SOX in Practice: Compliance Strategy and Testing Methodology

Most SOX programs fail in the same quiet way. Nobody misses a deadline. Nobody fabricates evidence. The controls are documented, the testing gets done, the certification gets signed and then a deficiency surfaces that everyone technically had visibility into but nobody was positioned to catch.
Understanding why that happens requires looking past the statute and into how compliance programs are actually built and tested.
The basics, briefly
The Sarbanes-Oxley Act of 2002 responded to the Enron and WorldCom collapse by shifting responsibility for financial reporting accuracy onto named executives and creating the PCAOB to oversee audit firms.
Two sections drive day-to-day work. Section 302 requires the CEO and CFO to certify each periodic report and the effectiveness of disclosure controls. Section 404 requires management to assess internal control over financial reporting, with an external auditor attestation for accelerated and large accelerated filers.
The distinction between those two matters more than it looks, as one of the cases below shows.
The typical compliance strategy
Mature programs follow a top-down, risk-based approach. The sequence matters, because getting it backwards produces bloated control inventories that consume budget without reducing risk.
Start with materiality and financial statements. Determine overall materiality, then identify which accounts and disclosures are material. Everything downstream flows from this.
Identify significant processes and relevant assertions. For each material account, determine which processes feed it and which assertions, such as existence, completeness, valuation, rights and obligations, and presentation, would carry actual risk. Not every assertion is relevant to every account.
Map to risks of material misstatement, then to controls. For each identified risk, find the control that addresses it. This order matters. Programs that start by cataloguing existing controls end up testing whatever happens to exist rather than what risk requires.
Layer in ITGCs. Access management, change management, and computer operations support nearly every automated control and system-generated report in scope. A weakness here can invalidate reliance on controls that otherwise operate perfectly.
Rationalize. Most long-running programs accumulate controls that address risks that no longer exist. Removing them isn't cutting corners. It's redirecting effort toward controls that matter.
Testing methodology
Testing answers two separate questions, and conflating them is a common source of trouble.
Design effectiveness asks whether the control, if it operated as described, would prevent or detect a material misstatement. Operating effectiveness asks whether it actually operated that way throughout the period. A well-designed control that operated twice out of twelve months fails. So does a control that operated perfectly every month but was never capable of catching the risk it was mapped to.
Four procedures do the work, in ascending order of evidential strength:
- Inquiry: asking the control owner how the control operates. Never sufficient on its own.
- Observation: watching it occur. Useful for physical controls, but only proves it happened once, while you were watching.
- Inspection: examining documentary evidence that it operated. The workhorse of most SOX testing.
- Reperformance: independently executing the control to confirm the outcome. It ordinarily provides stronger evidence; the appropriate mix of procedures depends on the control and assessed risk.
Sample sizes depend on control frequency, assessed risk, the period of reliance, expected deviations, and the testing methodology. There is no universal SOX sample-size table. Document why the selected population, sample, and procedures provide sufficient evidence, and evaluate whether exceptions call for additional testing.
When an exception is found, evaluation follows a severity ladder. A control deficiency exists when a control’s design or operation does not allow timely prevention or detection of misstatements in the normal course of work. A significant deficiency is severe enough to warrant attention by those overseeing financial reporting. A material weakness exists when there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis and it must be disclosed publicly.
Timing is the variable most teams underuse. A deficiency identified in the first quarter can be remediated and the remediated control retested before year-end. The same deficiency found in November usually cannot.
Two cases worth studying
Kraft Heinz illustrates what happens when incentives outrun controls. Between late 2015 and the end of 2018, procurement employees manipulated supplier agreements to hit performance targets tied to bonuses. The SEC found that the company failed to design and maintain effective internal accounting controls over its procurement division, and that finance personnel repeatedly overlooked indications that expenses were being improperly accounted for. The company restated 2016 and 2017 results, corrected $208 million in cost savings, and settled with the SEC in September 2021 for a $62 million civil penalty without admitting or denying the findings. It disclosed control weaknesses in 2019 and reported them fully remediated in 2020.
The lesson isn't that controls were absent. It's that gatekeeping personnel saw warning signs and didn't escalate. Control precision. The threshold at which a reviewer is required to investigate is what turns observation into detection.
Under Armour illustrates a subtler point. For six consecutive quarters starting in Q3 2015, the company accelerated customer orders from future quarters to close gaps against analyst estimates, pulling forward approximately $408 million. It settled with the SEC in May 2021 for $9 million.
The nuance: the SEC's order expressly did not find that the revenue was recorded outside GAAP. This was a disclosure failure. The company attributed growth to product categories without disclosing the pull-forward practice or the uncertainty it created for future quarters. The case illustrates the need to assess disclosure obligations alongside accounting recognition, rather than treating SOX solely as an ICFR exercise. Disclosure controls deserve explicit attention alongside ICFR.
What actually separates strong programs
Not headcount, and not documentation volume. It's whether testing happens early enough to matter, whether control descriptions are precise enough to test, and whether the routine work of gathering evidence has been automated so experienced people can spend their judgment where risk actually concentrates.
© 2026 Audagic. All rights reserved.
See Deterministic Testing in Action
Get early access and try Audagic on your own audit evidence.