For public companies, few compliance obligations carry more weight than the internal control requirements under the Sarbanes-Oxley Act. Section 404 of SOX is not a one-time hurdle. It is an annual accountability framework that puts your financial reporting integrity directly in front of regulators, investors, and auditors. Getting it right is non-negotiable.
Tampa-area businesses preparing for an IPO or managing life as a public company need a clear, practical understanding of what SOX 404 requires, who it applies to, and how to build the internal controls that will withstand scrutiny. This guide walks through everything your finance team and audit committee need to know.
Key Takeaways
- SOX Section 404 has two distinct components. Section 404(a) requires management to assess and report on internal controls. Section 404(b) requires an independent auditor to attest to that assessment for larger filers.
- Not every public company faces the same requirements. Filer classification – large accelerated, accelerated, or non-accelerated – determines whether the external auditor attestation applies to your company.
- Internal control weaknesses become public disclosures. Material weaknesses identified during a SOX 404 audit must be disclosed in your annual report, which can directly affect investor confidence and stock price.
- Documentation is everything. Strong internal controls are not enough if they are not properly documented. PCAOB-registered auditors will scrutinize both the design and operating effectiveness of your controls.
- Early preparation pays off. Companies that build SOX-compliant internal control frameworks before they are required are in a significantly stronger position when the first integrated audit arrives.
Quick Answer: What Is SOX Section 404?
Quick Answer: SOX Section 404 requires public companies to evaluate, document, and report on the effectiveness of their internal controls over financial reporting (ICFR) each year. For larger filers, an independent PCAOB-registered auditor must also attest to management’s assessment.
What Is SOX Section 404?
Section 404 of the Sarbanes-Oxley Act of 2002 established two related but distinct requirements for public companies regarding internal controls over financial reporting:
- Section 404(a) – Management Assessment: Every public company must include in its annual report (Form 10-K) a report by management that acknowledges its responsibility for establishing and maintaining adequate internal controls over financial reporting and provides an assessment of the effectiveness of those controls as of the end of the fiscal year.
- Section 404(b) – Auditor Attestation: For accelerated filers and large accelerated filers, the company’s independent PCAOB-registered auditor must attest to and report on management’s assessment of internal controls. This is the integrated audit requirement that adds a second layer of scrutiny beyond the financial statement audit.
Together, these requirements create a robust framework for financial reporting accountability – one that has fundamentally reshaped how public companies design, document, and test their internal control environments.
Who Does SOX 404 Apply To?
SOX 404 applies to all companies with securities registered under the Securities Exchange Act of 1934, but the specific requirements vary depending on filer classification. Understanding which category your company falls into determines the full scope of your SOX 404 obligations.
Filer Categories and SOX 404 Requirements
- Large Accelerated Filers – Companies with a public float of $700 million or more. Subject to both 404(a) management assessment and 404(b) auditor attestation. Face the most rigorous and comprehensive integrated audit requirements.
- Accelerated Filers – Companies with a public float between $75 million and $700 million. Also subject to both 404(a) and 404(b). The integrated audit applies but may be scoped differently than for large accelerated filers.
- Non-Accelerated Filers – Companies with a public float below $75 million. Required to comply with 404(a) management assessment but are exempt from the 404(b) auditor attestation requirement. This exemption significantly reduces audit costs for smaller public companies.
- Emerging Growth Companies (EGCs) – Companies that qualify as EGCs under the JOBS Act may be exempt from the 404(b) auditor attestation requirement for up to five years following their IPO, providing meaningful compliance relief during the critical early growth phase.
For Tampa businesses approaching or recently completing an IPO, understanding your filer classification from the outset shapes your audit firm selection, your internal control investment, and your compliance timeline.
What Are Internal Controls Over Financial Reporting (ICFR)?
Internal controls over financial reporting are the policies, procedures, and processes a company has in place to provide reasonable assurance that its financial statements are accurate and reliable. ICFR encompasses everything from how transactions are authorized and recorded to how financial data is consolidated and reported.
For SOX 404 purposes, management must evaluate ICFR against an established control framework. The most widely used framework is the COSO Internal Control – Integrated Framework, published by the Committee of Sponsoring Organizations of the Treadway Commission. PCAOB-registered auditors and the SEC both recognize COSO as the standard benchmark for this evaluation.
Key Components of an Effective ICFR Framework
- Control Environment: The tone at the top. This includes the board’s and management’s commitment to integrity, ethical values, and competence. It sets the foundation for every other control component.
