SOX Scoping: How to Identify Significant Accounts and Processes (2026 Practitioner Walkthrough)
SOX scoping for significant accounts and processes is where your entire ICFR program either earns its credibility or quietly accumulates risk. Get it right and your testing is focused, defensible, and proportionate. Get it wrong and you are either burning budget on low-risk controls or handing your auditor a finding on a gap you never knew existed.
This walkthrough is for internal audit managers, controllers, and SOX program leads who are doing the actual work, not reading about it conceptually. Every step below is grounded in PCAOB Auditing Standard No. 2201 (AS 2201) and SEC Release No. 33-8810, the two primary regulatory texts that govern this exercise. None of the consulting blog summaries currently ranking on this topic cite either document by paragraph number. That gap is exactly what creates scoping errors in practice.
Key takeaway: SOX scoping is a regulatory exercise with a specific legal standard at its core, not a judgment call made by comparing this year's trial balance to last year's scope document.
What Is the Regulatory Standard for a "Significant Account" Under SOX?
Under AS 2201.29, a significant account or disclosure is one where there is a "reasonable possibility of a material misstatement." That is a deliberately low bar. It does not require that misstatement be probable, only reasonably possible. An account can be significant even if its dollar balance is modest.
The PCAOB lists nine specific factors auditors must evaluate when identifying significant accounts:
- Size and composition of the account
- Susceptibility to misstatement due to errors or fraud
- Volume of activity, complexity, and homogeneity of transactions
- Nature of the account (estimates vs. routine transactions)
- Accounting and reporting complexity
- Exposure to losses in the account
- Possibility of significant contingent liabilities
- Existence of related-party transactions
- Changes from the prior period in account characteristics
This list matters because it is the standard your external auditor applies. If your scoping methodology does not address all nine factors, you are working from a different rulebook than your auditor, and that misalignment tends to surface at the worst possible moment.
For the management-side obligation, SEC Release No. 33-8810, Section II.A confirms that management's process should be tailored to the company's specific facts and circumstances. Management is not required to replicate the auditor's procedures, but it must reach a well-reasoned, documented conclusion using the same underlying logic.
Step 1: Set Your Scoping Materiality Threshold
Scoping materiality (sometimes called planning materiality) is the quantitative threshold that separates in-scope accounts from out-of-scope ones. This is a separate determination from deficiency evaluation materiality, which is used later to classify control failures as significant deficiencies or material weaknesses. Conflating the two is one of the most common and consequential practitioner errors in SOX programs.
Choosing a benchmark
PwC's Viewpoint guidance sets the typical range at 3-5% of pre-tax income for most companies. Many practitioners use a three-year normalized average to avoid volatility in a single year's earnings distorting the threshold. When pre-tax income is near zero or negative, alternative benchmarks apply:
| Situation | Common Benchmark |
|---|---|
| Profitable company, stable earnings | 3-5% of pre-tax income |
| Volatile or near-zero pre-tax income | 5-10% of revenues or gross profit |
| Asset-intensive business (banks, REITs) | 0.5-1% of total assets |
| Early-stage or loss-making company | Revenue or total assets |
Document the benchmark you chose and the rationale. You will need to explain this decision to your auditor and revisit it next year.
The two-threshold distinction
Deloitte's SOX guidance draws a clear line between scoping materiality and deficiency evaluation materiality. Scoping materiality is set early in the year to determine what goes into scope. Deficiency evaluation materiality is applied later, when a control failure is discovered, to decide whether it rises to a significant deficiency or material weakness. Using the same number for both purposes is technically incorrect and can lead to either under-scoping or misclassifying deficiencies.
Step 2: Identify Significant Accounts Using Quantitative and Qualitative Factors
Start with the trial balance and flag every financial statement line item (FSLI) whose balance or activity exceeds your scoping materiality threshold. That gives you the quantitative list. Then apply qualitative factors to catch accounts that fall below the threshold but still carry a reasonable possibility of material misstatement.
KPMG's SOX scoping guidance identifies the qualitative factors most likely to pull a sub-threshold account into scope:
- Management estimates and judgment: Goodwill impairment, allowance for credit losses (ASC 326), variable consideration under ASC 606, and pension obligations are all candidates regardless of balance size.
- History of errors or restatements: Any account that has generated a prior-period adjustment or SEC comment letter belongs in scope.
- Related-party transactions: These carry inherent fraud risk under AS 2201.29 factor 8.
- Recent accounting standard changes: Accounts affected by a new standard adoption (ASC 842 leases, ASC 326 CECL) in the current or prior year carry elevated transition risk.
- Regulatory sensitivity: Accounts that directly support a key metric in management guidance or an SEC filing disclosure warrant heightened scrutiny.
