SOX 404(a) vs. 404(b): Requirements, Filer Rules, and Readiness

Management's ICFR assessment, the auditor's attestation, filer status, and the readiness work public-company finance teams and pre-IPO companies underestimate.

What Is the Difference Between SOX 404(a) and 404(b)?

SOX 404(a) requires management's annual assessment of internal control over financial reporting (ICFR), after applicable transition relief. SOX 404(b) requires an independent registered public accounting firm to audit ICFR and report an opinion on its effectiveness for covered issuers. Under current rules, accelerated filers generally have public float of $75 million to less than $700 million, while large accelerated filers generally have public float of $700 million or more, subject to reporting-history conditions, exemptions, and transition rules.

SOX 404(a) compared with SOX 404(b)
RequirementSOX 404(a)SOX 404(b)
Responsible partyManagementIndependent PCAOB-registered public accounting firm
Conclusion and reportManagement assesses and reports whether ICFR is effectiveThe auditor audits ICFR and expresses an opinion on effectiveness
Current applicabilityExchange Act issuers required to provide a management assessment after applicable newly public-company transition reliefGenerally, accelerated filers with $75 million to less than $700 million of public float and large accelerated filers with $700 million or more, after the applicable reporting-history tests; exemptions and transition provisions can change the result
Framework or standardA suitable, recognized control framework; COSO 2013 is commonly usedPCAOB AS 2201 for an integrated audit of ICFR and the financial statements
Evidence and timingManagement designs, operates, evaluates, and documents controls through the assessment dateThe auditor performs independent risk assessment, walkthroughs, testing, and evaluation

Rule watch, updated August 27, 2026: The SEC proposed changes to accelerated- and large-accelerated-filer definitions on May 19, 2026. The proposal is not current law; confirm final rule status before relying on filer thresholds. See the SEC proposal.

Few regulatory requirements have shaped the modern public company finance function as profoundly as Section 404 of the Sarbanes-Oxley Act of 2002. SOX 404 establishes management ICFR assessment and reporting requirements and, for covered filers, an independent auditor-attestation requirement. For pre-IPO companies, management-side SOX readiness can be a substantial workstream on the path to public markets.

404(a) and 404(b): The Two Requirements

Section 404(a): Management assesses the effectiveness of the company's ICFR and includes its internal-control report in the annual report when the requirement applies. Emerging growth company or smaller reporting company status does not, by itself, remove management's 404(a) obligation after applicable newly public-company transition relief.

Section 404(b): An independent registered public accounting firm audits ICFR and reports an opinion on effectiveness. Under current SEC accelerated-filer rules, an accelerated filer generally has public float of at least $75 million but less than $700 million, and a large accelerated filer generally has public float of $700 million or more. The definitions also require at least 12 calendar months of Exchange Act reporting and at least one filed annual report. An issuer eligible as a smaller reporting company under the revenue test — generally annual revenues below $100 million and public float below $700 million, or no public float — is excluded from accelerated-filer status. Emerging-growth-company relief and other transition rules also can change when 404(b) begins; an EGC can lose its status before the end of the maximum five-year period if an earlier statutory condition is met.

The COSO Framework

SEC rules require management to use a suitable, recognized control framework to assess ICFR. The COSO Internal Control — Integrated Framework (2013) is commonly used, but the SEC does not mandate COSO. COSO defines five components and 17 underlying principles:

Control Environment: Tone at the top, commitment to integrity, board oversight, organizational structure, accountability.

Risk Assessment: Specifying objectives, identifying and analyzing risks, assessing fraud risk, identifying and assessing changes.

Control Activities: Selecting and developing control activities, deploying through policies and procedures, leveraging technology.

Information and Communication: Generating relevant information, communicating internally, communicating externally.

Monitoring Activities: Conducting ongoing and separate evaluations, evaluating and communicating deficiencies.

When management uses COSO, an effective system requires the five components to be present and functioning and to operate together; the 17 principles support management's evaluation of those components.

Entity-Level vs. Process-Level Controls

SOX programs distinguish between two layers:

Entity-Level Controls (ELCs): Controls that pervade across the organization — board oversight, code of ethics, whistleblower programs, monitoring activities, period-end financial reporting processes. ELCs are evaluated for both design and operating effectiveness.

Process-Level Controls: Controls embedded in specific transaction cycles — revenue recognition, procurement, payroll, treasury, financial close. For each significant account and disclosure, management identifies the relevant assertions (existence, completeness, accuracy, valuation, rights/obligations, presentation) and designs controls to address risks.

