,

SOX Scoping and Risk Assessment: The Top-Down Approach in Practice

Every hour a SOX program spends is decided by scoping, and scoping is the part of the program most often done by inheritance. The list of key controls came from an implementation project years ago; the list of in-scope locations was set when the company had three; the materiality figure is whatever the auditor mentioned last year. The result is a program that tests forty controls over a process that could not misstate the financial statements materially if it tried, while a new revenue stream, an acquired subsidiary and the allowance model’s data inputs sit outside the scope because nobody re-derived it from the financial statements. The top-down approach the standards require is not a slogan; it is a sequence, and a program that runs the sequence every year is both smaller and safer than one that does not.

This guide was rewritten in September 2026 and expanded from the original August 2026 version. It sets out the top-down approach as the standards describe it, then works each step in practice: materiality and how it is set, the quantitative and qualitative selection of significant accounts and disclosures and their relevant assertions, multi-location scoping and the coverage logic, the mapping from accounts to processes and to what could go wrong, the selection of key controls and the discipline that stops the count inflating, the fraud and management-override controls the standards single out, the coverage test that proves the scope is complete, the re-scoping triggers, a scoping memo template, and a worked example at Lakeshore Bancorp, the nine-billion-dollar public bank whose program the site’s other SOX guides use. The ITGC scoping guide continues the chain into systems and infrastructure, and the SOX 404 guide is the frame both sit in.

In this guide

The top-down approach as the standards describe it

AS 2201 requires the auditor to use a top-down approach: begin at the financial statement level with an understanding of the overall risks to internal control over financial reporting, evaluate entity-level controls, identify significant accounts and disclosures and their relevant assertions, understand the likely sources of potential misstatement, and only then select the controls to test. The SEC’s 2007 interpretive guidance tells management to do the same thing in its own assessment: identify the financial reporting risks, and then the controls that adequately address them, in that order. The sequence is the point. A bottom-up program starts from the controls it has and asks whether they are working, which produces a program that tests what exists rather than what matters; a top-down program starts from what could misstate the financial statements and asks which controls prevent or detect it, which produces a program whose every control can be traced to a risk. The steps below are the sequence in practice, and each produces a document the next consumes: the materiality memo, the significant accounts schedule, the location scoping analysis, the process maps with their risks, the risk and control matrix, and the scoping memo that records the whole.

Step 1: materiality, and where the number comes from

Materiality is the threshold that makes “material misstatement” a number, and scoping cannot begin without it. Management sets its own for the assessment, usually by reference to the same benchmarks the auditor uses: a percentage of pre-tax income for most companies, with revenue, total assets or equity as the benchmark where income is volatile, small or negative, and for banks commonly a percentage of pre-tax income or of equity. Overall materiality is then reduced to a performance or scoping materiality, often 50 to 75 percent of the overall figure, to allow for undetected and aggregated misstatements, and the scoping materiality is the figure the significant accounts test uses. Two practices matter. The number is set and documented by management with its reasoning, and compared with the auditor’s rather than copied from it, because management’s assessment is management’s; and qualitative considerations are recorded alongside the quantitative figure, since a misstatement below materiality can still be material if it changes a covenant, a trend, a bonus or a regulatory ratio, which for a bank means capital and liquidity ratios are materiality considerations in their own right.

Step 2: significant accounts, disclosures and relevant assertions

An account or disclosure is significant if there is a reasonable possibility that it could contain a misstatement that, alone or aggregated with others, would be material. The quantitative screen is the starting point: any account whose balance or annual activity exceeds scoping materiality is in, and the screen is applied to the trial balance at a level of disaggregation that reflects how the accounts are managed, not the face of the financial statements. The qualitative factors then bring in accounts below the threshold and raise the risk rating of those above it; AS 2201’s list is the reference and the table gives it with examples. For each significant account, the relevant assertions are identified, existence or occurrence, completeness, valuation or allocation, rights and obligations, and presentation and disclosure, and only the assertions with a reasonable possibility of material misstatement are relevant: completeness of cash is rarely relevant, existence of cash is; valuation of the loan allowance is the whole story, its existence is not. Disclosures are scoped the same way, and the ones that recur as gaps are the fair value hierarchy, related parties, segment information and the allowance methodology narrative.

