Skip to content
complianceofficer

SOX compliance: Sarbanes Oxley 404 controls, audit, requirements and testing

SOX compliance is meeting the Sarbanes-Oxley Act of 2002, which made a public company's own officers personally liable for its financial reporting. Three provisions do nearly all the work: Section 302 certifications every quarter, a Section 404(a) management assessment of internal control over financial reporting every year, and a Section 404(b) auditor attestation on that control system if you are an accelerated filer.

Nothing about that has changed since 2004. What has changed is the cost. Average programs now run $2.3 million and 15,580 hours a year, and the biggest driver is scope creep: more in-scope systems, more key controls, and a rulebook that keeps moving underneath a control matrix nobody has time to re-read.

Every threshold, date and figure here was checked against the SEC, the PCAOB, the US Code and KPMG's 2025 SOX survey in August 2026. Where the statute and the SEC rule disagree, this page says so.

Scan your SOX and financial reporting obligations

Pick your industry and size. The scan returns the obligations that apply to an organization like yours, what moved in the last 12 months, and the primary source behind each line. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 101 The statute

What SOX compliance actually requires, section by section

Sarbanes-Oxley runs to eleven titles, but a compliance program only lives in about six sections. Knowing which one a request comes from tells you who owns it and what evidence closes it. If somebody asks for a control narrative, that is 404. If somebody asks whether the CFO can sign, that is 302.

Section What it requires How often Who owns it
301 An independent audit committee that appoints and oversees the auditor, plus a confidential channel for complaints about accounting. Standing Board
302 CEO and CFO certify each periodic report: they reviewed it, it is not materially misleading, and they evaluated disclosure controls as of period end. Every 10-Q and 10-K CEO, CFO
404(a) Management states its responsibility for internal control over financial reporting, names the framework used, and reports whether the system was effective at year end. Annual, in the 10-K Management, internal audit
404(b) The external auditor issues its own opinion on internal control over financial reporting, integrated with the financial statement audit under PCAOB AS 2201. Annual, accelerated filers only External auditor
802 Criminal liability for destroying or altering records to obstruct a federal matter, plus an audit workpaper retention duty on the accountant. Continuous Everyone, and the audit firm
906 Criminal certification. Knowing false certification is up to $1,000,000 and 10 years; willful false certification is up to $5,000,000 and 20 years. Every periodic report CEO, CFO
1107 Retaliation against a whistleblower who provides truthful information to law enforcement is a federal crime. Applies to any employer, not just filers. Continuous HR, legal, compliance

The retention number almost everybody gets wrong. Section 802 wrote a five year workpaper retention duty into 18 U.S.C. 1520, and that is what the statute still says. The SEC then set the rule at seven years in Rule 2-06 of Regulation S-X. Seven is the number your auditor works to. Five is the number in the law that most published summaries quote, which is how you end up with two different answers from two people who are both reading a real source.

§ 102 Scope

Who has to comply with SOX, and what filer status changes

Every SEC registrant is in scope. Filer status does not decide whether SOX applies to you, it decides whether your auditor has to attest to your controls and how many days you get to file. Both are set by public float measured on the last business day of your second fiscal quarter, and since the SEC's 2020 amendments, by revenue as well.

Filer status Test 404(a) assessment 404(b) attestation 10-K due
Large accelerated Public float of $700 million or more Required Required 60 days
Accelerated Float of $75 million to under $700 million, and annual revenue of $100 million or more Required Required 75 days
Non-accelerated Float under $75 million, or float in the accelerated band with revenue under $100 million Required Exempt 90 days
Newly public First annual report after an IPO Deferred to the second 10-K Not yet, and up to five years for an emerging growth company Per status

The revenue test is the part that surprises people

Before 2020, float alone decided it: cross $75 million and your auditor had to attest. The SEC's March 2020 amendments added a revenue screen, so a company that qualifies as a smaller reporting company and books under $100 million in annual revenue stays non-accelerated no matter how the market values it. A clinical-stage biotech with a $400 million float and $12 million of revenue is exempt from 404(b). A distributor with an $80 million float and $300 million of revenue is not.

