AuditXYZ

Lesson 3 of 5

SOX Section 404: Internal Controls Over Financial Reporting

14 min readIntermediate

SOX Section 404: Internal Controls

Section 404 is the most significant and resource-intensive SOX requirement. It requires management to assess the effectiveness of internal control over financial reporting (ICFR) every year and, for larger companies, requires the external auditor to independently audit ICFR and issue an opinion. When people say "SOX compliance costs," they overwhelmingly mean 404 costs: scoping, documentation, testing, remediation, and the audit hours that go with them.

This lesson covers both halves of 404, the scoping discipline that controls cost, the COSO framework, how testing actually works, and what happens when controls fail.

Section 404(a): Management's Assessment

Section 404(a) requires management to include in the annual report (10-K) a report on ICFR stating that management is responsible for establishing and maintaining adequate ICFR, identifying the framework used to evaluate it, and giving management's assessment of ICFR effectiveness as of fiscal year-end — including disclosure of any material weaknesses. If a material weakness exists at year-end, management must conclude ICFR is not effective; there is no "effective except for" conclusion.

The assessment must be supported by evidence, not assertion. In practice that means a documented program: risk assessment, identified key controls, testing of design and operating effectiveness, and evaluation of deficiencies — performed by or on behalf of management (typically internal audit, a SOX team, or a co-sourced advisory firm). Every filer performs 404(a), from the smallest reporting company to the largest — the exemptions people talk about apply only to 404(b).

Section 404(b): The Auditor's Attestation

Section 404(b) requires the external auditor to audit ICFR and express an independent opinion on its effectiveness. This applies to accelerated filers and large accelerated filers; non-accelerated filers, smaller reporting companies below the accelerated thresholds, and emerging growth companies are exempt while their status lasts.

The auditor performs this work under PCAOB Auditing Standard 2201 (AS 2201), An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements. Key features of AS 2201 shape your entire year:

  • Integrated audit: one engagement covers both the financial statements and ICFR, with evidence shared between the two.
  • Top-down, risk-based approach: the auditor starts at the financial statements, identifies significant accounts and disclosures and their relevant assertions, then selects for testing only the controls that address the risk of material misstatement — the same logic your own scoping should follow.
  • Emphasis on entity-level controls and the period-end financial close, the two areas where misstatements most often originate or escape detection.
  • "As of" opinion: the auditor opines on ICFR at year-end, but operating-effectiveness testing covers a period, so controls must operate all year — a control fixed in December after failing for ten months creates a difficult evaluation.

The auditor does not simply re-perform management's testing; they form their own opinion, though they may use the work of internal audit and others in lower-risk areas. Expect the most auditor attention on management review controls, estimates and judgment areas, the close process, and IT general controls.

Scoping: Where the Money Is Saved or Wasted

Scoping determines cost more than any other decision. The sequence:

  1. Set materiality. Planning materiality is typically a percentage of a benchmark — commonly around 5 percent of pre-tax income, or revenue/asset-based benchmarks for companies near break-even. Your auditor sets their own; align early.
  2. Identify significant accounts and disclosures. Accounts where a misstatement could be material, considering size, volume, complexity, estimation uncertainty, and fraud susceptibility. Revenue, receivables, inventory, accruals, equity/compensation, taxes, and the close itself usually make the list.
  3. Map assertions to risks. For each significant account, which assertions matter (existence, completeness, valuation, rights and obligations, presentation)? Revenue completeness and existence carry presumed fraud risk.
  4. Trace to processes and systems. Identify the business processes (order-to-cash, procure-to-pay, hire-to-pay, close-to-report) and the applications feeding each account — this list drives ITGC scope.
  5. Select key controls. For each risk, the control(s) that would prevent or detect a material misstatement. Everything else is a non-key control you need not test for SOX.
  6. Consider locations and components for multi-entity businesses, scoping in units that are individually significant or risky.

