SOX Compliance Checklist
Scoping and Risk Assessment
The SOX team sets overall materiality and performance materiality used to scope significant accounts. Document the rule of thumb (typically 5% of pre-tax income or 0.5% of revenue) and the qualitative overlays. This number drives every downstream scoping decision — get external auditor alignment before locking it.
Apply the materiality threshold to the trial balance and identify accounts above scoping. Include qualitative scoping for revenue, taxes, and judgmental estimates regardless of size. Document the in-scope vs. out-of-scope rationale for each account.
Tie each significant account to the business processes that feed it (order-to-cash, procure-to-pay, payroll, financial close, treasury) and the financial statement assertions (existence, completeness, accuracy, valuation, cutoff, presentation).
Identify financially relevant systems (ERP, consolidation tool, EDI, sub-ledgers) and scope ITGCs across access management, change management, and computer operations. Coordinate with IT audit on SOC 1 reports for outsourced systems like the payroll provider.
Control Documentation and Walkthroughs
Update each in-scope process narrative and risk-control matrix to reflect the current year's system, personnel, and process changes. Stale narratives are the most common PCAOB inspection finding cited against issuers.
Walk one transaction end-to-end with each control owner. Confirm the control is performed as documented, by whom, with what evidence, and at what frequency. Capture screenshots of system-based controls in the workpaper.
Review the key control population with the external auditor. Over-keying inflates testing hours; under-keying creates audit findings. Aim for a tight key control set that covers each significant assertion at each significant account.
Map ERP roles to incompatible duty pairs (vendor master vs. AP payment, journal entry vs. journal approval, system admin vs. financial user). Document any compensating controls where SoD conflicts exist due to thin staffing.
Control Testing and Deficiency Evaluation
Pull samples per the AICPA / PCAOB guidance — typically 25 for daily controls, 5 for weekly, 2 for monthly, 1 for quarterly. Document the population, sample selection method, and tester. Re-perform the control rather than just inspecting evidence.
Capture every test result in the workpaper with cross-references to evidence. Note any exceptions with the specific failure mode — missing approval, late performance, wrong reviewer, evidence not retained.
For each exception, evaluate severity per AS 2201: control deficiency, significant deficiency, or material weakness. Use both quantitative (potential misstatement vs. materiality) and qualitative factors. Material weaknesses must be disclosed in the 10-K.
Document the root cause, remediation owner, target date, and validation approach for each deficiency. Coordinate with external auditors so the planned remediation will satisfy them — agreeing on the fix after the fact wastes a cycle.
After the remediation goes live, allow enough time for an adequate sample population, then re-test. To rely on the remediation for year-end, the operating period typically needs to be at least 60-90 days depending on control frequency.
Audit Committee and External Auditor Coordination
Verify each audit committee member meets NYSE / Nasdaq independence standards and that at least one member qualifies as an audit committee financial expert per Item 407(d)(5) of Regulation S-K. Re-confirm annually as part of D&O questionnaire.
Pre-approve all audit and permitted non-audit services. Pull the latest PCAOB inspection report on the firm and review independence representations under Rule 3526. Document the audit committee's independence assessment.
Provide the auditor's IA / SOX team access to workpapers, RCMs, and deficiency log so they can plan reliance on management's work per AS 2605. The earlier they see exceptions, the lower the chance of late-cycle scope expansion.
Walk the committee through testing status, open deficiencies, remediation progress, and any scope changes. Capture minutes and the executive session with the external auditor without management present.
Disclosure Controls and Certifications
Distribute sub-certifications to process owners and segment leaders covering disclosure controls, ICFR changes, and any known fraud or misstatement. The CEO/CFO 302 certs cascade up from these.
Identify any change during the quarter that materially affected, or is reasonably likely to materially affect, ICFR — system implementations, M&A integration, process owner turnover, remediated material weaknesses. Document the assessment supporting the 10-Q Item 4 disclosure.
Route the Section 302 certifications to the CEO and CFO with the supporting sub-cert package. Confirm wording matches Item 601(b)(31) exactly — non-conforming certifications are a recurring SEC comment letter topic.
For the Form 10-K only, issue management's annual assessment of ICFR effectiveness as of fiscal year-end. Disclose any material weaknesses and reconcile with the external auditor's 404(b) opinion. Non-accelerated filers are exempt from 404(b) but still owe 404(a).
Fraud Prevention and Whistleblower Program
Identify fraud risks across the three categories — fraudulent financial reporting, misappropriation of assets, and management override. Document anti-fraud controls including the journal entry review control mandated by AS 2401.
Required by Section 406. Track completion for the CEO, CFO, controller, principal accounting officer, and anyone performing similar functions. Any waiver granted to a senior officer requires Form 8-K disclosure within four business days.
The audit committee reviews all hotline submissions per Section 301. Track resolution status and confirm no retaliation. Anonymous accounting and auditing complaints must be channeled directly to the audit committee, not filtered through management.
Pull updated D&O questionnaires and reconcile against the related-party master list. Each transaction over the Item 404 threshold needs proxy disclosure and audit committee approval per the listing standard.
