Skip to content
complianceofficer

Blog · 21 Jul 2026 · 11 min read

SOX 404 compliance requirements: what management must do

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation

The short answer: SOX 404 has two parts. Section 404(a) requires management of every SEC reporting company to assess, document and state a conclusion on the effectiveness of internal control over financial reporting each year. Section 404(b) requires the external auditor to issue its own independent opinion on that same control environment, and it applies only to accelerated and large accelerated filers. Non-accelerated filers and emerging growth companies owe 404(a) but are exempt from 404(b) while that status lasts. A material weakness must be disclosed in the annual report either way.

That is the requirement in six sentences. The rest of this piece is what it means in practice: the annual cycle, what counts as a key control, how deficiencies get graded, what it costs, and the two areas auditors are pushing on hardest right now.

What Section 404 actually says

The Sarbanes-Oxley Act of 2002 was passed after Enron and WorldCom, and Section 404 is the part aimed squarely at whether a company's financial numbers can be trusted. It does not prescribe controls. It requires you to have a control framework, apply it, test it, and say publicly whether it worked.

Under 404(a), management must include in the annual report a statement of its responsibility for establishing and maintaining adequate internal control over financial reporting, identify the framework used to evaluate it, and state its conclusion on effectiveness as of fiscal year end. Almost every US registrant uses the COSO 2013 Internal Control Integrated Framework for this, and in practice an auditor will question any other choice.

Under 404(b), the registered public accounting firm that audits the financial statements also audits internal control over financial reporting and issues a separate opinion. This is the expensive half. It roughly doubles the testing that happens, because the auditor cannot simply accept management's work; it re-performs enough of it to support its own conclusion.

Who has to comply, and who is exempt

Filer status decides the answer, and it is worth being precise because companies move between categories as their public float changes.

Status 404(a) management assessment 404(b) auditor attestation
Large accelerated filer Required Required
Accelerated filer Required Required unless the smaller reporting company revenue test applies
Non-accelerated filer Required Exempt
Emerging growth company Required from the second annual report Deferred while EGC status lasts, up to five years
Private company Not applicable Not applicable

Two things trip up newly public companies. First, the 404(a) obligation begins with the second annual report, not the first, which sounds generous until you work backwards: designing, documenting and operating controls long enough to test them means the work starts roughly 18 months before that filing. Second, EGC status ends early if you exceed the revenue ceiling, issue enough non-convertible debt, or become a large accelerated filer, and companies have been caught planning for five years of relief and getting two.

Private companies are outside Section 404 entirely, but note that two SOX provisions apply to everyone: the criminal penalties for destroying or altering records to obstruct a federal investigation, and whistleblower retaliation protections.

What counts as a SOX control

A SOX control is any control that supports a financial statement assertion: existence, completeness, accuracy, valuation, rights and obligations, or presentation. That is the test. If a control does not trace back to an assertion in a significant account or disclosure, it does not belong in SOX scope, and one of the fastest ways to reduce a bloated program is to remove controls that never should have been in it.

In practice a risk and control matrix holds four broad types:

  • Entity-level controls. Tone at the top, the code of conduct, board and audit committee oversight, the whistleblower channel, and management review controls that operate across the company.
  • Process-level controls. The transactional layer: three-way match in procure-to-pay, credit approval in order-to-cash, account reconciliations, journal entry review, cut-off procedures at period end.
  • IT general controls. Logical access provisioning and periodic user access reviews, change management on financial systems, and job scheduling and backup. ITGCs matter far beyond their own line items, because every automated control depends on them.
  • Management review controls. The judgment-heavy reviews of estimates, reserves, impairment and forecasts. These attract the most auditor scrutiny because reviewer precision is hard to evidence: "I reviewed it" is not a control, but "I investigated every variance over $250,000 and documented the resolution" is.

The annual SOX cycle in practice

Almost every program runs the same eight stages. Where teams lose time is usually stages one and seven.

