SOX 404: What Sections 404(a) and 404(b) Require, and the Controls That Get Tested
Section 404 of the Sarbanes-Oxley Act has two parts that get conflated. Section 404(a) requires management of every SEC registrant to assess and report annually on the effectiveness of internal control over financial reporting. Section 404(b) requires the company's independent auditor to attest to that assessment, and it applies only to accelerated and large accelerated filers, with permanent exemption for non-accelerated filers and a temporary exemption of up to five years for emerging growth companies. The distinction decides a company's compliance cost more than any other fact about it, because the auditor attestation roughly doubles the rigor and documentation the control population has to withstand. This article covers who owes which part, how scoping works under the top-down approach, what a key control is, how testing and deficiency evaluation run, and where companies fail.
404(a): management's assessment
Management's report states that management is responsible for ICFR, identifies the framework used to evaluate it, almost always COSO, states management's conclusion on effectiveness as of year end, and discloses any material weakness. A newly public company first includes the report in its second annual report, which gives it one fiscal year after the IPO to build the program. The assessment has to rest on evidence: documented controls, testing performed during the year, and an evaluation of the deficiencies found. Management cannot conclude that controls are effective if a material weakness exists at year end, even if it was remediated the following month, which is why remediation timing drives so much of the calendar in a first assessment year.
404(b): the auditor's attestation
Where 404(b) applies, the auditor performs an integrated audit under PCAOB Auditing Standard 2201, forming an opinion on the financial statements and a separate opinion on ICFR. The auditor tests management's key controls independently and, critically, applies its own judgment about which controls are key, how much evidence is needed, and how severe a deficiency is. This is where the cost multiplier comes from: controls management considered adequate get challenged, sample sizes rise, and documentation that satisfied an internal reviewer gets rejected for missing the evidence of review. Companies approaching accelerated filer status, generally at $75 million of public float measured at the end of the second fiscal quarter, should assume the standard shifts a year before the attestation is due, because the auditor's first-year integrated audit relies on controls operating for the whole period.
Scoping: the top-down approach
AS 2201 prescribes a top-down, risk-based approach that management should mirror. It starts at the financial statements with materiality, identifies significant accounts and disclosures and the relevant assertions for each, maps the processes and systems that feed them, and identifies the points within those processes where a material misstatement could occur. Entity-level controls are evaluated first, because strong ones reduce the testing needed at the process level. Then key controls are selected: the controls that, if operating, would prevent or detect a material misstatement at each identified risk point. The output is a control population sized to the company's risk rather than to a template, typically 50 to 150 key controls for a single-segment company and several hundred for a complex multinational. Programs that skip the risk assessment and document every control they can find test three times as much as they need to and still miss the risks that matter.
What counts as a SOX control
SOX controls are classified along a few axes that determine how they are tested. Preventive controls stop an error before it posts, such as system-enforced approval limits, while detective controls catch it afterward, such as a reconciliation. Automated controls execute inside a system and are tested once for design plus a reliance on IT general controls, while manual controls depend on a person and are tested across a sample of instances. Management review controls, where a reviewer examines an estimate, analysis, or report, are the hardest to evidence, because the auditor wants proof of what the reviewer looked at, what precision they applied, and what they did about outliers, and a signature on a page rarely satisfies that. Key reports and other information produced by the entity get their own attention: any spreadsheet or system report a control relies on has to be shown accurate and complete, which is where IT general controls enter. Without effective controls over access, change, and operations for the systems producing those reports, the reports cannot be relied on, and every control downstream loses its evidence. Our guide to IT general controls covers that layer in detail.
Testing: design, operation, and sample sizes
Each key control is tested for design effectiveness, whether it would prevent or detect the misstatement if it operated as described, and operating effectiveness, whether it actually operated consistently across the period. Design is evaluated through a walkthrough of a single transaction from initiation to reporting. Operation is tested by inspection and reperformance across a sample drawn from the full population, with sizes scaled to frequency under common practice: one for annual controls, two for quarterly, two to five for monthly, five to fifteen for weekly, and twenty to forty for daily controls. Testing should run in at least two waves, interim and year-end roll-forward, so that deficiencies surface with time to remediate and re-test. The most common testing failure is a control that operated but cannot prove it, such as a review performed verbally or evidence discarded after the fact, and the fix is designing the evidence into the control rather than reconstructing it for the auditor.
Deficiencies: how they are rated and what triggers disclosure
A control deficiency exists when a control is missing or does not operate as designed. It becomes a significant deficiency when it is important enough to merit the audit committee's attention, and a material weakness when there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis. Severity turns on the magnitude of the potential misstatement and the likelihood it occurs, and deficiencies are also aggregated: several individually minor gaps in the same account or process can combine into a material weakness. A material weakness must be disclosed in the annual report along with remediation plans, and where 404(b) applies the auditor issues an adverse opinion on ICFR. The recurring sources of material weaknesses among newer public companies are consistent: ineffective ITGCs, especially user access and change management, inadequate segregation of duties in small finance teams, insufficient accounting expertise for complex areas such as revenue recognition and equity instruments, and management review controls without evidence of precision.
Acquisitions, new systems, and scope changes
Two events reliably disrupt a 404 program. An acquisition brings a business with its own systems, processes, and control environment into scope, and SEC staff guidance permits management to exclude a recently acquired business from its assessment in the year of acquisition, provided the exclusion is disclosed along with the acquired business's significance. Companies should use that year to bring the acquired controls up to standard rather than to defer the problem, because in year two the exclusion ends. A system implementation, especially an ERP change, moves the control population: automated controls in the old system disappear, new ones must be identified and tested, data migration has to be controlled and reconciled, and user access is typically rebuilt from scratch. Implementations that go live late in the fiscal year leave no operating period for the new controls to be tested, which is the mechanism by which a well-run finance function ends up disclosing a material weakness. The safe pattern is to go live early in the year or to hold the cutover until the next one.
Where first-year programs fail, and how to avoid it
The failure pattern is calendar-driven. Companies start documentation midyear, test in the fourth quarter, find deficiencies in November, and have no period left in which remediated controls can operate and be re-tested before year end. The avoidable version starts scoping in the first quarter of the assessment year or earlier, tests design by midyear, tests operation on an interim basis by the end of the third quarter, and reserves the fourth quarter for remediation and roll-forward. It also treats IT general controls as the first workstream rather than the last, because access and change findings are the slowest to remediate and the most likely to undermine everything else. BD Emerson runs 404 readiness and annual control testing through our SOX compliance consulting practice and supports internal audit functions through internal audit services, with the ITGC testing performed by practitioners who run SOC 2 and ISO 27001 programs. We prepare management's assessment and its evidence; the 404(b) opinion itself comes from the company's independent auditor.