The Top-Down Risk Assessment

PCAOB AS 2201 requires auditors to use a top-down approach in the ICFR audit. SEC guidance separately supports a risk-based evaluation by management. In practice, the two workstreams commonly follow these steps:

1. Identify financial reporting risks at the entity level.

2. Identify significant accounts, disclosures, and relevant assertions based on quantitative and qualitative materiality.

3. Identify likely sources of misstatement for each significant account.

4. Identify controls that address those misstatements.

5. Test the design and operating effectiveness of the identified controls.

This methodology is intended to focus testing on the controls most relevant to financial statement risk, rather than testing every control in the organization.

Information Technology General Controls (ITGCs)

When automated controls or system-generated reports are in scope, teams evaluate the relevant IT general controls over ERP platforms, billing systems, payroll systems, treasury workstations, and other financial-reporting technology. Common ITGC categories include:

Access management: User provisioning, deprovisioning, periodic access reviews, segregation of duties.

Change management: Authorization, testing, and approval of system changes.

IT operations: Job scheduling, backup, recovery, incident management.

Deficient ITGCs can reduce the ability to rely on affected automated controls or system-generated reports and may increase the other procedures needed to support the ICFR conclusion.

The Period-End Financial Reporting Process (PEFR)

The PEFR — closing the books, preparing journal entries, and drafting the financial statements — is often a high-focus area. Auditors evaluate the relevant risks and controls, including close procedures, journal entry controls, reconciliation reviews, and management review of the financial statements and disclosures.

Material Weakness vs. Significant Deficiency

The SEC and PCAOB define three categories of control deficiency:

Control Deficiency: A control fails to operate as designed, or no control exists for a relevant risk.

Significant Deficiency: A deficiency or combination of deficiencies less severe than a material weakness, yet important enough to merit attention by those responsible for oversight.

Material Weakness: A reasonable possibility that a material misstatement of the company's financial statements will not be prevented or detected on a timely basis.

If one or more material weaknesses exist, management cannot conclude that ICFR is effective. The annual report must describe material weaknesses, and the issue can affect remediation work, audit scope, reporting timelines, and related disclosures.

The Pre-IPO Readiness Roadmap

SOX readiness timing varies with the issuer's reporting status, systems, staffing, control maturity, and remediation needs. Pre-IPO teams should begin early enough to design controls, operate them, test them, and remediate deficiencies before the applicable reporting date. A practical roadmap includes:

1. Assess current state: Document existing controls, identify gaps.

2. Design and implement controls: Build the control framework around significant accounts.

3. Document policies and procedures: Written narratives, flowcharts, control matrices.

4. Implement supporting technology: ERP enhancements, GRC platforms, automated controls.

5. Operate controls and gather evidence: Several months of evidence is needed for testing.

6. Test controls: Internal audit or external advisors test design and operating effectiveness.

7. Remediate deficiencies: Iterate until the control environment is effective.

8. Auditor walkthroughs and testing: When Section 404(b) applies, the external auditor performs its own evaluation under PCAOB AS 2201.

Common Pitfalls in SOX Implementation

• Underestimating the documentation effort — narratives, control matrices, and evidence must be complete, current, and reviewable.

• Treating SOX as a project rather than an ongoing operating function.

• Insufficient segregation of duties in finance and IT teams (especially in startups).

• Inadequate journal entry controls — particularly review of manual journal entries.

• Reliance on key reports without ITGC support for the underlying system.

• Failure to test ELCs as rigorously as process-level controls.

• Late identification of material weaknesses, leaving insufficient time for remediation before the 10-K filing.

Budgeting for SOX Compliance

SOX compliance is resource-intensive, and the cost depends on company size, system complexity, number of significant processes, locations, remediation needs, internal audit staffing, external advisor support, and the external auditor's ability to rely on management testing. The practical budgeting question is not only the advisory fee; it is whether controls can operate long enough to produce evidence before management and the auditor need to conclude.

The Bottom Line

SOX 404 is not a checklist exercise. It is financial-reporting infrastructure that requires sustained investment, clear ownership, and integration with the business. Starting management-side readiness early gives pre-IPO teams more time to identify gaps, operate controls, retain evidence, and remediate deficiencies before the applicable annual-reporting requirements begin.

Need SOX 404 Readiness Support?

Request management-side help scoping controls, organizing evidence, and planning remediation. SEC-issuer audit and attestation remain with a qualified PCAOB-registered firm.

Request SOX 404 Support →
The Footnote

Where the real numbers live.

Tax strategy, capital markets insight, and planning moves — straight from Kurt's desk, monthly.

Monthly. No spam. Unsubscribe anytime.