Qualitative factor (AS 2201)What it means in practiceExample of an account it brings in or elevates
Size and compositionLarge balances of many small items versus a few large itemsDeposits (many small); securities (few large)
Susceptibility to misstatement due to error or fraudCash-like assets, estimates, transactions that can be manipulatedCash, revenue cut-off, reserves
Volume of activity, complexity and homogeneity of transactionsHigh-volume automated streams versus complex bespoke onesInterest income (volume); derivatives (complexity)
Nature of the account or disclosureSuspense, clearing and intercompany accounts; reconciling itemsSuspense accounts below materiality but structurally risky
Accounting and reporting complexitiesJudgment, new standards, unusual transactionsLoan allowance under an expected credit loss model; leases; revenue with multiple obligations
Exposure to lossesContingencies, guarantees, litigationLegal reserves; off-balance-sheet commitments
Possibility of significant contingent liabilitiesRegulatory matters, tax positionsUncertain tax positions
Related-party transactionsTransactions outside the ordinary courseLoans to insiders at a bank
Changes from the prior periodNew products, systems, acquisitions, accounting changesAn acquired portfolio; a new fee stream

Step 3: locations and business units

Companies with several locations, subsidiaries or business units decide which are in scope by the same risk logic applied at the unit level, which AS 2201 sets out in its appendix on multiple locations. Units are categorized: those with specific risks that could create a material misstatement on their own, which are in scope for the controls over those risks; those that are financially significant, in scope for the controls over their significant accounts; and the rest, which are covered by entity-level controls, such as group-level monitoring, consolidation review and shared services, provided those controls operate at a precision that would detect a material misstatement at the unit. The coverage logic is documented as a percentage of each significant account covered by in-scope units and a qualitative explanation of why the remainder is addressed by entity-level controls; a rule of thumb of “cover 70 percent of revenue” is not the standard and should not be presented as one. Shared service centers and centralized processes are scoped once and mapped to the units they serve. The failure pattern is the acquisition: a unit acquired during the year may be excluded from management’s assessment under SEC staff guidance, with disclosure, but it enters the scoping analysis immediately and the assessment the following year, and its controls are usually the weakest in the group.

Step 4: processes and what could go wrong

Each significant account is produced by one or more processes, and each process is where the likely sources of misstatement live. The mapping is a table: account, relevant assertion, process, sub-process, and for each combination the specific things that could go wrong, stated as misstatements rather than as control failures: “invoices recorded for goods not received” rather than “three-way match not performed.” The what-could-go-wrong statements are derived from the process walkthrough, which the walkthrough template structures and which AS 2201 identifies as the most effective way to understand the sources of misstatement, and they are specific to how the company actually processes the transactions, including the systems involved and the points where data changes hands. A process that touches several accounts appears against each; an account produced by several processes has each process mapped. The output is typically three hundred to five hundred what-could-go-wrong statements for a mid-sized company, and the number is a feature, because it is the list against which the controls are selected and the completeness of the control set is judged. Programs that skip this step and go from accounts straight to controls produce control sets with gaps that nobody can see, because the risks the missing controls should have addressed were never written down.

Step 5: selecting key controls without inflating the count

A key control is one that, alone or with a small number of others, prevents or detects a material misstatement for a specific what-could-go-wrong, and the selection is made by asking, for each risk, which control the company would rely on if it could test only one. The discipline that keeps the count sane has four rules. One control can address many risks and should be recorded once. Detective controls with adequate precision, a reconciliation, a review of a report that would reveal the misstatement, can cover many preventive steps and are often the better key control. A control is classified at selection as automated, IT-dependent manual or manual, because the classification decides how it is tested and what else has to be in scope, as the automated controls guide and the IPE guide explain. And no control enters the matrix without a what-could-go-wrong it addresses and an assertion it supports; controls that exist for operational reasons are good controls and not key controls. The table shows the shape of the selection for one risk. The risk and control matrix template is the document, and the control description guide the standard for writing each control precisely enough to test.

