SOX Compliance: What Sarbanes-Oxley Actually Requires
Where the Statute Came From and What It Changed
The Sarbanes-Oxley Act of 2002, Public Law 107-204, passed in the wake of Enron and WorldCom by margins that essentially never happen, 99 to 0 in the Senate. You can read the full text of the Act on sec.gov, and it’s worth a skim, because it’s shorter than most people assume and the operative sections run only a few paragraphs each.
Four structural changes came out of it. It created the Public Company Accounting Oversight Board, which took audit standard-setting and inspection away from the profession and gave it to a regulator overseen by the SEC; the standards live at pcaobus.org. It made the audit committee, not management, responsible for hiring, paying, and overseeing the outside auditor. It banned a list of non-audit services the auditor could no longer sell to an audit client. And it put the CEO and CFO personally on the hook for the numbers.
That last piece is the part practitioners mean when they say SOX compliance. It splits into a certification regime under Section 302 and an internal control regime under Section 404, and those two get conflated constantly even by people who work on them.
Section 302 vs 404(a) vs 404(b)
Section 302 is a certification, filed with every quarterly and annual report. The principal executive officer and principal financial officer each sign a statement saying they reviewed the report, that it contains no untrue statement of material fact and omits nothing material, that the financial statements fairly present the company’s condition, that they are responsible for establishing and maintaining disclosure controls and procedures and internal control over financial reporting, that they evaluated the effectiveness of disclosure controls as of period end, and that they disclosed to the auditor and audit committee any significant deficiencies, material weaknesses, and any fraud involving management or employees with a significant role in controls. It shows up as Exhibits 31.1 and 31.2 on every Form 10-K and 10-Q. Section 906 adds a separate criminal certification under 18 U.S.C. § 1350, filed as Exhibits 32.1 and 32.2, carrying fines up to $1 million and ten years for a knowing false certification, and up to $5 million and twenty years for a willful one.
Section 404(a) is management’s annual report on internal control over financial reporting. Management has to state its responsibility for ICFR, identify the framework used to evaluate it, in practice, the COSO 2013 Internal Control, Integrated Framework in nearly every filing you will ever read, and give a conclusion on whether ICFR was effective as of the fiscal year end. If it wasn’t, management has to say so and describe the material weakness. This appears in Item 9A of the 10-K.
Section 404(b) is the auditor’s attestation on that same internal control. The registered public accounting firm performs an integrated audit under PCAOB Auditing Standard 2201 and issues its own opinion on ICFR effectiveness, separate from its opinion on the financial statements. This is where the cost lives.
The practical difference: 302 is a statement about the report, made every quarter. 404(a) is a statement about the control system, made once a year. 404(b) is somebody else checking your 404(a) answer, and only some companies have to buy it.
Who Is Actually in Scope
SOX applies to issuers, companies with securities registered under Section 12 of the Exchange Act or required to file under Section 15(d). That includes foreign private issuers filing Form 20-F. It generally does not include private companies, with two exceptions worth knowing: Section 802’s record-destruction provisions and Section 1107’s anti-retaliation provisions apply to everyone, private or public. A private company with registered public debt is an issuer even though nobody trades its stock.
For issuers, the scope question turns on filer status, which is measured by public float on the last business day of the most recently completed second fiscal quarter:
A large accelerated filer has public float of $700 million or more. An accelerated filer has float of $75 million or more but under $700 million, has been reporting for at least twelve months, and has filed at least one annual report. A non-accelerated filer is everything else. Filing deadlines follow the same ladder: the 10-K is due in 60, 75, or 90 days respectively, and the 10-Q in 40, 40, or 45 days.
Section 404(a) applies to all of them, after the newly public transition described below. Section 404(b) does not. Dodd-Frank permanently exempted non-accelerated filers from the auditor attestation. The JOBS Act exempted emerging growth companies for as long as they hold that status. And in 2020 the SEC amended the accelerated filer definitions to exclude issuers that qualify as smaller reporting companies under the revenue test, broadly, annual revenues under $100 million, which pulled a meaningful group of small public companies out of 404(b) entirely.
An emerging growth company is one with total annual gross revenues below an inflation-indexed cap, most recently set in the neighborhood of $1.235 billion; confirm the current figure with the SEC before relying on it. EGC status runs for up to five fiscal years after the IPO and ends early if the company exceeds the revenue cap, becomes a large accelerated filer, or issues more than $1 billion of non-convertible debt in a three-year period. Filings across all of these categories are searchable on EDGAR, which is the fastest way to see how a comparable company worded its Item 9A.
