Est.

SOX Section 404 Internal Controls Documentation

Management must assess internal controls annually, while auditors attest only for larger filers.

Features Editor · · 12 min read
Cover illustration for “SOX Section 404 Internal Controls Documentation”
Compliance Workflows · August 15, 2026 · 12 min read · 2,588 words

SOX Section 404 is actually two rules, not one, and mixing them up is the fastest way to under-build a controls program. Section 404(a) makes management assess and report on internal control over financial reporting every year in the 10-K. Section 404(b) makes the external auditor independently attest to that same assessment, and it only applies to a narrower slice of companies. Don't confuse either one with Section 302, which makes the CEO and CFO personally certify the accuracy of financial statements each quarter and year. Section 302 is a signature on a certification; Section 404 is a demand that the controls actually work, and that demand is what generates the months of documentation work that eats up internal audit's calendar. Behind both sits Section 906, which carries real teeth: up to several million dollars and 20 years in prison for willful false certification, up to seven figures and 10 years for a knowing but non-willful violation. Those numbers aren't decoration. They're why ICFR documentation gets treated with the weight it does inside audit committees and general counsel's offices.

Which companies must comply with 404(a), which must also comply with 404(b), and who gets a pass

404(a) doesn't let anyone off the hook. Every public company, no matter the size, has to file management's annual assessment of ICFR effectiveness. There's no exemption tier, no revenue floor, no carve-out for smaller reporting companies.

404(b) is a different animal. Auditor attestation only applies to accelerated and large accelerated filers; non-accelerated filers and Emerging Growth Companies get an exemption under 404(c). The EGC classification, created by the JOBS Act, covers companies with less than approximately $1 billion in annual gross revenue, a number that gets adjusted for inflation every five years. An EGC can skip 404(b) for as long as it holds EGC status, but 404(a) still applies the entire time. That distinction trips people up constantly. Skipping the audit attestation is not the same as skipping the management assessment.

Newly public companies get a short grace period, and the timing catches people off guard often enough that it's worth spelling out. The first 10-K filed after an IPO usually doesn't require a 404(a) management assessment. The second one does, in full, and depending on public float, it may pull in 404(b) too. Say a company goes public in May 2024 with a December 31 fiscal year-end. Its FY2024 10-K, filed in early 2025, skips 404(a). Its FY2025 10-K, filed in early 2026, does not; full compliance is due, no extensions, no grace.

The harder transition is the one out of EGC status, because it isn't tied to a filing date. It's tied to a snapshot in time. Public float gets measured on June 30 each year, and calendar-year companies that cross the non-accelerated filer threshold on that date owe 404(b) the following year. Plenty of companies don't track this proactively, and they end up close to the 10-K deadline realizing they need auditor attestation with none of the infrastructure built to support it. Building that infrastructure, control documentation, testing evidence, the whole apparatus, takes months. Not weeks.

Table: SOX Section 404(a) vs. 404(b): Key Differences. Compares Obligation, Who Must Comply, EGC / Non-Accelerated Filers, First-Year IPO Filing, and 1 more by Section 404(a) and Section 404(b).

The COSO 2013 framework and why it is the only defensible documentation backbone today

A company still running its ICFR program on the 1992 COSO framework is running on borrowed time. Both the SEC and PCAOB treat the 2013 Internal Control – Integrated Framework as the standard now, and auditors will notice, and question, any company still clinging to the older version. The 2013 update did more than modernize the language. It broke the five components, control environment, risk assessment, control activities, information and communication, monitoring activities, into 17 specific principles, and each one needs its own affirmative documentation.

This is where a lot of programs quietly fail. The 17-principle structure isn't a formality bolted onto the five components for the sake of looking thorough. Each principle demands the company point to something concrete showing it's present and working: board minutes showing oversight of risk, a code of conduct with proof of enforcement, IT change management logs. Miss a principle entirely and an auditor will flag it as a documentation gap, sometimes escalating further depending on how central that principle is to the financial reporting risks at hand.

One thing worth tracking: COSO put out supplemental guidance in 2023 mapping those same 17 principles to sustainability reporting, under the name Internal Control over Sustainability Reporting. As SEC climate disclosure rules and similar international mandates keep developing, companies building ICFR documentation now should ask whether the same structure can stretch to cover ESG data later. Rebuilding a documentation framework from scratch a second time, a few years after finishing the first build, wastes real money and real time.

