Design vs Operating Effectiveness Testing Under SOX: 2026 Practitioner Walkthrough
If your SOX 404 program treats a passing walkthrough as proof that a control works, you have a gap that external auditors will find. Design effectiveness testing (TOD) and operating effectiveness testing (TOE) are legally distinct obligations under PCAOB AS 2201, and confusing them is one of the most common reasons internal audit teams get findings.
This guide walks through both phases in sequence: what each test requires, how to execute it, how many samples to pull, where the ITGC layer fits in, and how deficiencies get classified. It is written for SOX program managers, internal audit directors, and CFOs at accelerated and large accelerated filers who need more than a definition.
Key takeaway: TOD asks whether a control could work. TOE asks whether it did work. You must pass TOD before TOE is worth running. A failed design makes operating effectiveness testing pointless.
What Is the Difference Between Design and Operating Effectiveness Testing?
Design effectiveness (TOD) is a point-in-time assessment of whether a control is logically constructed to prevent or detect a material misstatement. Operating effectiveness (TOE) is a longitudinal, evidence-based assessment of whether that control actually functioned as designed throughout the audit period.
PCAOB AS 2201, Section .39 defines the design test precisely: the auditor determines whether the company's controls, "if they operated as prescribed by persons possessing the necessary authority and competence to perform the control effectively, satisfy the company's control objectives and can effectively prevent or detect errors or fraud that could result in material misstatements."
Section .41 addresses operating effectiveness: testing whether the control "has been operating as designed and whether the person performing the control possesses the necessary authority and competence to perform the control effectively." The same section states plainly: "Inquiry alone does not provide sufficient evidence to support a conclusion about the effectiveness of a control."
| Dimension | Design Effectiveness (TOD) | Operating Effectiveness (TOE) |
|---|---|---|
| Core question | Could this control work? | Did this control work? |
| Time horizon | Point in time | Full audit period (typically 12 months) |
| Primary procedure | Walkthrough | Sample-based testing |
| Evidence types | Inquiry, observation, inspection, reperformance of logic | Inspection of executed evidence, reperformance on samples |
| Typical failure | Control architecture has a gap (e.g., no segregation of duties) | Control was bypassed, skipped, or performed by an unauthorized person |
| Regulatory basis | AS 2201, Section .39-.40 | AS 2201, Section .41-.44 |
| Management framework | SEC Release No. 33-8810 (404a) | SEC Release No. 33-8810 (404a) |
The COSO 2013 Internal Control Framework underpins both evaluations. Design effectiveness maps to whether the five components and 17 principles are present and functioning; operating effectiveness maps to whether they are operating together in an integrated manner over time.
The Sequential Dependency: Why TOD Must Come First
If a control fails design testing, operating effectiveness testing is moot. There is no point sampling 25 instances of a control that is structurally incapable of addressing the risk it is supposed to cover.
This sequencing has a practical consequence that the top-ranking articles on this topic miss entirely: a design failure discovered mid-year requires remediation before TOE can be completed. If your team identifies in Q2 that a journal entry approval control lacks proper segregation of duties, you cannot simply continue testing operating effectiveness for the rest of the year. The control must be redesigned, implemented, and then tested for operating effectiveness over a sufficient period to support a year-end conclusion.
The remediation timeline matters for your 404(a) assessment. Management cannot conclude that ICFR is effective if a material weakness exists at year-end, per SEC Release No. 33-8810. If remediation is not complete by December 31, the material weakness must be disclosed in Item 9A of the Form 10-K.
For AI-assisted controls specifically, the sequencing question gets more complex. See SOX Reliance on AI Controls: What the Guidance Actually Says (2026) for how AS 2201 applies to automated and AI-driven controls.
How to Test Design Effectiveness: The Walkthrough
The walkthrough is the primary procedure for TOD under AS 2201, Section .40. It involves tracing a transaction from origination through the company's information systems to the point it appears in the financial report.
A proper walkthrough combines four procedures:
- Inquiry of the control owner and relevant personnel about how the control operates
- Observation of the control being performed in real time
- Inspection of relevant documentation, system configurations, and approval records
- Reperformance of the control logic to verify it produces the intended result
For a journal entry approval control, a TOD walkthrough would verify:
- The system requires a preparer and a separate approver (segregation of duties is enforced at the system level or by policy)
- The approver has the authority and competence to review the entry (not a junior staff member rubber-stamping a controller's work)
- Dollar thresholds trigger escalation to a senior reviewer
- Evidence of approval is captured and retained in the system
- The control addresses the specific risk: unauthorized or erroneous journal entries reaching the general ledger
If all four elements are present and logically coherent, the design is effective. A walkthrough of a single transaction is generally sufficient for TOD. It is not sufficient for TOE.