- Risk Assessment: Management’s ongoing process of identifying and analyzing risks that could prevent the organization from achieving reliable financial reporting, including the risk of fraud.
- Control Activities: The specific policies and procedures management implements to address identified risks. These include approvals, authorizations, reconciliations, segregation of duties, and physical controls over assets.
- Information and Communication: The systems and processes that capture, process, and communicate financial information to those who need it, both internally and to external parties.
- Monitoring Activities: Ongoing and separate evaluations of whether internal controls are present and functioning effectively. Internal audit functions typically play a central role here.
Section 404(a) vs. 404(b): Understanding the Difference
The distinction between management’s assessment under 404(a) and the auditor attestation under 404(b) is more than technical. It represents two fundamentally different perspectives on the same internal control environment.
Section 404(a): Management’s Responsibility
Under 404(a), management – typically the CEO and CFO – must:
- Accept formal responsibility for establishing and maintaining adequate ICFR
- Select and apply a suitable control framework (typically COSO)
- Identify and document all significant processes and related controls
- Test the operating effectiveness of key controls throughout the year
- Assess whether any identified deficiencies rise to the level of a significant deficiency or material weakness
- Disclose the results of this assessment in the annual report, including any identified material weaknesses
Section 404(b): The Auditor’s Independent Attestation
For companies subject to 404(b), the PCAOB-registered auditor conducts an independent assessment that goes beyond reviewing management’s work. The auditor must:
- Independently identify significant accounts and processes, not simply rely on management’s identification
- Evaluate the design of internal controls to determine if they are capable of preventing or detecting material misstatements
- Test the operating effectiveness of controls through independent procedures, including walkthroughs, observations, and reperformance
- Form an independent opinion on whether the company maintained effective ICFR as of the fiscal year-end
- Issue a separate report on ICFR that appears alongside the financial statement audit report in the annual filing
This integrated audit – combining the financial statement audit with the ICFR attestation – is one of the most demanding engagements in public company compliance. It requires a PCAOB-registered firm with deep experience in internal control audits, not just financial statement work.
Common Internal Control Deficiencies and How to Avoid Them
Internal control deficiencies fall into three categories under SOX 404, each with different disclosure and remediation implications:
- Control Deficiency: A design or operating flaw that reduces the likelihood of detecting or preventing a misstatement, but is unlikely to result in a material misstatement on its own. These do not require public disclosure but should be addressed promptly.
- Significant Deficiency: A control deficiency, or combination of deficiencies, that is less severe than a material weakness but important enough to merit attention from those responsible for financial oversight. Must be communicated to the audit committee.
- Material Weakness: A deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. Must be publicly disclosed in the annual report and will result in an adverse opinion on ICFR from the auditor.
Most Frequently Cited Material Weaknesses
Based on SEC filings and PCAOB inspection findings, the most common material weaknesses involve:
- Inadequate segregation of duties – Particularly prevalent in smaller public companies where one individual has too much control over financial processes without appropriate oversight
- Insufficient accounting resources – Companies that lack personnel with the technical accounting expertise to apply complex GAAP standards correctly
- Weak IT general controls – Access controls, change management, and system security deficiencies that affect the reliability of financially significant systems
- Inadequate period-end financial reporting controls – Weaknesses in the review and approval processes for financial statement preparation and disclosure
- Revenue recognition errors – Particularly in companies with complex contracts, multiple performance obligations, or variable consideration arrangements
Identifying these risks proactively and remediating them before your integrated audit is far less costly than disclosing a material weakness in a public filing.
Preparing for Your First SOX 404 Integrated Audit
For companies approaching their first integrated audit – whether as a newly public company or one that has crossed into accelerated filer status – preparation is everything. The companies that navigate this process smoothly are those that start well before the fiscal year end and treat internal control documentation as an ongoing discipline, not a year-end scramble.
Steps to Take Before Your Integrated Audit
- Engage your PCAOB-registered auditor early. Ideally, your audit firm should be involved in discussions about your internal control framework well before the fiscal year begins. Early engagement allows the auditor to identify potential gaps while you still have time to address them.
- Map your significant processes and controls. Document every significant financial reporting process – revenue, procurement, payroll, financial close, equity accounting – and identify the key controls within each. This process documentation becomes the foundation of both management’s assessment and the auditor’s testing.
