Skip to content

Evidence request lists

SOX 404 / ICFR

Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Business Process

SOX404-3
Business Process Controls (Revenue, Procurement, HR, Inventory)

Per SOX 404: business process controls including Revenue + Procure-to-Pay + HR/Payroll + Inventory + Treasury + each tied to financial statement assertions.

Artefacts an auditor will ask for
  • SOX 404 evidence for SOX404-3
Where this commonly fails
  • ELC + ITGC + deficiency partial

Deficiency

SOX404-5
Deficiency Evaluation and Remediation

Per SOX 404 + PCAOB AS 2201: deficiency evaluation + classification + remediation + retest.

Artefacts an auditor will ask for
  • SOX 404 evidence for SOX404-5
Where this commonly fails
  • ELC + ITGC + deficiency partial

Entity Level Control Activities

ENT-1
Code of Conduct and Ethics

A board-approved code of conduct exists, is communicated to all employees, and acknowledgement is obtained at hire and annually.

Artefacts an auditor will ask for
  • Code of Conduct
  • board approval minutes
  • communication plan
  • signed acknowledgements
  • annual training completion records
  • ethics hotline reports
Where this commonly fails
  • Code of Conduct not refreshed for current risks such as third-party and data ethics
  • Annual attestation tracking incomplete for contractors and joint venture personnel
  • Violations and follow-up actions not summarized to the Audit Committee
  • Training completion not reconciled to active employee population
  • Walkthroughs not refreshed annually for the attestation process
ENT-10
CEO/CFO Sub-Certification Process

Sub-certifications from process owners support CEO/CFO Section 302 and 906 certifications.

Artefacts an auditor will ask for
  • certification process
  • sub-cert template
  • signed sub-certifications
  • exception escalations
Where this commonly fails
  • Sub-certification population not reconciled to organizational structure each quarter
  • Sub-certifiers attest without documented evidence of their underlying review
  • Exceptions raised in sub-certifications not tracked to closure
  • Sub-certification questions not refreshed for new risks or business changes
  • Walkthroughs of the sub-certification process not refreshed annually
ENT-2
Audit Committee Oversight

The audit committee oversees ICFR, financial reporting, and external auditor independence with documented charter and meeting cadence.

Artefacts an auditor will ask for
  • audit committee charter
  • independence assessments
  • meeting minutes
  • Agendas
  • executive session records
  • auditor communications
Where this commonly fails
  • Audit Committee charter not refreshed when responsibilities change
  • Executive sessions with external auditor and internal audit not consistently held
  • Committee not evidencing review of significant estimates and judgments
  • Pre-approval policy for non-audit services not consistently followed
  • Minutes do not document challenge of management or follow-up on prior items
ENT-3
Whistleblower / Ethics Hotline

Anonymous reporting mechanism exists for accounting and audit concerns with audit committee escalation.

Artefacts an auditor will ask for
  • whistleblower policy
  • hotline vendor contract
  • complaint log
  • investigation files
  • audit committee reports
Where this commonly fails
  • Hotline availability not communicated in all languages and locations
  • Intake and triage procedures not documented with target response times
  • Investigation outcomes not summarized for the Audit Committee with trends
  • Retaliation protections not tested through periodic surveys or sampling
  • Hotline coverage not extended to third parties such as vendors and customers
ENT-4
Risk Assessment Process

Management performs annual ICFR risk assessment identifying significant accounts, disclosures, and risks of material misstatement.

Artefacts an auditor will ask for
  • risk assessment methodology
  • scoping memo
  • risk register
  • materiality calculation
  • significant account analysis
Where this commonly fails
  • Risk assessment not refreshed when business model, geography, or systems change
  • Fraud risks not addressed with the same rigor as financial reporting risks
  • Risk ranking methodology not documented or not applied consistently
  • Linkage from identified risks to specific controls not maintained
  • Output not communicated to process owners or the Audit Committee
ENT-5
Delegation of Authority

Board-approved delegation of authority matrix defines approval limits for commitments, expenditures, and contracts.

Artefacts an auditor will ask for
  • DOA policy
  • board resolutions
  • approval evidence for transactions above thresholds
  • system configuration
Where this commonly fails
  • Delegation of authority not reconciled to system approval limits across ERP and banking
  • Re-delegation in absence of approver not documented or not time-bound
  • Out-of-policy approvals not escalated or remediated
  • Authority matrix not refreshed when roles and reporting lines change
  • Compensating controls not documented when the approver is unavailable
ENT-6
Hiring and Background Checks

Background checks are performed for personnel in roles with financial reporting responsibility.

Artefacts an auditor will ask for
  • HR policy
  • background check vendor agreement
  • completed checks
  • exception approvals
Where this commonly fails
  • Background check evidence not retained for finance-sensitive roles
  • Re-screening cadence for elevated roles not defined or not executed
  • Contractor and acquired entity populations not in scope of standard process
  • Adverse findings not subject to a documented adjudication standard
  • Walkthroughs of hiring controls not refreshed annually
ENT-7
Performance Evaluation and Compensation

Performance reviews and incentive compensation align with control responsibilities and ethical behavior.

