J-SOX Compliance: Internal Control Documentation for Japanese Listed Companies
J-SOX requires TSE-listed companies to assess and report on internal controls over financial reporting. Here's what documentation is required, the 2023 reform changes, and how to review before audit.
Japan's internal control reporting system — commonly known as J-SOX — requires all listed companies on the Tokyo Stock Exchange to assess the effectiveness of internal controls over financial reporting (ICFR) and have that assessment audited by external auditors. With approximately 3,800 TSE-listed companies subject to these requirements, J-SOX is one of the most widely applied internal control frameworks in the world.
The 2023 J-SOX reform — the most significant revision since the framework's introduction in 2008 — expanded the scope of assessment, strengthened IT controls requirements, and enhanced governance expectations. Companies that maintained documentation sufficient for the original J-SOX framework now face gaps under the revised standards.
J-SOX Framework Overview
Comparison with US SOX
| Aspect | J-SOX | US SOX |
|---|---|---|
| Framework basis | COSO (with Japan-specific modifications) | COSO |
| Scope | ICFR assessment, with expanded 2023 scope | ICFR assessment (Section 404) |
| Components | 6 components (adds IT controls as separate component) | 5 components |
| Assessment approach | Top-down, risk-based | Top-down, risk-based |
| Auditor requirement | External audit of management's assessment | External audit of management's assessment |
| Reporting | Internal control report filed with securities report | Management assessment + auditor attestation |
J-SOX Six Components
J-SOX explicitly separates IT controls as a sixth component (US COSO integrates IT within the five components):
| Component | Documentation Focus |
|---|---|
| 1. Control environment | Organisational culture, integrity, board oversight, management philosophy |
| 2. Risk assessment | Risk identification, assessment of likelihood and impact, risk response |
| 3. Control activities | Policies, procedures, approvals, reconciliations, segregation of duties |
| 4. Information and communication | Information systems, internal and external communication channels |
| 5. Monitoring | Ongoing monitoring, separate evaluations, reporting of deficiencies |
| 6. IT controls | IT general controls, IT application controls, IT governance |
Required J-SOX Documentation
1. Entity-Level Controls Documentation
Entity-level controls apply across the entire organisation:
| Document | Requirement |
|---|---|
| Control environment assessment | Board and management commitment to integrity, competence standards, organisational structure |
| Risk assessment process | How the company identifies and assesses risks to financial reporting |
| Information and communication | Financial reporting information systems, communication of policies |
| Monitoring activities | Ongoing and periodic monitoring of internal controls |
| IT governance | Board and management oversight of IT that supports financial reporting |
2. Process-Level Controls Documentation
For each significant process, document:
| Document | Requirement |
|---|---|
| Process flowcharts | Visual representation of the process from initiation to recording |
| Process narratives | Written description of the process, roles, systems, and controls |
| Risk-control matrices (RCMs) | Mapping of risks to specific controls, with control descriptions |
| Control descriptions | For each key control: what, who, when, how, evidence |
| Key control identification | Which controls are key controls that must be tested |
Significant processes typically include:
- Revenue and receivables
- Procurement and payables
- Inventory and cost of goods sold
- Fixed assets
- Financial close and reporting
- Treasury and investments
- Payroll
- Tax
3. IT Controls Documentation
The 2023 reform strengthened IT controls requirements:
IT General Controls (ITGCs)
| Control Area | Documentation Required |
|---|---|
| Programme development | System development lifecycle documentation, testing, approval |
| Programme change management | Change request, approval, testing, implementation records |
| Computer operations | Job scheduling, monitoring, incident management |
| Access security | Access provisioning, authentication, periodic review, segregation |
| Data management | Backup, recovery, data integrity controls |
IT Application Controls
| Control Type | Documentation Required |
|---|---|
| Input controls | Validation, completeness checks, authorisation |
| Processing controls | Calculation accuracy, data matching, exception handling |
| Output controls | Completeness, accuracy, distribution |
| Interface controls | Data transfer between systems — reconciliation, error handling |
IT Governance (2023 Enhancement)
| Document | Requirement |
|---|---|
| IT strategy alignment | IT strategy documented and aligned with business strategy |
| IT risk management | IT risks identified, assessed, and managed |
| Cybersecurity framework | Security controls documented and monitored |
| Third-party IT management | Oversight of IT service providers, cloud services |
| IT change governance | Board/management oversight of significant IT changes |
4. Testing Documentation
| Document | Requirement |
|---|---|
| Test plan | Scope, approach, timing, sample sizes |
| Test procedures | Step-by-step testing procedures for each key control |
| Test results | Evidence of testing performed, results, exceptions identified |
| Sample selection | Methodology and documentation of sample selection |
| Walkthrough documentation | End-to-end walkthroughs of significant processes |
| Roll-forward testing | For controls tested before year-end — evidence of continued operation |
5. Deficiency Assessment Documentation
| Document | Requirement |
|---|---|
| Deficiency identification | All control deficiencies identified during assessment |
| Deficiency classification | Classification as deficiency, significant deficiency, or material weakness |
| Quantitative assessment | Potential misstatement amount for each deficiency |
| Qualitative assessment | Nature, cause, and financial reporting impact |
| Compensating controls | Any compensating controls that mitigate the deficiency |
| Remediation plan | Actions to remediate deficiencies with timelines and owners |
6. Internal Control Report
Filed with the securities report (Yukashoken Hokokusho):
| Element | Requirement |
|---|---|
| Scope of assessment | Business processes and entities assessed |
| Assessment framework | Framework used (J-SOX/COSO) |
| Assessment methodology | Top-down, risk-based approach |
| Assessment results | Whether internal controls are effective as of the assessment date |
| Material weaknesses | If any — description and remediation status |
| Subsequent events | Material changes to controls after the assessment date |
2023 J-SOX Reform: Key Changes
| Change | Impact on Documentation |
|---|---|
| Expanded scope | Broader coverage of business processes, including non-financial information that affects financial reporting |
| Enhanced IT controls | IT governance added as explicit requirement; cybersecurity documentation expected |
| Governance expectations | Stronger emphasis on board and management's role in internal controls |
| Risk assessment | More rigorous risk assessment documentation, including fraud risk |
| Group company scope | Clearer requirements for assessing controls at subsidiaries and affiliates |
| Reporting format | Enhanced internal control report with additional disclosures |
Common J-SOX Documentation Gaps
Gap 1: IT Controls Documentation Lagging Behind System Changes
IT control documentation that reflects the previous system environment rather than the current one. System upgrades, cloud migrations, and new application implementations create documentation gaps.
