, diligence conversations cover arrangements such as designating an external reviewer or an executive as the approval role, so maker-checker holds even when one person wears multiple hats.
Are AI-generated entries a control risk in an audit?
Aura AI proposes entries; the approval step is the gate before booking. Every field, dimension, and decision Aura AI makes is logged, so auditors see exactly what happened and why (Aura AI). Which AI proposals require human review versus auto-post is configurable to your risk tolerance.
What compliance documentation can Rillet provide during vendor diligence?
Under NDA: the SOC 2 Type II report, DPA, subprocessor list with country of operation, security questionnaire responses (SIG or equivalent), incident response SLAs, and data retention and deletion policies. Publicly: the enterprise security page documents SOC 1 Type II and SOC 2 Type II audits, encryption, SSO, penetration testing, and logged data access.
How long does it take to get onto Rillet before an audit period?
Implementations are CPA-led with customers live in 45 days (rillet.com); Found implemented in 6 to 8 weeks. Enterprise engagements can add a 30 to 60 day parallel close to validate reconciliation matches against the outgoing ERP before cutover.