SOX is the Sarbanes-Oxley Act, and for most compliance and finance teams it comes down to two sections. Section 302 is the quarterly certification where the CEO and CFO put their names behind the financial reports. Section 404 is the annual work behind that signature: management assesses whether its internal control over financial reporting is effective, and for many companies the external auditor independently attests to the same thing. The control framework that organizes the work is COSO. The unit of work is a key control, documented in a risk-control matrix, tested for both design and operating effectiveness. The most severe classification of a control failure is a material weakness, the finding that ICFR is not effective.
The Sarbanes-Oxley Act of 2002 is the federal statute governing the accuracy of public-company financial reporting and the internal controls that support it. Its operative mechanism is documentary: a public company asserts that its financial statements are reliable, and SOX prescribes the controls, testing, and certifications by which that assertion is supported and evidenced.
This article covers the scope of the Act, the requirements of Sections 302 and 404, the role of the COSO framework, the distinction between design effectiveness and operating effectiveness, the classification of deficiencies, and the annual cycle from scoping to opinion. Where a determination depends on a company's specific facts, the article states that rather than generalizing.
Who SOX applies to
The Sarbanes-Oxley Act of 2002 applies to public companies, called issuers, that file reports with the US Securities and Exchange Commission. If a company is listed on a US exchange or otherwise has registered securities, it is in scope. The Act also reaches the registered public accounting firms that audit those issuers, which is why it created the Public Company Accounting Oversight Board to oversee them.
Most SOX provisions do not bind private companies. The common exception in practice is the private company that is preparing for an initial public offering or an acquisition by a public company, which often builds SOX-ready controls a year or more ahead so the first reporting cycle as a public company is not a scramble. There is also a familiar split among public companies themselves on the auditor attestation requirement, which the next section covers.
Section 302: the certification
Section 302 requires the principal executive officer and principal financial officer, in practice the CEO and CFO, to personally certify each quarterly and annual report. The certification covers a few things in plain terms. They have reviewed the report. To their knowledge it does not contain a material misstatement or omission. The financial statements fairly present the company's condition. They are responsible for establishing and maintaining disclosure controls and procedures, and they have evaluated those controls. And they have disclosed any significant deficiencies and any fraud involving management to the auditors and the audit committee.
Section 302 assigns the certification obligation to named officers, and it is not delegable. The certification is not a warranty that no misstatement will occur; it attests that a control system exists, that the officers evaluated whether it operates, and that they disclosed what the evaluation found. A false certification carries personal consequences for the signing officers.
Section 404: internal control over financial reporting
Section 404 carries the substantive control obligation, and it has two parts.
Section 404(a) requires management to assess and report, each year in the annual report, on the effectiveness of the company's internal control over financial reporting, usually shortened to ICFR. Management has to state its responsibility for ICFR, identify the control framework it used, and give its conclusion on whether ICFR is effective as of year-end.
Section 404(b) requires the company's external auditor to independently attest to the effectiveness of ICFR. This is a separate opinion from the audit of the financial statements themselves, and the public-company audit standard that governs it is PCAOB AS 2201, the standard on an audit of internal control over financial reporting that is integrated with an audit of financial statements. Not every issuer is subject to 404(b). Smaller reporting companies and non-accelerated filers have historically been exempt from the auditor attestation, though they remain subject to 404(a) management assessment. Whether a specific company falls inside 404(b) depends on its filer status, which is a fact to confirm for each company rather than assume.
| Provision | Who acts | What it requires |
|---|---|---|
| Section 302 | CEO and CFO | Personal certification, each quarter and year, that the reports are accurate and that disclosure controls exist and were evaluated. |
| Section 404(a) | Management | Annual assessment and report on whether ICFR is effective, naming the control framework used. |
| Section 404(b) | External auditor | Independent attestation on ICFR effectiveness under PCAOB AS 2201, for issuers subject to it. |
The COSO framework
SOX requires management to base its ICFR assessment on a suitable, recognized control framework, and the one almost every US issuer uses is COSO, the framework from the Committee of Sponsoring Organizations of the Treadway Commission. Its 2013 Internal Control Integrated Framework organizes internal control into five components and seventeen underlying principles. A program that maps cleanly to the five components is a program an auditor can follow.
| COSO component | What it covers |
|---|---|
| Control environment | The tone at the top. Integrity, ethical values, board oversight, organizational structure, and accountability that set the foundation for everything else. |
| Risk assessment | Identifying and analyzing the risks of material misstatement across accounts and processes, including fraud risk, so controls can be aimed at the right places. |
| Control activities | The actual controls. Approvals, reconciliations, segregation of duties, system access controls, and the policies and procedures that carry them out. |
| Information and communication | The quality of the data flowing through the reporting process, and whether responsibilities are communicated up, down, and across the organization. |
| Monitoring activities | Ongoing and separate evaluations that confirm the components are present and working, and that deficiencies get reported and fixed. |
A practical way to read COSO is as a spectrum from the general to the specific. The control environment is the culture. Control activities are the individual checks a person performs every month. Entity-level controls sit closer to the environment end, and process-level controls sit closer to the activity end. A strong program needs both, because an entity-level control like audit committee oversight does not catch a missed reconciliation, and a reconciliation does not fix a culture that pressures people to hit a number.
Design vs operating effectiveness
Every key control is evaluated against two separate questions, and the two are frequently conflated in scoping.
Design effectiveness asks whether the control, if it operates as described, would prevent or detect a material misstatement in the relevant assertion. A control can be performed faithfully every day and still be poorly designed, where it was never aimed at the relevant risk. Design is tested by understanding the control and walking a transaction through it.
Operating effectiveness asks whether the control ran as designed throughout the period, by the right person, with the right competence and authority. Operating effectiveness is tested by examining evidence across the period, often a sample of instances, to confirm the control was performed consistently rather than once for the audit.
"The controller reviews the bank reconciliation monthly and signs it." The control is performed every month and the signature is always there. But the review is a sign-off with no evidence of what was actually examined, so an unreconciled item could pass through unnoticed. Designed weakly, even though it operates.
"The controller reconciles the bank account monthly, investigates and documents every reconciling item over the defined threshold, and signs and dates the workpaper. A second reviewer re-performs the math on a sample." Aimed at the risk, evidenced, and re-performable. An auditor can test both design and operation.
The distinction is operative because ICFR is concluded effective only where key controls are both designed appropriately and operating effectively. A well-designed control that was not performed is a finding, as is a control that was performed consistently but was never aimed at the relevant risk.
Key controls and the risk-control matrix
SOX does not require testing of every control in an organization. The program is built around key controls, the subset of controls that, if they failed, could allow a material misstatement to reach the financial statements. Identifying them starts from the financial statements and works backward: which accounts and disclosures are material, what could go wrong in each relevant assertion, and which controls address those risks.
The document that holds this together is the risk-control matrix, often called the RCM. It is the structural document of a SOX program, and a complete one allows an auditor to trace a line from a financial statement risk to the control that mitigates it to the test that evidences it. A typical RCM row carries these fields.
| RCM field | What it captures |
|---|---|
| Process / cycle | The business process, such as revenue, procure-to-pay, payroll, or financial close. |
| Risk of misstatement | What could go wrong, stated specifically rather than generically. |
| Assertion | The financial statement assertion at risk: existence, completeness, accuracy, valuation, rights and obligations, presentation. |
| Control description | What the control is, who performs it, how often, and what evidence it produces. |
| Control type | Preventive or detective, manual or automated, and whether it is a key control. |
| Test of design and operation | How design was evaluated and how operating effectiveness was tested, with sample size and results. |
The discipline that makes the RCM useful is specificity. "Management reviews results" is not a control description. "The FP&A director compares actual revenue to forecast by product line, investigates variances over the defined threshold, and documents the explanation before the close is finalized" is a testable control description. Imprecise descriptions are a common source of program failure, because an auditor cannot test what the matrix does not describe.
Walkthroughs and testing
The standard procedure for confirming that a control is understood and designed appropriately is a walkthrough: tracing a single transaction from its origination through the process and into the financial statements, following the control as it operates along the way. A walkthrough confirms the control exists as documented and is aimed at the relevant risk, on a sample of one.
Operating effectiveness requires a larger sample. For a control that runs many times in a period, testers examine a sample of occurrences and evaluate whether the control was performed each time as designed. Sample sizes scale with the frequency of the control and the degree of reliance placed on it. Automated controls can sometimes be tested once if the supporting general IT controls over change and access are themselves effective, which is why IT general controls sit underneath so much of a SOX program.