How top-down risk assessment scopes the controls a company actually needs to document

PCAOB Auditing Standard 2201 lays out the method for figuring out which controls actually matter: Top-Down Risk Assessment, or TDRA. It starts at the financial statement level, identifying material accounts and disclosures, then works down into the business processes and assertions, existence, completeness, valuation, rights, presentation, that support those numbers. From there, the company picks key controls addressing the "what could go wrong" risks at each assertion level. This scoping exercise decides everything downstream: how many controls get documented, how many process cycles get narratives, how much testing actually happens.

Most companies end up with controls clustered around the same handful of cycles: revenue and receivables, purchases and payables, payroll and compensation, inventory and cost of goods sold, cash and banking, financial close and reporting. These are the areas where misstatement risk concentrates, and where auditors expect the deepest documentation.

Scoping discipline matters more than most programs give it credit for. KPMG's 2025 SOX Survey found that 56% of organizations report their external auditors test fewer in-scope controls than management does. That's not a rounding error. It means companies are documenting and testing controls the auditor never touches, which is wasted hours and unnecessary cost with nothing to show for it in reduced audit risk.

Multi-location companies get more room here than people assume. AS 2201 does not require testing at every subsidiary or location. Risk-based coverage, picking sites by financial significance and misstatement risk, is permitted, and frankly it's the only sane way to run a global program. Entity-level controls can cover the lower-risk locations, which cuts the documentation load without cutting rigor where it actually counts.

None of this is set-it-and-forget-it, either. An acquisition, a new ERP rollout, a new product line: any of these can shift where the real risk sits. Scope that was accurate last year can miss what matters this year, so TDRA needs a refresh whenever the business changes in a material way, not just when the fiscal year turns over.

The documentation artifacts that make an ICFR assessment defensible

Every documented control needs a baseline set of attributes attached to it: a named owner, a stated frequency, a description of what evidence supports the review, whether that's a bank statement, an invoice, or a system-generated report. Without these, a control exists on paper and cannot be tested in any way that means anything.

Risk and Control Matrices, RCMs, sit at the center of the whole effort. A properly built RCM maps each financial statement risk to the specific control addressing it, and ties that connection explicitly back to the relevant COSO principle and financial statement assertion. Controls listed in isolation, with no named risk attached, are among the most common gaps auditors find, and they get flagged as design deficiencies almost automatically.

Process narratives and flowcharts do different jobs, even though people treat them as interchangeable half the time. A flowchart gives an auditor a fast visual read on how a transaction moves through a process. A narrative supplies the detail needed to judge whether the process, as designed, actually addresses the risk it claims to address. Both need to be current. A narrative describing a process the company retired eighteen months ago isn't a minor housekeeping issue. It's an immediate red flag suggesting the whole documentation set has gone stale.

IT General Controls, ITGCs, deserve particular attention because one weakness here can cascade fast. A single access-control failure can invalidate reliance on every automated control across every process touching that system. KPMG's 2025 SOX Survey found automated controls fell from 21% of total in-scope controls in FY2022 to 17% in FY2024, even as the average number of in-scope IT systems more than doubled, from 17 to 40. More systems, fewer automated controls: that combination means companies are leaning harder on IT-dependent manual controls, and each one of those needs full ITGC support documentation covering logical access, change management, computer operations, and program development, for every system in scope. That's a lot of surface area to keep current, and it only grows.

Management Review Controls, MRCs, draw heavy auditor scrutiny for a simple reason: effectiveness hinges on the reviewer's judgment, and judgment is inherently harder to document than a system-generated check. Good MRC documentation captures the precision threshold the reviewer used, what variance triggers a follow-up, say, along with evidence the threshold actually got applied. The common deficiency is documentation that shows a review happened without showing what the reviewer was looking for or what came of it.

Root cause analysis documentation has cleared a higher bar since the PCAOB's April 2024 guidance. Remediation documentation now has to explain not just what got fixed, but why the deficiency happened in the first place. Companies that remediate before the external audit starts, and document the root cause fully, stand in a much better position to argue a deficiency down from a material weakness.

How auditors evaluate ICFR documentation and what drives testing scope

Auditor testing does not mirror management testing, and it isn't meant to. That 56% gap mentioned earlier reflects deliberate auditor scoping decisions, not sloppiness. Management teams that document and test beyond what the audit scope requires are just spending money without buying more assurance.

Sample sizes track control frequency, not guesswork. Daily controls need larger samples; monthly or quarterly controls need smaller ones. Auditors adjust further depending on whether a company is 404(a) or 404(b), the assessed risk level, and whether it's a first-year filer. A control also has to run for a meaningful stretch, generally at least six months, before year-end testing can produce reliable evidence. A control stood up in October cannot carry the weight of a full fiscal year's assurance, no matter how well it's designed on paper.

