SOX Compliance Documentation: Review Requirements for Financial Reporting
SOX requires documented internal controls over financial reporting — and auditors verify the documentation, not just the controls. Here's what to document, common failures, and how to review before audit.
Sarbanes-Oxley doesn't just require internal controls over financial reporting. It requires documented internal controls — evidence that controls exist, operate effectively, and are tested. An undocumented control is, for audit purposes, a non-existent control.
SOX applies to all US-listed companies and their worldwide subsidiaries. That's approximately 5,500 SEC-reporting companies, each maintaining hundreds of pages of internal control documentation. The cost of SOX compliance averages $1.5-3.5M annually for mid-size companies — and documentation is the largest single cost driver.
SOX Documentation Requirements
Section 302: CEO/CFO Certification
The CEO and CFO must personally certify that:
- Financial statements are fairly presented
- Disclosure controls and procedures are effective
- Internal controls over financial reporting (ICFR) are effective
- Any material changes in ICFR have been disclosed
Documentation required:
- Signed certification for each quarterly and annual filing
- Evidence supporting the certification (the documentation trail that gives the CEO/CFO confidence to sign)
- Disclosure committee meeting minutes
Section 404: Internal Control Assessment
Management must assess and report on the effectiveness of ICFR. For accelerated filers, the external auditor must also attest to management's assessment.
Documentation required:
| Document | Purpose | Who Creates |
|---|---|---|
| Risk assessment | Identify significant accounts, locations, and business processes | Management (usually Internal Audit) |
| Scoping documentation | Define which controls are in scope for testing | Management |
| Process narratives/flowcharts | Describe how transactions are processed from initiation to financial statements | Process owners with Internal Audit |
| Risk and control matrices (RCMs) | Map risks to controls for each significant process | Internal Audit |
| Control descriptions | Detailed description of each control: who, what, when, how, evidence | Control owners |
| Test plans | How each control will be tested | Internal Audit |
| Test results | Evidence that controls operated effectively | Internal Audit |
| Deficiency evaluation | Assessment of any control failures: deficiency, significant deficiency, or material weakness | Management and auditors |
| Remediation plans | Actions to address identified deficiencies | Control owners |
| Management's assessment report | Formal conclusion on ICFR effectiveness | Management |
The SOX Documentation Hierarchy
Financial Statements
↑
Significant Accounts (Balance sheet / Income statement line items)
↑
Significant Processes (Revenue, procurement, payroll, treasury, etc.)
↑
Risks (What could go wrong in each process)
↑
Controls (What prevents or detects each risk)
↑
Control Documentation (Evidence that controls exist and operate)
↑
Testing (Evidence that controls were tested and found effective)
Every level must be documented. A break at any level creates a gap that auditors will identify.
Control Documentation Standards
Each control must be documented with enough detail that:
- Someone unfamiliar with the process could understand the control
- An auditor could test the control based on the description
- The control owner could perform the control consistently
The Five Elements of a Control Description
| Element | What to Document | Example |
|---|---|---|
| Who | The specific role (not person) that performs the control | "Revenue Accounting Manager" |
| What | The specific action taken | "Reviews the revenue recognition schedule for completeness and accuracy" |
| When | The frequency and timing | "Monthly, within 5 business days of month-end close" |
| How | The procedure followed | "Compares the schedule to source data (contracts, delivery confirmations, invoices), verifies calculation of revenue amounts, and checks classification against ASC 606 criteria" |
| Evidence | What artifact demonstrates the control operated | "Signed and dated revenue recognition schedule with review comments, filed in [location]" |
Weak vs Strong Control Descriptions
| Weak (Audit Risk) | Strong (Audit Ready) |
|---|---|
| "Manager reviews journal entries" | "The GL Manager reviews all manual journal entries over $50,000 monthly, verifying supporting documentation, mathematical accuracy, and account coding against the chart of accounts. Evidence: initialled journal entry form with reviewer signature and date, retained in SharePoint/Finance/JE folder." |
| "Reconciliation is performed" | "The Treasury Analyst reconciles the operating bank account (Account #XXXX) daily, comparing the bank statement to the GL balance, investigating and resolving variances over $500 within 2 business days. Evidence: completed reconciliation form with variance explanations, signed by preparer and reviewer." |
| "Access is restricted" | "The IT Security Administrator reviews user access to the ERP financial modules quarterly, comparing active users to the HR active employee list and role-based access matrix. Terminated users are removed within 24 hours of HR notification. Evidence: quarterly access review report with sign-off." |
Common SOX Documentation Failures
Failure 1: Controls Described Too Vaguely
"Management reviews the financial statements" describes an activity, not a control. What does the review check? What would cause management to reject the statements? What evidence is created? Vague descriptions make controls untestable.
Failure 2: Evidence Not Specified
A control without specified evidence is a control that can't be tested. If the evidence is "the manager reviews and approves," where is the approval documented? Email? Signature on a form? System workflow approval? Specify the evidence artifact and its location.