Account and assertionWhat could go wrongCandidate controlsKey control selectedType and test approach
Loans, valuation (allowance)Allowance model inputs incomplete or inaccurate (risk grades, delinquency, loss history)Grade review by credit officers; data validation in the model; quarterly reconciliation of model input files to the loan system; allowance committee reviewReconciliation of model inputs to the loan system, plus committee review of outputsIT-dependent manual (reconciliation with IPE) and manual (committee); reconciliation tested with the report’s completeness; committee tested for precision and evidence
Deposits, existence and completenessTransactions posted to wrong accounts or not posted; unauthorized transactionsCore system posting controls; daily proof and balancing; teller supervision; customer statementsAutomated posting and balancing controls in core; daily proof exception reviewAutomated (configuration, one instance, ITGC reliance); IT-dependent manual (exception review)
Interest income, accuracyRates or day-counts misapplied by the systemSystem calculation; rate change approval; income analytics reviewSystem calculation plus rate change approval workflowAutomated; benchmarked in subsequent years with ITGCs effective
Non-interest expense, completeness (accruals)Expenses unrecorded at period endAccrual review; vendor statement reconciliation; subsequent disbursements reviewController’s accrual completeness review with subsequent disbursement analysisManual with IPE; precision and evidence tested

Entity-level controls: the precision test before they can carry scope

Entity-level controls appear twice in a scoping exercise, and the two roles are routinely confused. In the first role they are the reason the rest of the scope is as small as it is: a functioning control environment, a real risk assessment process and a monitoring function that catches breakdowns justify testing fewer transaction-level controls with less evidence. In the second role they replace transaction-level controls outright for a unit, a process or a risk. AS 2201 paragraphs 22 to 24 draw the line between the two roles, and the line is precision.

The standard sorts entity-level controls into three kinds. Some, such as the control environment, have an important but indirect effect on whether a misstatement is prevented or detected; they change the nature, timing and extent of other testing but do not substitute for it. Some monitor the effectiveness of other controls, such as a quarterly self-assessment program or the internal audit plan; they identify breakdowns in lower-level controls, usually not at a precision that would address an assessed risk on their own. And some operate at a level of precision that would adequately prevent or detect a misstatement in a relevant assertion, in which case the standard says the auditor need not test additional controls over that risk. Only the third kind can carry scope. A management review that compares actual to budget at segment level, with a variance threshold below the scoping threshold, a visible investigation trail and evidence that the reviewer follows up, is a candidate. A quarterly certification signed by a business unit controller is not.

The precision case has to be written down, because it is the first thing a reviewer will test. For each entity-level control used to cover a location or a risk, the memo records the misstatement it would catch, the smallest misstatement it would catch, the assertion it addresses, the reviewer’s evidence and what happened the last time it flagged something. If the answer to the last question is that it has never flagged anything, the control is either sitting above a very clean process or is not operating, and the memo should say which and why. AS 2201’s Appendix B on multiple locations allows entity-level controls to cover units that individually and in aggregate could not create a material misstatement; it does not allow them to cover a unit that could. Lakeshore’s wealth subsidiary qualifies because its balance sheet sits below the scoping threshold, its revenue is fee-based and settled through the bank’s own systems, and the segment review runs at a threshold of $250,000 against a scoping threshold of $4.9 million. The mortgage subsidiary does not qualify, and the memo says so in one sentence rather than leaving the reader to infer it.

The paragraph 24 list is worth reading against the memo every year: the control environment, controls over management override, the risk assessment process, centralized processing and shared services, controls that monitor results of operations, controls that monitor other controls, the period-end financial reporting process, and the policies that govern significant business control and risk management practices. Two items on that list, the period-end process and management override, are never carried by other entity-level controls; they are tested directly, every year, at every registrant. Where centralized processing sits with a service organization rather than a shared service center, the SOC 1 report review guide covers how the service organization’s controls enter the scope. The control descriptions guide covers how to write the precision of a review control so that the statement is testable rather than decorative.

Fraud risk and management override: the controls the standards single out

AS 2201 requires the risk assessment to consider fraud specifically, and it names the controls that address the risk of management override: controls over significant unusual transactions, particularly late or unusual journal entries; controls over related-party transactions; controls over significant management estimates; and controls that mitigate incentives and pressures on management to falsify results. Every scope includes them, whatever the accounts analysis says, because management override is the mechanism of most financial statement fraud and it operates around the transaction-level controls rather than through them. The journal entry controls are the most testable: approval workflows with thresholds, review of manual entries by someone independent of the preparer, and the analytics over the full journal population that the journal entry analytics guide and the journal entry testing guide describe. Estimates are scoped through the accounts they drive, the allowance, reserves, fair values, impairment, with the controls over assumptions, data and review. Related parties are scoped through the identification process and the approval of transactions with them. And the incentives are addressed by the entity-level controls, compensation design, audit committee oversight and the whistleblowing channel, that the SOX 404 guide describes under the control environment.