- Conduct a risk assessment. Evaluate which accounts and disclosures carry the highest risk of material misstatement. This helps prioritize where to invest control design and testing resources.
- Test your controls throughout the year. Effective ICFR requires controls to operate consistently over time, not just at year-end. Build a testing calendar that validates control effectiveness on an ongoing basis.
- Address IT general controls. Many companies underestimate the importance of IT controls in the ICFR assessment. Work with IT and the audit team to ensure access controls, change management, and system integrity controls are documented and tested.
- Strengthen your audit committee. The audit committee plays a critical oversight role in SOX 404 compliance. Ensure members have the financial expertise and engagement level the process demands.
SOX 404 and the Role of Your PCAOB-Registered Auditor
The relationship between management and the external auditor in a SOX 404 engagement is more collaborative – and more demanding – than a standard financial statement audit. Understanding what your auditor needs and how to work effectively with them significantly affects the efficiency and outcome of the integrated audit.
A PCAOB-registered firm conducting an integrated audit will perform walkthroughs of your key processes, observe control performance, inspect documentation, and reperform certain controls independently. They will also evaluate whether management’s own testing was sufficiently rigorous to support the 404(a) assessment.
Companies that treat the integrated audit as a collaborative process – rather than an adversarial inspection – consistently achieve better outcomes. This means maintaining open communication with the engagement team, addressing questions promptly, and being transparent about known control gaps rather than waiting for the auditor to find them.
Understanding the full scope of PCAOB audit requirements provides critical context for how the integrated audit process fits into your broader compliance obligations as a public company.
Frequently Asked Questions
What is the difference between SOX 404(a) and 404(b)?
Section 404(a) requires management to assess and report on the effectiveness of internal controls over financial reporting in the annual report. Section 404(b) requires the company’s independent PCAOB-registered auditor to independently attest to management’s assessment. Both sections apply to accelerated and large accelerated filers, while non-accelerated filers and qualifying emerging growth companies are exempt from 404(b).
What is a material weakness under SOX 404?
A material weakness is a deficiency, or combination of deficiencies, in internal controls over financial reporting where there is a reasonable possibility that a material misstatement of the company’s financial statements will not be prevented or detected on a timely basis. Material weaknesses must be disclosed publicly in the annual report and result in an adverse auditor opinion on ICFR.
Does SOX 404 apply to private companies?
SOX 404 applies only to companies with securities registered with the SEC. Private companies are not subject to SOX 404 requirements. However, private companies preparing for an IPO often voluntarily implement SOX-compliant internal control frameworks in advance to smooth the transition to public company status and reduce the risk of material weakness disclosures in early public filings.
How long does a SOX 404 integrated audit take?
The timeline varies significantly based on company size, complexity, and the maturity of the internal control environment. For companies with well-documented, well-tested controls, the integrated audit can proceed concurrently with the financial statement audit with minimal additional time. For companies with significant control gaps or limited documentation, the process can extend the overall audit timeline substantially. Starting early and maintaining controls throughout the year is the most effective way to manage timing.
Can we remediate a material weakness before the fiscal year ends?
Yes, and doing so is strongly preferable to disclosing an unremediated material weakness. If a material weakness is identified and fully remediated before fiscal year-end – meaning the remediated control has been operating effectively for a sufficient period – the company may be able to avoid the disclosure. The key is identifying issues early enough to allow time for meaningful remediation and testing before the assessment date.
What framework should we use for our SOX 404 assessment?
The COSO Internal Control – Integrated Framework is the most widely accepted framework for SOX 404 assessments and is recognized by both the SEC and PCAOB. Most public companies use the 2013 version of the COSO framework. Some companies in specific industries may also reference other frameworks, but COSO remains the clear standard for financial reporting internal control assessments.
Work With a SOX 404 Specialist in Tampa
Hacker, Johnson & Smith PA has been PCAOB-registered since the Board’s inception in 2002, giving the firm more than two decades of experience conducting integrated audits for public companies across Florida. That depth of experience matters when navigating the complexity of SOX 404 compliance, particularly for companies in regulated industries like banking, insurance, and manufacturing where the internal control environment carries additional layers of scrutiny.
Whether your company is preparing for its first integrated audit, addressing identified control deficiencies, or looking for a more experienced audit partner, the team brings both the technical expertise and the advisory orientation to help you build a compliance framework that holds up. Reach out through the Audit Division page or contact the Tampa, Orlando, or Fort Lauderdale offices directly to discuss your SOX 404 needs.

