SOX 404 Compliance Checklist Template

A material weakness is usually reported at year end, but it rarely starts there. It starts with a scoping decision nobody revisited, a control owner who left in March, or a system change that never reached the risk and control matrix.

From its second annual report onwards, every company filing a 10-K must report on its internal control over financial reporting. This free SOX 404 compliance checklist runs that annual programme for controllers, SOX leads and internal audit: scoping, documentation, the testing plan, deficiency evaluation, the quarterly 302 certifications and management’s 404(a) report. A conditional phase adds auditor coordination when your filer status requires a 404(b) attestation. The result is one dated, signed record of how management reached its conclusion.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Section 302, 404(a) and 404(b): Three Different Deliverables

“SOX compliance” is three obligations with different owners and cadences. The certifications come every quarter. Management’s assessment is annual but built from work across the year. The auditor’s attestation depends on filer status, and many smaller registrants never need one.

The SEC does not prescribe how management should evaluate its controls. Its 2007 interpretive guidance describes a top-down, risk-based evaluation focused on the controls that address the risk of material misstatement, and a company following it satisfies the annual evaluation requirement. Auditors apply the same logic under PCAOB AS 2201, so this checklist starts from the financial statements, not last year’s control list.

Section 302

CEO and CFO certifications

When: every 10-Q and 10-K.

Covers: the report is not misleading, the conclusion on disclosure controls, and material changes in internal control.

Also: significant deficiencies, material weaknesses and relevant fraud disclosed to the auditor and audit committee.

Section 404(a)

Management’s report on ICFR

When: annually, as of the fiscal year end.

Covers: management’s responsibility, the framework used and a conclusion on effectiveness.

Rule: any material weakness means ICFR cannot be concluded effective.

Section 404(b)

The auditor’s attestation

When: annually, in an integrated audit with the financial statements.

Who: accelerated and large accelerated filers that are not emerging growth companies.

Standard: PCAOB AS 2201.

Filer position 302 certifications 404(a) report 404(b) attestation
Large accelerated filer: public float of $700 million or moreYesYesYes, unless an emerging growth company
Accelerated filer: public float of $75 million to under $700 million, unless the revenue test below appliesYesYesYes, unless an emerging growth company
Non-accelerated filer, including a smaller reporting company with revenue under $100 millionYesYesNo
Emerging growth companyYesYesNo, while EGC status lasts
First annual report after an IPOYesNot yet: a transition statement insteadNot yet

What the SOX 404 Compliance Checklist Covers

Six phases take the programme from scoping to the signed 10-K. A seventh appears only when your filer status requires an auditor’s attestation.

Phase 1

Phase 1: Confirm Filer Status & Programme Scope

The filer status and first-annual-report answers on the first task decide which Phase 6 tasks appear and whether Phase 7 appears at all.

  • Record the fiscal year and filer status — large accelerated, accelerated or non-accelerated, whether the company is an emerging growth company, and whether this is its first annual report
  • Carry forward open deficiencies and actions — from last year’s evaluation, the auditor’s communications and internal audit reports
  • Confirm the control framework and materiality — COSO 2013 as the recognised framework Rule 13a-15(c) requires, and the materiality figures agreed with the CFO
  • Record changes since last year — acquisitions, new ERP modules, restructured teams, newly outsourced processes and any generative AI tools now used in financial reporting
  • Agree the programme timetable with the audit committee — interim testing, roll-forward, year-end testing and the 10-K filing date
Phase 2

Phase 2: Top-Down Risk Assessment & Scoping

  • Start at the financial statement level — identify the risks of material misstatement, including fraud risk, and the entity-level controls that address them
  • Select significant accounts and disclosures — by size against materiality and by qualitative risk, each mapped to its relevant assertions
  • Scope locations and business units — by share of consolidated revenue and assets, specific risks and shared service centres
  • List service organisations in scope — obtain their SOC 1 reports and record the complementary user entity controls you must operate
  • Identify the IT systems behind each significant account — ERP, consolidation, payroll and any spreadsheet that feeds a reported figure
  • Approve the scoping memo — signed by the CFO or controller, with the reasoning for every account or location left out
Phase 3

Phase 3: Document Processes & Controls

  • Update process narratives or flowcharts — one per significant process, marking where a misstatement could arise
  • Update the risk and control matrix — each risk linked to its controls, with owner, frequency, key or non-key, preventive or detective, manual or automated
  • Document ITGCs for each in-scope system — user access, change management and IT operations, with the application controls that rely on them
  • Document key reports and spreadsheets — how each control checks the completeness and accuracy of the data it uses
  • Confirm every control owner by name — reassign controls held by leavers or by roles that no longer exist
  • Map controls to the 17 COSO principles — so the evaluation shows each principle present and functioning, not only transaction-level controls
Phase 4

Phase 4: Plan Management Testing

Each test cycle runs as its own checklist using the SOX Internal Control Testing Checklist. This phase sets the plan and collects the results.