The coverage test: proving the scope is complete

The scope is complete when every relevant assertion of every significant account and disclosure has at least one key control addressing each of its what-could-go-wrong statements, and the coverage test is the matrix that proves it: accounts and assertions down the side, key controls across, with the cells showing which control covers which risk. Empty rows are gaps, and they are always present in a first-year program and usually present in a mature one, because accounts and assertions change and the matrix is edited by adding controls rather than by re-deriving coverage. The test also finds the opposite: controls with no row, which are the candidates for removal, and assertions covered by a single manual control whose failure would leave nothing, which are the candidates for a second, preferably automated or detective, control. The coverage matrix is produced before testing begins, reviewed with the external auditor as part of the scoping discussion, and re-run after the year’s changes; the RCM Workbench is built to produce it from the matrix.

Timing: when scope is set, interim testing and the roll-forward

Scope is decided against the year-end assessment date but is set in the first quarter, because the testing that proves the controls operate has to run through the year. The working calendar at a calendar-year registrant is: scoping memo issued by the end of March on the prior year’s audited numbers and the current budget; a materiality refresh at the half year on actual results; interim testing of controls through the third quarter; roll-forward and year-end testing in the fourth quarter and January; and a final materiality check on the draft financial statements before the assessment is signed. Each date on that calendar is a scope decision point, and the memo should carry a dated version for each.

The roll-forward is where scope and timing meet. AS 2201’s roll-forward requirement is short: when controls are tested at an interim date, the auditor determines what additional evidence is needed for the remaining period, weighing the specific control and the risk associated with it, the sufficiency of the interim evidence, the length of the remaining period and the possibility of significant changes in internal control after the interim date. The same four factors are the right ones for management’s own program, and they mean the roll-forward is not a uniform procedure. A daily automated control with no entries in the general ledger’s change log needs an inquiry, a configuration re-check and a change-log review, as the automated controls testing guide sets out. A quarterly manual review with two new preparers since the interim test needs a fresh sample from the fourth-quarter operation. Any control whose interim test found exceptions needs remediation evidence, a re-performance after the fix and a period of operation long enough to show the fix held. The program should decide in advance what long enough means for each control frequency and write it into the memo, because a re-designed control that has operated twice by 31 December is either operating effectively at year-end or it is a deficiency, and the decision should not be made in January under deadline pressure.

Fourth-quarter changes carry a disclosure consequence beyond the testing question. Exchange Act Rule 13a-15(d) requires an evaluation each fiscal quarter of any change in internal control over financial reporting that has materially affected, or is reasonably likely to materially affect, that internal control, and Regulation S-K Item 308(c) requires the change to be disclosed for the last fiscal quarter, which for the annual report is the fourth quarter. A system migration or a re-designed close that goes live in November is therefore three things at once: a re-scope trigger, a roll-forward problem and a disclosure question. The program’s change log should tag each entry with all three outcomes so that the disclosure committee sees them together rather than learning about the migration from the auditor.

Acquisitions have their own timing rule. SEC staff guidance on management’s report permits a business acquired during the year to be excluded from management’s assessment, provided the exclusion is disclosed, the acquired business is identified and its significance to the consolidated financial statements is indicated; the staff does not expect the exclusion to extend beyond one year from the acquisition date or to be omitted from more than one annual report. That is why Lakeshore’s insurance agency, acquired in the current year, sits outside the assessment while its balances still flow through consolidation, and why its controls have to be in scope from the first day of the following year rather than from the day the next scoping memo is issued. Anything acquired more than a year before the assessment date is in the population from the start, and the consolidation controls that bring the excluded agency’s numbers in are in scope in the year of acquisition regardless.

