CFO ShortlistReportsICM Audit and SOX Controls
Technical Framework

ICM Audit and SOX Controls: What Your Auditor Will Ask About Sales Commissions

Commissions are a material expense, a management estimate, a capitalised asset under ASC 340-40, and a fraud risk factor in the auditor's own taxonomy. This report maps what the standards actually require of an incentive-compensation process — and, just as usefully, where they say nothing at all.

Independent · No pay-to-playPublished July 202614 min read
Summary

The Binding Constraint Is Evidence, Not Arithmetic

Most finance leaders who worry about commission controls worry about the wrong thing. They ask whether the numbers are right; an audit asks whether a control existed, operated, and left evidence of operating. A spreadsheet process rarely produces those artefacts.

One scoping point first, because most published writing gets it wrong. SOX 404(a) — management's own ICFR assessment — reaches essentially every SEC reporting company. 404(b), the auditor attestation, reaches only accelerated and large accelerated filers. Private companies owe nothing under 404.

The report is built on four points we think are systematically under-appreciated.

01 · The binding constraint is evidence, not arithmetic

An audit asks not whether the run was right but whether a control existed, operated, and left evidence of operating. Unreliability travels upward: an untested commission schedule contaminates the management review control above it, so a well-documented accrual review can fail on the quality of its inputs alone.

02 · The reviewer is the weakest link, and the research proves it

A solo reviewer catches roughly 63% of spreadsheet errors against 83% for a three-person team, and overconfidence appears in every empirical study. That is the case against reviewing by scanning for surprises. Build the review on a defined exception population instead, so it is repeatable and testable.

03 · CRM write access is the segregation-of-duties hole nobody reviews

If the analyst who runs the calculation can also edit opportunity owner, splits, quota or territory in the CRM, they control both the formula and its inputs. It is the highest-impact incompatible duty in incentive comp, and the most reliably missed: comp-system and CRM access are reviewed by different teams.

04 · Buying an ICM platform can create a new gap, not close one

Automation strengthens real attributes: enforced plan versioning, immutable audit trails, role-based access, exception reports. It does not create control effectiveness. Most teams obtain the vendor's SOC 1 Type 2, file it, and never map the complementary user entity controls — the documented failure at Yext, Inc.

A note on method. Incentive compensation is one of the few materially significant finance processes with no dedicated authoritative guidance: no PCAOB standard, no AICPA audit guide and no COSO publication names it, and we could not locate commission-specific control guidance from any Big Four firm despite targeted searching.

CFO Shortlist Take

Ask not whether your commission numbers are right but whether you could prove it to someone who does not trust you. Three things move faster than a software purchase: a system-generated manual-adjustment register reviewed at period end; an access review covering the crediting-relevant CRM fields, not just the comp system; and a payout review on a defined exception population.

Risk

Why Sales Commissions Are a Control-Relevant Process

Three things make commissions control-relevant: ASC 340-40, the accrual as an estimate, and the standards' link to fraud risk.

A balance-sheet asset, not a period expense

Under ASC 340-40, incremental costs of obtaining a contract are capitalised where the entity expects to recover them (25-1) and amortised on a systematic basis (35-1); costs incurred whether or not the contract was won are not incremental (25-3). Amortisation must consider anticipated renewals: where a renewal commission is not commensurate with the initial one, amortise over the expected customer relationship. Yext, Inc. carried roughly $61.3 million of such costs at 31 January 2022. We quote no compensation-cost-of-sales benchmark: those figures come from proprietary datasets.

The accrual is a management estimate

The accrual rests on deals not fully booked, attainment not final, year-end accelerator thresholds and clawback probability. So AS 2501 applies: test whether the method conforms to the framework (.10), the accuracy and completeness of the data used (.12 to .14), the reasonableness of significant assumptions individually and in combination (.15 to .18), and management bias (.30).

