,

SOX 404 Explained: The Complete Guide to ICFR Compliance

Section 404 of the Sarbanes-Oxley Act is two sentences long and has generated more audit hours than any other provision in the history of financial regulation. Twenty-odd years after it took effect, most of the people running SOX programs have never read it, most of the controls in the average program were added in a year when something went wrong and never removed, and the questions that actually decide the program’s cost and its outcome, which filer are we, what has to be tested, who tests it, and what happens when a control fails, are answered by inheritance rather than by design. This guide answers them from the statute and the standards outward, for the internal auditor who is asked to run, test, or rely on a SOX program and needs the whole picture in one place.

This guide was rewritten in September 2026 and expanded from the original August 2026 version. It sets out what 404(a) and 404(b) require and how they connect to the quarterly certifications, the filer categories and the exemptions that decide whether an auditor attests, the definitions that the whole program turns on, the annual calendar, the roles of management, internal audit, the external auditor and the audit committee, the mechanics by which a control failure becomes a disclosed material weakness, how efficient programs stay efficient, the failure patterns that recur, and a worked example at Lakeshore Bancorp, a nine-billion-dollar public bank whose program the site’s other SOX guides use. The SOX scoping guide covers the top-down risk assessment in depth, the ITGC scoping guide the technology layer, and the deficiency evaluation guide the severity mechanics; this guide is the frame they fit in.

In this guide

What 404(a), 404(b), 302 and 906 actually require

Section 404(a) requires management of every company filing periodic reports with the SEC to include in its annual report a statement of its responsibility for establishing and maintaining adequate internal control over financial reporting and an assessment, as of the end of the fiscal year, of the effectiveness of that control. The SEC’s rules implement this through Item 308 of Regulation S-K and require the assessment to be made against a suitable, recognized framework, which in practice means the COSO Internal Control Integrated Framework of 2013, and the SEC’s 2007 interpretive guidance tells management how to do it: top-down, risk-based, focused on the controls that address the risks of material misstatement. Section 404(b) requires the company’s registered public accounting firm to attest to and report on management’s assessment, which the PCAOB’s AS 2201 turns into an integrated audit of internal control over financial reporting, resulting in the auditor’s own opinion on effectiveness. Section 302 requires the chief executive and chief financial officer to certify each quarterly and annual report, including that they have evaluated the effectiveness of disclosure controls and procedures and disclosed to the auditor and the audit committee all significant deficiencies and material weaknesses, and Section 906 adds a criminal certification of the report’s fairness. The program that most people call “SOX” is the machinery that lets management make the 404(a) assessment and the officers sign the 302 certifications with evidence behind them, and, for the filers to which it applies, gives the auditor what 404(b) requires.

Filer status and the exemptions: who gets an auditor’s attestation

Whether 404(b) applies depends on filer status, and filer status has moved twice since the Act. The Dodd-Frank Act of 2010 permanently exempted non-accelerated filers from the auditor attestation. The JOBS Act of 2012 exempted emerging growth companies for up to five years after their initial public offering. And the SEC’s amendments adopted on 12 March 2020 and effective 27 April 2020 removed from the accelerated and large accelerated filer categories any issuer eligible to be a smaller reporting company with annual revenues under 100 million dollars, so that a company with a public float of, say, 300 million dollars but revenues of 80 million is a non-accelerated filer with no auditor attestation, while its management assessment under 404(a) continues. The public float thresholds stayed where they were, 75 million to under 700 million dollars for accelerated and 700 million and above for large accelerated, with exit thresholds of 60 million and 560 million to prevent companies bouncing between categories. The table sets out the categories; the audit committee should know which one the company is in and when it might change, because a company crossing into accelerated status acquires an integrated audit with a year’s notice at best.

Filer categoryCriteria (as amended April 2020)404(a) management assessment404(b) auditor attestationNotes
Large accelerated filerPublic float of 700 million dollars or more; not a low-revenue smaller reporting companyRequiredRequiredExit threshold: float under 560 million
Accelerated filerPublic float of 75 million to under 700 million; reported for at least twelve months; not a smaller reporting company with revenues under 100 millionRequiredRequiredExit threshold: float under 60 million
Non-accelerated filerEveryone else, including low-revenue smaller reporting companies since April 2020RequiredNot required (Dodd-Frank, permanent)Auditor still audits the financial statements and considers controls under the financial statement audit standards
Emerging growth companyRevenues under the JOBS Act threshold; within five years of IPO and other limitsRequiredExempt while EGC status lastsStatus can end early on revenue, float or debt tests
Newly public companyFirst annual report after registrationTransition relief: management report not required in the first annual reportNot required in the first annual reportProgram has to be built during the first year regardless
Banks and holding companies under FDICIAInsured institutions with total assets of one billion dollars or moreManagement report on internal control over financial reporting under 12 CFR Part 363Independent auditor attestation under Part 363, separate from SOX statusApplies to non-public banks too; usually integrated with the SOX program where both apply

The definitions the program turns on

Internal control over financial reporting is defined in the SEC’s rules as a process designed by, or under the supervision of, the principal executive and financial officers, and effected by the board, management and other personnel, to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles, including controls over the maintenance of records, the authorization of transactions and the prevention or timely detection of unauthorized acquisition, use or disposition of assets. Disclosure controls and procedures, the subject of the 302 certification, are broader, covering everything that has to be disclosed in the reports, and the two overlap without coinciding. The severity vocabulary comes from AS 2201’s appendix: a deficiency exists when the design or operation of a control does not allow management or employees, in the normal course of their functions, to prevent or detect misstatements on a timely basis; a material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis; and a significant deficiency is less severe than a material weakness yet important enough to merit the attention of those responsible for oversight. Everything in the program is organized around these: the controls are designed to prevent or detect material misstatement, the testing establishes whether they do, and the evaluation decides which word applies when they do not. The deficiency evaluation guide works the mechanics; the COSO principles guide covers the framework the assessment is made against.

Entity-level controls: what the assessment covers beyond transactions

The assessment is made against all five COSO components, and three of them, the control environment, risk assessment and monitoring, are addressed mostly by controls that operate at the level of the entity rather than the transaction. They matter for two reasons. AS 2201’s top-down approach requires the auditor to evaluate entity-level controls first, because their strength changes how much transaction-level testing is needed and a pervasive weakness in the control environment can be a material weakness on its own. And the paragraph 69 indicators are largely entity-level: an ineffective audit committee, senior management fraud, an inadequate close process. The table maps the components to the controls the program should document and test, and to their evidence; the program that has 212 transaction controls and one paragraph on “tone at the top” has not assessed the framework it claims to have used.

COSO componentEntity-level controls typically documentedEvidence tested
Control environmentCode of conduct and its acknowledgment; audit committee independence, expertise and charter; organizational structure and reporting lines; hiring, training and evaluation of accounting personnel; whistleblowing channelAcknowledgment records; committee minutes and self-assessment; competency evidence; hotline reports and their handling
Risk assessmentFinancial reporting risk assessment including fraud risk; identification of changes (new standards, systems, acquisitions) and their effect on controlsThe risk assessment itself; change log with scoping consequences
Control activitiesThe transaction-level controls; policies over technology (the ITGC program)The matrix and its testing
Information and communicationAccounting policies and their communication; the close and reporting process; information systems supporting reporting; upward and downward communication of control responsibilitiesPolicy manual currency; close checklist; sub-certification process
MonitoringInternal audit’s program assurance; management’s self-assessment; deficiency tracking and remediation; audit committee review of resultsInternal audit reports; deficiency log with closure evidence; committee papers

The annual program calendar

A SOX program runs on a calendar that starts before the fiscal year does and ends with the annual report, with the quarterly certifications as milestones along the way. The table gives the sequence for a calendar-year company. The two habits that separate well-run programs from the rest are visible in it: scoping is redone every year from the financial statements rather than rolled forward, and interim testing is done early enough that a failed control can be remediated and re-tested before year-end, which is what turns a potential material weakness into a remediated deficiency.

PeriodActivityOutputGuide
Q4 of prior year to Q1Risk assessment and scoping: materiality, significant accounts and disclosures, processes, locations, key controls, systems, service organizations; coordination with the external auditor on scope and relianceScoping memo; risk and control matrix; ITGC scoping memo; SOC report registerSOX scoping; ITGC scoping
Q1Documentation refresh and walkthroughs; design evaluation; remediation of design gapsUpdated narratives and matrices; design conclusionsWalkthrough template; Design versus operation
Q1 to Q2Quarterly 302 certification with sub-certifications from process owners; disclosure committeeCertifications; sub-certification recordsThis guide
Q2 to Q3Interim operating effectiveness testing, including ITGCs first; SOC 1 reviews; deficiencies raised and remediation startedTest results; deficiency logSample sizes; SOC 1 review
Q3Deficiency evaluation and aggregation at interim; remediation testing planned; audit committee updateInterim evaluation; remediation plansDeficiency evaluation
Q4Roll-forward and year-end testing; remediation re-testing; final deficiency evaluation; management’s report draftedYear-end results; final evaluationThis guide
Annual reportManagement’s 404(a) report; auditor’s 404(b) opinion where applicable; Item 308 and 308(c) disclosures; 302 and 906 certificationsFiled reportThis guide
ContinuousChange monitoring: new systems, acquisitions, process changes, personnel changes that trigger re-scoping or re-testingChange log with scoping decisionsSOX scoping