Gap 2: Risk-Control Matrices Not Updated
RCMs that haven't been updated to reflect process changes, organisational restructuring, or new risk factors. The 2023 reform's emphasis on fraud risk may require RCM updates.
Gap 3: Testing Documentation Quality
Test documentation that doesn't clearly evidence what was tested, how, and what was concluded. Auditors increasingly scrutinise management's testing quality.
Gap 4: Entity-Level Controls Treated as Formality
Entity-level control assessments that are generic self-assessments rather than substantive evaluations with evidence. The 2023 reform emphasises entity-level controls as foundational.
Gap 5: Group Company Assessment Gaps
Insufficient assessment of internal controls at significant subsidiaries, particularly overseas subsidiaries where documentation standards may differ.
Reviewing J-SOX Documentation
Process Documentation Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Process documentation currency | 3 | Flowcharts and narratives reflect current processes and systems |
| RCM completeness | 3 | All significant risks mapped to specific controls |
| Key control identification | 2 | Key controls identified with documented rationale |
| Control descriptions | 2 | Each control described with what, who, when, how, and evidence |
| IT controls coverage | 2 | ITGCs and application controls documented for all significant systems |
Testing Documentation Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Test plan completeness | 3 | All key controls included in test plan |
| Testing evidence quality | 3 | Clear evidence of testing performed and conclusions reached |
| Sample adequacy | 2 | Sample sizes appropriate for the control frequency and population |
| Exception documentation | 2 | All exceptions identified, investigated, and classified |
| Deficiency assessment | 2 | Deficiencies properly classified and remediation planned |
Frequently Asked Questions
Which companies must comply with J-SOX?
All companies listed on the TSE (Prime, Standard, and Growth markets) must assess and report on internal controls over financial reporting. This includes approximately 3,800 companies. Newly listed companies have a one-year grace period.
How does the 2023 reform affect existing J-SOX documentation?
The 2023 reform requires: expanded scope assessment (review scoping decisions), enhanced IT controls documentation (add IT governance, cybersecurity), stronger entity-level controls evidence, more rigorous fraud risk assessment, and enhanced internal control report disclosures. All existing documentation should be reviewed against the revised standards.
Can we use the same documentation for both J-SOX and US SOX?
For dual-listed companies, the frameworks share significant common ground (both based on COSO). However, J-SOX's explicit IT controls component and Japan-specific requirements mean documentation cannot be simply replicated. A harmonised approach that addresses both frameworks' requirements is more efficient than maintaining entirely separate documentation.
What are the consequences of reporting a material weakness?
The company must disclose the material weakness in the internal control report, describe its nature and impact, and outline remediation plans. The external auditor's report will reflect the material weakness. Market reaction — share price impact and investor confidence — is typically the most significant consequence. The JFSA may also increase supervisory attention.
Can AI review help with J-SOX documentation?
AI review can check process documentation for currency and completeness, verify RCMs map all identified risks to controls, assess testing documentation for evidence quality, and check deficiency classification consistency. Assessment of control effectiveness and internal control adequacy requires qualified internal audit and accounting professionals.
Key Takeaways
- J-SOX applies to all ~3,800 TSE-listed companies — assessment and reporting on ICFR effectiveness is mandatory.
- The 2023 reform expanded scope and strengthened IT controls — existing documentation likely has gaps under the revised standards.
- Six J-SOX components including IT controls as a separate component (unlike US COSO's five).
- Process documentation must be current — flowcharts, narratives, and RCMs reflecting actual current processes and systems.
- Testing documentation must clearly evidence what was tested, how, and what was concluded — quality is increasingly scrutinised.
- IT controls documentation is the most common gap area — particularly after system changes, cloud migrations, and new implementations.
- AI review checks currency, completeness, and consistency — control effectiveness requires qualified professional assessment.
This article is for informational purposes only. J-SOX requirements are governed by the FIEA, the Standards for Assessment and Audit of Internal Controls, and Practice Standards issued by the Business Accounting Council. Consult a qualified internal audit, accounting, or compliance professional for guidance specific to your company.