SOX Internal Control Testing Checklist Template

A control test is worth only what a reviewer can re-perform from the file. A sample nobody can reproduce, a system report nobody checked, or an exception closed without a severity decision turns a passing control into rework in the fourth quarter.

This free SOX control testing checklist runs one test cycle for a US-listed company: a quarterly round of management testing, an interim cycle, or the year-end roll-forward. Built for SOX leads, internal audit and co-source testers, it takes each key control from walkthrough and test of design through sampling, operating effectiveness testing, severity rating and retest. Every cycle ends with a reviewed test file, a deficiency log and a hand-off pack your external auditor can re-perform.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Two Tests per Control, and a Decision When One Fails

The annual SOX programme decides which controls are in scope. This checklist starts after that decision and produces evidence about each control due this cycle. If you need the programme itself (scoping, filer status, 302 certifications and the 404(a) report), use the SOX 404 Compliance Checklist.

The vocabulary comes from PCAOB AS 2201, adopted in 2007 as Auditing Standard No. 5. It governs the external auditor, not management. SEC Rule 13a-15(c) accepts many ways of evaluating internal control, with the SEC’s 2007 interpretive guidance as one route that satisfies it. Most testing teams still work to the auditor’s standard, because the auditor can use management’s testing only when it meets the auditor’s bar for competence and objectivity (AS 2201.16–.19). AS 2201 also separates two kinds of failure. A design deficiency means the control is missing, or would not meet its objective even if performed perfectly. An operating deficiency means a well-designed control was not performed as designed, or was performed by someone without the authority or competence to do it.

Test of design

Would this control catch a material misstatement?

Method: a walkthrough of one transaction, with inquiry, observation and inspection (AS 2201.42–.43).

Evidence: the control objective, the assertion covered, the precision of any review and the data it relies on.

If it fails: stop. Sampling a badly designed control proves nothing.

Test of operating effectiveness

Did it work every time in the period?

Method: inspection or re-performance of a sample across the period; inquiry alone is never enough (AS 2201.50).

Evidence: the population, the selection method, results per sample and the reviewer’s sign-off.

If it fails: investigate, then extend, compensate or conclude it is ineffective.

Rating an exception

Severity depends on what could happen, not what did

AS 2201.63–.64 rates a deficiency by two things: whether there is a reasonable possibility the controls will fail to prevent or detect a misstatement, and how large that misstatement could be. Whether a misstatement actually occurred does not decide it. A clean reconciliation this quarter does not make a missed review a minor finding.

What the SOX Internal Control Testing Checklist Covers

Five phases run every cycle. Phases 5 and 6 appear only when testing finds exceptions or earlier deficiencies still need a retest. Paragraph references are to PCAOB AS 2201.

Phase 1

Phase 1: Plan the Test Cycle

The first task records the cycle type and whether deficiencies from earlier cycles are still open. Those answers switch on the roll-forward task in Phase 4 and the retest phase.

  • Open the cycle and list the controls due for testing — from the risk and control matrix, with owner, frequency, risk rating and test script for each
  • Record changes since the last cycle — new systems, redesigned processes and new control owners; each is a reason to walk the control again
  • Confirm which tests the external auditor plans to use — and agree sample sizes and timing with them before fieldwork, not after
  • Assign testers who are independent of each control — nobody tests a control they perform or one owned by their manager
  • Send evidence requests to control owners — populations, reports and approvals needed, each with a due date
Phase 2

Phase 2: Walkthroughs & Test of Design

  • Walk one transaction through each process end to end — from initiation to the general ledger, using the same documents and systems as the team (.37)
  • Ask probing questions at each control point — what the performer checks, what they do with an exception and who covers absences (.38)
  • Conclude whether each control would prevent or detect a material misstatement — record the objective and the assertion it covers (.42)
  • Document the precision of every review control — the expectation, the threshold for investigation and how differences are resolved
  • Record the design conclusion before any sampling — a control that fails design goes straight to the deficiency log
Phase 3

Phase 3: Populations & Sample Selection

  • Obtain the complete population for the test period — every occurrence of the control, reconciled to a system or ledger total
  • Test the completeness and accuracy of reports the control uses — system reports and spreadsheets need their own evidence before you rely on them
  • Set each sample size from the control’s frequency and risk — using your testing methodology, not a number chosen on the day
  • Select samples across the whole period — random or systematic, not all from one month, one site or one approver
  • Record the selection method and any random seed — so a reviewer or auditor can reproduce the same selection
Phase 4

Phase 4: Test Operating Effectiveness

The roll-forward task appears only in the year-end cycle. The last task asks whether any exceptions were found, which decides whether Phase 5 appears.

  • Inspect or re-perform each sample against the test script — record the attribute tested and the result for every item
  • Confirm the performer had the authority and competence — the right person approved, within their delegated limit (.44)
  • Benchmark unchanged automated controls — only where IT general controls over program change are effective and tested (.B28–.B29)
  • Review SOC 1 reports for outsourced processes — check the period, the controls tested and exceptions, and ask what changed since (.B21, .B24)
  • Roll interim results forward to the year end — for controls tested early, obtain evidence for the remaining period (.55–.56)
  • Record the conclusion for each control with evidence attached — effective, or exceptions found and passed to evaluation
Phase 5

Phase 5: Exceptions & Deficiency Evaluation

Shown only when Phase 4 records at least one exception.

  • Investigate the cause of each exception — one-off error, a misunderstood control or a gap in the design
  • Decide how to respond — extend the sample, test a compensating control, or conclude the control is ineffective
  • Test any compensating control for precision — it counts only if it would catch a misstatement that could be material (.68)
  • Rate each deficiency — deficiency, significant deficiency or material weakness, by likelihood and magnitude (.63–.67)
  • Aggregate related deficiencies — several findings on one account, disclosure or assertion can add up to a material weakness
  • Check the indicators of a material weakness — senior management fraud, a restatement, a misstatement the controls missed, weak audit committee oversight (.69)
Phase 6

Phase 6: Remediation & Retest

Shown when this cycle found exceptions, or when Phase 1 recorded deficiencies from earlier cycles that still need a retest.

  • Agree a remediation plan with each control owner — root cause, the fix or redesigned control, an owner and a target date
  • Let the fixed control run long enough to sample — enough occurrences to test at the same sample size as the original test
  • Retest the design and operation of the new control — a new control in place long enough can replace the superseded one (.53)
  • Close a deficiency only with passing retest evidence — a fix made after the year end cannot make that year’s controls effective
Phase 7

Phase 7: Review, Sign-Off & Auditor Hand-Off

Assign the review tasks to someone who did not perform the testing.

  • Review every test file — re-perform part of each test, clear review notes and sign the file
  • Summarise the cycle — controls tested, passed and failed, and open deficiencies by severity and owner
  • Report significant deficiencies and material weaknesses to the CFO — the certifying officers must disclose them to the auditor and audit committee
  • Flag any material change in internal control this quarter — an input to the change in ICFR disclosure in the periodic report
  • Hand the test files to the external auditor — populations, selections, evidence and review sign-off in the agreed format

Sample Sizes by Control Frequency

No rule sets SOX sample sizes. AS 2201 says only that evidence should increase with the risk of the control (.46), that a control does not have to operate without any deviation to be effective (.48), and that testing closer to the year end gives more evidence (.52). The sizes in common use are audit firm practice guidance. The table shows one published example: the illustrative minimums for manual controls in KPMG’s 2004 guide to management’s Section 404 assessment, written under the predecessor standard, which KPMG said management should not simply adopt. Agree your own methodology with your auditor, and treat the table as a starting point, not legal advice.

Control frequency Occurrences a year Example minimum sample (KPMG, 2004) What testers get wrong
Annual11Testing it before it has run for the current year
Quarterly42–3Leaving out the fourth-quarter occurrence at year end
Monthly122–4Treating the review sign-off as the test
WeeklyAbout 525–10Picking weeks from one quarter only
DailyAbout 250 working days15–30Not proving the population is complete
Recurring manual (many times a day)Hundreds or thousands30–60Selecting items by hand rather than at random
AutomatedContinuousOne test of each configuration, when IT general controls are effectiveAssuming nothing changed without checking change logs

Practice varies more for frequent controls. A 2015 American Accounting Association study of sampling policies at the Big Four and two other international firms found planning inputs that give 22 to 59 items, usually planning for zero deviations. After a deviation, some firms double the sample while others turn to compensating controls or more substantive testing.

Two SEC proposals from May 2026 could change the rhythm of this work. One would let companies file a semiannual report instead of quarterly 10-Qs, with certifications twice a year. The other would limit the auditor’s 404(b) attestation to large accelerated filers with at least $2 billion of public float. At the time of review both were proposals, not final rules, and neither would remove management’s own annual assessment, so plan testing against the current rules.

Why Run Your SOX Control Testing in CheckFlow?

1

Every cycle starts on time

A recurring schedule opens the cycle each quarter, and dynamic due dates count evidence requests and fieldwork back from the date the auditor expects the files. A late request shows up weeks before year end.

2

Exceptions cannot be skipped

Conditional logic reads the exceptions answer at the end of Phase 4. Record an exception and the evaluation and retest phases appear with owners and due dates. Enforced step order keeps the design conclusion ahead of sampling, and a table inside the task holds each sample’s result.

3

A file the auditor can re-perform

Populations, selections and evidence sit on the task they support. The reviewer’s sign-off runs as an approval, the activity trail records who did what and when, and template versioning shows which test steps applied in each quarter.

CheckFlow is not a GRC platform or an audit firm, and it does not give an opinion on your controls. It runs the testing work, evidence and sign-offs your team and auditor rely on. Our guide to financial services workflow automation places quarterly SOX testing among the other recurring compliance reviews a regulated firm runs, and the SOX 404 Compliance Checklist collects each cycle’s results into management’s annual assessment.

Access conflicts in finance systems often cause design deficiencies. The Segregation of Duties Review Checklist finds and resolves them before your testers do.

Frequently Asked Questions

How many samples do you need for SOX control testing?

+

There is no regulatory number. Sample sizes come from your testing methodology and should rise with the risk of the control. Published audit firm examples, such as KPMG’s 2004 guidance, suggest one sample for an annual control, two or three for a quarterly control, two to four for a monthly one and larger samples for daily or more frequent controls. Where your auditor plans to use your testing, agree the sizes with them before fieldwork.

What is the difference between a walkthrough and a test of operating effectiveness?

+

A walkthrough follows one transaction from initiation to the ledger to understand the process and judge whether each control is designed to catch a misstatement. A test of operating effectiveness checks a sample of occurrences across the period to show the control actually worked each time. Depending on the risk of the control, AS 2201 says a walkthrough might also give enough evidence of operation, but most key controls need a sample.

Can the external auditor rely on internal audit’s SOX testing?

+

Yes, to a degree the auditor decides. Under AS 2201.16–.19 the auditor may use work by internal audit, other company staff or third parties, after assessing their competence and objectivity. The higher the risk of the control, the more the auditor must test it directly. Testers who report to the people running the controls are less objective, which is why the checklist assigns independent testers in Phase 1.

What happens when a SOX control test finds an exception?

+

Find out why it happened, then choose a response: extend the sample if you believe it was isolated, test a compensating control that is precise enough to catch a material misstatement, or conclude the control is ineffective. Each deficiency is then rated, alone and with related findings. A single exception does not automatically make a control ineffective, because AS 2201 accepts that controls can operate with some deviation.

How long must a remediated control operate before it is retested?

+

Long enough to produce the number of occurrences your methodology needs for that frequency. A quarterly control fixed in the third quarter may give only one occurrence before the year end, which is why remediation deadlines should sit well before it. AS 2201.53 lets the auditor test the new control instead of the one it replaced, if it has operated long enough to be tested.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Test Files Your Auditor Can Re-Perform, Every Quarter

Free trial — no credit card required.