CPA · CISA · CISM · CDPSE · CCSE · MBA
Internal controls documentation and testing evidence for a SOX 404 compliance programme

SOX 404 Compliance and Internal Control Over Financial Reporting

Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.

How many controls should a SOX 404 compliance programme have?

Usually 120 to 250 key controls including ITGCs, for a mid-market company with one ERP, one primary revenue stream and a single significant location. A SOX 404 compliance consultant in Los Angeles who arrives at 600 or more for that complexity is describing a mis-scoped programme, not an unusually rigorous one.

Section 404 requires management to assess the effectiveness of internal control over financial reporting. It does not require documenting every process in the company, which is why scoping, rather than testing, is where the money is won or lost: the gap between good and bad scoping is roughly a factor of three in annual cost, permanently.

Companies engage a SOX 404 compliance consultant in Los Angeles at one of two moments: shortly after becoming a public filer and realising that Section 404 is a programme rather than a project, or two years in, when the programme has grown to eleven hundred controls and nobody can remember why most of them exist.

Both problems have the same root cause: scoping. The eleven-hundred-control programme was not built by someone being unusually careful. It was built by someone who never drew a boundary, followed by three years of people adding controls that nobody felt authorised to remove.

What a SOX 404 compliance consultant in Los Angeles does first: scoping

The scoping exercise determines which accounts are material, which processes feed them, which locations are significant, and which controls actually address a risk of material misstatement. Everything downstream inherits those decisions.

The failure pattern is consistent and expensive. A first-year programme is built by documenting every process anyone can describe, mapping a control to each step, and calling the result a control matrix. It produces hundreds of controls that address no material risk, each of which must then be tested annually, evidenced, and remediated when it fails. Nobody ever removes them, because removing a control feels like reducing rigour.

Proper scoping works in the opposite direction, from the financial statements backwards. Which balances are quantitatively or qualitatively material. What could go wrong in each. Which controls, if they operated, would prevent or detect that. Everything else is a business process, not a SOX control, and should be managed as one.

Where ITGCs sit, and why they get underestimated

Every automated control, every system-generated report used in a control, and every calculation performed by the ERP depends on the general IT controls underneath it. If access management, change management and IT operations are not effective, the application controls sitting on top cannot be relied upon, and the deficiency is pervasive rather than isolated, which is how a single access-review failure becomes a material weakness.

This is the area where finance-led SOX programmes most often come apart, because it requires someone who can read an access listing, understand a change ticket, and evaluate whether a privileged account should exist. Holding CISA alongside the CPA licence is the practical reason this practice handles both halves rather than subcontracting one. The dedicated detail is on the IT audit and ITGC page.

First-year programmes

A newly public company (whether through IPO, direct listing or de-SPAC) faces a compressed timeline in which the finance team is simultaneously learning to file 10-Qs. The realistic sequence over the first year is: scope in the first quarter, document and design in the second, remediate through the third, and test in the fourth so that management's assessment rests on controls that have actually operated.

The decision that most affects year two is how much of the programme lives in a tool versus in spreadsheets, and how much of the testing the company can perform itself. A programme designed so that the consultant must return annually to run it is a programme designed badly.

Deficiency evaluation, the judgment that matters most

When a control fails, three questions follow: what is the magnitude of potential misstatement, what is the likelihood, and does a compensating control catch it. The answers determine whether the failure is a deficiency, a significant deficiency, or a material weakness, and the last of those requires disclosure and moves markets.

This is where experience is not substitutable. The evaluation is a judgment made under pressure, usually late in the year, usually with the external auditor holding a different preliminary view. Having sat on the auditor's side of that conversation for twenty years changes how it is prepared for: with the analysis documented before the discussion rather than assembled during it.

Reducing an existing programme

For companies already two or three years in, the more common engagement is rationalisation. The pattern is recognisable, control counts that only ever increase, testing that consumes the fourth quarter, and a matrix containing controls that duplicate one another or that address risks that ceased to exist when a system was replaced.

Rationalisation works through the same backwards logic as initial scoping, and typically removes 30 to 50% of controls from an unrationalised programme without reducing coverage of material risk. The constraint is rarely analytical. It is that removing controls requires a documented rationale the external auditor will accept, and writing that rationale is the actual work.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Risk assessment and scoping memo tied to material financial statement line items
  • Process narratives and flowcharts for in-scope processes
  • Risk and control matrix with assertion-level mapping
  • ITGC scoping and control design across in-scope systems
  • Test plans, sampling methodology and executed testing workpapers
  • Deficiency evaluation and aggregation analysis
  • Remediation plans sequenced by dependency
  • Management’s assessment support and external auditor coordination
  • Control rationalisation analysis for established programmes

How a typical engagement runs

  1. Scope

    Work backwards from the financial statements to material accounts, relevant assertions, significant processes and locations. Everything downstream depends on this being done properly.

  2. Document and design

    Narratives, flowcharts and a risk and control matrix, including ITGCs. Gaps in control design are identified here, when they are cheap to fix.

  3. Remediate

    Design and implement the missing controls, then let them operate long enough to be tested. Controls that have never operated cannot support an assessment.

  4. Test and conclude

    Execute testing, evaluate exceptions, aggregate deficiencies, and prepare management’s assessment, with the external auditor’s likely position anticipated rather than discovered.

SOX 404 Compliance across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

SOX 404 Compliance: questions we are asked

Not answered here? Ask Javed directly

How many controls should a SOX programme have?

There is no correct number, but there is a useful sanity check. A mid-market company with one ERP, one primary revenue stream and a single significant location can usually be covered by something in the range of 120 to 250 key controls including ITGCs.

Programmes at 600, 900 or 1,200 controls at that complexity are almost always mis-scoped rather than unusually rigorous. Each excess control carries an annual cost in testing, evidence and remediation, and none of them reduce the risk of material misstatement.

When does a newly public company have to comply with Section 404?

Management's assessment under 404(a) is generally first required in the second annual report following the IPO. The auditor attestation under 404(b) depends on filer status, and emerging growth companies and smaller reporting companies have exemptions and phase-ins that can defer it considerably.

The trap is treating the deferral as time available. Controls must have operated before they can be tested, so a company that starts designing in the year the assessment is due has no operating history to test against, and remediation collides with the filing deadline. Starting in the first year is materially cheaper than starting in the second.

What is the difference between a significant deficiency and a material weakness?

Both are control deficiencies; they differ in severity. A significant deficiency is less severe than a material weakness but important enough to merit attention by those responsible for financial reporting oversight. A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis.

The practical distinction is disclosure. A material weakness must be disclosed, and it affects the auditor's opinion on ICFR. Two points are frequently missed: deficiencies aggregate, so several individually minor issues in the same process can combine into a material weakness; and an ITGC failure is often pervasive rather than isolated, because everything relying on that system inherits the problem.

Can you test controls if you also designed them?

For management's own testing programme, yes; this work is performed on behalf of management, which is expected to design and assess its own controls. That is a different role from the external auditor's.

Where independence does bite is if this practice were also performing your financial statement audit or ICFR attestation. It cannot do both, and which side applies is agreed before the engagement begins. The audit and attestation page sets out the same rule from the other direction.

Our external auditor disagrees with our scoping. What now?

Common, and usually resolvable, but the resolution depends on documentation rather than argument. The auditor's position is typically that a process or location you excluded could produce a material misstatement, and the answer is a quantitative and qualitative analysis showing why it could not.

Where the analysis was written at the time of scoping, these conversations are short. Where it is reconstructed afterwards, the auditor tends to prevail regardless of the merits, because contemporaneous rationale is what makes a scoping decision defensible.

Related services

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about sox 404 compliance

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a sox 404 compliance engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now