Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOX scoping and materiality explained

SOX Scoping and Materiality: A Clear Top-Down Guide (2026)

SOX scoping and materiality decide the size of the whole programme before a single control is documented, and they are the two judgements auditors examine first. Scoping under PCAOB Auditing Standard 2201’s top-down approach begins at the financial statements, identifies entity-level controls, then significant accounts and disclosures and their relevant assertions, then the likely sources of misstatement within them, and only then selects the controls to test — so that the control population is derived from risk rather than from an inventory of everything the company does.

Materiality is the threshold that makes “significant” and “material” mean something: the planning materiality the auditor sets for the financial statements as a whole, the lower performance materiality applied to accounts, and the qualitative factors AS 2201 lists that can make a small account significant.

Neither the Act nor the standard prescribes a percentage; the common practice rules of thumb — around five per cent of pre-tax income, or a fraction of revenue or assets where income is volatile — are conventions the auditor calibrates and management should understand rather than adopt blindly. This guide walks through the top-down scoping sequence as AS 2201 sets it out, the materiality concepts and how they are applied to accounts and locations, the multi-location and service-organisation rules, the documentation a scoping memo needs, and the errors that make programmes too big or, worse, too small.

SOX scoping and materiality: the AS 2201 top-down approach
Financial statements and materiality → entity-level controls (.22–.27) → significant accounts and disclosures and relevant assertions (.28–.33) → likely sources of misstatement, walkthroughs (.34–.38) → controls to test (.39–.41) · locations and business units (.B10–.B16) · service organisations (.B17–.B27) · documented in a scoping memo the auditor reads first.

Why SOX scoping and materiality come first

AS 2201 .21 describes the top-down approach: begin at the financial statement level with an understanding of the overall risks to ICFR, focus on entity-level controls, then on significant accounts and disclosures and their relevant assertions, then verify the understanding of the risks in the company’s processes, and select for testing the controls that sufficiently address the assessed risk of misstatement to each relevant assertion.

The order is the point. A programme that starts from the process inventory tests controls that address no material risk and misses the ones that do; one that starts from materiality and the accounts tests what could produce a material misstatement and nothing else. Our guide to SOX compliance places scoping as step one of the ICFR cycle.

SOX scoping and materiality: the concepts

Concept What it is How it is used in scoping
Overall (planning) materiality The magnitude of misstatement that could reasonably influence the decisions of financial statement users, set by the auditor for the statements as a whole The reference point for ‘material’ in significant-account identification and deficiency evaluation
Performance (tolerable) materiality A lower amount applied to individual accounts and disclosures so that aggregated misstatements stay below overall materiality The quantitative screen for significant accounts; accounts above it are presumptively significant
Qualitative factors AS 2201 .29’s risk factors: size and composition; susceptibility to error or fraud; volume, complexity and homogeneity of transactions; nature of the account; accounting and reporting complexity; exposure to losses; related-party transactions; changes from the prior period What makes an account below the quantitative screen significant anyway — and what raises the risk of one above it
Common practice benchmarks Rules of thumb such as around 5% of pre-tax income from continuing operations, or fractions of revenue, total assets or equity where income is small or volatile The auditor’s starting point, disclosed to management; not a standard

Management’s scoping uses the auditor’s materiality where it is shared, or its own reasoned estimate documented in the scoping memo; the two should reconcile, because AS 2201 .31 states that significant accounts and their relevant assertions are the same for the audit of internal control and the audit of the financial statements.

SOX scoping and materiality in sequence: the top-down approach

Step AS 2201 What is done Output
1. Entity-level controls .22–.27 Identify and evaluate the control environment, controls over management override, the risk assessment process, centralised processing, monitoring of results and of other controls, and the period-end financial reporting process (.26–.27); decide which are precise enough to affect testing of other controls Entity-level control inventory; effect on process-level testing
2. Significant accounts, disclosures and assertions .28–.33 Apply materiality and the .29 qualitative factors to every financial statement line and disclosure; for each significant one, identify the relevant assertions — existence or occurrence, completeness, valuation or allocation, rights and obligations, presentation and disclosure Significant account and assertion matrix
3. Likely sources of misstatement .34–.38 For each significant account and assertion, understand the flow of transactions from initiation through recording; identify where misstatement could arise; identify controls that address them and controls over unauthorised acquisition, use or disposition of assets — usually by walkthrough Process narratives and flowcharts with ‘what could go wrong’ points
4. Controls to test .39–.41 Select the controls that sufficiently address the assessed risk to each relevant assertion — preventive and detective, manual and automated — noting that one control may address several assertions and several controls one assertion Key control matrix
5. Systems and ITGCs .47 and .B28–.B33 The systems on which selected controls and reports depend, and the IT general controls over them In-scope system inventory; our guide to SOX ITGC covers the domains

