Sarbanes-Oxley made internal control a named personal responsibility: under Sections 302 and 404, executives sign to say the controls over financial reporting work, and auditors test whether that signature is justified. SOX compliance is therefore less about a single project than an annual cycle you have to be able to evidence. This guide sets out the five steps that cycle runs on, and where COSO fits into it.
The controls themselves rest on a risk assessment; if that discipline is new to you, our risk assessment guide covers the general method.
Why COSO comes first
SOX does not define what a good control looks like. It requires management to use a recognised framework, and in practice that means COSO — the Internal Control – Integrated Framework, with its five components of control environment, risk assessment, control activities, information and communication, and monitoring.
This is why the two are usually bought together. COSO supplies the structure auditors expect; SOX supplies the legal obligation and the annual testing rhythm. Our COSO ERM & Internal Control Toolkit covers both halves of COSO with 21 templates — the internal control and ICFR policies, control design and documentation standard, evaluation and testing procedure, deficiency evaluation policy, plus the ERM side with risk appetite statement, risk register and portfolio view.
The five steps of the ICFR cycle
| Step | What it produces |
|---|---|
| 1. Scope | Significant accounts, locations and processes in scope, with materiality set |
| 2. Assess risk | Top-down risk assessment and fraud risk assessment |
| 3. Document | Entity-level, process-level and IT general controls, with narratives and matrices |
| 4. Test | Design and operating effectiveness testing, with evidence retained |
| 5. Evaluate and report | Deficiency severity assessment, remediation, 302 and 404 sign-off |
Where SOX programmes go wrong
Scoping too widely. The top-down, risk-based approach exists so you do not test everything. Teams that skip a proper materiality and significant-accounts analysis end up testing hundreds of controls they were never required to.
Treating ITGCs as an afterthought. Access management, change management and operations underpin every automated control and every report the business relies on. If IT general controls fail, the application controls resting on them fail with them.
Confusing a deficiency with a material weakness. These are graded — deficiency, significant deficiency, material weakness — and the grading drives what has to be disclosed. It needs a documented evaluation method agreed before findings arrive, not after.
Forgetting information produced by the entity. If a control relies on a report, the completeness and accuracy of that report is itself in scope. IPE is one of the most common audit findings.
Documenting it
The documentation load is the reason SOX readiness takes a year rather than a quarter. Our SOX Compliance Toolkit provides 45 ICFR templates covering the full cycle — compliance programme charter, scoping memorandum, top-down and fraud risk assessments, materiality worksheet, entity-level controls workbook, application controls inventory and IPE standard, through to testing and the year-one implementation roadmap.
Frequently asked questions
Is COSO required for SOX compliance?
SOX requires a suitable recognised framework rather than COSO specifically, but COSO is the framework auditors and the SEC expect in practice. Choosing anything else means justifying the choice.
What is the difference between SOX 302 and 404?
Section 302 is the quarterly certification by executives that disclosures are accurate and controls are in place. Section 404 is the annual assessment of internal control over financial reporting, which for accelerated filers is also audited externally.
Do private companies need SOX compliance?
Not legally, but many adopt the framework anyway — typically when preparing for an IPO, when private equity owners require it, or when customers ask for evidence of financial control maturity.