The Post-IPO Transition Nobody Budgets For
Here’s the part that surprises newly public CFOs. A company does not have to include management’s report on internal control over financial reporting in its first annual report after going public. That first 10-K carries the Section 302 certifications, those start immediately, with the first periodic report, but Item 9A can state that the annual report does not include a management report on ICFR because of a transition period established by SEC rules for newly public companies.
So the clock looks roughly like this. Year zero: IPO. First 10-K: 302 certifications, disclosure controls evaluation, no 404(a) management report. Second 10-K: 404(a) management assessment required. 404(b) auditor attestation required only if the company is by then an accelerated or large accelerated filer and is no longer an EGC, which, for most companies that IPO’d below the revenue cap, means it can be deferred until EGC status lapses at the end of the fifth fiscal year, or earlier if float crosses $700 million and the company becomes a large accelerated filer.
That gap is where companies get hurt. Management reads “no 404(a) report required in year one” as “SOX starts later” and defers building the program. Then the second-year assessment arrives with no documented process narratives, no control matrix, no evidence retention, and no history of operating effectiveness, and a control that has only operated twice cannot be tested for a full year. The work that should have started at the IPO gets compressed into two quarters, done by consultants at premium rates, under a deadline that cannot move.
The de-SPAC path is worse. A company merging into an already-public shell inherits that shell’s filer status and reporting history, sometimes landing at a full 404(a) requirement far sooner than a traditional IPO would have. The wave of material weakness disclosures in de-SPAC 10-Ks was not a coincidence; it was a scoping surprise. If a public transaction is on your horizon, the readiness work belongs alongside the rest of the preparation described in our guide to what an IPO involves.
The Control Types That Make Up a SOX Program
AS 2201 directs a top-down, risk-based approach: start at the financial statements, identify material accounts and disclosures, work down to the relevant assertions, then to the processes and controls that address the risk of material misstatement. You are not documenting everything the company does. You are documenting what could make the financial statements materially wrong.
Entity-level controls sit above the processes: the control environment, the audit committee’s oversight, the code of conduct, the whistleblower hotline, risk assessment, and management’s monitoring activities. Strong entity-level controls can reduce the testing needed at the process level; weak ones expand it.
Process-level controls are the transactional ones inside revenue, procure-to-pay, payroll, inventory, treasury, and financial close. Three-way match. Credit approval. Bank reconciliation review. Journal entry approval above a threshold. Each gets documented with a description, a frequency, an owner, and the evidence it produces.
IT general controls are the foundation everything automated rests on, and they’re where first-year programs fail most often. Four domains: access to programs and data (provisioning, terminations, periodic access reviews, privileged accounts), program change management (change requests, testing, approval, segregation between developer and production), program development, and computer operations (job scheduling, backup, incident handling). If ITGCs are deficient, every automated control and every system-generated report that depends on those systems becomes unreliable, which is how one weak access review turns into a material weakness across three cycles.
Management review controls are the reviews a human performs, the CFO reviewing the flux analysis, the controller reviewing the reserve calculation. Auditors scrutinize these harder than anything else, because “I reviewed it” is not a control. What was the review threshold, what did the reviewer do when something exceeded it, and where is the evidence of the follow-up?
Information produced by the entity is the quiet killer. If a control relies on a report, the completeness and accuracy of that report has to be established too. An aging report pulled from a system nobody validated is not audit evidence.
Deficiency, Significant Deficiency, Material Weakness
These three terms carry very different consequences and get used loosely in hallway conversation, which causes real problems in an audit committee meeting.
A control deficiency exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis. Design deficiency: the control wouldn’t catch the error even if performed perfectly. Operating deficiency: the control is well designed but wasn’t performed, or was performed by someone without the authority or competence to do it.
A significant deficiency is a deficiency, or combination of deficiencies, less severe than a material weakness yet important enough to merit attention by those responsible for oversight of financial reporting. It must be communicated to the audit committee. It does not have to be disclosed publicly and does not by itself make ICFR ineffective.
A material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis. One material weakness means ICFR is not effective, full stop. Management must say so in Item 9A, describe the weakness, and describe the remediation plan. If 404(b) applies, the auditor issues an adverse opinion on internal control.
Two things about that definition trip people up. First, the threshold is “reasonable possibility,” not probability. The bar is lower than most managers assume. Second, an actual misstatement is not required. A control gap severe enough to permit a material error is a material weakness even if the numbers happened to come out right. Conversely, a restatement almost always implies at least one material weakness, because the misstatement got through.
Remediation takes time by design. Fixing a control in November does not make it effective at December 31, because effectiveness is judged on whether the control operated over a sufficient period. A control that runs monthly usually needs several months of clean operation and a fresh test before the auditor will conclude it works. That is why a material weakness identified in Q4 typically stays disclosed through at least one more annual report.