Locations and business units

Rule AS 2201 Application
Test controls over specific risks that present a reasonable possibility of material misstatement to the consolidated statements .B11 Locations are scoped by the risks they carry to the consolidation, not by a fixed percentage of revenue or assets
Lower-risk locations may be covered by entity-level controls .B11 Central monitoring, group-level review and standard processes can provide the evidence for small units
Coordinate with work performed by others .B12 Internal audit’s location work can reduce the auditor’s own coverage
Vary locations year to year .B13 Rotation of lower-risk locations for unpredictability
Acquired entities and discontinued operations are in scope from the assessment date .B14 The SEC allows a first-year exclusion of an acquired business from management’s assessment; .B16 lets the auditor mirror it with disclosure
Equity-method investees .B15 Controls over the company’s reporting of its share, not controls at the investee

The coverage-percentage habit — scoping locations until, say, 70% of revenue is covered — is not in the standard. The standard asks whether a location presents a reasonable possibility of material misstatement, and a small location with a high-risk process can be in scope while a large one with standard central controls is covered at entity level.

Service organisations

AS 2201 .B17–.B27 bring service organisations into scope where their services are part of the company’s information system — payroll processors, cloud ERP providers, transfer agents, claims administrators. The evidence is a service auditor’s report on controls placed in operation and tests of operating effectiveness — a SOC 1 Type 2 — covering the period, plus the complementary user-entity controls it assumes, which the company must implement and test as its own. A SOC 1 whose period ends months before year end needs a bridge letter and the company’s own roll-forward consideration. Our guide to SOX 404 covers the attestation these reports feed.

The SOX scoping and materiality memo

  1. Materiality. Overall and performance materiality with the basis, and the qualitative factors applied.
  2. Significant accounts, disclosures and assertions. The matrix, with the reason each line is in or out.
  3. Entity-level controls. The inventory and the conclusion on which are precise enough to reduce process-level testing.
  4. Processes and sources of misstatement. The process list mapped to accounts, with walkthrough references.
  5. Locations and business units. In scope, covered at entity level, or out, with the risk reasoning; acquisitions and exclusions.
  6. Systems, service organisations and ITGCs. The in-scope system inventory, the SOC 1 reports relied on and their user-entity controls.
  7. Fraud risk. The fraud risk assessment and the controls over management override (.14–.15 and .24).
  8. Changes from last year. What moved in or out and why — the section the auditor reads most carefully.

Errors in SOX scoping and materiality

  • Starting from processes. Documenting every process and then asking which controls to test, instead of deriving processes from significant accounts.
  • Quantitative screens only. Ignoring .29’s qualitative factors, so a small, judgemental, fraud-prone account is left out.
  • Coverage percentages for locations. Scoping to a revenue percentage rather than to the risk each location carries.
  • Entity-level controls overrated. Claiming a monthly group review is precise enough to replace process-level testing without evidence of its precision (.23).
  • Service organisations forgotten. Cloud ERP and payroll SaaS with no SOC 1, or SOC 1s whose user-entity controls nobody implemented.
  • Materiality never reconciled. Management scopes at one threshold and the auditor at another, and the control matrices disagree.
  • No change log. A scoping memo copied from last year with the acquisition, the new system or the divested unit missing.

Frequently asked questions

What is the top-down approach to SOX scoping?
AS 2201 .21: begin at the financial statement level with the overall risks to ICFR; focus on entity-level controls; identify significant accounts and disclosures and their relevant assertions; understand the likely sources of misstatement in the processes, usually by walkthrough; then select the controls that sufficiently address the assessed risk to each relevant assertion.

What materiality threshold does SOX use?
None is prescribed. The auditor sets overall materiality for the financial statements and a lower performance materiality for accounts; common practice benchmarks such as around 5% of pre-tax income are conventions the auditor calibrates. AS 2201 .29’s qualitative factors can make an account significant regardless of size.

How are locations scoped?
By risk, under AS 2201 .B10–.B16: test controls at locations that present a reasonable possibility of material misstatement to the consolidated statements, cover lower-risk locations through entity-level controls, coordinate with internal audit, and vary the locations year to year. A fixed coverage percentage is not in the standard.

Are cloud providers and payroll processors in scope?
Where their services are part of the company’s information system, yes (AS 2201 .B17–.B27). A SOC 1 Type 2 report covering the period, plus the company’s own implementation and testing of the complementary user-entity controls, is the evidence.

What does the auditor read first?
The scoping memo: materiality and its basis, the significant account and assertion matrix, the entity-level control conclusions, locations and service organisations, and the changes from the prior year.

Where this leaves you

Do SOX scoping and materiality in AS 2201’s order and document the reasoning: set and reconcile materiality, apply the qualitative factors, evaluate the entity-level controls honestly, derive significant accounts, assertions and processes before touching a control matrix, scope locations and service organisations by the risk they carry, and keep a change log — because the size of the programme, and the first question the auditor asks, both come from this memo.

References

More on SOX

The scoping memo template, the materiality worksheet, the significant account and assertion matrix, the entity-level control inventory, the location and service organisation scoping records and the fraud risk assessment are in the SOX Compliance Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.