Common mistake: Many internal audit teams document a walkthrough and then assert operating effectiveness without pulling a sample. Grant Thornton's 2024 SOX practice guidance identifies this as one of the most common audit findings: treating a walkthrough as a substitute for operating effectiveness testing is a deficiency in the testing methodology itself.
How to Test Operating Effectiveness: Sampling and Evidence
TOE requires selecting a sample from the full population of control executions over the audit period and inspecting evidence that the control operated as designed for each item. The procedures mirror TOD in type (inquiry, observation, inspection, reperformance) but differ fundamentally in scope: you are testing a representative slice of the year, not a single transaction.
Step-by-Step TOE Process
- Define the population. Identify every instance the control was supposed to operate during the period (e.g., all journal entries over $50,000 requiring senior approval from January 1 to December 31).
- Determine the sample size based on control frequency (see table below).
- Select the sample using random or systematic selection. Document the selection methodology.
- Inspect evidence for each sample item: approval timestamps, system logs, sign-off documentation, exception reports.
- Reperform where needed. For a three-way match control, pull the invoice, PO, and receiving report and verify the match yourself.
- Evaluate exceptions. A single deviation in a sample of 25 is not automatically a control failure, but it requires evaluation of the nature and cause.
- Document the rationale for your sample size, selection method, and conclusion.
TOE Sample Size Guidance by Control Frequency
Sample sizes are not codified in PCAOB standards, but AS 2315 (Audit Sampling) requires auditors to consider the tolerable rate of deviation, expected deviation rate, and desired confidence level. The AICPA Guide: Audit Sampling (2023 edition) provides the statistical underpinning: at a 95% confidence level, 5% tolerable deviation rate, and 0% expected deviations, the required sample size is 59. At 90% confidence with the same parameters, it is 45.
In practice, Big-4 firms apply the following widely accepted benchmarks:
| Control Frequency | Industry-Standard Sample Size |
|---|---|
| Annual | 1 |
| Quarterly | 2 |
| Monthly | 5 |
| Weekly | 15-25 |
| Daily / High-frequency | 25-60 |
These figures align with BDO's published SOX advisory guidance, which recommends attribute sampling calibrated to confidence level and tolerable deviation rate. Documenting your rationale for the chosen sample size is not optional. Auditors will ask, and "that's what we always do" is not a defensible answer.
For automated controls that operate consistently and where the ITGC environment is effective, PCAOB Staff Guidance allows a single test of the control's operation to be sufficient. This "test once, rely broadly" approach is entirely contingent on ITGC TOE passing first.
The ITGC Layer: How IT General Control Failures Cascade
This is the aspect of SOX testing that trips up even experienced teams. IT general controls (ITGCs) covering logical access, change management, computer operations, and program development must pass both TOD and TOE before any automated application control can be relied upon.
Here is why: an automated application control (say, a system-enforced three-way match) is only as reliable as the IT environment it runs in. If change management ITGCs fail TOE because unauthorized changes to the system were possible during the year, the auditor cannot conclude that the automated control operated consistently, even if every sample of the application control itself looks clean.
As Deloitte's 2024 SOX guidance puts it: ITGC failures cascade into application control TOE conclusions. The practical implication:
- Failed ITGC TOE for change management = automated application controls are untestable for the affected period
- Failed ITGC TOE for logical access = controls dependent on access restrictions cannot be relied upon
- Remediation of ITGCs mid-year may allow TOE reliance for the post-remediation period only
For SOX programs that rely heavily on automated controls, ITGC testing is not a back-office IT exercise. It is a gating condition for a large portion of the control portfolio. Audit Analytics data for 2023 shows IT and system control failures were the root cause of 18% of material weaknesses disclosed that year.
For a deeper look at how AI-driven controls interact with the ITGC layer, see AI Journal Entry Testing and SOX 404 Controls: A 2026 Practitioner Walkthrough.