Chronic scoping failures run in both directions: programs bloated with hundreds of non-key controls tested out of caution (cost without assurance), and programs that miss a newly material account — a fast-growing revenue stream, a first-time impairment — until the auditor flags it in Q4.

The COSO Framework

SEC rules require management to use a "suitable, recognized framework," and in practice virtually every company uses the COSO Internal Control — Integrated Framework (2013). COSO defines five components, decomposed into 17 principles, all of which must be present and functioning:

ComponentWhat It CoversExample SOX Controls
Control environmentTone at the top, integrity, board oversight, competence, accountabilityCode of conduct, audit committee charter, hiring/competency practices
Risk assessmentIdentifying and analyzing risks to reporting objectives, incl. fraud risk and changeAnnual SOX risk assessment, fraud risk assessment, materiality analysis
Control activitiesThe policies and procedures that mitigate risks — incl. over technologyReconciliations, approvals, segregation of duties, ITGCs
Information & communicationQuality of information, internal and external communicationReport validation (IPE controls), whistleblower hotline, policy communication
Monitoring activitiesOngoing and separate evaluations, deficiency reportingInternal audit testing, management review of KPIs, deficiency tracking

Most SOX effort concentrates in control activities, but auditors — following AS 2201's emphasis — increasingly probe the other four components, especially fraud risk assessment and whether the board receives and acts on deficiency reporting.

Types of Controls You'll Document

  • Preventive vs. detective: approvals and system enforcement stop errors up front; reconciliations and reviews catch them after. Healthy processes layer both.
  • Automated vs. manual: automated controls (three-way match in the ERP, system-calculated depreciation, enforced approval workflows) are cheaper to test — often a test of one, plus reliance on ITGCs — and less error-prone. Shifting key controls from manual to automated is the most reliable long-term cost reducer in SOX.
  • Management review controls (MRCs): reviews of estimates, analyses, and fluxes by knowledgeable managers. These attract intense auditor scrutiny: evidence must show what the reviewer looked at, the precision of the review (what size error it would catch), and what follow-up occurred. "Reviewed and approved" with a signature is no longer sufficient evidence.
  • IPE (information produced by the entity): any report or spreadsheet a control relies on must itself be shown accurate and complete — parameters validated, source verified. IPE gaps are among the most common comments in first-year audits.
  • Entity-level controls (ELCs): the COSO-wide controls above; strong ELCs can reduce, but rarely eliminate, transaction-level testing.

Testing: Design and Operating Effectiveness

Design effectiveness asks: if this control operates as described, would it prevent or detect a material misstatement in the targeted assertion? It is evaluated through walkthroughs — following a single transaction end to end, examining documents, and interviewing performers at each step.

Operating effectiveness asks: did the control actually operate as designed, by someone competent and authorized, throughout the period? Testing methods, in increasing strength: inquiry (never sufficient alone), observation, inspection of evidence, and re-performance. Sample sizes follow frequency conventions — commonly around 25 for daily controls, and progressively fewer down to 1 for annual controls, with samples spread across the period. Auditors typically test interim through roughly Q3 and then perform roll-forward procedures covering the remaining months to support the year-end "as of" opinion.

Deficiency Evaluation

Every exception found in testing is evaluated on two axes — the likelihood that a misstatement could occur, and its potential magnitude — and classified:

  • Control deficiency: the control doesn't allow prevention or timely detection of misstatements in the normal course. Reported to management; no external disclosure.
  • Significant deficiency: less severe than a material weakness but important enough to merit attention from those responsible for oversight. Reported to the audit committee and the auditor (and referenced in 302 certifications), but not publicly disclosed by name.
  • Material weakness: a deficiency, or combination, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. Requires management to conclude ICFR is not effective, with public disclosure in the 10-K and an adverse ICFR opinion from the auditor for 404(b) filers.