Use this template in Manifestly
- Month-End Close Checklist
- New Vendor Onboarding Checklist
- New Employee Onboarding Checklist
- Staff Offboarding Checklist
- Quarterly Bookkeeping Checklist
- Year-End Accounting Checklist
- Deal Closure Checklist
- Monthly Bookkeeping Close Checklist
- Engagement Budgeting Checklist
- Project Cost Control Checklist
- Tax Audit Documentation Checklist
- Engagement Risk Management Checklist
- Monthly Financial Close Checklist
- Contract Review Checklist
- Segregation of Duties Assessment
- Acquisition Integration Checklist
- Profitability Analysis Checklist
- Post-Merger Audit Checklist
- Financial Ratio Analysis Checklist
- M&A Due Diligence Checklist
- Legal Entity Management Checklist
- Cash Flow Analysis Checklist
- Risk Assessment Checklist
- Year-End Bookkeeping Checklist
- Year-End Tax Planning Checklist
- Monthly Financial Review Checklist
- Financial Audit Checklist
- Billing Process Checklist
- Client Engagement Closeout Checklist
- Corporate Tax Preparation Checklist
- Cost-Benefit Analysis Checklist
- Fraud Prevention Checklist
- Weekly Bookkeeping Checklist
- Cash Application Checklist
- Daily Bookkeeping Checklist
- Internal Audit Preparation Checklist
- Customer Credit Approval Checklist
- Internal Control Procedures Checklist
- Accounts Receivable Aging Report Checklist
- Quarterly Internal Control Review Checklist
- Corporate Tax Return Preparation Checklist
- Budget Variance Analysis Checklist
- Monthly Accounting Close Checklist
- Accounts Payable Aging Report Checklist
- Client Engagement Letter Renewal
- Capital Expenditure (CapEx) Approval Checklist
- Payroll Tax Filing Checklist
- Employee Expense Reimbursement Checklist
- Annual Financial Statements Checklist
- Quarterly Payroll Tax Compliance Checklist
- Grant Accounting Checklist
- End-of-Month Sales and Revenue Reporting
- Collections Management Checklist
- Cost Accounting Checklist
- System Access Control Checklist
- Accounting Policy Update Cycle
- Financial Analysis Checklist
- New Client Onboarding Checklist
- Firm Insurance Renewal Checklist
- Cash Flow Management Checklist
- Payroll Services Checklist
- New Employee Onboarding Checklist (Accounting Department)
- Business Tax Compliance Checklist
- Employee Expense Policy Compliance Checklist
- Credit and Collections Checklist
- Regulatory Compliance Checklist
- External Audit Preparation Checklist
- Investment Reconciliation Checklist
- Monthly Management Reports Checklist
- Annual Budget Preparation Checklist
- Accounts Payable Ledger Checklist
- AP Payment Processing Checklist
- Merger and Acquisition Due Diligence Checklist
- Lease Accounting Checklist
- Journal Entry Checklist
- Chart of Accounts Maintenance Checklist
- Payroll Processing Checklist
- Accounting Department Workflow Optimization
- Financial Reporting Checklist
- New Business Structuring Checklist
- Audit Preparation Checklist
- Accounts Payable Checklist
- Financial Project Planning Checklist
- Yearly Accounting Department Goals Setting
- Consulting and Advisory Services Checklist
- Account Reconciliation Checklist
- Chart of Accounts Review Checklist
- Tax Planning Checklist
- Fixed Assets Audit Checklist
- Vendor Setup and Maintenance Checklist
- Client Onboarding Checklist
- Individual Tax Return Preparation Checklist
- Employee Termination Checklist (Accounting Department)
- Cash Flow Analysis Checklist
- Risk Management Checklist
- Expense Reporting and Reimbursement Checklist
- Monthly Close Process
- Business Valuation Checklist
- Bank Reconciliation Checklist
- Sales Tax Reporting Checklist
- Internal Controls Review Checklist
- Budgeting and Forecasting Checklist
- Financial Statement Audit Checklist
- Accounting Standards Update Adoption Checklist
- Monthly Bookkeeping and Accounting Close
- Business Succession Planning
- Financial Statement Preparation Checklist
- Inventory Accounting Close Checklist
- Accounts Receivable Checklist
- Monthly Financial Reporting Checklist
- Financial Risk Assessment Checklist
- Quarterly Financial Reporting Checklist
- Performance Review Checklist (Accounting Staff)
- Vendor Contract Negotiation Checklist
- Accounting Software Migration Checklist
- Quarterly Budget Review Checklist
- Debt Management Checklist
- Fixed Assets Management Checklist
- Loan Covenant Compliance Checklist
- Accounting Software Implementation Checklist
- Cash Management Checklist
- Annual Attorney Professional Conduct Review
- Restaurant New Hire Checklist
- Restaurant Policy Update Checklist
- Retail Policy Update and Compliance Checklist
- New Hire Paperwork Checklist
- Department of Transportation (DOT) Audit Checklist
- Restaurant Permit and Licensing Renewal Checklist
- Marketing Strategy Checklist
- E-commerce Risk Management Checklist
- E-commerce Legal Compliance Checklist
- CRM Data Entry Checklist
- Cybersecurity Incident Response Checklist
- Agency Compliance and Risk Management Checklist