The same amendments raised the exit threshold. Once you are an accelerated or large accelerated filer, you drop back to non-accelerated when float falls below $60 million, not $50 million. That matters in a down year, because it decides whether you are paying for an attestation you no longer owe.

Exemption from 404(b) is not exemption from 404. A non-accelerated filer still documents its controls, still tests them, and still publishes a conclusion signed by management. What it loses is the second pair of eyes, which in practice means deficiencies get found later and by the wrong people. If you are heading toward accelerated status, our SOX compliance software page walks through what the first attestation year adds.

§ 103 The cycle

How SOX 404 control testing works across the year

SOX 404 is a top-down, risk-based exercise. You start at the financial statements and work down to the control, never the other way around. Every hour spent testing a control that no material misstatement could ever flow through is an hour you cannot spend on the ones that matter, and scope discipline is the single biggest lever on program cost.

Step 1

Scope by materiality

Set overall materiality, then find the accounts, disclosures and locations that could hold a misstatement that size. Those become significant accounts and in-scope entities. Everything downstream inherits this decision.

Step 2

Name what could go wrong

For each significant process, state the specific error or fraud risk by assertion: existence, completeness, valuation, rights, presentation. A risk written as "revenue may be misstated" is not usable; "revenue recognized before control transfers" is.

Step 3

Build the control matrix

Map one or more controls to each risk, and record whether each is preventive or detective, manual or automated, and how precisely it operates. Precision is what auditors challenge most, and it is what a vague review control always fails.

Step 4

Test design first

Walk one transaction end to end and ask whether this control, operating as described, would actually catch the risk. A control that cannot work by design does not need a sample; it needs redesigning before the year is over.

Step 5

Test operating effectiveness

Sample from the full period population and examine real evidence. Interim testing needs a roll-forward through year end. Document the population, how you selected from it, and what you looked at, because that is what gets reperformed.

Step 6

Evaluate and conclude

Aggregate every exception, judge severity, remediate what you can before year end, then write the assessment. Remediation after year end is disclosable progress, not a change to the year end conclusion.

There is no prescribed sample size. PCAOB AS 2201 sets none, and neither does the SEC. The familiar table of 25 for a daily control, 2 for a quarterly one, 1 for an annual one is practice convention that spread through audit firm methodology, not a rule you can cite. It is defensible, but defend it as judgment tied to control frequency and risk, because that is the question you will get. Our detailed walkthrough of the mechanics is in SOX 404 testing.

§ 104 Severity

Control deficiency, significant deficiency, material weakness

Every exception you find lands in one of three buckets, and only the top one changes your 404 conclusion. The judgment turns on two independent questions: how likely is it that a misstatement gets through, and how big could that misstatement be. Both come from PCAOB AS 2201, Appendix A.

Severity Test Who must be told Effect on the 404 opinion
Control deficiency A control is missing, or does not operate as designed Process owner, tracked internally None on its own
Significant deficiency Less severe than a material weakness, but important enough to merit attention by those responsible for oversight of financial reporting Audit committee, in writing None, but disclosed to the committee
Material weakness A reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis Audit committee, board, and the market in the 10-K Internal control over financial reporting is not effective

Read the material weakness definition slowly, because two words in it do the work. "Reasonable possibility" is a lower bar than probable; it includes outcomes that are reasonably possible but unlikely. And the magnitude test asks about potential misstatement, not the error you actually found. A $4,000 error discovered by luck in a process where a $4 million error could have passed unchecked is a material weakness, and a $2 million error caught by the very control you were testing may not be one.

AS 2201 paragraph .69 also names four circumstances that are indicators of a material weakness on sight: fraud involving senior management at any size, a restatement to correct a material misstatement, a material misstatement found by the auditor that your controls should have caught, and ineffective audit committee oversight. Any one of those puts the burden on you to explain why it is not a material weakness. The full walkthrough, with examples of each severity level, is in material weakness vs significant deficiency.

