Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOX control testing explained

SOX Control Testing: The Clear Guide to Sample Sizes (2026)

SOX control testing is the part of the programme that turns a documented control into evidence — and the question every tester asks first, how many items to sample, has an answer that is not in the statute, not in the SEC’s rules and not in PCAOB Auditing Standard 2201.

AS 2201 sets the principles: the evidence needed depends on the risk associated with the control (.46–.47); inquiry alone is not sufficient (.50); tests are ranked from least to most persuasive as inquiry, observation, inspection and re-performance (.50); testing over a longer period and closer to the assessment date gives more evidence (.52); the more extensively a control is tested the more evidence it yields (.54); interim testing needs roll-forward (.55–.56); and the auditor should vary the nature, timing and extent from year to year (.61).

The sample-size tables that every programme uses are professional convention built on those principles — the AICPA’s audit sampling guidance and the large-firm methodologies converge on similar numbers for a control operating with no expected deviations — and a company applies them through its own testing methodology. This guide sets out the AS 2201 principles, the conventional sample sizes by control frequency with the assumptions behind them, the design and operating tests, the treatment of exceptions, roll-forward, and the errors that produce testing that proves nothing.

SOX control testing: the conventional sample sizes by frequency
Annual 1 · Quarterly 2 · Monthly 2–5 · Weekly 5–15 · Daily 20–40 · Multiple times a day 25–60 · Automated 1 (plus ITGCs and benchmarking) — professional convention for a control expected to operate without deviation; risk raises the numbers, an exception restarts the assessment.

What AS 2201 actually says about SOX control testing

Paragraph Principle What it means for a testing methodology
.42–.43 Test design effectiveness: would the control, operated as prescribed by competent people with authority, prevent or detect material misstatement? A walkthrough and inquiry per control, every year or on change
.44–.45 Test operating effectiveness: is the control operating as designed, by a person with the authority and competence to perform it? Sampled evidence of occurrences across the period
.46–.47 The evidence needed depends on the risk associated with the control — including its nature, the misstatement it addresses, judgement involved, reliance on IT general controls, competence and turnover of the performer, whether it is manual or automated, and changes since last tested Sample sizes scale with risk; a key manual control with judgement gets more items than a routine automated check
.50 Inquiry alone does not provide sufficient evidence; tests in order of persuasiveness: inquiry, observation, inspection of documentation, re-performance Every tested control needs inspection or re-performance, not a conversation
.52–.53 Testing over a longer period and nearer the as-of date provides more evidence Spread samples across the year; weight towards year end
.54 The more extensively a control is tested, the greater the evidence Larger samples for higher-risk controls
.55–.56 Roll-forward: evidence about operation for the period after interim testing Update procedures for key controls; inquiry alone insufficient for the update
.61 Vary nature, timing and extent from year to year for unpredictability Rotate interim periods and sample selections
.B28–.B33 Benchmarking automated controls when ITGCs are effective Test the automated control once, then the ITGCs and the unchanged status

Our guide to SOX compliance places testing as step four of the ICFR cycle; the SOX ITGC guide covers the general controls that benchmarking depends on.

The conventional SOX control testing sample sizes

The table below is professional convention, not regulation: it is what the AICPA’s audit sampling guidance and the major firms’ ICFR methodologies produce for a control expected to operate without deviation at a moderate level of assurance, and what most companies adopt in their testing methodology after agreeing it with their auditor. Higher-risk controls sit at the top of each range or above it; the auditor’s own samples for 404(b) may differ.

Control frequency Population per year Conventional sample (no deviations expected) Notes
Annual 1 1 The occurrence, tested in full
Quarterly 4 2 Often all 4 for key controls
Monthly 12 2–5 Higher end for key controls with judgement
Weekly 52 5–15
Daily ~250 20–40 Business days
Multiple times a day / per transaction Thousands 25–60 Statistical or attribute sampling; 25 at low risk, 40–60 at higher risk
Automated application control Continuous 1 (test the logic once), plus ITGC testing Benchmark in later years under AS 2201 .B28–.B33 if unchanged and ITGCs effective
IT general control — recurring (access requests, changes, leavers) Varies Per the frequency of occurrence, as above Population completeness must be proven

Two assumptions drive the numbers. The first is that no deviations are expected: attribute-sampling tables give roughly 25 items for 90% confidence that the deviation rate is below 10% with zero deviations found, and the frequency-based conventions step down from there for smaller populations. The second is that the control is a single control operating uniformly; a control performed by several people, at several locations or through several systems is several populations, and each is sampled.