- Advisor and Staff Onboarding Checklist
- New Hire Onboarding Checklist
- Financial Services IT Security Audit Checklist
- Litigation Preparation Checklist
- Internal Audit Checklist
- PCI DSS Compliance Checklist
- Contract Review Checklist
- Annual Financial Reporting Checklist
- Intellectual Property Management Checklist
- Annual Compliance Program Review
- Project Monitoring Checklist
- Operational Risk Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Regulatory Reporting Checklist
- Advisor and Employee Onboarding Checklist
- Quarterly Performance Measurement Checklist
- IT Policy Review Checklist
- Project Closure Checklist
- Monthly Financial Reporting Checklist
- Quarterly Operations and Compliance QA Review
- Cybersecurity Risk Assessment Checklist
- Know Your Customer (KYC) Checklist
- User Access Review Checklist
- Data Protection Checklist
- Employee File Audit Checklist
- Email Deliverability Checklist
- HR Compliance Checklist
- Law Firm Ethics Compliance Review
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Licensing Renewal Checklist
- Motor Carrier TSA Security Compliance Checklist
- Risk Assessment Checklist
- School First Aid and Emergency Medication Audit
- Annual School Compliance Audit
- Annual Risk Management Review Checklist
- Vendor Contract Review Checklist
- Business Continuity Plan Checklist
- HR Audit Checklist
- Insurance Marketing Campaign Checklist
- Cloud Security Checklist
- Insurance Program Launch Project Monitoring Checklist
- Anti-Money Laundering Compliance Checklist
- System Backup Checklist
- Data Privacy Compliance Checklist
- Quarterly Risk Monitoring Checklist
- Insurance Program Initiation Checklist
- Law Firm Compliance Checklist
- Training Materials Checklist
- Professional Responsibility Compliance Review
- Employee Offboarding Checklist
- Network Security Checklist
- Regulatory Reporting Checklist
- IT Asset Inventory Management Checklist
- Manufacturing Regulatory Compliance Checklist
- Compliance Audit Checklist
- Training Needs Assessment Checklist
- Email Compliance Checklist
- Audit Preparation Checklist
- Skills Development Checklist
- Law Firm Compliance Checklist
- Financial Statement Review Checklist
- Employee Termination Checklist
- Project Planning Checklist
- Project Execution Checklist
- Security Audit Checklist
- Quarterly Compliance Monitoring Checklist
- Regulatory Compliance Checklist
- E-commerce Sales Tax Reporting Checklist
- Annual Risk Assessment Checklist
- Compliance Audit Checklist
- Client Satisfaction Survey Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Financial Services Project Initiation Checklist
- Brokerage HR Policy Compliance Checklist
- Data Privacy Compliance Checklist
- Employee Handbook Annual Review
- Expense Management Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Regulatory Compliance Checklist
- Listing Agreement Intake Checklist
- Employee Records File Audit
- Employee Termination Checklist
- Law Firm Risk Management Checklist
- ISO/IEC 27001 Compliance Checklist
- Complaint Resolution Checklist
- IT Regulatory Compliance Review
- HR Compliance Checklist
- Business Continuity Checklist
- Lead Generation Checklist
- Insurance Program Launch Execution Checklist
- Employee Benefits Checklist
- Law Firm Risk Management Checklist
- Fair Housing Compliance Audit
- Real Estate Website Audit Checklist
- Real Estate Ethics & Compliance Review
- Software Licensing Compliance Checklist
- Property Risk Assessment Checklist
- Lease Agreement Checklist
- Security Audit Checklist
- Legal Compliance Checklist for New Properties
- Fair Housing Compliance Checklist
- IT Security Audit Checklist
- Claims Auditing Checklist
- Document Retention Policy Checklist
- Insurance Training and Development Checklist
- Quarterly Industry Standards Compliance Review
- Risk Management Checklist
- Employee Records Management Checklist
- Building Code Compliance Checklist
- GDPR Compliance Review Checklist
- Legal Entity Management Checklist
- Quarterly Internal Control Review Checklist
- Legal Document Storage Checklist
- Anti-Money Laundering Compliance Checklist
- Regulatory Compliance Checklist
- Insurance Compliance Checklist
- Real Estate Contract Review Checklist
- Employee Termination Checklist
- GDPR Compliance Checklist
- Continuing Education Checklist
- Real Estate License Renewal Checklist
- MLS Listing Review Checklist
- HIPAA Compliance Checklist
- Real Estate Legal Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Professional Development Checklist
- Brokerage Trust Account Management Checklist
- Cybersecurity Protocol Checklist
- HR Compliance Checklist
- Data Security Review Checklist
- Risk Management Checklist
- Sales Tax Reporting Checklist
- Property Safety Inspection Checklist
- Employee File Audit Checklist
- Brokerage Technology Inventory Audit
- Payroll Processing Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