Fraud risk, in the standards’ own words

This is not an inference. AS 2401 paragraph .85, the appendix of fraud risk factor examples, lists at A.2: "Significant portions of their compensation (for example, bonuses, stock options, and earn-out arrangements) being contingent upon achieving aggressive targets." At A.3 it names inadequate segregation of duties as an opportunity for misappropriation and "recent or anticipated changes to employee compensation or benefit plans" as an incentive — so a mid-year plan change cutting a rep's earning power is a fraud risk factor in the auditor's taxonomy.

No standard enumerates commission-specific schemes. The testing agenda: crediting and quota manipulation after the close, retroactive rate-table changes, deal-data manipulation, unapproved off-plan payments, and ghost participants.

One base rate, honestly labelled: the ACFE's Occupational Fraud 2024 reports a $145,000 median loss across 1,921 cases, led by missing controls (32%), control override (19%) and no management review (18%) — but it is self-reported case data, not a random sample.

Scope

What Actually Applies to You — and How Deficiencies Are Classified

Almost every article on commission controls either overstates the obligation or tells private companies none of it applies.

Your situationWhat you oweWhere commissions bite
Large accelerated and accelerated filersManagement's ICFR assessment under SOX 404(a), plus a separate external-auditor attestation under 404(b).The auditor tests commission controls in their own right — design, operation, and the ITGCs they depend on.
Non-accelerated filersAssessment under 404(a) only. Permanently exempted from 404(b) by Dodd-Frank Section 989G (2010).Management must still conclude, and document why, that the controls are effective.
Smaller reporting companies under $100 million in annual revenueAssessment under 404(a). The SEC's 2020 amendments to Rule 12b-2 excluded them from accelerated-filer status, and so from 404(b), for annual reports due on or after 27 April 2020.The misconception is that no 404 duty exists. Management's own assessment obligation is unchanged.
Private company with a GAAS financial statement auditNo SOX 404 duty. AU-C 265 governs: the auditor need not search for deficiencies but must communicate identified material weaknesses and significant deficiencies in writing no later than 60 days after the report release date.Scrutiny is broadly the same; the consequence differs — a letter to the audit committee, not a public disclosure.
Private company with a PE sponsor, covenants, or an IPO aheadFormally as above; practically, diligence applies 404-style criteria first.A standard diligence question, because the process is undocumented and the ASC 340-40 balance material.

Section 302 runs independently of 404: the CEO and CFO certify quarterly and must disclose all significant deficiencies and material weaknesses to the audit committee and the auditor. An AU-C 265 letter to a private audit committee is not a 404 disclosure event, though the definitions match.

Deficiency classification, done correctly

A deficiency in ICFR exists where the design or operation of a control does not allow management or employees, in the normal course of their assigned functions, to prevent or detect misstatements on a timely basis (AS 2201 Appendix A, ¶A3) — design where a necessary control is missing, operating where a designed control does not operate or its performer lacks competence; AU-C 265 .A37 names insufficient segregation of duties as an example of the former. A significant deficiency is less severe than a material weakness yet important enough to merit oversight attention (¶A11). A material weakness means a reasonable possibility that a material misstatement will not be prevented or detected (¶A7).

  • Severity has two inputs and only two: reasonable possibility of failure and the magnitude of the potential misstatement — not the count of exceptions, and not whether a misstatement actually occurred. A material weakness can exist with zero identified errors.
  • Compensating controls must be precise. SAPA 11 requires a level of precision that would catch a misstatement that could be material.
  • Deficiencies aggregate. Both AS 2201 and AU-C 265 say "a deficiency, or a combination of deficiencies," and SAPA 11 criticised firms for ignoring combined effects. A flux review on total commission expense does not compensate for a broken participant-level calculation.

Trap: the “more than inconsequential” language is superseded

If anyone describes a significant deficiency as a misstatement "more than inconsequential but less than material," they are quoting a standard that no longer exists. That three-tier language came from PCAOB Auditing Standard No. 2 (2004), which AS No. 5 — now AS 2201 — replaced, deleting the concept entirely. A significant deficiency is defined qualitatively, by whether it merits oversight attention. It is the commonest error in commentary here.