The quarterly obligations: 302 certifications, sub-certifications and Item 308(c)

The annual assessment gets the attention, but the officers sign four times a year, and the quarterly machinery is where programs are thinnest. Each quarterly report carries the 302 certifications, in which the chief executive and chief financial officer state that they have evaluated the effectiveness of disclosure controls and procedures as of the end of the period, that they have disclosed to the auditor and the audit committee all significant deficiencies and material weaknesses and any fraud involving management or employees with a significant role in internal control, and that the report contains no material misstatement. Item 308(c) of Regulation S-K adds the quarterly disclosure of any change in internal control over financial reporting that materially affected, or is reasonably likely to materially affect, it. Behind the signatures sits a process the audit should test: sub-certifications from process and control owners, gathered each quarter with specific questions about control operation, changes, deficiencies and known errors; a disclosure committee that reviews the sub-certifications, the deficiency log, the change log and the draft filing; and a record connecting the officers’ certification to that review. The failure pattern is a sub-certification that is a signature block circulated by email with no questions and no follow-up, so that the officers certify on the strength of nothing. The test is to read a quarter’s sub-certifications, trace the exceptions raised to the disclosure committee’s minutes and the deficiency log, and compare the change log with the 308(c) disclosure, which for a company that implemented a new system mid-year should say so.

Roles: management, internal audit, the external auditor and the audit committee

Four parties run a SOX program, and the most contested question in most companies is what internal audit does in it. Management owns the assessment: the controller’s organization or a SOX office maintains the documentation, process owners operate the controls and sub-certify, and management tests the controls or has them tested on its behalf. The external auditor, for 404(b) filers, performs its own integrated audit under AS 2201 and may use the work of others, including internal audit and management’s testers, where it has evaluated their competence and objectivity, which is the reliance that decides how much of the testing is done twice. The audit committee oversees the whole, receives the deficiency evaluations and the auditor’s communications, and is itself part of the control environment the assessment covers. Internal audit’s position is one of three, and the choice should be explicit. It can perform management’s testing on management’s behalf, which is efficient and common, and which under the Global Internal Audit Standards is work done for management that internal audit cannot then independently assure. It can provide independent assurance over the program, testing a sample of management’s work and the program’s design, which preserves independence and adds a layer. Or it can advise, on scoping, design and remediation, without testing. Functions that do the first without saying so, and then report to the audit committee as if they had done the second, have created a problem the external quality assessment will find; the reliance criteria guide and the Standards guide cover the independence rules, and the table summarizes the roles.

PartyResponsibilityStandard or ruleTypical failure
Management (CEO, CFO, controller, SOX office)Design, operate, document and assess ICFR; certify; discloseSections 302, 404(a), 906; Item 308; SEC 2007 guidance; COSO 2013Assessment outsourced in substance to the auditor; scoping rolled forward
Process and control ownersOperate controls; retain evidence; sub-certifyCompany policyControls performed for the tester rather than for the business
Internal auditOne of: test for management; independent assurance over the program; advisoryGlobal Internal Audit Standards on independence and relianceRole undeclared; management’s testing presented as assurance
External auditorIntegrated audit and opinion for 404(b) filers; consideration of controls in every auditAS 2201; reliance on the work of othersScope disagreements discovered at year-end; duplicate testing
Audit committeeOversight of the program, the evaluation and the auditorExchange listing rules; Item 407; AS 2201 indicatorsReceives results without understanding severity mechanics