Management's 404(a) vs. the Auditor's 404(b): Different Obligations
Many practitioners conflate these, and the confusion creates real scope gaps.
Management's 404(a) assessment is governed by SEC Release No. 33-8810. Management must evaluate and report on whether ICFR is effective as of year-end. Management selects the framework (COSO 2013 is standard), scopes the key controls, performs or directs testing, and signs the assessment that appears in Item 9A of the 10-K.
The external auditor's 404(b) attestation is governed by PCAOB AS 2201. The auditor must independently attest to management's assessment. The auditor cannot simply rely on management's testing. Under AS 2605, the auditor may consider the work of internal audit when determining the nature, timing, and extent of their own procedures, but must obtain sufficient independent evidence.
As KPMG's 2024 Audit Committee Guide notes, these are legally distinct obligations. The auditor's TOD and TOE procedures will not be identical to management's, and the auditor's conclusions are independent.
404(b) applies only to accelerated filers (public float of $75 million or more) and large accelerated filers (public float of $700 million or more). Smaller reporting companies (public float below $250 million or revenues below $100 million) are exempt from 404(b) under SEC Release No. 33-10513. For SRCs, only the 404(a) management assessment is required, which affects the depth of TOD and TOE documentation your program needs to produce.
| Obligation | Governed By | Who Performs It | Applies To |
|---|---|---|---|
| 404(a) management assessment | SEC Release 33-8810 | Management (often with internal audit) | All accelerated filers and large accelerated filers |
| 404(b) auditor attestation | PCAOB AS 2201 | External auditor independently | Accelerated filers (float ≥ $75M); SRCs exempt |
For a full SOX 404 compliance checklist covering both obligations, see SOX 404 Compliance Checklist: Requirements, Controls and Assessment Guide.
Deficiency Classification: Design Failures vs. Operating Failures
Both a design failure and an operating failure can produce any level of deficiency, from a control deficiency to a material weakness. The classification depends on the severity of the gap, not its type.
PCAOB AS 2201, Section .69 defines the thresholds:
- Control deficiency: A deficiency in the design or operation of a control that does not rise to the level of a significant deficiency or material weakness.
- Significant deficiency: A deficiency, or combination of deficiencies, that is less severe than a material weakness yet important enough to merit attention by those responsible for oversight.
- Material weakness: A deficiency, or combination of deficiencies, "such that there is a reasonable possibility that a material misstatement of the company's annual or interim financial statements will not be prevented or detected on a timely basis."
Section .B7 lists indicators that almost always signal a material weakness: identification of fraud by senior management, a financial restatement, the auditor identifying a material misstatement that management did not catch first, and ineffective audit committee oversight.
The Aggregation Requirement
AS 2201, Section .76 requires that when a deficiency is identified, the auditor evaluate whether it, individually or in combination with other deficiencies, constitutes a material weakness. This aggregation requirement is a frequent source of audit surprises. Multiple control deficiencies in the same process area, each individually minor, can together constitute a significant deficiency or material weakness.
Management teams that evaluate deficiencies in isolation and conclude each is a control deficiency, without considering their combined effect, are taking a risk. External auditors are required to aggregate.
Disclosure Consequences
- Material weaknesses must be disclosed publicly in Item 9A of the Form 10-K. Management cannot conclude ICFR is effective if a material weakness exists.
- Significant deficiencies do not require public disclosure in the 10-K but must be communicated to the audit committee.
- Control deficiencies are communicated to management.
In fiscal year 2023, Audit Analytics found that 136 accelerated and large accelerated filers disclosed at least one material weakness, representing approximately 4.5% of that filer population. The most common root causes were insufficient accounting resources or expertise (32%), complex transactions (21%), and IT/system control failures (18%).
Rollforward Testing: When Interim Results Are Not Enough
Many SOX programs test operating effectiveness as of an interim date, say September 30, to get ahead of the year-end crunch. This is permitted, but it creates an obligation.
If TOE is completed at an interim date, additional procedures are required to update the conclusion through year-end. EY's 2024 Financial Reporting Developments guide identifies these rollforward procedures as including additional sample testing, inquiry, and observation for the remaining period. The extent of rollforward work depends on the length of the gap and whether the control environment changed.
For controls with a higher risk of material misstatement, AS 2201, Section .42 discourages rotation strategies that leave those controls untested in a given year. High-risk controls should be tested annually, not rotated out.
