Glossary›SOX 404 Controls
Reporting & Regulatory

SOX 404 Controls

Updated September 2026Finance Software Glossary

SOX 404 controls are the internal controls over financial reporting (ICFR) that Section 404 of the Sarbanes-Oxley Act of 2002 requires US public companies to maintain, document and test. Management must assess control effectiveness each year and for most larger filers an external auditor must attest to that assessment.

Section 404 has two parts. Under 404(a), management of a US public company must document its internal controls over financial reporting and assess their effectiveness annually. Under 404(b), accelerated and large accelerated filers must also have their external auditor attest to that assessment. Typical controls include account reconciliations, journal entry approvals, access restrictions and management review controls.

In practice teams maintain a risk and control matrix, test controls through the year and fix deficiencies before year end. A deficiency that could allow a material misstatement is a material weakness and must be disclosed.

In software: Workiva offers SOX documentation and testing alongside its filing tools, AuditBoard focuses on SOX and internal audit workflows and FloQast added compliance management so close tasks double as control evidence.

Building a shortlist?

The CFO Shortlist app matches your requirements to the vendors we cover, free, in less time than one vendor demo.

Start your shortlist
Or browse all vendor profiles

Independent FP&A & EPM advisory for mid-market finance teams.

Helping CFOs, Controllers, and FP&A leaders choose, negotiate, and implement the right finance stack – without pay-to-play bias.

© 2026 CFO Shortlist. All rights reserved.

•

Independent, buyer-first EPM advisory.

•

No vendor compensation or pay-to-play sponsorships.