From failed control to disclosed material weakness: the mechanics

A control failure becomes a material weakness through a sequence the program has to run deliberately. A test exception is recorded as a deficiency, with its nature (design or operation), the control, the accounts and assertions affected, and the population exposed. The deficiency is evaluated for severity by the likelihood that the control’s failure would fail to prevent or detect a misstatement and the magnitude of the potential misstatement, considering the factors AS 2201 lists in paragraphs 65 and 66, and compensating controls are considered only if they operate at a precision that would prevent or detect a material misstatement. Deficiencies affecting the same account or assertion are aggregated, because several less severe deficiencies can together constitute a material weakness. The indicators in paragraph 69, fraud by senior management of any size, a restatement to correct a material misstatement, a material misstatement in the current period the controls did not catch, and ineffective audit committee oversight, are treated as indicators of a material weakness whatever the other analysis says, and the prudent official test in paragraph 70 asks whether a prudent official with knowledge of the facts would conclude there is reasonable assurance that transactions are recorded as necessary. If the answer is a material weakness as of year-end, management’s report states that ICFR was not effective and describes the weakness, the auditor’s opinion is adverse, and the disclosures under Item 308 follow, with changes in ICFR reported quarterly under Item 308(c). Remediation is then tested in a subsequent period; a weakness remediated after year-end is still a weakness at year-end. The deficiency evaluation guide works this sequence through examples, and the severity ratings guide covers the aggregation logic for internal audit findings that feed it.

How efficient programs stay efficient

Programs grow because every year adds controls and no year removes them. The efficient ones do five things. They rescope annually from the financial statements and remove controls that no longer address a risk of material misstatement, so that the key control count reflects the business rather than its history; a program with four hundred key controls at a mid-sized company usually has a hundred and fifty that matter. They classify controls correctly, automated, IT-dependent manual, manual, because the classification decides the testing effort: an automated control tested by configuration, one instance and ITGC reliance costs a fraction of one sampled forty times, as the automated controls guide shows, and an IT-dependent manual control tested without its report’s completeness costs the finding later. They coordinate with the external auditor at the scoping memo so that reliance is agreed before testing and the shared layers, ITGCs above all, are tested once. They rely on service auditors’ reports properly, read rather than filed, with the complementary user entity controls operated and tested as the SOC 1 guide describes. And they invest in the two areas where deficiencies actually arise, management review controls with their precision and their IPE, and the IT general controls that everything else rests on, rather than spreading effort evenly. Cost is measured in hours per key control and in the proportion of testing that was duplicated; both should fall year on year in a program that is being managed.

The first year: building a program after an IPO or a threshold crossing

A company that has just gone public, or has just crossed into accelerated status, has to build in a year what others have refined over twenty, and the sequence matters more than the resources. The first quarter is spent on the risk assessment and scoping, because everything else is wasted if the scope is wrong, and on the accounting resources question, because the commonest first-year material weakness is insufficient technical accounting expertise for the transactions the newly public company is now reporting. The second quarter documents the processes with walkthroughs, evaluates design and fixes the design gaps, which in a first-year program are numerous and mostly about segregation, review precision and IT general controls. The third quarter tests operating effectiveness for the first time, early enough that remediation can be tested before year-end, and reviews the service organizations’ reports the company has probably never read. The fourth quarter rolls forward and evaluates. Three shortcuts are tempting and each is a known cause of a first-year weakness: buying a template matrix and treating it as the scope; deferring the IT general controls because the systems are “standard”; and letting the external auditor’s requests define the program, which produces a program that satisfies this year’s auditor and nobody else. The transition relief for newly public companies, no management report in the first annual report, is a reprieve for the report, not for the program; the 302 certifications start with the first quarterly filing, and the officers are certifying disclosure controls from the first day. The audit plan template and the risk and control matrix template are the two documents the first year is built on.

The failure patterns that recur

The material weaknesses disclosed each year cluster in a small number of patterns, and a program that has never had one should test itself against the list. Management review controls that were performed but not at a precision that would detect a material misstatement, and could not evidence what the reviewer looked at, the pattern the management review controls guide addresses. Information produced by the entity relied on without its completeness and accuracy being tested, so that a review of a wrong report was a review of nothing, covered in the IPE guide. IT general control failures over access and change that removed the basis for reliance on automated controls and reports, the subject of the ITGC dependency guide. Insufficient accounting resources and expertise for complex or unusual transactions, the entity-level pattern behind most restatement-driven weaknesses at smaller companies. Scoping that missed an acquisition, a new system or a new revenue stream because the assessment was rolled forward. And remediation that was declared rather than tested, so that the same weakness appeared two years running. Each pattern has an internal audit response in the guides on this site, and the pattern most worth testing in a program that has been clean for years is the first, because precision is where reviewers and auditors most often disagree.