  • Write the annual testing plan — which controls, who tests them, when, and how much evidence each needs given its risk
  • Confirm tester competence and objectivity — internal audit, a SOX team or a co-source provider, never the person who operates the control
  • Schedule the interim and roll-forward test cycles — with enough time after interim testing to remediate before year end
  • Test controls that changed during the year — after the change date, so the control in place at year end is the one tested
  • Attach the results of each completed cycle — test conclusions, exceptions and the reviewer’s sign-off
Phase 5

Phase 5: Evaluate Deficiencies & Remediate

  • Log every deficiency in one register — the control, what failed, root cause, owner and the date it was found
  • Assess severity individually and in aggregate — against the AS 2201 definitions of significant deficiency and material weakness, allowing for compensating controls
  • Check for material weakness indicators — fraud by senior management, a restatement, a misstatement the controls missed, ineffective audit committee oversight
  • Remediate and retest before year end — the new control must operate long enough to be tested as effective
  • Report deficiencies to the audit committee — with severity, remediation status and expected completion date
Phase 6

Phase 6: Certify & Report

Each quarter’s certification runs on its own recurring checklist. For a first annual report after an IPO, the transition statement task replaces the management report tasks.

  • Attach each quarter’s 302 certification pack — sub-certifications from process owners, the disclosure controls conclusion and any material change in ICFR
  • Confirm disclosures to the auditor and audit committee — all significant deficiencies, material weaknesses and any fraud involving people with a significant role in ICFR
  • Conclude on ICFR as of the fiscal year end — effective or not effective; one unremediated material weakness means not effective
  • Draft management’s report for the 10-K — responsibility statement, the framework used, the conclusion and any material weakness
  • Include the newly public company transition statement — in place of management’s report, as Item 308 allows for the first annual report
  • Obtain audit committee review and CEO and CFO sign-off — before the 10-K and its certifications are filed
Phase 7 — 404(b) Filers Only

Phase 7: External Auditor Coordination

Shown only when the company is an accelerated or large accelerated filer and not an emerging growth company, and this is not its first annual report.

  • Agree the integrated audit timetable and request list — interim, roll-forward and year-end visits, with an owner for every request
  • Agree which management tests the auditor will use — the auditor weighs testers’ competence and objectivity under AS 2201.16–.19
  • Support walkthroughs and evidence requests on schedule — track each request to closure with the file provided
  • Reconcile deficiency lists with the auditor — agree the population and severity before the audit committee meets
  • File the auditor’s attestation and communications — the report in the 10-K and the written communications in this year’s record

The SEC Rules Behind Each Phase

The Act is brief. The detail sits in the SEC’s Exchange Act rules, Regulation S-K and, for auditors, PCAOB standards. The table maps each requirement to its source and the phase that evidences it. Foreign private issuers and investment companies follow variations of these rules, so treat the table as a starting point, not legal advice.

Requirement Source What it asks for Evidenced in
Maintain disclosure controls and ICFRRule 13a-15(a)Controls designed by or under the supervision of the CEO and CFOPhases 2–3
Recognised control frameworkRule 13a-15(c); COSO 2013A suitable framework set by a body that followed due processPhases 1 and 3
Quarterly disclosure controls evaluationRule 13a-15(b)Effectiveness as of the end of each fiscal quarterPhase 6
Changes in ICFRRule 13a-15(d); Item 308(c)Evaluate and disclose changes that materially affected, or are reasonably likely to materially affect, ICFRPhase 6
Officer certificationsSection 302 (Rule 13a-14(a)); Section 906 (18 U.S.C. 1350)CEO and CFO certifications with each 10-Q and 10-KPhase 6
Management’s annual assessmentSection 404(a); Rule 13a-15(c); Item 308(a)A conclusion on ICFR as of the fiscal year end, disclosing any material weaknessPhases 2–6
Deficiency severityAS 2201, Appendix ADefinitions of deficiency, significant deficiency and material weaknessPhase 5
Auditor attestationSection 404(b); Item 308(b); AS 2201An auditor’s report on ICFR for accelerated and large accelerated filersPhase 7

