search

SOX Compliance Checklist for Small Public Companies

5/13/2026

Most SOX guidance is written for large filers and then applied to small ones, which is how a company with nine people in accounting ends up documenting four hundred controls.

The requirements do scale, and the scaling is real rather than rhetorical. What determines a smaller company's cost is a single early decision — scoping — and companies that get it wrong spend two or three times what they needed to while producing a control set nobody can actually operate.

What Applies to You

Three distinct requirements, and they do not all apply to everyone.

Certification of periodic reports. The principal executive and principal financial officers must certify each periodic report, including statements about the report's accuracy, their responsibility for disclosure controls and procedures, their evaluation of the effectiveness of those controls, and their responsibility for internal control over financial reporting. This applies to every filer, in every periodic report — quarterly as well as annual.

Management's annual assessment of internal control over financial reporting. Management must assess ICFR annually, using a suitable framework, and state a conclusion. This applies to every filer, including smaller ones with no auditor attestation.

The auditor's attestation on ICFR. This is the requirement with exemptions. Certain smaller filer categories are exempt, and newly public companies have transition relief for a defined period. Confirm your own status, because it is the difference between an internal exercise and an audited one — and losing an exemption is a major event that requires a year or more of preparation rather than a quarter.

Two things worth stating for companies that are exempt from the attestation: management's assessment is still required, and it is still a filed statement management is accountable for. "No auditor attestation" is not "no obligation."

Disclosure Controls and ICFR Are Not the Same Thing

Conflated constantly, and the distinction has practical consequences.

Internal control over financial reporting addresses the reliability of financial reporting and the preparation of financial statements.

Disclosure controls and procedures are broader. They cover controls ensuring that information required in filed reports — including non-financial information — is recorded, processed, summarized, and reported within required timeframes, and that it reaches the people making disclosure decisions.

Which means a company with excellent ICFR can still have deficient disclosure controls: the material contract nobody told the disclosure committee about, the subsequent event that reached legal and not finance, the segment change that never made it into the discussion and analysis.

The requirement is an evaluation each period, not annually. Smaller companies frequently perform a serious annual ICFR assessment and treat the quarterly disclosure controls evaluation as a signature, which is precisely backwards relative to what the certification says.

Scoping: The Decision That Sets the Cost

A top-down, risk-based approach, in this order:

  1. Start with materiality, both for the financial statements as a whole and for identifying significant accounts.
  2. Identify significant accounts and disclosures — those with a reasonable possibility of containing a material misstatement, considering size, composition, susceptibility to error or fraud, complexity, subjectivity, volume, and change.
  3. Identify the relevant assertions for each. Not all assertions matter for all accounts, and scoping every assertion for every account is the most common source of overwork.
  4. Understand the flow of transactions in the processes feeding those accounts, and identify where a material misstatement could occur.
  5. Select the controls that address those risks — the fewest controls that provide coverage, not every control that exists.
  6. Consider locations and business units on a risk basis rather than covering all of them.

The recurring small-company failure is scoping too broadly: documenting every procedure the accounting department performs, which produces a control set too large to test, too large to maintain, and too large for anyone to distinguish the important controls within.

The opposite failure is real too — omitting a significant process because it is small in dollar terms while being highly susceptible to misstatement.

The Checklist

Entity-level controls

  • Control environment and tone, evidenced through what management actually does, not a values statement
  • Board and audit committee oversight, with minutes reflecting substantive discussion
  • The audit committee's specific obligations: appointment and oversight of the auditor, pre-approval of audit and permitted non-audit services, independence assessment, and disclosure regarding a financial expert
  • A whistleblower mechanism. The audit committee must establish procedures for receiving and handling complaints about accounting, internal accounting controls, and auditing matters, including confidential, anonymous submission by employees. This is a specific requirement, and having a channel nobody knows about does not satisfy its purpose
  • A code of ethics, with the required disclosure regarding senior financial officers
  • Delegation of authority and approval limits, current and enforced
  • Risk assessment, performed and documented, including fraud risk
  • Monitoring, including internal audit where it exists and management's own monitoring where it does not

Process-level controls

Cover the significant processes identified in scoping — typically revenue and receivables, purchasing and payables, payroll, inventory where relevant, treasury and cash, equity and share-based compensation, income taxes, and long-lived assets.