Failure 3: Outdated Process Documentation
Process narratives and flowcharts written during the initial SOX implementation (often 10+ years ago) that haven't been updated as processes changed. The documentation describes a system migration ago, two reorganisations ago, and three ERP upgrades ago.
Failure 4: Missing IT General Controls (ITGCs)
ITGCs (access management, change management, computer operations, program development) underpin application controls. If ITGCs are poorly documented, every application control that relies on the IT system is at risk.
Failure 5: No Deficiency Evaluation Framework
When a control fails, the deficiency must be evaluated: is it a deficiency, significant deficiency, or material weakness? Without a documented evaluation framework with clear criteria, this assessment is inconsistent and subjective.
Reviewing SOX Documentation
Risk and Control Matrix Review
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | Every significant risk has at least one control; every control maps to at least one risk |
| Control precision | 3 | Controls are specific enough to address the identified risk (not generic) |
| Evidence specification | 2 | Every control specifies the evidence artifact and its location |
| Frequency alignment | 2 | Control frequency matches the risk frequency (daily transaction risk needs at least monthly control) |
| Ownership | 2 | Every control has a named owner (role, not person) |
| Consistency | 1 | Terminology and format consistent across all RCMs |
Process Narrative/Flowchart Review
| Criterion | Weight | What to Check |
|---|---|---|
| Accuracy | 3 | Matches current process (not historical) |
| Completeness | 3 | End-to-end process documented, including exceptions and manual interventions |
| Control points identified | 2 | Controls clearly marked within the process flow |
| System references | 2 | IT systems and reports referenced by name and version |
| Segregation of duties | 2 | Incompatible duties separated and documented |
Test Documentation Review
| Criterion | Weight | What to Check |
|---|---|---|
| Sample adequacy | 3 | Sample size appropriate for the control frequency and population |
| Test procedure alignment | 3 | Testing actually tests the control as described (not a different attribute) |
| Evidence retention | 2 | Test evidence retained and traceable to the specific test |
| Exception handling | 2 | Any exceptions noted, investigated, and evaluated |
| Timeliness | 1 | Testing completed within the planned timeframe |
SOX Documentation Review Schedule
| Timing | What to Review | Who |
|---|---|---|
| Q1 (Planning) | Scoping documentation, risk assessment, RCMs updated for current year changes | Internal Audit + Management |
| Q2-Q3 (Testing) | Control descriptions current, test plans aligned, interim testing documented | Internal Audit |
| Q4 (Year-end) | Complete documentation package, deficiency evaluations, remediation evidence | Internal Audit + External Auditor |
| After significant changes | Affected process documentation, new/modified controls, change impact assessment | Process owners + Internal Audit |
Frequently Asked Questions
Does SOX apply to private companies?
SOX Section 404 applies to SEC-reporting companies. Private companies are not directly subject to SOX, but many adopt SOX-like controls voluntarily, especially if they're considering an IPO, are acquired by a public company, or want to demonstrate strong governance to investors and lenders.
What's the difference between a deficiency, significant deficiency, and material weakness?
- Deficiency: A control gap exists but is unlikely to result in material misstatement
- Significant deficiency: A deficiency (or combination) that is less severe than a material weakness but important enough to merit attention from those responsible for oversight
- Material weakness: A deficiency (or combination) such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis
Material weakness requires disclosure in the annual report and the auditor's report.
How many controls should we have?
There's no right number. A mid-size company typically has 100-300 key controls. The goal is sufficient controls to mitigate identified risks — not maximum controls. Over-scoping increases compliance costs without reducing risk.
Can AI review help with SOX documentation?
AI review can check documentation quality: control descriptions for the five elements (who, what, when, how, evidence), consistency across RCMs, completeness of process narratives, and alignment between risk descriptions and control objectives. It cannot assess whether controls are actually effective — that requires testing by qualified auditors.
How do we reduce SOX compliance costs?
Reduce documentation scope (are all in-scope controls truly key?), automate testing where possible, standardise documentation formats, and use AI review to catch documentation gaps before the external auditor finds them. Every gap the external auditor finds costs 3-5x more to remediate than one found internally.
Key Takeaways
- SOX requires documented internal controls — an undocumented control is a non-existent control for audit purposes.
- Every control needs five elements: who, what, when, how, and evidence. Missing any element makes the control untestable.
- Process documentation must match current practice — outdated narratives are among the most common audit findings.
- Review documentation quarterly and before external audit. Internal discovery costs 3-5x less than external discovery.
- IT General Controls underpin everything — poorly documented ITGCs put all application controls at risk.
- AI review checks documentation quality (completeness, consistency, specificity) — control effectiveness requires human testing.
- Deficiency evaluation needs a documented framework with clear criteria for classification.
This article is for informational purposes only. SOX compliance requirements are interpreted and assessed by the PCAOB and SEC. Consult your external auditor or a qualified SOX compliance professional for guidance specific to your organisation.