The Sections Beyond 302 and 404
The rest of the Act shapes governance in ways that show up in policy manuals rather than control matrices, and they are enforceable.
Section 301 requires each audit committee member to be independent, gives the committee direct responsibility for appointing, compensating, and overseeing the auditor, and requires procedures for receiving confidential, anonymous employee complaints about accounting or auditing matters, the hotline. Section 407 requires disclosure of whether the audit committee has a financial expert, and if not, why not. Section 201 bars the auditor from providing a list of non-audit services to an audit client, including bookkeeping, financial information systems design, appraisal and valuation, actuarial services, internal audit outsourcing, and management functions. Section 203 requires rotation of the lead and concurring audit partners every five years.
Section 402 prohibits personal loans to directors and executive officers, which is why executive relocation arrangements get structured so carefully. Section 802 makes knowing destruction or alteration of records to obstruct an investigation a federal crime under 18 U.S.C. § 1519, with up to twenty years, and sets an auditor workpaper retention floor that SEC Rule 2-06 of Regulation S-X extended to seven years. Section 806 protects employees of public companies who report suspected securities fraud from retaliation, with complaints filed through the Occupational Safety and Health Administration at the Department of Labor within 180 days.
Section 304 requires the CEO and CFO to reimburse the company for bonuses and incentive-based compensation received in the twelve months following a filing that later required restatement due to misconduct. Dodd-Frank went further: exchange listing standards adopted under Exchange Act Rule 10D-1 now require listed issuers to maintain a clawback policy recovering erroneously awarded incentive compensation over a three-year lookback after a restatement, with no misconduct required at all. That is a meaningful expansion, under SOX 304 an honest mistake left the executive’s bonus alone; under the listing standards it does not.
This guide is general information, not legal, accounting, or securities advice, and it can’t account for your filer status, your exchange listing, your fiscal year, or the specific facts of your control environment. Filer thresholds, EGC revenue caps, and PCAOB standards change, and the consequences of getting scope wrong fall on individuals who signed a certification. Before you conclude that a provision does or does not apply to your company, consult a licensed CPA and securities counsel who can review your actual filings and facts. No one can promise a clean opinion or a particular regulatory outcome, and you should be skeptical of anyone who does.
Related Services from The Reed Corporation
Helpful Guides You Might Also Like
Sources & References
Frequently Asked Questions
What does SOX compliance require, and which companies actually have to comply?
SOX compliance is shorthand for a set of obligations the Sarbanes-Oxley Act of 2002 imposed on issuers, and the honest starting point is that most of what people call SOX is really two sections out of a much longer statute. The full text on sec.gov runs to eleven titles covering audit oversight, auditor independence, corporate responsibility, financial disclosures, analyst conflicts, criminal penalties, and more. What a finance team lives with day to day is Section 302, Section 404, and the governance requirements around the audit committee.
Scope first, because it decides everything else. SOX applies to issuers: companies with a class of securities registered under Section 12 of the Securities Exchange Act, or required to file reports under Section 15(d). That captures every company listed on the New York Stock Exchange or Nasdaq, foreign private issuers filing Form 20-F, and, this one surprises people, private companies that registered public debt. A family-owned manufacturer with no public stock but a registered bond issue is an issuer and files the same certifications as anyone else.
Private companies with no registered securities are outside the reporting requirements, but not outside the Act entirely. Section 802’s criminal provisions on destroying or altering records to obstruct a federal investigation apply to any person, and Section 1107’s prohibition on retaliating against someone who gives truthful information to law enforcement applies broadly as well. Beyond that, private companies encounter SOX indirectly all the time: as an acquisition target being diligenced by a public buyer that will have to consolidate you into its own ICFR assertion, as a service organization whose customers need a SOC 1 report on your controls, or as a company two years from a public transaction.
For issuers, the depth of the requirement scales with filer status, which is set by public float measured on the last business day of the second fiscal quarter. Large accelerated filers have float of $700 million or more and file the 10-K within 60 days of year end. Accelerated filers have float from $75 million up to $700 million and file within 75 days. Non-accelerated filers file within 90 days. The SEC’s 2020 amendments added an important carve-out: an issuer that qualifies as a smaller reporting company under the revenue test, broadly, annual revenues under $100 million, is excluded from accelerated filer status even if its float would otherwise qualify.
What each category owes looks like this. Section 302 certifications: everyone, every quarterly and annual report, from the first periodic report after going public. Section 404(a) management assessment of internal control: everyone, starting with the second annual report after the IPO. Section 404(b) auditor attestation on internal control: only accelerated and large accelerated filers that are not emerging growth companies. Non-accelerated filers are permanently exempt under a Dodd-Frank amendment, and EGCs are exempt for the duration of their EGC status under the JOBS Act.