A practical approach is to build a Significant Account and Disclosure (SAD) matrix: list every FSLI, record its balance and activity, apply the quantitative threshold, then add a qualitative risk column. Every account that is either above the threshold or flagged qualitatively is significant and goes into scope. Document the rationale for every exclusion, not just every inclusion. Auditors ask about exclusions.
Step 3: Map Significant Accounts to Business Processes
Once you have your significant accounts, map each one to the business processes (also called transaction cycles) that drive activity into it. This is where the scope expands from a list of accounts to a list of processes that require control documentation and testing.
Common process-to-account mappings:
| Business Process | Typical Significant Accounts |
|---|---|
| Revenue and accounts receivable | Revenue, AR, deferred revenue, allowances |
| Procure-to-pay / accounts payable | AP, accrued liabilities, inventory (purchases) |
| Inventory and cost of goods sold | Inventory, COGS, reserves |
| Payroll and HR | Compensation expense, accrued payroll, benefits |
| Financial close and reporting | All FSLIs (journal entries, reconciliations) |
| Treasury and debt | Cash, debt, interest expense, derivatives |
| Tax | Income tax expense, deferred tax assets/liabilities |
| Fixed assets | PP&E, depreciation, impairment |
One account can map to multiple processes. Revenue, for example, typically touches order-to-cash, financial close (cut-off entries), and tax (revenue recognition timing differences). Each process that feeds a significant account is in scope for control documentation.
AS 2201.26 requires a top-down approach: start at the financial statement level, work down through significant accounts to the relevant assertions, then identify the controls that address those assertions. The regulatory text is explicit: "The top-down approach begins at the financial statement level and with the auditor's understanding of the overall risks to internal control over financial reporting."
Step 4: Scope Relevant Assertions, Not Every Assertion
This is the efficiency lever that most SOX programs miss entirely. AS 2201.39-40 requires controls only for the assertions where there is a reasonable possibility of material misstatement, not for every assertion on every significant account.
The five financial statement assertions are:
- Existence/occurrence - does the balance or transaction actually exist?
- Completeness - are all transactions recorded?
- Valuation/allocation - is the amount correct?
- Rights and obligations - does the company have the rights it claims?
- Presentation and disclosure - is the item correctly classified and disclosed?
For a cash account at a company with strong bank reconciliation controls, the existence and completeness assertions are well-covered. The valuation assertion carries minimal risk. You do not need a separate control for every assertion on cash. For a goodwill balance subject to annual impairment testing, valuation is the high-risk assertion and that is where control effort should concentrate.
Applying this logic across your SAD matrix can meaningfully reduce the number of key controls you need to document and test, without creating audit exposure.
Step 5: Scope Locations and Subsidiaries
AS 2201.61-67 governs multi-location scoping. The standard requires that you identify locations or business units that present a reasonable possibility of material misstatement, and it allows a coverage approach: select a combination of locations that together represent a large portion of financial statement amounts.
In practice, most programs use a tiered structure:
- Full scope: Locations that individually exceed scoping materiality or carry specific high-risk characteristics (recent acquisition, new ERP, history of control failures).
- Specific scope: Locations below the threshold that are included because of qualitative risk factors.
- Out of scope: Locations that are individually immaterial and carry no qualitative flags.
One important rule: certain high-risk locations must be included regardless of size. A subsidiary that recently completed a significant acquisition, a business unit under SEC investigation, or a location with a known history of fraud cannot be excluded on quantitative grounds alone.
Document the coverage percentage your selected locations represent as a share of consolidated revenues, assets, and pre-tax income. Auditors expect to see this calculation, and they will form their own view on whether coverage is adequate.
Step 6: Scope IT Applications for ITGC Testing
The question for IT scoping is straightforward: does a manual control rely on data or a report generated by an IT system? If yes, that system is in scope for IT General Controls (ITGCs), regardless of whether it is on-premise or cloud-hosted.
EY's SOX guidance frames the test this way: if a control uses a system-generated report, exception report, or automated calculation, the IT application producing that output is in scope for logical access, change management, and computer operations controls.
For cloud and SaaS applications, direct ITGC testing is often not possible because the company does not control the infrastructure. The standard approach is to obtain the vendor's SOC 1 Type II report and evaluate whether the relevant controls are covered. You then document any Complementary User Entity Controls (CUECs) that the SOC 1 report places on your organization. For a detailed walkthrough of this process, see our ITGC scoping guide for SaaS environments.
For AI-assisted financial controls, the scoping question is still unsettled. As of mid-2026, no AI-specific PCAOB guidance exists, but AS 2201 principles apply: if an AI model generates output that a control relies on, the model and its underlying data pipeline are in scope. See our analysis of SOX reliance on AI controls for the current regulatory position.