§ 105 What changes

What changes for SOX audits on 15 December 2026

The statute is stable. The auditing standards underneath it are not. A block of PCAOB changes adopted in 2024 takes effect 15 December 2026, after the Board postponed the package by a year in File No. PCAOB-2025-01, dated 28 August 2025. None of it changes what management owes under Section 404(a), and all of it changes how your auditor behaves in the 404(b) audit, which is where your requests and your fees come from.

AS 2201, amended .09 and new .99

The internal control audit standard itself. Paragraph .09 tightens planning, and a new paragraph .99 tells the auditor what to do when information surfacing after the report was issued suggests the engagement was deficient. Expect more questions about information that arrives late, including yours.

QC 1000, firm quality control

The new firm-level quality control standard, originally due 15 December 2025 and postponed a year. It reaches you indirectly: more internal monitoring inside your audit firm generally means more documentation asked of the client, earlier.

AS 2110 and AS 1215

Risk assessment and audit documentation, both amended on the same date. Documentation changes are the ones that reach your team fastest, because the evidence the auditor has to retain is usually evidence you have to produce.

What it does not change

No new sample sizes, no new control count, no change to the 404(a) assessment, and no change to filer thresholds. If a vendor tells you these amendments create a new management obligation, read the release: PCAOB Release No. 2024-005 is addressed to auditors.

The practical move is calendar work rather than control work. Ask your engagement partner, in the planning meeting for the first fiscal year that starts after 15 December 2026, which requests change and when they land. Firms that answer that question in the fourth quarter cause a scramble; firms that answer it in the first cause a workplan.

§ 106 Cost

What SOX compliance costs, and why it keeps rising

KPMG's 2025 SOX survey is the most useful public benchmark, because it reports the drivers and not just the total. The headline is that fiscal 2024 programs cost 44 percent more than fiscal 2022 programs, and almost none of that came from the rules changing.

Measure FY22 FY24 What it tells you
Average program cost $1.6 million $2.3 million Up 44 percent in two years
Average hours 11,800 15,580 Effort, not just rates, is driving cost
Key controls in scope 463 546 Scope grew 18 percent
In-scope systems 17 40 The real driver: the estate more than doubled
Testing hours per control 12 16 Each control also got more expensive
Controls that are automated 21 percent 17 percent Automation share went backward

That last row is the one worth sitting with. Companies added 23 systems to scope and let the automated share of their controls fall, which means the new systems arrived wrapped in manual controls. Satisfaction with SOX technology dropped from 92 percent to 58 percent over the same period even though 68 percent had GRC tooling in place, so the tools were bought and then not trusted.

Two cheap levers usually exist before you buy anything. Rationalize the control matrix, since a 546 control population almost always contains duplicates surviving from an ERP migration nobody closed out. And check whether your auditor is relying on your work: 56 percent of respondents had fewer auditor in-scope controls, but 90 percent could not quantify what that saved them, which is a negotiation nobody is having. Full category numbers sit on our compliance software pricing benchmark.

§ 107 Where software helps

Where software helps a SOX program, and where it does not

A SOX tool cannot make a judgment for you. It can stop you from losing the judgments you already made, which is most of what goes wrong in year three of a program.

Worth automating

  • The risk and control matrix as a live object, versioned, so last year's rationale survives this year's staff turnover.
  • Evidence requests and their status, so the quarter does not end in a spreadsheet of chased emails.
  • Deficiency tracking from exception through remediation to retest, with dates that survive an auditor asking when.
  • Change detection on the rulebook and on your own systems, so a new subsidiary or a new revenue stream reaches scoping before year end.

Not worth believing

  • Any claim to produce a SOX certification. No such thing exists for a company.
  • Pre-built control libraries treated as your scope. A library is a starting list, and adopting it whole is how you get to 546 controls.
  • Automated severity assessment. Reasonable possibility and magnitude are judgments the standard assigns to people.
  • Replacing the external auditor. Under 404(b) the opinion has to come from a registered public accounting firm.