Two evaluation subtleties: deficiencies aggregate — several individually minor issues in the same account or process can combine into a material weakness — and a material actual misstatement is not required; the reasonable possibility of one suffices. Certain indicators weigh heavily toward material weakness: identified fraud by senior management, restatement of prior financials, a material misstatement caught by the auditor rather than by controls, and ineffective audit committee oversight.

Common real-world material weakness themes: insufficient qualified accounting personnel (the classic first-year post-IPO finding), ineffective ITGCs undermining automated controls and reports, poor controls over complex or judgmental areas (revenue recognition, business combinations, tax), and ineffective management review controls.

Section 404 Program Checklist

  • Materiality established and aligned with the external auditor
  • Significant accounts, disclosures, and relevant assertions documented via a top-down risk assessment
  • Processes and financially significant systems mapped to each significant account
  • Risk-and-control matrices maintained with clearly designated key controls and owners
  • COSO 2013 mapping shows all 17 principles present and functioning
  • Walkthroughs performed for every significant process, refreshed for changes
  • Test plans set sample sizes by frequency, spread across the period, with roll-forward strategy
  • MRC evidence demonstrates precision, items examined, and follow-up; IPE completeness and accuracy validated
  • ITGCs tested for all in-scope systems (see next lesson)
  • Deficiency log maintained with severity evaluation, aggregation analysis, and remediation owners
  • Remediated controls re-tested over a sufficient operating period before year-end
  • Management's assessment documented and 10-K ICFR report drafted; audit committee briefed quarterly

Frequently Asked Questions

What's the practical difference between 404(a) and 404(b)?

404(a) is management's own annual assessment — universal, and self-directed. 404(b) adds an independent audit of ICFR under PCAOB AS 2201 with a public auditor opinion — and it is the expensive half, typically doubling or more the rigor, evidence expectations, and fees. Companies exempt from 404(b) still do real testing for 404(a), but with more discretion over extent.

Are smaller companies and EGCs really exempt from 404(b)?

Yes — non-accelerated filers, qualifying smaller reporting companies, and emerging growth companies are exempt from the auditor attestation. The exemption ends when the status ends: crossing the accelerated-filer float threshold or losing EGC status (five years post-IPO, or revenue above roughly $1.235 billion, among other triggers) brings 404(b) with little runway, so companies approaching those lines should build to 404(b) standards early.

How many key controls should we have?

There is no correct number, but ranges are informative: focused programs at newly public, single-segment companies often run 80–150 key controls; sprawling multinationals may exceed 500. If your count is high relative to business complexity, run a rationalization exercise — every key control implies documentation, testing, auditor testing, and potential deficiencies, so each one should map to a real risk of material misstatement.

Can we rely on our SOC 1 reports for outsourced processes?

Yes — for payroll processors, cloud ERPs, transfer agents, and similar providers, a SOC 1 Type II report covering your period lets you (and your auditor) rely on the service organization's controls instead of testing them directly. You must still review the report, map its controls to your risks, test the complementary user entity controls it assumes you perform, and cover any period gap between the report's end date and your year-end.

What happens when a material weakness is disclosed?

Management reports ICFR as not effective in the 10-K; the auditor (if 404(b) applies) issues an adverse ICFR opinion — note the financial statement opinion can still be clean; remediation plans are disclosed and tracked in subsequent filings; and the company typically faces stock pressure, heightened audit fees, and possible shareholder suits. Remediation is only complete when the redesigned control has operated effectively for a sufficient period and been re-tested — announcing a fix is not the same as closing the weakness.

When does a newly public company first face 404?

The first 404(a) assessment is generally due with the second annual report after the IPO (the first 10-K enjoys a transition accommodation), while 302 certifications start with the first periodic filing. 404(b) applies only if and when the company is an accelerated or large accelerated filer and not an EGC. The audit preparation lesson in this series covers the pre-IPO readiness timeline.

In the next lesson, we will cover IT general controls.


Section 404 programs live or die on organized evidence and testing workflow. AuditXYZ helps you compare compliance automation platforms and auditors to find SOX-capable tooling and audit partners in one place.