SOX 404 / ICFR
Evidence request list. 19 controls, 19 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Business Process
Per SOX 404: business process controls including Revenue + Procure-to-Pay + HR/Payroll + Inventory + Treasury + each tied to financial statement assertions.
- SOX 404 evidence for SOX404-3
- ELC + ITGC + deficiency partial
Deficiency
Per SOX 404 + PCAOB AS 2201: deficiency evaluation + classification + remediation + retest.
- SOX 404 evidence for SOX404-5
- ELC + ITGC + deficiency partial
Entity Level Control Activities
A board-approved code of conduct exists, is communicated to all employees, and acknowledgement is obtained at hire and annually.
- Code of Conduct
- board approval minutes
- communication plan
- signed acknowledgements
- annual training completion records
- ethics hotline reports
- Code of Conduct not refreshed for current risks such as third-party and data ethics
- Annual attestation tracking incomplete for contractors and joint venture personnel
- Violations and follow-up actions not summarized to the Audit Committee
- Training completion not reconciled to active employee population
- Walkthroughs not refreshed annually for the attestation process
Sub-certifications from process owners support CEO/CFO Section 302 and 906 certifications.
- certification process
- sub-cert template
- signed sub-certifications
- exception escalations
- Sub-certification population not reconciled to organizational structure each quarter
- Sub-certifiers attest without documented evidence of their underlying review
- Exceptions raised in sub-certifications not tracked to closure
- Sub-certification questions not refreshed for new risks or business changes
- Walkthroughs of the sub-certification process not refreshed annually
The audit committee oversees ICFR, financial reporting, and external auditor independence with documented charter and meeting cadence.
- audit committee charter
- independence assessments
- meeting minutes
- Agendas
- executive session records
- auditor communications
- Audit Committee charter not refreshed when responsibilities change
- Executive sessions with external auditor and internal audit not consistently held
- Committee not evidencing review of significant estimates and judgments
- Pre-approval policy for non-audit services not consistently followed
- Minutes do not document challenge of management or follow-up on prior items
Anonymous reporting mechanism exists for accounting and audit concerns with audit committee escalation.
- whistleblower policy
- hotline vendor contract
- complaint log
- investigation files
- audit committee reports
- Hotline availability not communicated in all languages and locations
- Intake and triage procedures not documented with target response times
- Investigation outcomes not summarized for the Audit Committee with trends
- Retaliation protections not tested through periodic surveys or sampling
- Hotline coverage not extended to third parties such as vendors and customers
Management performs annual ICFR risk assessment identifying significant accounts, disclosures, and risks of material misstatement.
- risk assessment methodology
- scoping memo
- risk register
- materiality calculation
- significant account analysis
- Risk assessment not refreshed when business model, geography, or systems change
- Fraud risks not addressed with the same rigor as financial reporting risks
- Risk ranking methodology not documented or not applied consistently
- Linkage from identified risks to specific controls not maintained
- Output not communicated to process owners or the Audit Committee
Board-approved delegation of authority matrix defines approval limits for commitments, expenditures, and contracts.
- DOA policy
- board resolutions
- approval evidence for transactions above thresholds
- system configuration
- Delegation of authority not reconciled to system approval limits across ERP and banking
- Re-delegation in absence of approver not documented or not time-bound
- Out-of-policy approvals not escalated or remediated
- Authority matrix not refreshed when roles and reporting lines change
- Compensating controls not documented when the approver is unavailable
Background checks are performed for personnel in roles with financial reporting responsibility.
- HR policy
- background check vendor agreement
- completed checks
- exception approvals
- Background check evidence not retained for finance-sensitive roles
- Re-screening cadence for elevated roles not defined or not executed
- Contractor and acquired entity populations not in scope of standard process
- Adverse findings not subject to a documented adjudication standard
- Walkthroughs of hiring controls not refreshed annually
Performance reviews and incentive compensation align with control responsibilities and ethical behavior.
- compensation philosophy
- performance review templates
- completed reviews
- compensation committee approvals
- Incentive plans not assessed for fraud risk or earnings management pressure
- Clawback and recoupment provisions not consistently embedded in awards
- Performance criteria not reconciled to reported financial outcomes
- Calibration committee documentation not retained
- Compensation Committee oversight of executive incentives not evidenced
Internal audit reports functionally to the audit committee and executes risk-based audit plan covering ICFR.
- IA charter
- annual audit plan
- audit reports
- issue tracker
- audit committee status reports
- Internal Audit plan not refreshed for changes in risk or business operations
- Coverage of ICFR not reconciled to the SOX risk universe
- Findings tracked to closure but root cause and theme analysis missing
- Quality Assurance and Improvement Program not in place or stale
- Reporting lines or budget not aligned with independence expectations
Disclosure committee reviews periodic SEC filings (10-K, 10-Q) and certifies completeness and accuracy of disclosures.
- disclosure committee charter
- DCL checklists
- meeting minutes
- Sub-certifications
- filing approval
- Disclosure Committee charter not refreshed for new disclosure topics
- Cross functional representation incomplete for areas such as legal and IT
- Materials and minutes do not evidence challenge of significant disclosures
- Quarterly cadence not aligned with filing timelines
- Walkthroughs of the Disclosure Committee process not refreshed annually
Entity-Level
Per Sarbanes-Oxley Section 404 + PCAOB AS 2201: Entity-Level Controls. Requirements include (a) control environment + (b) risk assessment + (c) information and communication + (d) monitoring + (e) management oversight.
- SOX 404 evidence for SOX404-1
- ELC + ITGC + deficiency partial
FRP
Per SOX 404: Period-End FRP including account reconciliations + close checklist + management review + significant estimates and judgments.
- SOX 404 evidence for SOX404-2
- ELC + ITGC + deficiency partial
Fraud Risk and Management Override
Annual fraud risk assessment identifies schemes, considers incentives/pressures, opportunities, and rationalizations.
- fraud risk methodology
- fraud risk register
- control mapping
- mitigation plans
- Fraud risk assessment treated as a checkbox rather than a tailored exercise
- Schemes not mapped to specific accounts, assertions, and processes
- Anti-fraud programs not linked to identified scheme risks
- Assessment not refreshed when business model or incentives change
- Output not communicated to process owners or the Audit Committee
Controls mitigate management override risk including independent review of top-side journal entries and unusual transactions.
- override risk policy
- top-side JE review
- audit committee review of estimates
- related party transactions
- Top-side and topside-only entries not separately identified and reviewed
- Manual journal entries posted by management without independent review
- Late entries near period close not subject to enhanced scrutiny
- Compensating controls not documented when normal segregation fails
- Reports used to identify override risk are IPE without ITGC testing
Manual journal entries are reviewed and approved by someone other than the preparer with supporting documentation.
- JE policy
- approval matrix
- approved JEs with support
- exception reports
- Risk-based criteria for entry selection not defined or not refreshed
- Same user posts and approves entries below threshold, breaking segregation
- Support documentation not consistently attached for manual entries
- Review of high-risk entries evidenced only by signature without documented inquiry
- Recurring or templated entries not periodically validated for continued validity
Annual conflict of interest disclosures are obtained from directors, officers, and key employees.
- COI policy
- completed disclosures
- review and resolution log
- Disclosure population incomplete for contractors, board, and acquired entity staff
- Disclosed conflicts not adjudicated or mitigated with documented plans
- Annual refresh not reconciled to current employee and contractor lists
- Related party disclosures not reconciled to vendor and customer master data
- Walkthroughs of the conflict disclosure process not refreshed annually
ITGC
Per SOX 404 + COBIT: ITGC including access management + change management + computer operations + program development + backup + recovery.
- SOX 404 evidence for SOX404-4
- ELC + ITGC + deficiency partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.