Worked example: Lakeshore Bancorp’s program in one year

Lakeshore Bancorp is a nine-billion-dollar publicly traded regional bank, a large accelerated filer with a public float well above the threshold, subject to 404(b) and, as an insured institution with assets over one billion dollars, to the management report and auditor attestation requirements of FDICIA’s Part 363, which it integrates into one program. The SOX office sits in the controller’s organization with three staff; internal audit’s twenty-two auditors provide independent assurance over the program and test the IT general controls and certain shared layers under an explicit reliance arrangement with the external auditor, a position the audit committee approved in writing so that the function’s independence over the program is preserved. The FY26 scoping produced eleven processes feeding the significant accounts, a matrix of 212 key controls, 68 automated, 91 IT-dependent manual and 53 manual, and nine in-scope systems, as the ITGC scoping example describes.

The calendar ran as designed with one exception that illustrates the mechanics. Interim testing in the third quarter found that the quarterly user access review over the wire transfer platform had approved every user in two consecutive quarters in under ten minutes each, including two operations staff who had transferred out of treasury and retained the ability to release wires. The deficiency was evaluated in September: the control was a key access control over a system that moves material amounts daily, the failure was in operation, the population exposed was every wire released by the two users, which the bank traced and found legitimate, and the compensating dual-control release on the platform, an automated control tested effective, would have prevented a single person from releasing a wire alone. Magnitude and likelihood together placed it as a significant deficiency rather than a material weakness, with the reasoning recorded against the paragraph 65 and 66 factors and the prudent official test. Management remediated the review in October with the data pack and decision-quality thresholds the user access review guide describes, internal audit re-tested it in December, and it was reported to the audit committee and communicated to the external auditor as a remediated significant deficiency at year-end. Management’s 404(a) report concluded that ICFR was effective; the auditor’s opinion was unqualified; the 302 certifications carried the disclosure to the audit committee.

ElementLakeshore FY26
Filer statusLarge accelerated filer; 404(a) and 404(b); FDICIA Part 363 integrated
Scope11 processes; 212 key controls (68 automated, 91 IT-dependent manual, 53 manual); 9 in-scope systems; 3 service organizations with SOC 1 reports
Testing splitSOX office tests process controls for management; internal audit tests ITGCs, the directory and scheduler layers and provides assurance over the program; external auditor relies on internal audit’s ITGC work and tests the general ledger and core banking customer-side controls itself
Deficiencies14 deficiencies at interim; 1 significant deficiency (wire platform access review), remediated and re-tested; 0 material weaknesses
HoursSOX office and process owners about 3,100; internal audit about 800 on ITGCs and 300 on program assurance; external auditor reliance reduced duplicate testing by an estimated 600 hours
ReportsManagement report effective; unqualified auditor opinion; significant deficiency communicated to the audit committee and disclosed to the auditor under 302; Part 363 report filed

The lesson the CAE drew for the audit committee was about timing rather than about the wire platform: the deficiency was found in September because interim testing was scheduled early, and a deficiency of the same kind found in the year-end testing in January would have been a significant deficiency that could not be remediated within the period, with the disclosure consequences that follow. The calendar is a control.

Common mistakes

  • Not knowing the filer status. Whether 404(b) applies, and when it might start to, decides the program’s size; check float and revenue every year.
  • Rolling scope forward. Rescope from the financial statements annually; remove controls that no longer address a risk.
  • Leaving internal audit’s role undeclared. Testing for management, assuring the program or advising are different things; choose one and tell the audit committee.
  • Testing late. Interim testing early enough to remediate and re-test is what keeps deficiencies from becoming year-end weaknesses.
  • Treating deficiency evaluation as a form. Likelihood, magnitude, aggregation, compensating precision, indicators, prudent official; record the reasoning.
  • Misclassifying controls. Automated, IT-dependent manual and manual are tested differently; the classification drives the cost and the findings.
  • Ignoring the shared layers. ITGCs and the directory carry every automated control; agree who tests them once.
  • Filing SOC 1 reports. Read them, map the CUECs, evaluate the exceptions.
  • Declaring remediation. A remediated control is one that has been re-tested for a sufficient period.
  • Presenting the program to the audit committee as pass or fail. Show the deficiency population, the evaluations and the trend.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading