SOX 404 Compliance
Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.
SOX 404 support
Audits, reviews, compilations, agreed-upon procedures and benefit plan audits, work that only a licensed CPA firm can issue.
Only a licensed CPA firm. The defining feature of these engagements is that a third party relies on the result: a lender lends against it, a board governs on it, an insurer underwrites from it, a buyer prices from it. That reliance is what the licence exists to support, and it is why a consultancy, a bookkeeper or an enrolled agent cannot perform the work regardless of how capable they are.
Audit and attestation services from a California CPA firm come in levels, and choosing the level is the decision that matters. A compilation, a review and an audit are not degrees of care applied to the same piece of work. They are different amounts of assurance, at materially different costs, and they satisfy different requirements.
Most companies asking about an audit do not actually need one. Determining which level of service satisfies the requirement (and saying so even when the more expensive option was already assumed) is the first useful thing this engagement does.
They differ in the amount of work performed and, correspondingly, in the level of assurance the report conveys.
Financial statements are presented in the correct form from information you provide. No assurance is expressed, no verification is performed. Appropriate for internal use, or where a lender has specifically said a compilation is acceptable. Fast and inexpensive.
Analytical procedures and enquiry, producing limited assurance, a conclusion that nothing came to our attention suggesting the statements are materially misstated. This is the level most private-company lender covenants actually require, and the level most often over-bought.
Substantive testing, third-party confirmation, evaluation of internal control relevant to the audit, and an opinion providing reasonable assurance. Required for most institutional investors, larger credit facilities, many regulatory filings, and any situation where an outside party's exposure is significant.
Specific procedures, defined by you and the party relying on the result, with findings reported factually and no opinion expressed. Useful for a narrow question (verifying a royalty calculation, testing a specific covenant, confirming a schedule in a purchase agreement) where a full audit would be disproportionate.
A practical note that saves money more often than any other advice on this page: read the actual covenant language before commissioning anything. Loan agreements frequently say "reviewed financial statements" and are read as requiring an audit, at roughly three times the cost.
A plan with 100 or more eligible participants generally requires an annual audit filed with Form 5500. This is a specialised area with its own failure modes, and it is one where the Department of Labor has been publicly critical of audit quality across the profession.
The recurring findings are consistent: participant eligibility not tested against the plan document, employee deferrals not remitted within the required timeframe, compensation definitions applied inconsistently between payroll and the plan, and reliance on a custodian's certification broader than the certification actually supports.
Plan sponsors are frequently unaware that late remittance of deferrals is a prohibited transaction requiring correction and reporting, regardless of how brief the delay was or whether any participant was harmed.
The single largest determinant of how painful an audit is (and how much it costs) is the state of your workpapers before fieldwork begins. An audit where every account reconciliation exists, is current, and ties to the general ledger runs efficiently. One where reconciliations are prepared in response to the auditor's request does not, and the additional time is billed.
A prepared-by-client list is issued well before fieldwork and is deliberately specific. Where a company is undertaking a first audit, that list arrives early enough to be a work plan rather than a surprise, and the controller-level support to complete it is available separately, subject to the independence rules described below.
AICPA independence requirements restrict what a firm performing an attestation engagement may also do for the same client. Bookkeeping, management functions and certain advisory services can impair independence in fact or in appearance, and once impaired the opinion is not usable.
The consequence is simple and is agreed in writing before an engagement letter is signed: this practice will either perform your attestation work, or perform the non-attest work around it. Not both. Where a conflict exists, you will be told which service to take elsewhere, and, where it helps, who is competent to provide it.
Confirm what the relying party actually requires. This step regularly reduces the engagement from an audit to a review and saves the client a multiple of the fee.
Understand the business, identify where material misstatement is most likely, and evaluate the controls relevant to those areas. The PBC list is issued here.
Substantive testing, confirmations, analytical procedures and, where relied upon, controls testing. Open items are communicated as they arise rather than accumulated.
Draft statements and report, a management letter covering control observations, and a direct conversation with the board or audit committee where one exists.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
Frequently not. Loan agreements commonly specify "reviewed" or even "compiled" financial statements, and companies routinely commission an audit because the word "audited" was used informally in conversation with a relationship manager.
Send the covenant language before commissioning anything. The difference between a review and an audit is commonly two to three times the fee and several weeks of your finance team's time, and a lender who accepts a review has no reason to be told otherwise.
It scales with transaction volume, number of entities, revenue-recognition complexity, inventory, and (heavily) the readiness of your records. A single-entity services company with clean reconciliations sits at the low end. Multiple entities, inventory, percentage-of-completion revenue, or a first-year audit with no prior auditor to rely on all push it up.
The most reliable way to reduce the fee is not negotiation. It is completing the prepared-by-client list before fieldwork starts, because audit hours spent waiting for a reconciliation are billed at the same rate as audit hours spent testing one.
Predictably: opening balances will need to be verified because there is no predecessor auditor's work to rely on; revenue cut-off around period end will be tested and will produce adjustments; accrual completeness will be challenged; and at least one account will turn out to contain something that has been rolling forward unexplained for years.
None of that is unusual. It is why a readiness assessment ahead of a first audit is worth doing, it converts surprises found during billable fieldwork into work items handled beforehand at a lower rate.
Generally when the plan has 100 or more eligible participants at the beginning of the plan year, with a transition rule that allows a plan crossing the threshold to defer for a period. Note the test is eligible participants, not contributing ones, plans with automatic enrolment cross the line sooner than sponsors expect.
If you are approaching the threshold, plan a year ahead. The most common finding in first-year plan audits is late remittance of employee deferrals, which is a prohibited transaction requiring correction and reporting even when the delay was short and nobody was harmed.
No; that is precisely what the independence rules prohibit, and a report issued in those circumstances would not be usable by the party relying on it.
What is possible is either side of the line. This practice can perform readiness work for a company whose audit is issued elsewhere, or perform the attestation for a company whose preparation is handled by its own team or another firm. Which role applies is settled before any engagement letter exists.
Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.
SOX 404 supportReadiness, remediation and the attestation itself, held by one licensed firm instead of split between a consultancy and a remote auditor.
SOC 2 servicesWhere the business can fail, whether the control that should catch it works, and what to fix first.
Risk & controlsThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp