Section 404: internal control over financial reporting
Section 404 requires public companies to establish, maintain, and report on the effectiveness of their internal control over financial reporting (ICFR). Management must formally assess these controls annually, and for most larger companies, an external auditor must provide an independent attestation of that assessment.
What it means
The intent of Section 404 is to prevent material misstatements in financial statements, whether caused by error or fraud. It shifts the focus from simply reviewing the final numbers to auditing the processes that produce those numbers. If the process (the control) is broken, the resulting data is considered unreliable regardless of whether an actual error occurred during that specific period.
In practice, this means identifying every point in your financial reporting pipeline where a significant mistake could occur and implementing a "control" to mitigate that risk. This encompasses everything from IT permissions and system access (IT General Controls) to manual reviews and approvals of journal entries (Business Process Controls).
How to meet it
- Conduct a scoping exercise to identify all "significant accounts" and the business processes that impact them.
- Map out financial workflows using narratives or flowcharts to identify where risks exist and where controls are currently applied.
- Implement a Risk Control Matrix (RCM) that links specific financial risks to the corresponding control activity, its frequency, and the owner.
- Establish clear segregation of duties (SoD) to ensure that no single individual has enough authority to both execute and conceal an error or fraud.
- Perform periodic "walkthroughs" where a transaction is traced from initiation to the final financial statement to verify controls are functioning as designed.
- Execute a formal testing plan throughout the year to validate that controls operate consistently across different samples of data.
Evidence an auditor asks for
- The Risk Control Matrix (RCM) and process documentation (narratives/flowcharts).
- Signed-off evidence of control execution, such as dated approval signatures on reconciliations or system logs showing a reviewer approved a transaction.
- User access reviews proving that permissions to financial systems are audited and revoked for terminated employees.
- Change management tickets demonstrating that updates to financial software were tested and approved before being pushed to production.
- Documentation of any identified control deficiencies and the subsequent remediation plans implemented to fix them.
Common pitfalls
- Relying on "verbal controls" where a process is followed but no written or digital record exists to prove it happened.
- Failing to update documentation when a business process changes, leading to a gap between how work is actually done and how it is audited.
- Treating SOX as a once-a-year event rather than a continuous operational requirement, resulting in "fire drills" during the audit window.
- Over-reliance on automated controls without verifying the underlying IT General Controls (ITGCs) that ensure those systems remain secure and unchanged.