SOX 404 Compliance Checklist: Requirements, Controls and Assessment Guide
SOX Section 404 compliance is the most resource-intensive obligation a public company carries. It demands that management assess internal controls over financial reporting (ICFR) every year, and for accelerated and large accelerated filers, an external auditor independently attests to that assessment. Get it wrong and you face a material weakness disclosure, potential loss of Form S-3 shelf eligibility, and the kind of investor confidence hit that takes quarters to repair.
This checklist is for controllers, internal audit leads, and CFOs at mid-to-large public companies who need a structured, practitioner-grade roadmap, not a generic overview. It covers who must comply, what the PCAOB and SEC actually require, and the specific control activities to complete each quarter.
Key takeaway: SOX 404 is not a year-end event. The controls must operate effectively for the full fiscal year, and auditors test exactly that. Build the cadence into Q1, not Q4.
What Are SOX 404 Requirements?
Section 404 of the Sarbanes-Oxley Act of 2002 has two operative subsections with distinct obligations.
- 404(a): Management of every public company must annually assess and report on the effectiveness of ICFR. The assessment is disclosed in the Form 10-K.
- 404(b): The company's external auditor must independently attest to management's ICFR assessment. The auditor's opinion is included in the annual audit report and governed by PCAOB Auditing Standard AS 2201.
- 404(c): Non-accelerated filers (public float below $75 million) and emerging growth companies (EGCs) are exempt from 404(b). EGCs retain that exemption for up to five years post-IPO, provided annual gross revenues stay below $1.235 billion and non-convertible debt issuances stay below $1 billion in any three-year period.
| Filer Category | Public Float | 404(a) Required | 404(b) Required |
|---|---|---|---|
| Large Accelerated Filer | $700M+ | Yes | Yes |
| Accelerated Filer | $75M to $700M | Yes | Yes |
| Non-Accelerated Filer | Below $75M | Yes | No |
| Emerging Growth Company | Varies | Yes | No (up to 5 years post-IPO) |
Note: The SEC's May 2026 proposed filer status rulemaking would restructure these categories. For detail on how those changes could affect your 404(b) obligations, see SEC Filer Status Rulemaking 2026: The Compliance Transition Playbook.
What Is the SOX 404 Assessment?
The 404 assessment is management's formal, documented conclusion on whether ICFR is effective as of fiscal year-end, based on testing performed throughout the year.
Most companies use the COSO 2013 Internal Control Integrated Framework as the evaluation framework, which the SEC recognizes as suitable for this purpose. The assessment covers five COSO components: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
Management's assessment must:
- Identify all significant accounts and disclosures, and the relevant financial reporting risks associated with each.
- Map those risks to specific controls (the risk and control matrix, or RCM).
- Test whether those controls are designed appropriately and operating effectively over the full reporting period.
- Evaluate any identified deficiencies and classify them as control deficiencies, significant deficiencies, or material weaknesses.
- Disclose material weaknesses in the 10-K. A single material weakness means management cannot conclude that ICFR is effective.
For companies subject to 404(b), the external auditor performs an integrated audit: the financial statement audit and the ICFR audit run simultaneously, with the auditor assessing both design and operating effectiveness independently.
SOX 404 Compliance Checklist: By Quarter
The most common mistake companies make is treating SOX 404 as a Q4 sprint. Auditors test controls across the entire fiscal year, so a control that broke in Q2 and was not remediated creates an operating effectiveness finding even if it works perfectly in December. Structure your compliance activities by quarter.
Q1: Foundation and Scoping
- Conduct an organizational risk assessment and update the risk profile to reflect business changes since last year (new systems, acquisitions, restructurings, personnel changes).
- Confirm the in-scope process list: revenue, procurement, payroll, close-to-report, treasury, and any significant estimates (goodwill, reserves, tax).
- Identify and confirm control owners for every key control. If anyone has left the organization, assign replacements immediately.
- Identify new technology platforms (ERP changes, SaaS additions, cloud migrations) that touch financial data and assess whether they require new IT general controls (ITGCs).
- Educate control owners on minimum evidence standards, frequency requirements, and what constitutes a control failure.
- Confirm the COSO mapping is current and reflects the actual control environment.
Q2: Documentation, IT Controls, and Design Testing
- Document process narratives or flowcharts for each in-scope subprocess. These must reflect how controls actually operate, not how they were designed three years ago.
- Assess IT general controls across all key systems: user access management, change management, computer operations, and data integrity. ITGCs are the foundation; if they fail, every automated control built on top of them is at risk.
- Assess SOC 1 reports (Type II) for key SaaS providers and third-party processors. Map the complementary user entity controls (CUECs) to your own control framework.
- Test control design: do the controls, as documented, actually address the identified risks? Identify gaps and update or create controls to close them.
- Obtain management buy-in to prevent control override. Management override is the highest-risk deficiency type and one auditors scrutinize closely.
- Update the risk and control matrix (RCM) for any design changes.
Q3: Operating Effectiveness Testing and Deficiency Remediation
- Execute the operating effectiveness testing program. Higher-risk controls (manual journal entries, significant estimates, revenue recognition) warrant larger sample sizes and more frequent testing.
- Remediate deficiencies identified in Q1 and Q2 testing. Document root cause analysis, the corrective action plan, and the timeline.
- Assess whether any deficiency, individually or in combination with others, rises to the level of a significant deficiency or material weakness. Aggregation matters: two significant deficiencies in the same process area can constitute a material weakness.
- Work with subject-matter experts to update review and approval procedures, system access configurations, and controls over key spreadsheets and reports used in financial reporting (IPE controls).
- Conduct a pre-audit dry run: simulate the external auditor's walkthrough for your highest-risk processes. Identify gaps before the auditor does.
Q4: Year-End Assessment and Auditor Coordination
- Complete rollforward testing for any controls not tested through year-end.
- Prepare the year-end evaluation and summary of aggregated deficiencies for the audit committee.
- Coordinate with external auditors on reliance: the more robust your internal audit evidence (collected per IIA standards), the more the external auditor can rely on it, reducing duplication and cost.
- Confirm the disclosure committee has reviewed all identified deficiencies and assessed disclosure obligations.
- Draft management's ICFR report for inclusion in the Form 10-K (Item 9A). The report must: state the framework used (COSO 2013), include management's conclusion on effectiveness, and disclose any material weaknesses.
- For 404(b) filers: confirm the external auditor's attestation report is complete and will be filed with the 10-K.
SOX 404 Controls List: The Core Control Categories
SOX does not prescribe specific controls. It requires management to design controls that address the identified risks. In practice, every SOX program covers these categories:
Entity-Level Controls (ELCs)
- Tone at the top and code of conduct
- Audit committee oversight and independence
- Whistleblower hotline and anti-retaliation policy
- Disclosure committee charter and meeting cadence
- Period-end financial reporting process
IT General Controls (ITGCs)
- Logical access controls (user provisioning, deprovisioning, privileged access review)
- Change management (segregation of development, testing, and production environments)
- Computer operations (job scheduling, backup and recovery, incident management)
- Data integrity controls for interfaces between systems
Process-Level Controls
- Segregation of duties across authorization, custody, and recording functions
- Three-way match for procurement (purchase order, receiving report, invoice)
- Revenue recognition controls tied to ASC 606 performance obligations
- Journal entry controls: approval requirements, restricted posting access, review of unusual or top-side entries
- Account reconciliations with documented review and sign-off
- Cutoff controls ensuring transactions are recorded in the correct period
- Significant estimate controls (goodwill impairment, tax provisions, reserves) with documented assumptions and management review
Financial Close Controls
- Consolidation controls and intercompany elimination procedures
- Financial statement tie-out and disclosure checklist
- Management review controls over key reports used in financial reporting (IPE validation)
Deficiency Classification: What Triggers a Material Weakness?
Not every control failure is a material weakness, but the classification has serious consequences. Under AS 2201 and SEC guidance, deficiencies are classified as follows:
| Classification | Definition | Disclosure Required |
|---|---|---|
| Control Deficiency | Control does not prevent or detect misstatements on a timely basis | No public disclosure |
| Significant Deficiency | More than remote likelihood of a more-than-inconsequential misstatement | Communicated to audit committee |
| Material Weakness | More than remote likelihood of a material misstatement | Disclosed in 10-K; management cannot conclude ICFR is effective |
Factors that elevate a deficiency to material weakness include: the magnitude of the potential misstatement, the financial statement line items affected, whether compensating controls exist and are operating effectively, and whether the deficiency was identified by management or by the external auditor (auditor-identified findings carry more weight).