The correct framing: “spreadsheet equals material weakness” is false

No standard makes using a spreadsheet a deficiency, and saying otherwise costs you credibility with your own auditors. What creates one is the absence of control attributes over a spreadsheet key to a material account.

Duties

Segregation of Duties: Start With Who Can Edit the CRM

If you audit one thing this quarter, audit this: can the person who runs the calculation also edit opportunity owner, split records, quota or territory in the CRM? If so, the preparer controls both the formula and its inputs, and no downstream review fixes it.

It is missed for organisational reasons: comp-system access is reviewed by finance, CRM access by sales operations or IT against unrelated criteria. The test runs in an afternoon — intersect the CRM profiles carrying edit rights to owner, splits, close date, booking amount, territory and quota against whoever prepares or approves the calculation.

There is no standard-setter-published duties matrix for sales commissions, so the matrix below is a synthesis and should be presented to your auditors as such. The criteria are COSO 2013 Principle 10 and GAO Green Book ¶10.12 to 10.14, which direct management to separate authority, custody and accounting — in comp: plan design; plan approval; quota and territory setting; source-data ownership; calculation; review; payout authorisation; and adjustment authority.

RefIncompatible combinationWhy it fails
SOD-1Calculates the payout and can edit CRM crediting, quota, territory or opportunity dataThe preparer controls both the formula and its inputs. Most often missed, because CRM write access is granted operationally and never reviewed against the comp role.
SOD-2Calculates the payout and can approve itAuthorisation versus recording. Nothing independent stands between the calculation and cash.
SOD-3Participates in the plan and calculates or adjusts itDirect self-interest — including managers who approve their own team's crediting exceptions.
SOD-4Approves the payout and performs the GL or payroll reconciliationWhoever authorised the number also attests it tied out, removing the detective control.
SOD-5Administers the comp system and prepares or approves the calculationAn administrator can change rate tables, crediting rules and sometimes the audit log, then transact under those changes. Owning the participant master enables ghost participants.
SOD-6Performs the calculation and its review, or posts the accrual and can change the calculationRe-performing your own arithmetic in your own model does not test the model, and accrual access lets the figure be reverse-engineered.

A two-person finance team cannot segregate eight functions, and the framework says so: Green Book ¶10.14 requires alternative control activities where segregation is impractical, and SEC Release 33-8810 accepts a tailored approach for smaller companies. In practice: a methodology documented independently of the incumbent; independent recalculation of a risk-based sample each period; a second approval on adjustments above a threshold, enforced in the application; and a named backup who has run a full cycle. An unmitigated gap is a design deficiency.

The highest-risk category: retroactive plan and crediting changes

A retroactive change re-rates a closed period: an amount already accrued, possibly paid, possibly capitalised under ASC 340-40, possibly reported. Four controls are the minimum: prohibition absent named-officer approval, at minimum the Controller and the sales leader; an impact analysis quantifying the effect on current-period expense, the prior-period accrual and the capitalised asset; an assessment of whether the prior-period effect is an error correction rather than a change in estimate; and a system-enforced trail capturing before, after, actor and approval.

Spreadsheets

Spreadsheet and End-User Computing Risk

The reason spreadsheet-run commissions attract deficiency findings is structural. A spreadsheet is an application that escaped the IT control environment: nobody approved its design, tested its changes, or restricted who can edit it.

The IIA's GTAG 14, Auditing User-developed Applications (2010) is the standard reference. It treats a user-developed application as key if it initiates or monitors material financial transactions or if its loss would impair a key control — a commission workbook meets both. It is a practice guide, not a mandate, but auditors test close to its attribute list: access and logical security; version control; an automatic change trail administered separately from its users; formula and logic integrity, meaning protected ranges, no formulas in input areas and documented logic; input completeness reconciled to source by count and value; output validation; and review evidenced by tickmarks rather than a signature. Add a UDA inventory, without which the tested population is not demonstrably complete.