Work an example. A company IPOs in March with a $410 million public float and $140 million of revenue. It’s an EGC because revenue is far below the indexed cap. Its first 10-K includes the Exhibit 31 certifications and a disclosure controls conclusion, and states in Item 9A that no management report on ICFR is included under the transition available to newly public companies. Its second 10-K includes a full 404(a) management assessment. Because it is an EGC, no auditor attestation. In year four the float climbs to $940 million as of the June measurement date, making it a large accelerated filer, which terminates EGC status immediately, so for that fiscal year it must produce both the 404(a) assessment and a 404(b) auditor attestation, on a 60-day filing deadline instead of 75. A company that had budgeted roughly $250,000 a year for internal SOX resources is now looking at incremental audit fees frequently in the $400,000 to $900,000 range for the integrated audit, plus additional internal and consulting hours, in a year when the deadline also shortened by fifteen days. That transition is knowable eighteen months in advance and is still missed constantly.
The most common scoping mistake is assuming SOX compliance begins when the auditor starts asking. It begins with the certification, and the certification begins with the first periodic report. A CEO who signs an Exhibit 31 certification in the first quarter after an IPO has personally represented that disclosure controls and procedures were evaluated and that any material weaknesses were disclosed to the auditor and audit committee. If no evaluation actually occurred, that certification is a problem independent of anything in Section 404.
A second mistake is treating filer status as static. Float moves with the stock price and with secondary offerings, and it is measured on one specific day each year. Companies drift into accelerated filer status without noticing, then discover in the fourth quarter that an attestation is required for a year that is nearly over. Put the measurement date on the finance calendar and run the calculation the week it happens.
A third is forgetting that outsourced processes stay in scope. Payroll processors, equity administrators, revenue platforms, and cloud hosting providers all sit inside the control environment. Management remains responsible, and the usual evidence is a SOC 1 Type 2 report from the provider plus documented testing of the complementary user entity controls that report assumes you perform. Our guide to SOC reports covers how those fit together, and it is a routine first-year gap: the company obtains the report, files it, and never tests the controls the report says are its responsibility.
Where this is going: the direction of policy over the past fifteen years has been to narrow 404(b) rather than expand it, through the Dodd-Frank exemption, the JOBS Act, and the 2020 accelerated filer amendments. Section 302 and 404(a) have not narrowed at all, and enforcement attention on certifications and on disclosure of known material weaknesses has been steady. If you are planning a public transaction, build the program to satisfy 404(a) from day one and treat 404(b) as a later, more expensive layer. The documentation, the evidence retention, and the operating history are the same work either way. The only thing that changes is who else reads it.
What is the difference between SOX 302, 404(a), and 404(b)?
Different obligations, different frequencies, different signers, different costs. Getting them straight is most of what separates a company with a functioning SOX compliance program from one that is improvising.
Section 302 is a personal certification about a specific filing. It is signed by the principal executive officer and the principal financial officer and attached to every 10-Q and 10-K as Exhibits 31.1 and 31.2. The certifying officers state that they reviewed the report; that based on their knowledge it contains no untrue statement of material fact and omits no material fact necessary to make the statements not misleading; that the financial statements and other financial information fairly present in all material respects the financial condition, results of operations, and cash flows; that they are responsible for establishing and maintaining disclosure controls and procedures and internal control over financial reporting; that they designed those controls or supervised their design; that they evaluated the effectiveness of disclosure controls and presented conclusions as of period end; that they disclosed any change in ICFR during the quarter that materially affected it; and that they disclosed to the auditor and the audit committee all significant deficiencies and material weaknesses and any fraud involving management or employees with a significant role in ICFR.
Two distinctions inside 302 get muddled. Disclosure controls and procedures are broader than ICFR. They cover everything that goes into a filing, including non-financial disclosures like legal proceedings and risk factors, and they are evaluated every quarter. ICFR is specifically about the reliability of financial reporting and the preparation of statements under GAAP, and its effectiveness is formally assessed annually. A company can have effective ICFR and deficient disclosure controls, though in practice a material weakness in ICFR almost always drags the disclosure controls conclusion down with it.
Section 906 is the criminal cousin, filed as Exhibits 32.1 and 32.2 under 18 U.S.C. § 1350. It’s shorter, it’s furnished rather than filed, and it carries direct criminal exposure: up to $1 million and ten years for knowingly certifying a report that does not comply, up to $5 million and twenty years for doing so willfully.