Re-scoping triggers

Scope is re-derived annually and revisited when the business changes. The triggers that force an interim re-scope are new products or revenue streams, acquisitions and disposals, new systems or migrations, changes in accounting standards or policies, changes in materiality from changed results, reorganizations that move processes between units or to shared services, outsourcing, and any deficiency or misstatement in an area previously judged low risk. The program monitors them through the project portfolio, the deal pipeline, the accounting policy committee and the change log, and each trigger produces a documented scoping decision, even where the decision is that nothing changes. The ITGC scoping guide lists the technology triggers in the same form.

Coordinating scope with the external auditor without surrendering it

The external auditor performs its own scoping under AS 2201 and is not bound by management’s memo, but the two exercises should agree on the population and differ only on judgment. The practical way to get there is to share the scoping memo, the significant account table and the key control list before fieldwork begins, and to ask for three things back in writing: the accounts and disclosures the auditor treats as significant that management does not, the controls the auditor intends to test that are not on management’s key control list, and the controls for which the auditor intends to use internal audit’s or management’s testing. Each answer changes the program’s work. The first is a candidate for adding to management’s scope or for a documented disagreement. The second usually reveals a control management should have classified as key. The third sets the bar for internal audit’s test documentation, because work the auditor will use has to meet the auditor’s evidence standard, not just management’s.

The extent of that use is governed by AS 2201 paragraphs 16 to 19 and by AS 2605 on the internal audit function. The auditor may use the work of internal auditors, other company personnel and third parties working under the direction of management or the audit committee, after assessing their competence and objectivity, and the governing principle is that as the risk associated with a control increases, the need for the auditor to perform its own work on that control increases. A program that wants its testing used should therefore expect the auditor to test the highest-risk controls directly whatever the quality of management’s work, and should point its own effort at the volume of moderate-risk controls where its testing can substitute for the auditor’s. Arguing for more reliance on the top-risk controls wastes the meeting; offering complete, re-performable workpapers on the other two hundred is what changes the reliance decision and, eventually, the fee.

Two habits keep the relationship from distorting the scope. The first is that a request from the external auditor is not a scope change; it is an input to one. When the auditor asks for testing of a control management did not classify as key, the program decides whether to add it to the key list, to test it once without changing the list, or to explain why it is not key, and records the decision in the memo. Without that step the key control count drifts upward by a handful every year and nobody can say why. The second is that disagreements on materiality and on the significant account list are documented at the time, with both positions, rather than resolved by quietly adopting the auditor’s number. A scoping threshold that drops in September because the auditor’s is lower is a change the audit committee should hear about, and the SOX 404 guide describes how the program’s status reporting to the committee should present it.

The scoping memo template

The scoping memo records the sequence and its outputs, is approved by the chief financial officer, reviewed by internal audit and discussed with the external auditor before testing starts, and is the document the audit committee can ask for when it wants to know why something was or was not in scope. It is five to ten pages plus attachments. The planning memo template is its engagement-level counterpart, the ITGC scoping memo its technology continuation, and the templates directory lists the companions.

SOX scoping memo. Financial year: ________ Prepared by: ________ Date: ________ Approved by (CFO): ________ Reviewed by (internal audit): ________ Discussed with external auditor on: ________

1. Filer status and program basis. [Filer category and the tests supporting it; 404(b) applicability; FDICIA or other overlapping requirements; framework (COSO 2013); changes from the prior year.]

2. Materiality. [Benchmark, percentage and amount for overall materiality; performance or scoping materiality; qualitative considerations; comparison with the auditor’s figure.]

3. Significant accounts and disclosures. [Attachment A: trial balance at scoping level with the quantitative screen; qualitative factors applied; relevant assertions per account; accounts excluded and why.]

4. Locations and business units. [Attachment B: unit analysis with categorization (specific risk, financially significant, covered by entity-level controls); coverage by account; shared services; acquisitions and the exclusion decision.]

5. Entity-level controls. [Controls by COSO component; precision assessment for those relied on to cover units or accounts; fraud and management override controls.]

6. Processes and what could go wrong. [Attachment C: account-to-process map; what-could-go-wrong statements by assertion; walkthrough references.]

7. Key controls. [Attachment D: the risk and control matrix; control counts by type; controls removed and added this year with reasons.]

8. Coverage test. [Attachment E: the coverage matrix; gaps identified and closed; single-control assertions and the decision on each.]