The empirical base rate is unflattering. Powell, Baker and Lawson (2009) audited 50 operational workbooks containing 270,722 formulas: 94% contained errors and 86% contained errors producing wrong results. Panko (2015) found errors in 94% of spreadsheets across 85 field audits, and 63% of errors caught by solo inspectors against 83% by three-person teams, concluding that "every empirical study has found overconfidence."

Be precise about what these studies measured

Both research streams audited general operational spreadsheets, not commission files, and neither measured dollar impact. There is no published study of commission-spreadsheet error rates and no defensible figure for the average dollar error in a commission payment. State the findings as evidence about spreadsheets as a class, never about anyone's payout accuracy.

So self-review by the preparer is not a control, and a single reviewer's unaided inspection is a weak one. The design response is a defined exception population: joiners and leavers, payouts or attainment above a threshold, every manual adjustment, every new plan type, every split not summing to 100%.

Evidence

Systems, Evidence, and the Review Control Above Them

The most expensive misconception here is that buying a platform converts a control problem into a solved one. Yext, Inc. disclosed, with its FY2020 audit, a material weakness "associated with processes to calculate, record and account for sales commissions," attributed to "controls related to reliance on certain outsourced IT service providers." Ernst & Young issued an adverse ICFR opinion as of 31 January 2021; remediation took roughly two years. A commissions-process failure alone sufficed for an adverse opinion; outsourcing did not transfer responsibility; and the remediation is a blueprint whose order matters — plan governance, then systems, then ITGCs, then automated and review controls.

Yext is a well-documented case, not a base rate. We do not claim commissions are a leading cause of material weaknesses; no dataset by cause was available to us. We cite no "shadow accounting" prevalence statistic either — every version traces to vendor blogs with no methodology.

The SOC 1 report you filed and never mapped

If part of your calculation runs on an outsourced platform, the audit path runs through a SOC 1 Type 2; a Type 1 covers design at a point in time only. Then map each complementary user entity control — a control the service auditor's opinion assumes you perform — to a named control of yours with an owner and evidence it operated; assess the gap period to your year-end; and identify carved-out subservice organisations.

Information produced by the entity, and the review above it

Commission calculations run on extracts, and extracts are information produced by the entity — the most reliable failure point in an ICFR audit. SAPA 11 cites firms that failed to test controls over the completeness and accuracy of system-generated reports, including the query logic and parameters used; the PCAOB's March 2025 Spotlight records the same finding in 2024. So document the query definition, reconcile output to source, and control changes to it.

SAPA 11 also names six factors driving a review control's precision: the objective of the review, the level of aggregation, the consistency of performance, the correlation to relevant assertions, the predictability of expectations, and the criteria for investigation. Grant Thornton names the failure mode: "Mere 'sign off' by the control owner … does not provide sufficient detail of the steps taken."

The request list follows: plan inventory and approved versions; a participant listing reconciled to payroll with its change log; the transaction population and its query definition; calculation output by line item; the manual-adjustment register and dispute log; the accrual memo, look-back and three-way reconciliation; and the SOC 1 with CUEC mapping.

The right way to think about tooling

Automation strengthens nameable attributes: plan versioning and effective dating the engine enforces rather than trusts; immutable calculation and adjustment trails users cannot disable; role-based access mappable to a duties matrix; and exception reports that give a review control a defined population. It cannot supply plan governance or map its own CUECs.

Questions

Frequently Asked Questions

Next reads

Could you evidence your last commission run to an auditor?

Bring your process to a free Direction Session and we will walk the control gaps, the evidence you are missing, and whether tooling is actually your bottleneck. Independent, no vendor compensation.

Independent FP&A & EPM advisory for mid-market finance teams.

Helping CFOs, Controllers, and FP&A leaders choose, negotiate, and implement the right finance stack – without pay-to-play bias.

© 2026 CFO Shortlist. All rights reserved.

Independent, buyer-first EPM advisory.

No vendor compensation or pay-to-play sponsorships.