Section 404(a) is management’s annual opinion on the control system itself. It appears in Item 9A of the Form 10-K. Management states its responsibility for establishing and maintaining ICFR, identifies the framework used, essentially always the COSO 2013 Internal Control, Integrated Framework and its five components and seventeen principles, and concludes whether ICFR was effective as of the last day of the fiscal year. Note the “as of” language. This is a point-in-time conclusion, not a statement about the whole year, which is why a control fixed in October can still support an effective conclusion at December 31 if it has operated long enough to be tested.
Producing that conclusion requires real work: scoping material accounts by quantitative and qualitative risk, documenting processes, identifying key controls, testing design and operating effectiveness with sample sizes appropriate to control frequency, evaluating exceptions, and aggregating deficiencies to decide whether any rise to a material weakness. Annual controls might be tested with a sample of one; daily controls commonly require samples in the twenties or beyond.
Section 404(b) is the auditor’s separate opinion on ICFR. The audit firm performs an integrated audit under PCAOB AS 2201, applying a top-down risk-based approach: begin at the financial statement level, identify entity-level controls, work down to significant accounts and disclosures and their relevant assertions, then to the processes and specific controls that address the risk of material misstatement. The auditor does its own testing. It may rely to some degree on management’s work depending on competence, objectivity, and the risk associated with the control, but it cannot simply accept management’s conclusion. The output is a distinct opinion paragraph on internal control alongside the financial statement opinion.
Costs separate sharply here. A 404(a)-only program at a mid-size issuer is largely internal effort plus perhaps a consultant: often somewhere between $150,000 and $400,000 a year fully loaded. Adding 404(b) typically adds several hundred thousand dollars of incremental audit fees, tightens documentation standards considerably, and lengthens the year-end calendar. A company moving from 404(a) to 404(b) should expect its total controls cost to roughly double, and should expect the auditor to reject evidence that management had been comfortable with, screenshots without dates, approvals by email without a documented threshold, reports whose completeness was never validated.
Worked example: a Nasdaq-listed company with $180 million of revenue crosses $700 million of float in June of year four. Its EGC status ends immediately, it becomes a large accelerated filer, and both the 404(b) attestation and a 60-day 10-K deadline apply for that fiscal year. Management had been testing 42 key controls internally with two staff. The auditor scopes 71 key controls, requires ITGC testing across three systems that had never been examined, and finds that access reviews for the ERP were performed but not evidenced. Incremental audit fees come in around $610,000, outside consulting to remediate ITGCs runs $220,000, and the company adds an internal SOX manager at roughly $175,000 loaded. That is more than a million dollars of new annual cost, arriving in a year the finance team also lost fifteen days of close calendar.
The most common mistake is treating the 302 certification as a formality that the legal team assembles. It is a personal representation by two individuals, made quarterly, and it explicitly covers whether known deficiencies were communicated. The right practice is a documented sub-certification process: business and functional leaders sign representations upward each quarter, disclosure committee meets, issues get logged and resolved, and the officers sign on the strength of that record. Companies that skip it are asking two executives to certify facts they have no systematic way of knowing.
A second mistake is confusing an effective 404(a) conclusion with an absence of problems. Significant deficiencies do not make ICFR ineffective and are not publicly disclosed, but they must be communicated to the audit committee, and an accumulation of them across related processes can aggregate into a material weakness. Track them formally; the aggregation analysis is the part auditors challenge hardest.
Looking forward, expect continued attention to the quality of management review controls and to information produced by the entity, both of which have driven a large share of recent inspection findings. Companies that build evidence discipline early, dated, retained, reperformable, carry that advantage into every subsequent year, including the year 404(b) finally applies. We help finance teams put that discipline into the close calendar through client accounting services before an auditor is the one asking.
When does a newly public company have to comply with SOX 404?
Later than the certifications, sooner than most teams plan for, and the gap between those two facts is where newly public companies get into trouble with SOX compliance.
Start with what applies immediately. Section 302 certifications begin with the first periodic report filed after the registration statement goes effective. The CEO and CFO sign Exhibits 31.1 and 31.2 saying they evaluated disclosure controls and procedures as of period end and disclosed any material weaknesses and any fraud involving management to the auditor and audit committee. There is no transition relief for that. A company that IPOs in March files a Form 10-Q for the June quarter carrying full certifications.
Now the relief. A newly public company is not required to include management’s annual report on internal control over financial reporting in its first annual report filed after the offering. Item 9A of that first 10-K typically states that the annual report does not include a management report on ICFR because of the transition period established by SEC rules for newly public companies. The auditor’s attestation is likewise not required for that first annual report.
From the second annual report forward, Section 404(a) applies in full: management scopes, documents, tests, and concludes on ICFR effectiveness, and publishes that conclusion. Whether 404(b) applies depends on filer status and EGC status. An emerging growth company is exempt from the auditor attestation for as long as it holds that status, up to five fiscal years after the IPO, ending sooner if annual gross revenues exceed the inflation-indexed cap (most recently around $1.235 billion, though you should confirm the current figure), if the company becomes a large accelerated filer, or if it issues more than $1 billion of non-convertible debt over three years. A non-accelerated filer is permanently exempt from 404(b) regardless of EGC status.
Here is the timeline for a calendar-year company that IPOs in May of Year 1. Second-quarter and third-quarter 10-Qs in Year 1: certifications only. The Year 1 10-K, filed in early Year 2: certifications, disclosure controls conclusion, no management ICFR report. Year 2 10-K, filed in early Year 3: full 404(a) management assessment. That means the assessment covers ICFR as of December 31 of Year 2, roughly nineteen months after the IPO, and the controls being tested must have been operating throughout Year 2. Practically, the program has to be designed and running by January of Year 2, which is about seven months after the bell.
Almost nobody builds it that fast if they start after the IPO. Documenting processes across revenue, procure-to-pay, payroll, treasury, inventory, equity, and financial close takes months. ITGCs across the ERP, the billing system, and the equity platform take longer, because the fixes are technical: role-based access design, a change management workflow, segregation between development and production, and evidenced quarterly access reviews. A control that starts operating in September cannot support a year-long testing population by December, so first-year populations are thin and sample sizes are constrained.
Cost example. A software company IPOs in May of Year 1 with $95 million of revenue. Readiness work begun six months before the IPO, process documentation, a control matrix of about 60 key controls, ITGC remediation on two systems, and a dry-run test cycle, costs roughly $380,000 in consulting plus internal time, spread over three quarters. The same company starting in January of Year 2 compresses that into two quarters at rush rates, typically $550,000 to $700,000, and still enters the Year 2 assessment with several controls that have only operated for part of the year. The second company is materially more likely to report a material weakness in its Year 2 Item 9A, which is a disclosure that follows the company through at least one more annual report because remediation has to operate and be tested before it can be called effective.
The de-SPAC route deserves its own warning. A private company merging into an already-public shell inherits that entity’s reporting history and filer status. Depending on the shell’s history, the combined company can face a 404(a) requirement in its first annual report after closing rather than the second, and the private-side finance team, often three or four people with no public reporting experience, has weeks rather than quarters. The volume of material weakness disclosures across de-SPAC filings reflects exactly that compression, and you can read dozens of real examples by searching Item 9A language on EDGAR.
The most damaging mistake is reading the first-year relief as permission to defer the work. It is relief from publishing a conclusion, not relief from having controls. The certifications still require an evaluation, the auditor is still auditing the financial statements and will still report deficiencies it encounters, and the second-year assessment tests a full year of operation. Treat the first year as a build year with a dry run in the second half, not as a year off.
Two more errors show up repeatedly. The first is under-resourcing the tax provision. Income tax accounting is the single most frequent source of material weaknesses at newly public companies, because the calculation is complex, the reviewer is often the same person who prepared it, and the outside provider’s work gets accepted without independent review. Our guide to ASC 740 covers why the provision is so error-prone. The second is ignoring service organizations. Payroll, equity administration, revenue platforms, and hosting all sit inside the control environment, and management stays responsible. Obtain the SOC 1 Type 2 report, read the complementary user entity controls it assumes you perform, and test them. That last step is skipped constantly.
Looking ahead, plan the SOX calendar backward from the second annual report and put three dates on it: the month the control matrix must be final, the month a dry-run test cycle must be complete, and the float measurement date each June that determines filer status. Companies that hold those three dates almost never end up with a surprise. Companies that discover them in October almost always do.
What is the difference between a control deficiency, a significant deficiency, and a material weakness?
Severity, and severity drives consequence. Under a SOX compliance program these three terms have defined meanings, and the one you land on determines whether an issue is a note in a tracker, a private communication to the audit committee, or a public disclosure that your internal control is not effective.
A control deficiency exists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis. Deficiencies split into two kinds. A design deficiency means the control, even if performed exactly as intended, would not catch the misstatement, a review that never compares against an independent source, or a threshold set so high the errors that matter pass under it. An operating deficiency means the design is sound but execution failed: the control wasn’t performed, was performed late, was performed by someone without the competence or authority to do it, or was performed without evidence.
A significant deficiency is a deficiency, or a combination of deficiencies, in internal control over financial reporting that is less severe than a material weakness yet important enough to merit attention by those responsible for oversight of the company’s financial reporting. It must be communicated in writing to the audit committee. It does not require public disclosure, and by itself it does not make ICFR ineffective.