  • Scoping. Set materiality, identify significant accounts and disclosures, and select in-scope locations and systems. Redone every year, because acquisitions and system migrations change it.
  • Risk and control matrix. Map each risk to a control, an owner, a frequency and the assertion it supports.
  • Documentation and walkthroughs. Narratives and flowcharts refreshed annually, with a walkthrough of one transaction end to end to confirm the process still works as written.
  • Design effectiveness. Would this control catch the error it exists to catch? Assessed before any operating testing, because testing a badly designed control just proves it operated badly.
  • Operating effectiveness testing. Sample sizes driven by control frequency: a daily control needs far more samples than a quarterly one. Interim testing plus a roll-forward to year end is the normal pattern.
  • Deficiency evaluation. Grade what you found, and aggregate it. Three unrelated minor exceptions in the same account can combine into something that is not minor.
  • Remediation and retest. A remediated control must operate long enough to be retested before year end, which is why exceptions found in Q4 are so painful.
  • Assertion. Management concludes under 404(a); the auditor issues its opinion under 404(b).

How deficiencies are graded

The three-tier ladder is about severity of potential misstatement, not about whether an error actually happened. A control deficiency exists when a control does not let management or employees prevent or detect misstatements on a timely basis in the normal course of their duties. It becomes a significant deficiency when it is important enough to merit the attention of those responsible for oversight, meaning the audit committee. It becomes a material weakness when there is a reasonable possibility that a material misstatement of the financial statements would not be prevented or detected on a timely basis.

Only material weaknesses must be disclosed publicly, and disclosure has consequences: a hit to the share price, higher audit fees, and often a covenant conversation. This is why deficiency aggregation is negotiated so carefully with auditors, and why programs that track exceptions in a spreadsheet struggle. You cannot aggregate what you cannot see in one place.

What SOX 404 costs

The 2025 KPMG SOX survey gives the clearest public benchmark. The average SOX program now costs $2.3 million a year and consumes 15,580 hours, against $1.6 million in FY22, and 45 percent of companies reported a year-over-year increase. Average hours rose 32 percent over the same two years, from 11,800.

The driver is scope, not price inflation. Average in-scope systems more than doubled from 17 in FY22 to 40 in FY24, and average key controls grew 18 percent to 546, while the share of automated controls did not rise to match. More systems, same manual testing model, predictable result. If your program feels like it doubled in two years, that is because the average one did.

The cost lever most teams underuse is automation of the evidence layer rather than headcount. A control that produces its own timestamped evidence when it runs costs a fraction of one that requires a tester to request a screenshot, chase the owner, and file it. The same logic applies upstream: when the close process itself is clean and the numbers roll straight through into board-ready GAAP financial statements without manual re-keying between systems, there are simply fewer places for a control to be needed at all.

Two things auditors are pushing on in 2026

First, cybersecurity as an ICFR matter. Auditors increasingly treat a material security weakness in a system that produces financial data as a potential ICFR deficiency, rather than as a separate infosec topic. In practice that pulls access management, change control and incident response on financial systems deeper into SOX scope, and it means the security evidence you already collect for SOC 2 is worth reusing rather than recreating.

Second, AI-assisted processes. Finance teams have put AI into reconciliations, anomaly detection, forecasting and disclosure drafting faster than they have documented oversight over it. If a model proposes journal entries or flags exceptions and nobody can evidence who reviews its output, on what basis, and what happens when it is wrong, that is a control gap in a familiar shape. Expect to be asked how the model was validated and how its output is reviewed with precision.

Getting ahead of the next change

The uncomfortable pattern in both of those items is that they did not arrive as a new rule with a compliance date. They arrived through guidance, inspection focus and auditor practice, and the companies that adjusted early found out from reading, not from a notification. That is the structural weakness in most SOX programs: the control set is maintained diligently, and the assumptions underneath it are not.

Complianceofficer watches what regulators and standard setters actually publish, explains each change in plain language, and maps it to the policies and controls you already hold, so the assumptions get challenged on a schedule rather than at year end. If you are choosing tooling for the cycle itself, our SOX compliance software page covers the RACM, testing and deficiency workflow, and best compliance software compares the platforms that serve public company programs against the security automation tools that do not. Run the compliance scan above with your sector selected to see the obligation register it builds, with the last twelve months of movement and every source linked.

General regulatory information, not legal advice. Written by the team at ComplianceOfficer building Complianceofficer; verify anything consequential with qualified counsel.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.