Segregation of duties, SoD, generates some of the most common findings in any audit. The idea is simple enough: no one person should control every phase of a transaction, so the employee who creates a vendor record shouldn't also approve payments to that vendor. What makes SoD tricky is that the failure usually lives in system access, not the written policy. Documentation can look pristine while the underlying access controls are broken underneath it, which is why SoD documentation needs actual system access reports, not a policy statement asserting duties are separated.

Auditors also split design effectiveness from operating effectiveness and treat them as genuinely different questions. A well-designed control that was never actually performed fails on operating effectiveness, full stop, regardless of how sound it looks on paper. What moves a control from documented to tested-and-effective is evidence of execution: signed approvals, system logs, dated reconciliation sign-offs. Without that trail, a beautifully designed control is just a description of somebody's intentions.

Where documentation breaks down and how material weaknesses develop

The headline trend looks encouraging. Adverse reporting rates fell to just over 15% in 2024, based on analysis from Baker Tilly and Moss Adams covering more than 5,000 management-only assessments and more than 3,000 external auditor assessments between 2020 and 2024. But that improvement sits on top of a baseline that hasn't moved nearly as much: Protiviti puts the ongoing rate at roughly 20 to 25% of U.S. companies reporting at least one material weakness every year. Progress at the margin is real. It is not the same thing as solving the underlying problem.

Non-accelerated filers carry a disproportionate share of this burden. A meaningful chunk disclose material weaknesses across multiple consecutive years, which tells you that classifying deficiency severity correctly isn't a one-time compliance task. It's a recurring, annual pressure point for smaller companies running leaner control teams.

KPMG's 2025 analysis of non-IPO companies found material weaknesses climbing in three specific areas. Financial close is one, often traceable back to weak reconciliation documentation or the MRC precision gaps described above. Control environment is another, where tone-at-top and entity-level deficiencies cascade down through the rest of the framework. Non-routine and complex transactions round out the list, an area where standard RCMs don't really apply and controls get built ad hoc, usually under time pressure.

Here's a number worth pausing on: average key controls grew 18%, to 546, between FY2022 and FY2024, per that same KPMG survey. More controls isn't the same thing as better documentation discipline. If anything, piling on controls without tightening documentation makes the underlying problem worse, not better, because there are simply more artifacts that can go stale, lose an owner, or drift from the process they're supposed to describe.

Beyond the statistics, the breakdown patterns repeat themselves year after year. Documentation describes last year's process instead of the current one. Controls have no named owner, so nobody's accountable when testing turns up a gap. Evidence gets kept for some instances of a recurring control but not all of them, which undermines the completeness of the entire testing population. IT system changes made mid-year never make it into updated ITGC documentation. None of this is exotic. These are ordinary lapses that pile up quietly until an auditor's sample happens to land on the wrong instance.

The real cost of SOX 404 compliance and what drives it higher

Diagram: Auditor Hours and Fees: 2012 vs. 2024. Visualizes: Visualize the dramatic growth in auditor testing hours and fees over twelve years, using figures cited in the article from one audit committee member's account.

The average SOX program now runs $2.3 million a year and eats 15,581 hours, according to KPMG's 2025 SOX Survey, and average budgets climbed 44% between FY2022 and FY2024. Those aren't small numbers for any finance organization to absorb, and most don't have much slack to absorb them with.

One audit committee member's account, cited in that same survey, shows where the cost pressure actually comes from. Auditor hours spent testing controls rose from roughly 3,000 in 2012 to 8,000 in 2024, with fees climbing from about $900,000 to $3 million over the same stretch. The company hadn't grown anywhere near that fast; the member pinned the increase on evolving PCAOB requirements, not business expansion. That distinction matters, because it means the cost curve is being pushed up by regulatory expectation, not by the underlying complexity of the business getting audited.

404(b) attestation itself adds a measurable, front-loaded cost. GAO's 2025 analysis found the transition to auditor attestation raised audit fees by roughly 13% in the first year, a median bump of $219,000. Companies with public float at or above $75 million, the non-exempt group, paid costs roughly 19% higher than their exempt counterparts, per that same GAO analysis.

Put together, these numbers tell a consistent story. SOX compliance cost is not primarily a function of company size or transaction volume. It's a function of documentation depth, control count, and the sheer number of IT systems a company has to pull under ITGC coverage. Companies that treat documentation as a living record, updated as things change, rather than an annual scramble, tend to come out ahead on both counts: they spend less, and they face fewer surprises when the auditors show up.

Sources

  1. sarbanes-oxley-101.com
  2. finrep.ai
  3. crowe.com
  4. cbh.com

More in Compliance Workflows