Auditen
Home / Frameworks / SOX / Section 404: internal control over financial reporting
SOX · s.404

Section 404: internal control over financial reporting

Section 404 requires public companies to establish, maintain, and report on the effectiveness of their internal control over financial reporting (ICFR). Management must formally assess these controls annually, and for most larger companies, an external auditor must provide an independent attestation of that assessment.

What it means

The intent of Section 404 is to prevent material misstatements in financial statements, whether caused by error or fraud. It shifts the focus from simply reviewing the final numbers to auditing the processes that produce those numbers. If the process (the control) is broken, the resulting data is considered unreliable regardless of whether an actual error occurred during that specific period.

In practice, this means identifying every point in your financial reporting pipeline where a significant mistake could occur and implementing a "control" to mitigate that risk. This encompasses everything from IT permissions and system access (IT General Controls) to manual reviews and approvals of journal entries (Business Process Controls).

How to meet it

Evidence an auditor asks for

  • The Risk Control Matrix (RCM) and process documentation (narratives/flowcharts).
  • Signed-off evidence of control execution, such as dated approval signatures on reconciliations or system logs showing a reviewer approved a transaction.
  • User access reviews proving that permissions to financial systems are audited and revoked for terminated employees.
  • Change management tickets demonstrating that updates to financial software were tested and approved before being pushed to production.
  • Documentation of any identified control deficiencies and the subsequent remediation plans implemented to fix them.

Common pitfalls

  • Relying on "verbal controls" where a process is followed but no written or digital record exists to prove it happened.
  • Failing to update documentation when a business process changes, leading to a gap between how work is actually done and how it is audited.
  • Treating SOX as a once-a-year event rather than a continuous operational requirement, resulting in "fire drills" during the audit window.
  • Over-reliance on automated controls without verifying the underlying IT General Controls (ITGCs) that ensure those systems remain secure and unchanged.