Step 7: Document the Scoping Rationale
A scoping decision is only as defensible as its documentation. The SEC's Release 33-8810 requires management to reach a well-reasoned, documented conclusion. In practice, that means your scope document should include:
- The materiality benchmark chosen and the rationale
- The SAD matrix with quantitative and qualitative analysis for each FSLI
- The process-to-account mapping
- The location coverage calculation
- The IT application inventory and the in/out-of-scope determination for each
- Explicit documentation of every exclusion and the basis for it
Thin documentation of exclusions is one of the most common triggers for auditor pushback. If you cannot explain in writing why an account is out of scope, assume your auditor will put it back in.
When to Update Scope Mid-Year
Treating last year's scope as the default is a compliance error. AS 2201 requires that scope reflect current-year risks. The following events should trigger a formal mid-year rescoping:
- Acquisitions or divestitures that change the consolidated balance sheet materially
- New ERP implementation or significant system migration
- Adoption of a new accounting standard (ASC 842, ASC 326, ASC 606)
- Significant personnel changes in key control owner roles
- New related-party transactions or business lines
- Discovery of a control deficiency or fraud in a previously out-of-scope area
As Bridgepoint Consulting notes, "Last-minute surprises may not leave enough time to implement appropriately documented controls or to remediate deficiencies." The cost of a mid-year scope update is always lower than the cost of a year-end finding on an area you never covered.
According to Protiviti's 2024 SOX and Internal Controls Benchmarking Survey, a majority of respondents said SOX scope has significantly or moderately expanded over the past two years, with more than half reporting internal compliance costs exceeding USD 1 million annually. That cost pressure makes right-sizing scope, rather than defaulting to last year's list, a CFO-level priority.
How Management Scope and Auditor Scope Can Differ
This is a point that almost no practitioner resource addresses clearly. Management's scope under Section 404(a) and the external auditor's scope under Section 404(b) can legitimately differ. The SEC's Release 33-8810 explicitly states that management's evaluation need not replicate the auditor's procedures.
Management can use a broader range of evidence, including self-assessments, internal audit work, and monitoring activities. The auditor applies its own professional judgment under AS 2201 and may include accounts or locations that management excluded, or vice versa. When the auditor expands scope beyond management's scope, ask for the specific AS 2201 basis. "We think it's material" is not a sufficient explanation. The auditor should be able to point to one of the nine factors in AS 2201.29.
For a full comparison of Section 302 and 404 obligations, see our SOX 302 vs 404 certification guide. For the testing phase that follows scoping, see our design vs. operating effectiveness testing walkthrough.
The Role of Entity-Level Controls in Right-Sizing Scope
AS 2201.14-17 provides the regulatory basis for a narrower process-level scope at companies with strong entity-level controls. A robust control environment, effective audit committee oversight, and well-functioning monitoring controls can reduce, though not eliminate, the need for granular process-level control testing.
This is not a loophole. It is the intended logic of the top-down approach. Companies that invest in strong governance and monitoring can, with proper documentation, justify a more focused process-level scope. The COSO 2013 Internal Control Framework Principles 6, 7, and 8 (specify objectives, identify and analyze risk, assess fraud risk) provide the conceptual anchor for this argument.
FAQ
What is the difference between scoping materiality and deficiency evaluation materiality? Scoping materiality is set at the start of the year to determine which accounts and processes are in scope for ICFR testing, typically 3-5% of pre-tax income. Deficiency evaluation materiality is applied later to classify a discovered control failure as a control deficiency, significant deficiency, or material weakness. These are separate thresholds with separate purposes and should never be conflated.
Can an account be significant even if it is below the quantitative threshold? Yes. Under AS 2201.29, the standard is a reasonable possibility of material misstatement, not a dollar threshold. Accounts subject to management estimates, related-party transactions, or a history of errors can be significant regardless of balance size.
Do I need controls for every assertion on every significant account? No. AS 2201.39-40 requires controls only for the assertions where there is a reasonable possibility of material misstatement. Scoping to relevant assertions, rather than all five for every account, is a legitimate and often significant efficiency gain.
How do I handle a SaaS application in ITGC scoping? Obtain the vendor's SOC 1 Type II report, confirm that the relevant ITGC domains are covered, and document any CUECs your organization is responsible for. Direct ITGC testing is generally not possible for SaaS systems you do not control. See our ITGC scoping for SaaS environments guide for the full process.
What triggers a mid-year scope update? Acquisitions, divestitures, new ERP systems, new accounting standard adoptions, significant personnel changes in control owner roles, and newly discovered control deficiencies in previously out-of-scope areas all require a formal rescoping.
Does my external auditor's scope have to match management's scope? No. Management's scope under Section 404(a) and the auditor's scope under Section 404(b) can legitimately differ. When your auditor expands scope beyond your own, ask for the specific AS 2201.29 factor that supports the addition.







