SOX 404(b) compliance requires a public company’s independent external auditor to test and issue a formal opinion on the effectiveness of the company’s internal controls over financial reporting. The requirement applies to accelerated filers and large accelerated filers, with several exemptions that can pull a company out of scope. The auditor’s work is separate from management’s own assessment under Section 404(a) and involves independent testing under Public Company Accounting Oversight Board standards, in what the PCAOB calls an integrated audit.
What Section 404(b) Requires
Section 404 of the Sarbanes-Oxley Act splits into two obligations. Under 404(a), management must assess the effectiveness of internal controls over financial reporting (ICFR) each year and include that assessment in the Form 10-K. Under 404(b), the company’s registered public accounting firm must independently attest to and report on management’s assessment, following PCAOB standards, as part of the same engagement as the financial statement audit rather than a separate one.
The distinction matters in practice. Management designs, documents, and tests its own controls under 404(a), then reports its conclusion. Under 404(b), the external auditor runs independent tests on those same controls and issues its own opinion. If the auditor disagrees with management, or finds problems management missed, the auditor’s opinion is what appears in the filing. The auditor is not rubber-stamping management’s work, and that is where most of the cost and stress of compliance concentrates.
Which Companies Have to Comply
Whether 404(b) applies depends on your SEC filer category, which turns primarily on public float measured at the end of the second fiscal quarter. For calendar-year companies, that is the last business day in June. The measurement is the aggregate worldwide market value of voting and non-voting common equity held by non-affiliates.
Large Accelerated Filers
A large accelerated filer has a public float of $700 million or more. These companies must include the auditor’s ICFR attestation in the annual report and file the 10-K within 60 days after fiscal year-end.
Accelerated Filers
An accelerated filer has a public float of $75 million or more but less than $700 million and has a 75-day 10-K filing deadline. Accelerated filers generally must comply with 404(b), subject to the revenue-based exclusion below.
The Revenue-Based Exclusion
In March 2020, the SEC amended the accelerated filer definition to exclude companies that are eligible to be smaller reporting companies and had annual revenues of less than $100 million in their most recent fiscal year. A company meeting this exclusion is treated as a non-accelerated filer even if its public float sits in the $75 million to $700 million range. It still has to complete the 404(a) management assessment, but the 404(b) auditor attestation is no longer required. If your public float puts you in accelerated-filer territory but your revenue is under $100 million, check this exclusion carefully.
Non-Accelerated Filers
Companies with public float below $75 million are non-accelerated filers and are permanently exempt from 404(b). The Dodd-Frank Act codified this by adding subsection (c) to the statute, stating that the auditor attestation requirement does not apply to issuers that are neither large accelerated filers nor accelerated filers. Non-accelerated filers have 90 days after fiscal year-end to file the 10-K and still owe the 404(a) management assessment.
Emerging Growth Companies
The JOBS Act exempts emerging growth companies (EGCs) from 404(b) regardless of public float. A company qualifies as an EGC if it had total annual gross revenues of less than $1.235 billion in its most recently completed fiscal year. EGC status generally lasts up to five years after IPO, unless the company crosses an exit threshold sooner, such as becoming a large accelerated filer or exceeding the revenue limit.
Foreign Private Issuers
Foreign private issuers listed on U.S. exchanges follow the same filer-category thresholds as domestic issuers, and the 2020 revenue exclusion applies equally. They file annual reports on Form 20-F or 40-F rather than Form 10-K, but the ICFR attestation requirements are substantively the same. Filer status should be evaluated at each fiscal year-end based on public float measured at the end of the second fiscal quarter.
The Framework the Audit Uses
Both management’s 404(a) assessment and the auditor’s 404(b) attestation evaluate controls against a recognized framework, and nearly every public company uses the Committee of Sponsoring Organizations (COSO) Internal Control — Integrated Framework (2013 version). SEC rules require management to identify the framework it used. COSO organizes controls into five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Every documented and tested control should map back to at least one of these components. Auditors evaluate all five, and a gap in any one, particularly the control environment, can undermine an otherwise strong set of transaction-level controls.
How to Prepare for the 404(b) Audit
Preparation is a multi-phase internal project. An SEC study of first-time 404(b) compliers found companies spent an average of roughly 2,900 internal staff hours on Section 404 compliance, not counting external auditor fees.
Scope Based on Risk
Start by identifying the accounts, business units, and financial statement assertions that carry the highest risk of material misstatement. A top-down, risk-based approach focuses effort on areas like revenue recognition, complex estimates, and accounts with high transaction volume or significant judgment. Assertions such as existence, completeness, valuation, and rights and obligations guide which controls need testing for each significant account. The goal is not to test everything.
Document the Processes and Controls
Every in-scope process needs narratives, flowcharts, and identification of the specific controls embedded in it. Documentation must be thorough enough for the external auditor to trace a transaction from initiation through recording and reporting. This work typically culminates in a Risk and Control Matrix that maps each key control to the assertion it addresses, the COSO component it falls under, and the risk it mitigates.