The financial close and reporting process deserves separate attention, because it is the highest-risk process at a small company and the one most likely to produce a material weakness. Its controls include the close calendar and checklist, account reconciliations with evidence of review, journal entry review and approval, consolidation, disclosure preparation and review, and the review of significant estimates and judgments.

IT general controls

The area smaller companies most often fail, and the failures are consistent:

  • Logical access — provisioning, deprovisioning, and periodic access review, which is the specific control most often missing or unevidenced
  • Privileged and administrative access, restricted and monitored
  • Change management for financially relevant systems, with testing and approval before implementation
  • Job scheduling and monitoring, and backup and recovery
  • Segregation between development and production
  • Service organizations. Where a third party performs a financially relevant function, obtain and read the service organization control report — including the complementary user entity controls, which list the controls the service provider assumes you perform. Skipping that section means relying on controls nobody is executing, and the skill is covered in the Certified AICPA SOC Report Analyst program

Management review controls

The controls auditors challenge hardest, because they are the ones most often described rather than performed.

A management review control that holds up specifies: what is reviewed, against what criteria or expectation, at what level of precision — what size of variance would be investigated — what the reviewer actually does when something exceeds the threshold, and evidence of the review and any follow-up.

"The controller reviews the results" is not a control. "The controller compares actual gross margin by product line to the prior period and to budget, investigates variances exceeding a defined threshold, documents the explanation, and signs the analysis" is.

Spreadsheet and end-user computing controls

Small companies run on spreadsheets, and financially significant ones need controls proportionate to their role: restricted access, protected formulas, separation of inputs from calculations, version control, change documentation, and independent verification of outputs. Building the underlying capability — Essential Excel Skills or the Excel training for accountants catalog — is a genuine control investment, not a training nicety.

The Segregation of Duties Problem Nobody Solves

Worth addressing honestly rather than pretending.

A company with a small accounting department cannot achieve textbook segregation of duties. The same person may initiate a payment and reconcile the account. That is a structural fact of the company's size, not a failure of diligence, and the standard advice to "segregate duties" is not actionable.

What is actionable is documented compensating controls, and the ones that work at small companies:

  • Owner, CEO, or board review of specific reports — bank statements received unopened by someone outside accounting, check registers, new vendor additions, payroll registers, and journal entries above a threshold
  • Dual authorization for payments above a limit, and for changes to bank details
  • Independent reconciliation review, even where the preparer is the only person who could prepare it
  • System-enforced approvals where the system can enforce what staffing cannot
  • Rotation of duties, including mandatory vacation coverage, which surfaces what one person has been doing alone
  • Analytical review by someone outside the process, sensitive enough to detect a material amount

The essential point: these must be documented as the control and evidenced as operating. A company relying on the owner looking at things, with no record, has a practice rather than a control — and an auditor cannot conclude on a practice.

Evaluating Deficiencies

The framework matters because the conclusion is a filed statement.

A control deficiency exists when a control fails to prevent or detect a misstatement on a timely basis.

A significant deficiency is less severe than a material weakness and important enough to merit attention by those responsible for oversight.

A material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. Its presence requires a conclusion that ICFR is not effective.

Two points practitioners get wrong. Severity does not depend on whether a misstatement actually occurred — it depends on the reasonable possibility of one, so a deficiency that happened to catch nothing can still be a material weakness. And deficiencies aggregate: several individually minor deficiencies affecting the same account or assertion can combine into a material weakness.

Remediation timing is the trap. A control implemented late in the year may not have operated long enough for management to conclude it is effective as of the assessment date. Remediation identified in the fourth quarter frequently cannot be concluded effective for that year, which is an argument for interim testing rather than a year-end scramble.

Structured coverage is available through the Sarbanes-Oxley compliance training catalog, the audit training courses listing, internal auditing training, the Certificate in Forensic Accounting, and ethics training and professional conduct.