SOX control testing: design tests and operating tests

Test Method Output Frequency
Design effectiveness Walkthrough with the performer: trace a transaction through the process using the same documents and systems (AS 2201 .37); confirm the control’s timing, precision, authority and evidence Design conclusion; updated narrative and matrix Annually, and on any change to the process, system or performer
Operating effectiveness Select the sample from a complete population; for each item inspect the evidence that the control operated as designed and, for key controls, re-perform it Sample results; exceptions; conclusion Across the period, with roll-forward
Precision of review controls For management review controls, evidence of what the reviewer looked at, the threshold that would trigger follow-up, and follow-up performed Whether the review is precise enough to detect a material misstatement With the operating test
Information produced by the entity Test the completeness and accuracy of any report the control relies on: parameters, source, logic, totals IPE conclusion Per report, per period

Exceptions and what they do to the sample

  1. Determine whether it is a deviation. A missing signature where the approval is evidenced elsewhere may be a documentation lapse; a payment released without approval is a deviation.
  2. Evaluate the cause and the extent. Isolated or systematic, one performer or all, one period or the year.
  3. Do not simply extend the sample. One deviation in a sample designed for zero means the control’s deviation rate can no longer be concluded acceptable from that sample; testing more items to “dilute” it is the error auditors challenge. The conventional response is to assess the deficiency, identify compensating controls and test them, and remediate and re-test the control for the remaining period.
  4. Evaluate the deficiency. Severity on the reasonable-possibility and magnitude tests; our guide to material weakness vs significant deficiency covers the assessment.
  5. Re-test after remediation. A remediated control needs a sufficient period of operation and a new sample before year end to be concluded effective as of the assessment date.

Roll-forward in SOX control testing

Where operating tests are performed at an interim date, AS 2201 .55–.56 require additional evidence about the remaining period, considering the control’s risk, the results of the interim tests, the length of the remaining period and any changes. In practice a company’s methodology sets roll-forward samples — a further one to five items depending on frequency and risk — plus inquiry and inspection of evidence that the control continued unchanged, and treats any change in the process, system or performer as a trigger to re-test rather than roll forward. Inquiry alone is not enough for the update on key controls.

Errors that make SOX control testing prove nothing

  • Samples from incomplete populations. Selecting from the tickets the team knows about rather than from a system log reconciled to them; the sample tests the list, not the control.
  • Inquiry recorded as testing. “Discussed with the controller, who confirmed the reconciliation is performed monthly” is not evidence under .50.
  • Review controls without precision. A sign-off on a report with no evidence of what was reviewed or what threshold would have triggered action.
  • Untested IPE. Testing the reviewer’s sign-off on a report nobody proved was complete and accurate.
  • Extending samples after an exception. Diluting a deviation instead of evaluating it.
  • Roll-forward by inquiry. Asking whether anything changed instead of inspecting evidence that the control ran.
  • The same sample every year. .61 asks for variation; the auditor notices when it is absent.
  • One population for many performers. A control performed at five locations sampled as if it were one.

Frequently asked questions

What sample sizes does SOX require?
None are set by the Act, the SEC or PCAOB AS 2201. AS 2201 sets principles — evidence scaled to the risk of the control, inquiry insufficient alone, more evidence from longer periods and more items — and the conventional sizes come from professional practice: 1 for annual, 2 for quarterly, 2–5 monthly, 5–15 weekly, 20–40 daily, 25–60 for per-transaction controls, with higher numbers for higher-risk controls.

Why are the conventional sample sizes what they are?
They descend from attribute-sampling tables — about 25 items give roughly 90% confidence that the deviation rate is below 10% when no deviations are found — stepped down for smaller populations, on the assumption of a single control operating uniformly with no expected deviations.

What happens if we find one exception?
The sample can no longer support a conclusion that the control is effective; the exception is evaluated as a deficiency, compensating controls are identified and tested, the control is remediated and re-tested for the remaining period. Extending the sample to dilute the exception is the practice auditors challenge.

Can automated controls be tested once?
The logic is tested once; in later years, AS 2201 .B28–.B33 allow benchmarking — relying on the prior test — if IT general controls over changes, access and operations are effective and tested and the control has not changed.

What is roll-forward?
Under AS 2201 .55–.56, the additional evidence needed when controls are tested at an interim date to cover the period to the assessment date: further samples, inspection that the control continued unchanged, and re-testing if the process, system or performer changed. Inquiry alone is insufficient.

Where this leaves you

Run SOX control testing on AS 2201’s principles and the conventional sample sizes as a starting point: walk through every control’s design, sample operating evidence from complete populations at sizes scaled to risk and frequency, prove the precision of review controls and the accuracy of the reports they use, treat an exception as a deficiency rather than a reason to sample more, roll forward with evidence and not inquiry, and vary the approach year to year — because the numbers are convention, and the evidence behind them is what the auditor and the certifying officers rely on.

References

More on SOX

The testing methodology with the sample-size table and risk adjustments, the walkthrough and test-of-controls templates, the population completeness and IPE testing checklists, the exception evaluation form and the roll-forward procedure are in the SOX Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.