Take IT General Controls Seriously
IT controls are where first-time compliers most often underestimate the effort. The PCAOB requires auditors to understand how information technology affects the flow of transactions and to evaluate IT general controls (ITGCs) as part of the integrated audit. ITGCs cover logical access, change management, computer operations, and information security. If ITGCs are weak, the auditor cannot rely on any automated controls in the affected systems, and the scope of manual testing expands sharply.
Test Design and Operating Effectiveness
Management tests its controls to confirm they are both properly designed and operating effectively. Design effectiveness asks whether the control, if working as intended, would prevent or detect a material misstatement. Operating effectiveness asks whether the control actually worked consistently across the year. This testing supports the 404(a) assessment and previews what the external auditor will find.
Remediate Before Year-End
Management and the auditor evaluate ICFR effectiveness as of the fiscal year-end date, so any deficiency still present at year-end will appear in the reports. Remediating a control in October for a December 31 year-end gives the auditor time to test the fixed control before issuing an opinion. Waiting until December is risky, because the new control may not have operated long enough for the auditor to conclude it works. Companies that find material problems late in the year often face a choice between rushing a fix and accepting an adverse opinion.
What the External Auditor Actually Does
The 404(b) attestation is governed by PCAOB Auditing Standard No. 2201, which requires an integrated audit covering both internal controls and financial statement balances in one coordinated engagement. The auditor does independent work rather than reviewing management’s testing and agreeing.
The auditor uses the same top-down, risk-based approach as management but makes independent judgments about which controls are significant and which assertions carry the greatest risk. It identifies significant accounts and disclosures, evaluates entity-level controls, and works down to the process and transaction level. A strong control environment lets the auditor reduce the extent of detailed transaction testing on the financial statements; a weak one means more substantive procedures and higher audit fees.
The auditor must also evaluate how IT affects the financial reporting process, including the extent of IT involvement in the period-end close. Automated application controls such as system-enforced three-way matching or automated revenue calculations are lower risk when the underlying ITGCs work. When ITGCs fail, every automated control that depends on those systems is treated as unreliable.
The Opinion and the Deficiency Hierarchy
When the audit is complete, the auditor issues a formal opinion on whether the company maintained effective ICFR as of the assessment date. This opinion is separate from the opinion on the financial statements. SEC rules specify that the opinion must be either unqualified or adverse, with a disclaimer available only in rare scope-limitation circumstances. There is no qualified opinion for ICFR.
- Unqualified opinion. The company maintained effective ICFR in all material respects. This is the clean result.
- Adverse opinion. The auditor identified one or more material weaknesses. This is mandatory whenever a material weakness exists; the auditor has no discretion to soften the conclusion.
- Disclaimer of opinion. A scope restriction prevented the auditor from performing enough work to form a conclusion. This is rare and typically signals a serious breakdown in the ability to cooperate with the audit.
The PCAOB defines three levels of control deficiencies, and the distinctions drive disclosure and market consequences. A control deficiency is a weakness in the design or operation of a control that could allow a misstatement to occur; it does not require public disclosure. A significant deficiency is less severe than a material weakness but important enough to merit the attention of those overseeing financial reporting, and must be communicated to the audit committee, though it is not individually disclosed in the auditor’s public report. A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a timely basis. A single material weakness triggers an adverse opinion.
The line between a significant deficiency and a material weakness is where the most contentious auditor-management conversations happen. The auditor evaluates both the likelihood and magnitude of potential misstatement, and a combination of individually minor deficiencies can aggregate into a material weakness when they affect related accounts or processes.
What an Adverse Opinion Costs
An adverse ICFR opinion is more than a footnote. Research on companies that disclosed internal control weaknesses found management turnover was 15 to 26 percent more likely, auditor turnover 6 to 9 percent more likely, and class-action lawsuits 5 to 10 percent more likely compared with companies without such disclosures. Markets have shown negative reactions to first-time adverse opinions, though correcting a previously disclosed weakness produces a positive market response.
Beyond market reaction, a material weakness invites increased SEC scrutiny. Management cannot conclude that ICFR is effective if any material weakness exists; the rules explicitly prohibit it. The company must disclose the weakness in its annual report and describe remediation efforts, which typically becomes a multi-quarter project under heightened board and investor attention. Audit fees almost always rise the following year as the auditor expands testing scope to verify remediation.
The 404(b) result also flows back into the personal certifications the CEO and CFO sign under Section 302 of the Act. Those officers certify that they have evaluated controls, disclosed all significant deficiencies and material weaknesses to the auditors and audit committee, and disclosed any fraud involving employees with a significant role in internal controls. Section 906 attaches criminal penalties to knowing false certifications, up to $1 million and 10 years in prison, rising to $5 million and 20 years for willful violations. Those penalties apply to the individual officer, not the company. In practice, most officers avoid criminal exposure by working closely with auditors to identify and disclose weaknesses before signing, but the statutory framework makes clear that internal controls are a personal responsibility of senior leadership.