9. Systems, service organizations and IPE. [Reference to the ITGC scoping memo; SOC report register; relied-on reports and the ITGC-or-tie-out decision.]

10. Testing strategy and responsibilities. [Who tests what; reliance arrangements; interim and year-end timing; sample size policy.]

11. Re-scoping. [Triggers monitored; owner; log of interim decisions.]

Worked example: Lakeshore Bancorp scopes its program

Lakeshore Bancorp, the nine-billion-dollar publicly traded regional bank with twenty-two internal auditors, re-derives its SOX scope every year in the fourth quarter, with the SOX office producing the memo and internal audit reviewing it as part of its assurance over the program. For FY26 the sequence took six weeks. Materiality was set at 5 percent of normalized pre-tax income, about 6.5 million dollars, with scoping materiality at 75 percent of that, and the memo recorded the bank’s capital ratios as qualitative considerations that could make a smaller misstatement material. The quantitative screen at the scoping level of the trial balance brought in loans and the allowance, deposits, investment securities, interest income and expense, non-interest income including fees, non-interest expense led by compensation, derivatives, and the related disclosures; the qualitative factors added the suspense and clearing accounts, insider loans as related-party items, and the fair value hierarchy disclosure, and elevated the allowance to the highest risk rating for its judgment and its new expected-loss model data flows.

The unit analysis covered the bank, its mortgage subsidiary and its wealth management subsidiary: the bank and the mortgage subsidiary were financially significant and in scope for their significant accounts, the wealth subsidiary was covered by entity-level monitoring and consolidation controls whose precision was assessed and documented, and a small insurance agency acquired in the year was excluded from the assessment with disclosure and scheduled for the following year. The account-to-process map produced eleven processes and 340 what-could-go-wrong statements. Key control selection produced 212 controls, 68 automated, 91 IT-dependent manual and 53 manual, down from 241 the prior year after the coverage matrix showed 29 controls with no risk they uniquely addressed. The coverage test also found three assertions with no key control, all disclosure completeness assertions around the allowance methodology and the fair value hierarchy, which were closed by adding disclosure checklist controls with a precision the auditor accepted. The systems chain then ran into the ITGC scoping memo, with nine systems in scope, and the memo was discussed with the external auditor in December, where the only disagreement, over the wealth subsidiary’s coverage, was resolved by the precision analysis in section 5.

StepLakeshore FY26 result
MaterialityOverall 6.5 million dollars (5 percent of normalized pre-tax income); scoping 4.9 million; capital ratios as qualitative considerations
Significant accounts and disclosures9 account groups plus suspense and clearing, insider loans, and 4 disclosures; allowance rated highest risk
UnitsBank and mortgage subsidiary in scope; wealth subsidiary via entity-level controls with documented precision; acquired agency excluded with disclosure
Processes and risks11 processes; 340 what-could-go-wrong statements
Key controls212 (68 automated, 91 IT-dependent manual, 53 manual); 29 removed, 3 added from the coverage test
Fraud and overrideJournal entry workflow and analytics; estimate controls over the allowance; insider loan approvals; entity-level controls documented
Systems and service organizations9 systems; 3 SOC 1 reports; per the ITGC memo
TimingSix weeks; memo approved in December; auditor discussion resolved one disagreement

Common mistakes

  • Rolling the scope forward. Re-derive it from the financial statements every year; the changes are where the risk is.
  • Borrowing the auditor’s materiality. Set management’s own, document the reasoning, and compare.
  • Screening at the face of the financial statements. Disaggregate to the level at which the accounts are managed.
  • Treating every assertion as relevant. Only the assertions with a reasonable possibility of material misstatement drive controls.
  • Using a coverage percentage as the standard. Categorize units by risk and document the precision of the entity-level controls that cover the rest.
  • Skipping the what-could-go-wrong step. Without it, gaps in the control set are invisible.
  • Inflating key controls. One control per risk it uniquely addresses; remove the ones with no row in the coverage matrix.
  • Forgetting the override controls. Journals, estimates, related parties and incentives are in scope regardless of the accounts analysis.
  • Never running the coverage test. Empty rows are the finding the auditor will make for you.
  • Leaving the acquisition for next year in every sense. Exclude it with disclosure if eligible, but scope it now.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading