SOX Compliance & ICFR
Service description
SOX 404 compliance is the process of documenting, testing, and certifying the internal controls over financial reporting that public companies — and companies preparing to go public — must maintain. Management assesses and reports on control effectiveness every year, and larger companies' auditors must independently attest to that assessment.
Common industries
Public companies and companies preparing for an IPO, across every industry the SEC regulates.
ROI
Getting controls right ahead of an IPO or first SOX year avoids material-weakness findings that spook investors and delay deals.
Benefit
Build and test the internal controls over financial reporting that public and pre-IPO companies must document and certify (SOX 404).
Why get it
Federal securities law requires management to assess and report on internal control effectiveness every year, with independent auditor attestation for larger filers; a company entering its first SOX year needs its controls built and tested before certification is due.
When you benefit
An initial build-and-test project ahead of a company's first SOX year or IPO, then a recurring annual cycle of testing and certification alongside the 10-K filing.
What it costs
A project fee for the initial build, then a recurring fee for annual testing.
When you pay
The initial project is commonly billed in phases — design, documentation, and testing — while the recurring annual engagement is typically billed as one fee tied to the testing cycle.
Other costs
Remediating a control gap or material weakness found during testing — new controls, additional staff, or system changes — is separate from the advisory or testing fee.
Risks to know
A material weakness disclosed in a SOX 404 report can unsettle investors and delay a deal or offering. Building controls too close to the certification deadline leaves little time to fix a gap testing finds before management has to certify.
When risks arise
Gaps are most commonly found during the testing that precedes certification, so a company that starts documentation and testing late compresses the time available to remediate before the certification date.
The process
The provider helps the company document its key controls, assesses design effectiveness, and tests operating effectiveness across a testing cycle. Findings are reviewed with management, who prepares its own internal control report; the company's independent auditor separately attests to that assessment where required.
Your commitment
The company identifies the financial processes and controls in scope, gives the provider access to document and test them, and assigns internal owners who can walk through and support each control being tested.
Documents to gather
- Process narratives and risk-and-control matrices for key financial processes
- Prior-year control testing results and any open remediation items
- Organizational chart identifying control owners
- Draft internal control report language for the annual filing
Helpful reading
- Companies spending more time on SOX compliance — Journal of Accountancy
- Do PCAOB Audit Inspections and ICFR Assessments Protect the Public Interest? — The CPA Journal
Further research
Not open yet
SOX Compliance & ICFR isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.