A material weakness is a deficiency, or a combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the company’s annual or interim financial statements will not be prevented or detected on a timely basis. One is enough to make ICFR ineffective. Management must disclose it in Item 9A, describe its nature, and describe the remediation plan. Where 404(b) applies, the auditor issues an adverse opinion on internal control. The definitions come from PCAOB AS 2201, and reading the standard’s own words is worth ten minutes.
Two features of the material weakness definition consistently surprise management. First, the threshold is “reasonable possibility,” which is a lower bar than “probable.” Second, no actual misstatement is required. If a gap could have permitted a material error, it is a material weakness even if the financial statements turned out correct. Running the other way, a restatement almost always implies a material weakness, because by definition a material error got through the controls.
Evaluating severity involves two questions. What is the magnitude of the potential misstatement, considering the size of the account and the transactions exposed? And what is the likelihood that the control’s failure would fail to be caught by anything else, is there a compensating control that operates at a level of precision sufficient to detect a material error? Precision is the word that carries the weight. A monthly budget-to-actual review with a $500,000 investigation threshold does not compensate for a revenue control when materiality is $900,000; it does when materiality is $4 million.
Worked example. A company with $240 million of revenue sets planning materiality at $2.4 million. Testing of the quarterly access review over the ERP finds that two of four quarters were performed but never evidenced, and one terminated employee retained journal entry access for 47 days. Standing alone, magnitude is unclear, nobody posted anything improper, but the exposure is any journal entry, which touches every account. Now add a second finding: the journal entry approval control has a $250,000 threshold, and testing shows six of forty sampled entries above that threshold were posted without documented approval. Individually each might be a significant deficiency. Together, an access failure combined with an approval failure over the same journal entry process means a material misstatement could be posted and not detected. That aggregation is a material weakness, and management discloses it in Item 9A with a remediation plan: automated access provisioning tied to the HR termination feed, quarterly reviews with retained evidence, a system-enforced approval workflow, and a monthly reconciliation of posted entries to approvals.
Remediation timing is where expectations break. Fixing a control in November does not produce an effective conclusion at December 31, because the auditor and management must conclude the control operated effectively for a sufficient period. A quarterly control needs at least a couple of clean cycles; a monthly control usually needs several months plus a fresh test. A material weakness identified late in the year therefore normally remains disclosed in the following year’s first quarter and often through the next 10-K. Companies that promise the audit committee a one-quarter fix are usually promising something the standard does not permit.
The most common mistakes in this area are procedural rather than technical. First, arguing about labels instead of fixing the control, weeks spent negotiating whether something is significant or material, while the underlying gap keeps operating. Second, failing to aggregate. Deficiencies are evaluated individually and in combination, and companies routinely log twelve “minor” issues across the close process without ever performing the combination analysis the standard requires. Third, treating evidence as optional. An unevidenced control is an untestable control, and an untestable control is a deficiency regardless of whether the work actually happened. Fourth, over-relying on a management review control described in one sentence. If the documentation does not state what was compared, what threshold triggered investigation, and what happened when it did, the auditor cannot conclude the control operates at sufficient precision.
The disclosure consequences are real but frequently overstated in the room. Markets have grown used to first-year material weaknesses at newly public companies, and a clearly written Item 9A with a dated remediation plan and named ownership reads as competence. What actually damages a company is a surprise: an Item 4.02 Form 8-K announcing that previously issued financial statements can no longer be relied upon, after two years of clean assertions. The certification the officers signed was never a claim of perfection. It was a claim of honesty about what management knew.
Where this heads: inspection findings keep concentrating on management review controls and on the completeness and accuracy of information produced by the entity, so expect scrutiny of report validation and review precision to keep rising. The practical response is unglamorous. Write control descriptions that state the source, the comparison, the threshold, and the follow-up. Retain dated evidence. Run the aggregation analysis every quarter rather than once at year end. Teams that do those three things spend far less time arguing about severity, because far fewer issues reach the point where the argument matters. We help finance groups build that documentation discipline into the monthly close through business management support.
How much does SOX compliance cost, and what does a first-year program look like?
Cost tracks three things: the number of key controls, the number of systems in scope, and whether an auditor has to issue an opinion on your controls. Everything else is detail. A realistic SOX compliance budget is built from those three variables rather than from a benchmark someone quoted at a conference.