Two SEC proposals from May 2026 would change parts of this. The filer status proposal of 19 May would raise the large accelerated filer threshold from $700 million to $2 billion of public float and fold accelerated filers into the non-accelerated category, so only large accelerated filers would need a 404(b) attestation. The proposal of 5 May would let companies elect to file a semiannual Form 10-S instead of quarterly 10-Qs, certifying semiannually. Neither would change management’s 404(a) assessment. At the time of review both were proposals only, their comment periods closed in July 2026, so plan against the current rules.

Why Run Your SOX Programme in CheckFlow?

1

One programme, many cycles

A recurring schedule starts this checklist yearly, the certification checklist quarterly and each test cycle on its own date. Dynamic due dates count back from the filing deadline, so a late scoping memo shows months before it squeezes year-end testing.

2

Filer status shapes the checklist

Conditional logic reads the Phase 1 answers. A non-accelerated filer never sees the auditor coordination phase, a newly public company gets the transition statement instead of a management report, and a large accelerated filer cannot skip the tasks it needs.

3

A conclusion the committee can trace

The scoping memo and management’s report run as approvals. RCMs, test results and certification packs sit on the task they support, the activity trail records who signed off and when, and template versioning ties each year to its checklist.

CheckFlow is not a GRC platform or an audit firm, and it does not issue an opinion on your controls. It runs the work, evidence and sign-offs behind management’s assessment. Test steps for each cycle live in the SOX Internal Control Testing Checklist, and CheckFlow’s compliance checklist software shows how the same approach covers your whole compliance calendar.

ERP access conflicts are reviewed with the Segregation of Duties Review Checklist, and many key controls operate inside the Month-End Close Checklist, where reconciliations and journal approvals leave the evidence your testers sample.

Frequently Asked Questions

What is the difference between SOX 302 and SOX 404?

+

Section 302 is a personal CEO and CFO certification with every 10-Q and 10-K. They certify, among other things, their evaluation of disclosure controls and that they have told the auditor and audit committee about significant deficiencies, material weaknesses and relevant fraud. Section 404(a) is management’s annual report on whether internal control over financial reporting is effective as of the year end. Section 404(b) is the auditor’s attestation, required only for some filers.

Does every public company need a SOX 404(b) auditor attestation?

+

No. Only accelerated and large accelerated filers need one, and emerging growth companies are exempt while their status lasts. Since the SEC’s 2020 amendments, a company eligible to be a smaller reporting company with revenue under $100 million is not an accelerated filer. Every registrant still files the 404(a) report and the certifications.

What is a material weakness in internal control?

+

PCAOB AS 2201 defines it as a deficiency, or combination of deficiencies, that creates a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis. A significant deficiency is less severe but still merits the attention of those overseeing financial reporting. Management cannot conclude ICFR is effective while a material weakness exists, and must disclose it.

When does a newly public company have to comply with SOX 404?

+

The 302 certifications apply from the first periodic report. Management’s 404(a) report starts with the second annual report; the first carries a statement that it includes no assessment or attestation. An emerging growth company can defer 404(b) for up to five years after its IPO, unless it loses EGC status sooner, for example by reaching $1.235 billion in annual revenue.

Which framework do companies use for SOX 404?

+

Rule 13a-15(c) requires a suitable, recognised framework, and in the US that is usually COSO’s Internal Control – Integrated Framework (2013), with five components and 17 principles. It superseded the 1992 framework on 15 December 2014. COSO’s February 2026 guidance on generative AI builds on the 2013 framework rather than replacing it.

Is the SEC changing SOX 404(b) or quarterly reporting?

+

It has proposed to. In May 2026 the SEC proposed optional semiannual reporting on a new Form 10-S, and a filer status overhaul that would limit 404(b) to large accelerated filers with at least $2 billion of public float. At the time of review neither had been adopted and no effective date had been set, so the current thresholds and quarterly certifications apply.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

A Year-End Conclusion Built Over Twelve Months, Not Three Weeks

Free trial — no credit card required.