Key takeaway: Testing at September 30 and doing nothing for Q4 is not a defensible strategy for high-risk controls. Plan rollforward procedures into your testing calendar.
Worked Example: Journal Entry Approval Control
Here is how TOD and TOE look side by side for a single key control.
Control: All journal entries above $100,000 require review and approval by the Controller before posting to the general ledger. The ERP system enforces the approval workflow.
TOD Test Steps
- Obtain the control description and process narrative from the control owner.
- Walk through one journal entry from initiation to posting: observe the preparer creating the entry, confirm the system routes it to the Controller for approval, inspect the approval timestamp and sign-off in the system.
- Confirm the Controller has the authority and competence to evaluate the entry (review their role, access rights, and relevant experience).
- Verify the $100,000 threshold is enforced at the system level, not just by policy.
- Confirm evidence of approval is retained and retrievable.
TOD conclusion: If all five elements are present and logically coherent, the control is designed effectively. Document the walkthrough with screenshots, the process narrative, and your conclusion.
TOE Test Steps
- Define the population: all journal entries above $100,000 posted during the fiscal year (say, 480 entries).
- Select a sample of 25 entries (daily/high-frequency equivalent given the volume; adjust based on your confidence level and tolerable deviation rate).
- For each sample item, inspect the ERP approval record: was it approved by the Controller before posting? Was the approval timestamp prior to the posting timestamp?
- Verify the approver was the Controller (not a delegate without documented authority) for each sample item.
- Identify any exceptions: entries posted without approval, approved by an unauthorized person, or approved after posting.
- Evaluate exceptions and determine whether they constitute a control deficiency, significant deficiency, or material weakness based on the nature and frequency of the deviation.
TOE conclusion: If all 25 sample items show timely approval by the Controller, the control is operating effectively for the period. Document the population, sample selection methodology, evidence inspected, and conclusion.
Note that this control also depends on ITGCs: if change management or logical access ITGCs failed TOE, the system-enforced approval workflow cannot be relied upon, and the TOE conclusion for this application control is compromised.
A Note on Data Analytics and Full-Population Testing
For high-frequency controls with large populations, data analytics tools can test the entire population rather than a sample, eliminating sampling risk entirely. Wolters Kluwer's internal control testing guidance notes this capability. If your team has access to a data analytics solution that can pull every journal entry approval record and flag exceptions, a full-population test is more defensible than a 25-item sample.
This is an area where AI tools for SOX compliance are adding real value in 2026: automated extraction and testing of full populations for controls like journal entry approval, access provisioning, and three-way match. The TOE conclusion is stronger, and the documentation is more complete.
FAQ
Can a control pass design testing but still have a material weakness? Yes. A well-designed control that is consistently bypassed or performed by someone without the necessary authority will fail TOE. If the deviation is severe enough, it can constitute a material weakness regardless of how sound the design is.
What happens if a control fails TOD mid-year? Stop TOE testing for that control. The control must be redesigned and implemented. TOE can only be performed over the period the remediated control was in operation. If remediation is not complete by year-end, a material weakness must be disclosed.
Do I need to test both TOD and TOE every year? For TOD, yes, walkthroughs are generally required annually. For TOE, AS 2201, Section .42 allows some rotation for lower-risk controls that have not changed, but high-risk controls must be tested every year. Management's 404(a) assessment and the auditor's 404(b) attestation may differ on rotation decisions.
How does a SOC 1 Type I vs. Type II report map to TOD and TOE? A SOC 1 Type I report covers design effectiveness only (point in time). A SOC 1 Type II report covers both design and operating effectiveness over a specified period. If your company relies on a service organization, a Type II report provides TOE evidence for the controls at that service organization, but you still need to evaluate whether those controls are relevant to your ICFR assertions.
What is the PCAOB's inspection track record on TOE testing? Not good. The PCAOB's 2023 inspection report summary found deficiencies in testing the operating effectiveness of controls in approximately 30% of audit engagements reviewed. Undersampling and insufficient evidence for TOE conclusions are the most common findings.
Can compensating controls offset a design deficiency? Partially. A design deficiency in one control may be mitigated by another control that addresses the same risk. However, the compensating control must itself be both designed and operating effectively. The deficiency in the original control still exists and must be evaluated for severity, even if the compensating control reduces the likelihood of a material misstatement reaching the financial statements.