Take the ranges honestly. A non-accelerated filer running 404(a) only, with one ERP and a straightforward revenue model, can hold total incremental cost, internal time, a consultant for documentation and testing, and modest audit fee uplift, somewhere in the $150,000 to $350,000 a year band. An accelerated filer subject to 404(b) with two or three in-scope systems is commonly in the $600,000 to $1.5 million range once incremental audit fees, a dedicated internal resource or two, co-sourced testing, and remediation are included. A large accelerated filer with multiple entities, foreign operations, and a dozen systems runs well beyond that. First year always costs more than steady state, typically 1.5x to 2x, because documentation, control design, and ITGC remediation are one-time builds.
Where the money goes, roughly: incremental external audit fees for the integrated audit are usually the single largest line where 404(b) applies; internal headcount is next; co-sourced or outsourced testing follows; then remediation projects, which are lumpy and technical and land mostly in IT; then software, which is the smallest line and the one companies over-buy first.
A worked first-year plan for a company that just went public with $120 million of revenue, one ERP, a separate billing system, an equity administration platform, and an outsourced payroll provider:
Quarter 1, scoping and planning. Set planning materiality, identify significant accounts and disclosures using quantitative thresholds and qualitative risk, map processes to accounts, and inventory systems. Output is a scoping memo and a preliminary process list. Roughly 200 hours of internal time plus $40,000 of advisory support.
Quarter 2, documentation. Write process narratives and flowcharts for order-to-cash, procure-to-pay, payroll, treasury, equity, income tax, and financial close. Build a risk-and-control matrix identifying key controls and mapping each to a risk and an assertion. Expect 55 to 80 key controls at this size; anything over 120 usually means the scoping was too broad and someone documented activities rather than controls. Roughly $110,000 of advisory plus heavy internal involvement from process owners.
Quarter 3, design assessment and ITGC remediation. Walk through each control, assess whether the design would actually catch a material error, and fix what wouldn’t. Then the hard part: IT general controls across the ERP and billing system. Role-based access redesign, a documented change management workflow with segregation between development and production, and quarterly user access reviews with retained evidence. ITGC remediation is where first-year budgets break, commonly $150,000 to $300,000 including internal IT time, because the fixes are configuration and process changes rather than documentation.
Quarter 4, testing and dry run. Test operating effectiveness with sample sizes matched to frequency. Annual controls may be a sample of one; quarterly, two; monthly, three to five; weekly, into the teens; daily, into the twenties or higher. Evaluate exceptions, perform the aggregation analysis, and draft the Item 9A conclusion. Roughly $90,000 of co-sourced testing plus internal review.
All in, that program lands near $400,000 to $500,000 in the first year, of which perhaps $250,000 recurs. Doing the same work in two rushed quarters instead of four routinely costs 40% more and produces a thinner testing population, which raises the odds of a first-year material weakness. A disclosure that carries into at least one more annual report because remediation must operate and be retested before it can be called effective.
The most expensive mistake is buying software first. Controls management platforms are useful once you have a stable control matrix and a repeatable testing calendar. Purchased before that, they become an expensive place to store an undecided process, and companies spend implementation dollars configuring workflows they later rewrite. Get the matrix right in a spreadsheet, run one full cycle, then automate what proved stable.
The second most expensive mistake is over-scoping. Teams anxious about the auditor document every activity in the finance department and end up with 200 “key” controls, each of which must be tested annually, evidenced, and defended. Every unnecessary control has a recurring cost in testing hours and a recurring risk of an exception. The top-down, risk-based approach in PCAOB AS 2201 exists precisely to prevent this: start at the financial statements, work down to what could make them materially wrong, and stop.
Third, companies under-scope the tax provision and over-rely on their outside preparer. Income tax accounting is a persistent source of material weaknesses, and “our tax firm prepares it” is not a control, someone inside the company with sufficient competence must review the calculation, understand the significant judgments, and evidence that review. The same logic applies to any outsourced process, including the payroll provider and the equity administrator, where a SOC 1 Type 2 report has to be obtained, read, and paired with documented testing of the complementary user entity controls it assumes you perform. Our guide to SOC reports walks through that relationship.
Fourth, evidence hygiene. Undated screenshots, approvals in email threads with no stated threshold, and reports whose completeness was never validated are the three findings that consume the most audit time at first-year companies. Fixing evidence standards costs almost nothing in Q1 and costs a great deal in Q4.
Looking ahead, budget for the transitions rather than the steady state. The float measurement date each June determines filer status; crossing $700 million converts a company to a large accelerated filer, ends EGC status immediately, triggers 404(b), and shortens the 10-K deadline to 60 days all in the same year. That is the single largest cost step-change in a public company’s life, and it is knowable a year in advance from the stock price. Model it, staff for it before it arrives, and you convert a crisis into a line item. Filings from comparable companies on EDGAR and the reporting requirements set out in the Act itself are free reference material for exactly that planning.