Artefacts an auditor will ask for
  • compensation philosophy
  • performance review templates
  • completed reviews
  • compensation committee approvals
Where this commonly fails
  • Incentive plans not assessed for fraud risk or earnings management pressure
  • Clawback and recoupment provisions not consistently embedded in awards
  • Performance criteria not reconciled to reported financial outcomes
  • Calibration committee documentation not retained
  • Compensation Committee oversight of executive incentives not evidenced
ENT-8
Internal Audit Function

Internal audit reports functionally to the audit committee and executes risk-based audit plan covering ICFR.

Artefacts an auditor will ask for
  • IA charter
  • annual audit plan
  • audit reports
  • issue tracker
  • audit committee status reports
Where this commonly fails
  • Internal Audit plan not refreshed for changes in risk or business operations
  • Coverage of ICFR not reconciled to the SOX risk universe
  • Findings tracked to closure but root cause and theme analysis missing
  • Quality Assurance and Improvement Program not in place or stale
  • Reporting lines or budget not aligned with independence expectations
ENT-9
Disclosure Committee

Disclosure committee reviews periodic SEC filings (10-K, 10-Q) and certifies completeness and accuracy of disclosures.

Artefacts an auditor will ask for
  • disclosure committee charter
  • DCL checklists
  • meeting minutes
  • Sub-certifications
  • filing approval
Where this commonly fails
  • Disclosure Committee charter not refreshed for new disclosure topics
  • Cross functional representation incomplete for areas such as legal and IT
  • Materials and minutes do not evidence challenge of significant disclosures
  • Quarterly cadence not aligned with filing timelines
  • Walkthroughs of the Disclosure Committee process not refreshed annually

Entity-Level

SOX404-1
Entity-Level Controls (ELC)

Per Sarbanes-Oxley Section 404 + PCAOB AS 2201: Entity-Level Controls. Requirements include (a) control environment + (b) risk assessment + (c) information and communication + (d) monitoring + (e) management oversight.

Artefacts an auditor will ask for
  • SOX 404 evidence for SOX404-1
Where this commonly fails
  • ELC + ITGC + deficiency partial

FRP

SOX404-2
Period-End Financial Reporting Process (FRP)

Per SOX 404: Period-End FRP including account reconciliations + close checklist + management review + significant estimates and judgments.

Artefacts an auditor will ask for
  • SOX 404 evidence for SOX404-2
Where this commonly fails
  • ELC + ITGC + deficiency partial

Fraud Risk and Management Override

FRAUD-1
Fraud Risk Assessment

Annual fraud risk assessment identifies schemes, considers incentives/pressures, opportunities, and rationalizations.

Artefacts an auditor will ask for
  • fraud risk methodology
  • fraud risk register
  • control mapping
  • mitigation plans
Where this commonly fails
  • Fraud risk assessment treated as a checkbox rather than a tailored exercise
  • Schemes not mapped to specific accounts, assertions, and processes
  • Anti-fraud programs not linked to identified scheme risks
  • Assessment not refreshed when business model or incentives change
  • Output not communicated to process owners or the Audit Committee
FRAUD-2
Management Override Controls

Controls mitigate management override risk including independent review of top-side journal entries and unusual transactions.

Artefacts an auditor will ask for
  • override risk policy
  • top-side JE review
  • audit committee review of estimates
  • related party transactions
Where this commonly fails
  • Top-side and topside-only entries not separately identified and reviewed
  • Manual journal entries posted by management without independent review
  • Late entries near period close not subject to enhanced scrutiny
  • Compensating controls not documented when normal segregation fails
  • Reports used to identify override risk are IPE without ITGC testing
FRAUD-3
Journal Entry Review and Approval

Manual journal entries are reviewed and approved by someone other than the preparer with supporting documentation.

Artefacts an auditor will ask for
  • JE policy
  • approval matrix
  • approved JEs with support
  • exception reports
Where this commonly fails
  • Risk-based criteria for entry selection not defined or not refreshed
  • Same user posts and approves entries below threshold, breaking segregation
  • Support documentation not consistently attached for manual entries
  • Review of high-risk entries evidenced only by signature without documented inquiry
  • Recurring or templated entries not periodically validated for continued validity
FRAUD-4
Conflict of Interest Disclosure

Annual conflict of interest disclosures are obtained from directors, officers, and key employees.

Artefacts an auditor will ask for
  • COI policy
  • completed disclosures
  • review and resolution log
Where this commonly fails
  • Disclosure population incomplete for contractors, board, and acquired entity staff
  • Disclosed conflicts not adjudicated or mitigated with documented plans
  • Annual refresh not reconciled to current employee and contractor lists
  • Related party disclosures not reconciled to vendor and customer master data
  • Walkthroughs of the conflict disclosure process not refreshed annually

ITGC

SOX404-4
IT General Controls (ITGC) - Access, Change, Operations

Per SOX 404 + COBIT: ITGC including access management + change management + computer operations + program development + backup + recovery.

Artefacts an auditor will ask for
  • SOX 404 evidence for SOX404-4
Where this commonly fails
  • ELC + ITGC + deficiency partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.