← All postsHow-to

SOX compliance: the year is spent on evidence, not on the law

Sarbanes-Oxley is short. What consumes a finance team is proving that controls operated all year — and proving it with records made at the time.

How-toS

SOX compliance is the work a public company does to satisfy the Sarbanes-Oxley Act: management asserts that internal control over financial reporting is effective, and — above a size threshold — the external auditor attests to that assertion. The law is short. The programme built to satisfy it is not.

The distinction that decides how expensive a year becomes is between having controls and being able to evidence them. A control that operated every month but left no dated artefact is, for SOX purposes, a control that cannot be tested — and a control that cannot be tested is a deficiency waiting to be written up.

What a SOX compliance programme actually consists of

  • Scoping: which entities, accounts and processes are material enough to be in scope, documented with the rationale.
  • Process documentation: narratives or flowcharts showing how transactions flow, updated when the process changes rather than annually.
  • A risk and control matrix linking each financial statement risk to the control that addresses it.
  • Control operation: the controls actually running, with evidence produced as a by-product.
  • Testing: design and operating effectiveness, sampled across the period rather than at year end.
  • Deficiency evaluation: severity, aggregation, and remediation with dates.

Where deficiencies actually come from

In practice most findings are not clever. Reviews performed without any record of what was reviewed. Access that was never removed when someone changed role. Journals posted and approved by the same person. Spreadsheets central to a number, with no version control and no check on their formulas. Controls that were redesigned mid-year with nobody updating the documentation.

The common thread is that each is a documentation failure at least as much as a control failure. The work happened, or mostly happened; what is missing is the record proving it happened when the tester needs it to have happened.

Evidence created after the fact rarely survives contact with a tester, because it is dated after the fact. Design each control so the artefact is produced when the control runs — an approval that records who and when, a reconciliation that is signed on completion, an access review with the list attached.

Running the year rather than the deadline

  1. Confirm scope early and write down why anything material was excluded.
  2. Walk through each significant process once a year with the people who perform it, not with last year’s narrative.
  3. Test throughout the year, so a failure found in Q2 can still be remediated and retested.
  4. Track deficiencies as a live list with owners and dates, not as an appendix produced in December.
  5. Re-perform the access reviews and the segregation of duties check after every reorganisation.
  6. Keep the evidence where the control runs, so testing is a request rather than an excavation.

Ettex is not a SOX platform and does not test controls — that work belongs to people. What Ettex Records holds is the evidence layer: the process documentation with its version history, the reviews and their sign-offs, the artefacts each control produced, filed against the control rather than in an inbox. When the tester asks for the June approval, it is retrieved rather than reconstructed. The internal controls themselves still have to be designed and operated by the business.

Proportion

SOX programmes tend to grow: more controls, more testing, more documentation, without anyone asking whether the added control addresses a real risk to the financial statements. A programme with three hundred key controls in a mid-cap company is usually not more assured than one with eighty — it is more expensive and less well performed.

Frequently asked

Which companies have to comply with SOX?

Companies with securities registered in the United States, including many foreign private issuers. Requirements differ by filer status: smaller reporting companies and non-accelerated filers face management assertion without an auditor attestation on ICFR.

What is the difference between Section 302 and Section 404?

Section 302 requires officers to certify the accuracy of each periodic report and the effectiveness of disclosure controls. Section 404 requires an annual management assessment of internal control over financial reporting, with auditor attestation for larger filers.

What is a material weakness?

A deficiency, or combination of deficiencies, such that there is a reasonable possibility a material misstatement would not be prevented or detected on a timely basis. It is a severity conclusion, not a category of error.

Do private companies need SOX compliance?

Not legally, but companies preparing for an IPO or an acquisition by a public company build the programme in advance, because the first year of readiness is the longest one.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.