Complianceofficer watches the regulations and the standards themselves and points at the specific control or policy each change breaks, which is the part a control repository does not do. For the product view of the 404 cycle, see SOX compliance software, and for the wider control estate see audit management software and regulatory change management.

§ 108 Questions buyers ask

SOX compliance questions

What is SOX compliance?

SOX compliance means meeting the Sarbanes-Oxley Act of 2002, the US law that makes a public company's own executives personally answerable for its financial reporting. In practice it comes down to three duties: the CEO and CFO certify each report under Section 302, management assesses and reports on internal control over financial reporting under Section 404(a), and larger filers get that control system audited by their external auditor under Section 404(b).

Who is subject to SOX compliance?

Every company that files reports with the SEC under the Securities Exchange Act, which means US-listed public companies of any size, plus their consolidated subsidiaries and foreign private issuers. Size changes what you owe, not whether you are in scope. A non-accelerated filer still certifies under Section 302 and still reports management's assessment under Section 404(a). What size buys you is exemption from the Section 404(b) auditor attestation.

Is SOX compliance only for public companies?

The internal control provisions, Sections 302 and 404, apply only to SEC registrants. Two parts of the act reach everyone: Section 802 makes it a federal crime for anyone to destroy or alter records to obstruct an investigation, and Section 1107 protects whistleblowers at any employer. Private companies also hit SOX indirectly, through IPO readiness, acquisition by a filer, or a debt covenant that borrows the standard.

What are the SOX compliance requirements?

Five things carry almost all the work. Officer certifications on every 10-K and 10-Q under Section 302. An annual management assessment of internal control over financial reporting under Section 404(a), stated as effective or not effective. An auditor attestation on that control system under Section 404(b) if you are an accelerated or large accelerated filer. An independent audit committee under Section 301 with a whistleblower channel. Records retention under Section 802.

Is there a SOX compliance certification?

No. There is no such thing as a SOX certified company and no body issues a SOX certificate. What exists is a management assertion in your 10-K, and for larger filers an auditor's opinion on internal control over financial reporting. Any vendor selling you SOX certification is selling something the law does not recognize. Individuals can earn professional credentials in internal controls, but that certifies the person, not the company.

What is a SOX compliance audit?

Two different things get called this. Internally, it is management's own annual test of key controls: walkthroughs, design evaluation, then operating effectiveness testing across the year, ending in the Section 404(a) assessment. Externally, it is the auditor's integrated audit under PCAOB AS 2201, where the same firm opines on both the financial statements and internal control over financial reporting. Only the second one produces an opinion.

What is the difference between SOX 302 and SOX 404?

Section 302 is quarterly and personal: the CEO and CFO sign a statement in every 10-Q and 10-K that they reviewed the report, that it is not materially misleading, and that they evaluated disclosure controls as of period end. Section 404 is annual and structural: management documents and tests internal control over financial reporting and reports a conclusion, and larger filers have an auditor attest to it. 302 covers disclosure controls, 404 covers financial reporting controls.

How much does SOX compliance cost?

KPMG's 2025 SOX survey put the average program at $2.3 million and 15,580 hours in fiscal 2024, up 44 percent in cost from $1.6 million in fiscal 2022. The averages hide a wide range: a first-year non-accelerated filer with 150 controls and no 404(b) attestation runs far below that, while a large accelerated filer with 500-plus key controls and multiple ERP instances runs well above. Control count and system count drive the number more than revenue does.

How do you perform SOX compliance testing?

Work backward from the financial statements. Scope in the accounts and locations that are material, identify what could go wrong in each significant process, name the control that addresses it, then test that control twice: once for design, by walking a transaction through it, and again for operating effectiveness across the period. Document the population, the selection basis and the evidence examined. PCAOB AS 2201 prescribes no sample sizes, so your sample sizes are a judgment you have to defend.

Last updated August 2026.

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.

§ 90

Related registers