The Material Weaknesses Small Companies Actually Report

Knowing the common ones tells you where to look first:

  • Insufficient accounting personnel or technical expertise, particularly for complex or non-routine transactions
  • Segregation of duties, unaddressed by documented compensating controls
  • IT general controls, especially access review and change management
  • Management review controls lacking precision or evidence
  • The period-end close process, including reconciliations and journal entry review
  • Accounting for complex transactions — equity instruments, business combinations, revenue arrangements, income taxes
  • Controls over spreadsheets used in financially significant calculations

Keeping the Cost Down

  • Scope tightly, using materiality and risk rather than covering everything
  • Rationalize the control set — the fewest controls that cover the risks, tested well, beats hundreds tested superficially
  • Automate what the system can enforce, since automated controls are cheaper to test than manual ones
  • Test at interim and roll forward, so remediation has time to operate
  • Use service organization reports properly, including reading the complementary user entity controls
  • Do not create controls to have controls. Every documented control must be performed, evidenced, and tested forever

Where Small Companies Get This Wrong

  • Assuming no auditor attestation means no obligation, when management's assessment is still required and filed
  • Treating the quarterly disclosure controls evaluation as a signature
  • Conflating disclosure controls with ICFR
  • Scoping too broadly, producing an unmaintainable control set
  • Describing management review controls rather than specifying precision, criteria, and evidence
  • Ignoring segregation of duties as unsolvable, instead of documenting compensating controls
  • Access reviews not performed or not evidenced
  • Service organization reports filed unread, with complementary user entity controls never examined
  • Financially significant spreadsheets uncontrolled
  • Remediating in the fourth quarter and finding the control cannot be concluded effective

The framing that makes this manageable: SOX at a small company is not about having many controls. It is about identifying the few places where a material misstatement could actually arise, having a small number of controls there that people genuinely perform and can prove they performed, and being honest about the segregation problem your size creates rather than pretending it away.

Frequently Asked Questions

What SOX requirements apply to a smaller public company?

Officer certification of every periodic report, including an evaluation of disclosure controls and procedures each period, and management's annual assessment of internal control over financial reporting. The auditor's attestation on ICFR is where exemptions exist for certain smaller filer categories and newly public companies — but management's assessment is still required and still filed.

What is the difference between disclosure controls and ICFR?

ICFR addresses the reliability of financial reporting and statement preparation. Disclosure controls are broader, covering all information required in filed reports including non-financial information, and ensuring it reaches the people making disclosure decisions in time. A company can have sound ICFR and deficient disclosure controls — the material contract nobody told the disclosure committee about.

What determines the cost of SOX compliance at a small company?

Scoping. A top-down, risk-based approach starting with materiality, identifying significant accounts and only the relevant assertions, understanding transaction flows, and selecting the fewest controls that cover the risks. Documenting every procedure the accounting department performs is the most common and most expensive error.

How should segregation of duties be handled when the department is too small?

By documenting compensating controls and evidencing that they operate — owner or board review of bank statements received unopened, check registers, new vendor additions and payroll registers; dual authorization above a limit and for bank detail changes; independent reconciliation review; system-enforced approvals; duty rotation; and analytical review by someone outside the process. A practice with no record is not a control an auditor can conclude on.

What makes a management review control hold up?

Specificity: what is reviewed, against what criteria or expectation, at what level of precision — the variance size that triggers investigation — what the reviewer does when the threshold is exceeded, and evidence of the review and follow-up. "The controller reviews the results" is a description, not a control.

Why does remediation timing matter?

Because a control implemented late in the year may not have operated long enough for management to conclude ICFR is effective as of the assessment date. A deficiency identified and fixed in the fourth quarter frequently cannot be concluded remediated for that year, which is the argument for interim testing rather than a year-end assessment.

CPATrainingCenter.com 9715 Rod Road Suite A Alpharetta, GA 30022 1-770-410-1219 support@CPATrainingCenter.com
Certifications CPA CFP Enrolled Agent Payroll
Licensing & Events Securities Insurance Webinars Seminars
Stay Up To Date
Need Training Or Resources In Other Areas? Try Our Other Training Center Sites:
HR Banking Financial Services Insurance Mortgage Payroll Real Estate Safety
Training By Delivery Format & Subjects Covered:
Special Promotions Online Training Resource Materials Seminars Webinars All CPA/Accounting Subjects
Facebook Copyright CPATrainingCenter.com 2026