Audit Readiness, Corporate Tax Strategy & Fiduciary GovernancePlaybook3 min readUpdated September 2026

Building a SOX 404 Program Before You Have To

Section 404 compliance sounds like a public-company problem until you actually become one, at which point you discover how long it takes to build internal controls that a walkthrough, let alone an external auditor, will actually accept. Companies that start this work only after an S-1 is filed are usually the ones scrambling through their first attestation cycle.

Here's the process broken into the order it actually has to happen in, from scoping to sustained evidence collection.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Scope before you document anything

Start by identifying which financial statement accounts and processes actually carry material risk of misstatement: revenue recognition, payroll, inventory, whatever genuinely moves the numbers that matter for your business, rather than trying to document every process in the company at once. A risk assessment that ties specific accounts to specific processes is what keeps the scope from ballooning into documenting every spreadsheet anyone touches, and it's also what an auditor will ask to see first: not your control matrix, but the reasoning behind why those particular processes made the list.

How do you document process narratives and control points?

For each in-scope process, write a narrative describing how a transaction actually flows from start to finish, then identify the specific points in that flow where something could go wrong and a control catches it: an approval before a payment goes out, a reconciliation that would surface an error, a segregation of duties that keeps one person from both initiating and approving the same transaction. Classify each control as preventive or detective, and as manual or automated, since that classification drives how you'll test it later. Don't skip entity-level controls either, board oversight, a code of conduct, a whistleblower channel, since those get evaluated alongside the process-level ones.

Test design first, then operating effectiveness

A walkthrough tests whether a control's design would actually catch the risk it's meant to address, which is a different question from whether it operated the way it's supposed to every time. Once design looks sound, testing operating effectiveness means sampling actual instances of the control over a period and confirming it happened as documented. A control that operates daily needs a larger sample to support a conclusion than one that operates quarterly, and skipping straight to a small sample on a frequently operating control is a common way testing looks complete but isn't.

How do you classify and remediate control gaps?

Not every gap you find is the same severity. A minor issue that's unlikely to matter on its own is a control deficiency; something important enough that the audit committee should know about it is a significant deficiency; and a gap where there's a reasonable possibility a material misstatement wouldn't be prevented or detected in a timely way is a material weakness, the classification that draws the most attention from investors and auditors alike. Remediate promptly once you've classified something, and retest after the fix before declaring it resolved, since an unretested remediation is still an open item as far as an auditor is concerned. Keep a written log of every deficiency, its classification, the remediation taken, and the retest date, so the history is there the next time someone asks how a prior-year issue was actually closed out.

Sustaining it without rebuilding evidence every quarter

The first year of building a controls program is mostly documentation work; every year after that is mostly evidence collection, and manually screenshotting approvals and reconciliations at quarter-end doesn't scale past a handful of controls. Continuous-controls platforms, which started in the SOC 2 world, can pull evidence directly from the systems where the control actually happens instead of relying on someone remembering to capture it manually, but confirm which SOX and IT general controls a given platform actually covers before you rely on it. That shift, from evidence assembled after the fact to evidence collected as the control runs, is what keeps a controls program sustainable once it's built, rather than something the team dreads rebuilding from scratch every single quarter close.

Build the program in this order:

  1. Scope the accounts and processes that carry material misstatement risk, such as revenue recognition and payroll, instead of documenting everything at once.
  2. Write a process narrative for each in-scope process and mark the control points, like approvals, reconciliations and segregation of duties.
  3. Test control design through walkthroughs, then test operating effectiveness by sampling real instances of each control over a period.
  4. Classify each gap as a control deficiency, significant deficiency or material weakness, and remediate the most serious ones first.
  5. Move to ongoing evidence collection, using continuous-controls tooling where it can pull evidence directly from the source systems.
Executive Capability Standard

What Good Looks Like

In-scope processes have documented narratives and control points, tested for both design and operating effectiveness, with deficiencies classified and remediated on a defined timeline rather than left open indefinitely.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Run a risk assessment identifying which financial statement accounts and processes actually carry material misstatement risk for your business.
2. Do Manually:Write process narratives and a control matrix for your top few in-scope processes, classifying each control as preventive or detective, manual or automated.
3. Delegate:Have an internal controls lead or outside advisor run walkthroughs and sample testing on a defined schedule, not on an ad hoc basis.
4. Automate:Move evidence collection for automated controls into a continuous-controls platform such as Vanta or Drata rather than gathering it manually each quarter.
5. Buy:Bring in outside SOX readiness advisors for your first full cycle if your internal team has never built or tested a controls program before.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

When do we actually have to comply with SOX 404?

Management's own assessment of internal controls, under 404(a), applies once you're a public reporting company. External auditor attestation of those controls, under 404(b), has exemptions and delays for emerging growth companies and smaller non-accelerated filers, so the two requirements don't necessarily start on the same timeline.

What's the difference between a significant deficiency and a material weakness?

A significant deficiency is important enough to merit attention from the audit committee, but doesn't rise to the level of a material weakness. A material weakness exists when there's a reasonable possibility a material misstatement wouldn't be prevented or detected in a timely way, which is the more severe classification and the one investors and auditors focus on most.

Do we need a SOX program before we actually IPO?

Starting the scoping, documentation, and testing work well before an S-1 is filed is what keeps the first attestation cycle from becoming a scramble. Building process narratives and testing controls takes real time, and companies that wait until the IPO year to start are usually the ones that struggle to get through their first cycle cleanly.

Can automated evidence collection replace manual control testing entirely?

It replaces the manual work of gathering evidence, not the judgment involved in evaluating whether a control's design actually addresses the risk. A continuous-controls platform can pull the evidence that a control operated; someone still has to assess whether the control, and the evidence behind it, actually supports the conclusion you need.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides