Watch DemoRead About It
Browse ServicesService Provider InfoSign In / Up
Audit & AssuranceAll statesComing soon

SOX Compliance & ICFR

Service description

SOX 404 compliance is the process of documenting, testing, and certifying the internal controls over financial reporting that public companies — and companies preparing to go public — must maintain. Management assesses and reports on control effectiveness every year, and larger companies' auditors must independently attest to that assessment.

Common industries

Public companies and companies preparing for an IPO, across every industry the SEC regulates.

ROI

Getting controls right ahead of an IPO or first SOX year avoids material-weakness findings that spook investors and delay deals.

Benefit

Build and test the internal controls over financial reporting that public and pre-IPO companies must document and certify (SOX 404).

Why get it

Federal securities law requires management to assess and report on internal control effectiveness every year, with independent auditor attestation for larger filers; a company entering its first SOX year needs its controls built and tested before certification is due.

When you benefit

An initial build-and-test project ahead of a company's first SOX year or IPO, then a recurring annual cycle of testing and certification alongside the 10-K filing.

What it costs

A project fee for the initial build, then a recurring fee for annual testing.

When you pay

The initial project is commonly billed in phases — design, documentation, and testing — while the recurring annual engagement is typically billed as one fee tied to the testing cycle.

Other costs

Remediating a control gap or material weakness found during testing — new controls, additional staff, or system changes — is separate from the advisory or testing fee.

Risks to know

A material weakness disclosed in a SOX 404 report can unsettle investors and delay a deal or offering. Building controls too close to the certification deadline leaves little time to fix a gap testing finds before management has to certify.

When risks arise

Gaps are most commonly found during the testing that precedes certification, so a company that starts documentation and testing late compresses the time available to remediate before the certification date.

The process

The provider helps the company document its key controls, assesses design effectiveness, and tests operating effectiveness across a testing cycle. Findings are reviewed with management, who prepares its own internal control report; the company's independent auditor separately attests to that assessment where required.

Your commitment

The company identifies the financial processes and controls in scope, gives the provider access to document and test them, and assigns internal owners who can walk through and support each control being tested.

Documents to gather

Helpful reading

Further research

Suggest an edit to this page →

Not open yet

SOX Compliance & ICFR isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.