Deficiency severity: deficiency, significant deficiency, material weakness
When a control fails a test, the finding gets classified by severity, and the classification drives everything that follows. The three levels build on each other.
| Severity | Definition | Consequence |
|---|---|---|
| Control deficiency | A control is missing, or it is designed or operating such that it does not allow management or employees to prevent or detect misstatements on a timely basis. | Tracked and remediated. Generally not separately reported externally on its own. |
| Significant deficiency | A deficiency, or combination of deficiencies, less severe than a material weakness but important enough to merit attention by those responsible for financial reporting oversight. | Reported to the audit committee. ICFR can still be effective. |
| Material weakness | A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented or detected on a timely basis. | ICFR is reported as not effective, and the conclusion is disclosed publicly. A share-price reaction commonly follows. |
Two judgments decide where a finding lands: the magnitude of the potential misstatement and the likelihood it could occur. A single material weakness forces management to report that ICFR is not effective, and where 404(b) applies, the auditor reaches the same conclusion in its own opinion. The severity classification therefore determines the external reporting outcome. Severity is a matter of professional judgment applied to specific facts rather than a formula, and the practice standard is to document the reasoning rather than record a conclusion alone.
The annual SOX cycle
A mature program runs SOX as a continuous cycle rather than a year-end exercise, distributing the work across the year so that the conclusion is supported by the time the 10-K is due.
| Phase | What happens |
|---|---|
| 1. Scoping and risk assessment | Determine which accounts, disclosures, and locations are material and in scope. Refresh the risk assessment and confirm which controls are key. Set materiality. |
| 2. Documentation | Update process narratives, flowcharts, and the risk-control matrix so they match how the business actually operates this year, not last year. |
| 3. Design evaluation and walkthroughs | Walk each key control to confirm it is designed to address its risk and operates as documented. |
| 4. Operating effectiveness testing | Test samples across the period. This runs through the year, often in interim and year-end rounds, so issues surface with time to fix them. |
| 5. Deficiency evaluation and remediation | Classify any exceptions by severity, remediate where possible before year-end, and re-test remediated controls. |
| 6. Assessment and reporting | Management concludes on ICFR effectiveness, the CEO and CFO certify, the auditor renders its attestation where 404(b) applies, and the conclusions go into the annual report. |
Compressing the cycle into the final weeks of the year removes the remediation window: a control that fails a late test has no time to be remediated and re-tested, so a remediable deficiency can be reported as a material weakness on timing alone. Distributing testing across the year preserves the interval in which a control failure can be corrected before it becomes a reportable condition.
The PCAOB standards behind the audit
The external auditor's attestation runs on PCAOB standards, and those standards have moved. AS 2201 still governs the integrated audit of internal control over financial reporting. Sitting above it now is AS 1000, General Responsibilities of the Auditor in Conducting an Audit, which the PCAOB adopted in 2024 to consolidate and replace several older foundational standards (AS 1001, 1005, 1010, and 1015). It is effective for audits of fiscal years beginning on or after December 15, 2024, and it shortened the auditor's documentation-completion window from 45 days to 14. A current ICFR audit references AS 1000 alongside AS 2201.
A SOX readiness checklist
The following conditions are verified before the cycle closes.
- The scope ties to material accounts, disclosures, and locations, with the rationale documented.
- The risk-control matrix traces each financial statement risk to a control to a test, with no orphan risks.
- Every key control description is specific enough to test: who, what, how often, what evidence.
- Each key control has both a design evaluation and operating effectiveness testing on file.
- IT general controls over access and change support every automated control the program relies on.
- Exceptions are classified by severity with the magnitude-and-likelihood reasoning written down.
- Remediated controls were re-tested, not just re-described.
- The Section 302 sub-certifications support the CEO and CFO signatures up the chain.
- Significant deficiencies and any management fraud were reported to the audit committee.
- The management assessment names the control framework used and reconciles with the auditor's view where 404(b) applies.
The output of a SOX program is a record an auditor can follow: an identification of what could be misstated, controls built to prevent or detect it, testing of whether those controls operate, and a signed conclusion on the result. A program that can produce that record supports the certification; a program that cannot is exposed to a material weakness finding and its public disclosure.