A disclosed material weakness typically triggers heightened SEC scrutiny, increased audit fees, and in some cases, loss of Form S-3 eligibility for capital markets transactions.
The 4 Pillars of SOX Compliance
The "four pillars" framing maps to the core obligations that run through the entire SOX Act:
- Internal Controls Over Financial Reporting (ICFR): The Section 404 requirement. Management designs, maintains, and annually assesses controls; accelerated filers also get external attestation.
- CEO and CFO Certification: Section 302 requires the principal executive and financial officers to certify each quarterly and annual filing, attesting to the accuracy of disclosures and the effectiveness of disclosure controls and procedures. See SOX 302 Sign-Off Checklist for Q2 2026 Form 10-Q for the quarterly mechanics.
- Auditor Independence and Oversight: Sections 201-203 restrict non-audit services, require lead audit partner rotation every five years, and establish the PCAOB as the standard-setter for public company audits.
- Corporate Governance and Accountability: Section 301 mandates independent audit committees with financial expertise; Section 802 imposes criminal penalties for document destruction; Section 906 adds criminal liability for false certifications.
Practical Tips That Most Checklists Skip
The ranked pages cover the standard framework steps. Here is what practitioners actually learn the hard way:
Risk-based testing saves real money. Not all controls carry equal risk. Controls tied to significant estimates, manual journal entries, and revenue recognition warrant quarterly testing and larger sample sizes. Lower-risk, automated controls with strong ITGCs can be tested once annually. Calibrate your testing plan to the risk profile, not to "same as last year."
Automated controls are only as strong as the ITGCs beneath them. An automated three-way match is a strong control, but if change management over the ERP is deficient, the auditor will not rely on it. Fix ITGCs first.
SOC report gaps create surprise findings. If a key SaaS provider's SOC 1 Type II report has a qualified opinion or a gap period, you need compensating controls to cover that period. Review SOC reports in Q2, not Q4.
Aggregation is where material weaknesses hide. A significant deficiency in revenue cutoff and a separate significant deficiency in the financial close review process, both affecting the same revenue accounts, can aggregate to a material weakness. Evaluate deficiencies in combination, not in isolation.
AI-assisted controls require additional documentation. If your team uses AI tools in any ICFR-relevant process, the PCAOB expects evidence that the output was reviewed and validated by a human with appropriate competence. For a full treatment of this emerging area, see SOX 404 Compliance Checklist for AI-Assisted Controls (2026).
FAQ
Who must comply with SOX 404? All U.S.-listed public companies and foreign private issuers listed on U.S. exchanges must comply with Section 404(a). Section 404(b) auditor attestation applies to accelerated filers (public float $75M or above). Non-accelerated filers and EGCs are exempt from 404(b).
What framework should management use for the 404 assessment? The SEC does not mandate a specific framework but requires that it be "suitable and recognized." The COSO 2013 Internal Control Integrated Framework is the dominant choice for U.S. public companies. Some companies supplement COSO with COBIT for IT controls.
How long must SOX documentation be retained? Section 802 requires retention of audit-related records for seven years. This covers workpapers, control evidence, reconciliations, and any communications related to the audit.
What happens if a material weakness is disclosed? Management cannot conclude that ICFR is effective. The weakness must be disclosed in Item 9A of the Form 10-K. Companies often face increased audit fees, SEC comment letters, and may lose Form S-3 eligibility until the weakness is remediated and at least one subsequent clean assessment is filed.
Can internal audit's work reduce external audit fees under 404(b)? Yes. Under AS 2201, external auditors can use the work of others, including internal audit, if they assess the competence and objectivity of the internal audit function and test a portion of the work directly. Strong internal audit documentation collected per IIA standards is the lever that drives down external audit cost.
What is the difference between SOX 302 and SOX 404? Section 302 requires CEO and CFO certification of each quarterly and annual filing, covering disclosure controls and procedures. Section 404 requires an annual assessment of ICFR specifically, with external auditor attestation for larger filers. The two sections overlap but are not identical: a company can have effective 404 ICFR and still have a 302 disclosure control failure if the reporting process itself breaks down.







