TeamSync
Why TeamSync
Intelligent-repositoryDocuTalkeSignaturesAudit TrailContract Lifecycle ManagementSecurity & DeploymenteDiscoverySemantic SearchAI SummarisationMetadata Extraction + OCR/ICRRBAC + Backup + RestoreAgentic AI WorkflowView all capabilities →
Finance & BankingHealthcareEnergy & UtilitiesManufacturingPublic SectorAEC
Compliance
BlogsFAQsCase StudiesWhite Papers
Contact
Intelligent-repositoryThe platformDocuTalkAI on your corpus eSignaturesSES, AdES, QESAudit TrailWorkflow & auditContract Lifecycle ManagementNative, not bolted-onSecurity & DeploymentDeploy your wayeDiscoveryHold at the sourceSemantic SearchHybrid retrievalAI SummarisationCitation-groundedMetadata Extraction + OCR/ICRCapture, typedRBAC + Backup + RestoreThe control surfaceAgentic AI WorkflowAI that acts
View all capabilities
Finance & BankingPCI, SOX & AML-ready document workflows for banksHealthcareHIPAA-first records, clinical workflows, audit trailsEnergy & UtilitiesPermits, safety & environmental compliance at scaleManufacturingCompliance-ready document workflowsPublic SectorFOIA, FedRAMP & records management for agenciesAECRFI, submittal & closeout document control at scale
View all industries
BlogsPractical writing on regulated content and AIFAQsCommon questions on deployment, security & complianceCase StudiesMeasured outcomes from regulated deploymentsWhite PapersTechnical papers on architecture, audit & regulation
TeamSync

The regulated content + AI platform for financial services, healthcare and life sciences, public sector, legal, energy, and AEC.

Capabilities
  • All Capabilities
  • DocuTalk AI
  • Electronic Signatures
  • Intelligent Repository
  • Audit Trail
  • E-Discovery
  • Contract Management
Industries
  • Financial Services
  • Healthcare
  • Energy
  • Manufacturing
  • Public Sector
  • AEC
Compliance
  • All Compliance
  • DPDP
  • HIPAA
  • SOC 2
  • ISO 27001
  • FedRAMP High
  • GDPR Art. 17
  • eIDAS QES
  • FDA 21 CFR Pt. 11
Resources
  • All Resources
  • Blog
  • FAQs
  • Case Studies
  • White Papers
AboutTermsPrivacyDPASub-processorsCookie PolicySitemap
© 2026 TeamSync. All rights reserved.TeamSync is a product of AngelBot AI.
Follow us
Home›Blog›General
GeneralAugust 31, 2026

SOX Controls Explained: The Full List of Entity, Process, and IT Controls

TT
TeamSync Team
5 min read
Share
SOX Controls Explained: The Full List of Entity, Process, and IT Controls
On this page
  • Why SOX controls stay under the microscope
  • What SOX controls actually are and why public companies rely on them
  • The three buckets that make up a real SOX control environment
  • How companies decide which SOX controls belong in scope
  • The full list of SOX controls by category with examples auditors expect to see
  • Where SOX programs usually get stuck: evidence, reports, spreadsheets and SOC 1 reliance
  • How SOX control testing works from walkthroughs to deficiency ratings
  • Why IT changes, AI workflows and cyber incidents can quietly break a SOX control
  • What strong SOX programs deliver beyond compliance
  • See how we keep control owners, evidence and testing in sync

Why SOX controls stay under the microscope

In a 2024 statement from the SEC’s chief accountant, Paul Munter said PCAOB inspections found insufficient audit evidence in 40% of inspected audits in the 2022 cycle, up from 34% and 29% in the prior two cycles. He also called out a familiar pain point in ICFR work: across the last three annual inspection cycles, auditor testing of management review controls had the highest rate of deficiency. Add the ACFE’s 2024 Report to the Nations, which found 32% of occupational fraud cases involved a lack of internal controls and 19% involved override of existing controls and you can see why audit committees do not treat SOX as paperwork. Even the SEC still brings cases here. In January 2025 it charged Singularity Future Technology after eight years of ineffective ICFR and disclosure controls and a restatement tied to those weaknesses. 

The environment is getting harder, not simpler. A May 11, 2026 KPMG survey said 93% of US companies expect to deploy or scale AI in finance over the next 18 months, with half planning multi-agent workflows. A June 2026 Deloitte note on cloud ERP transformation said 49% of surveyed North American CFOs saw cost-management pressure driven by investment in AI and cloud. At the same time the SEC’s cybersecurity disclosure rules and staff guidance updated in May 2025 keep pushing companies to reassess how cyber risk affects disclosure and reporting. That is why SOX controls stay in view all year. They are internal controls over financial reporting designed to keep reporting accurate, transparent and reliable and they have to stand up to annual management assessment and for many issuers, an integrated external audit. 

What SOX controls actually are and why public companies rely on them

Teams ask us every version of the same question: what are SOX controls, what is a SOX control, what is SOX control and even what is SOX controls. In plain English, SOX controls are internal controls over financial reporting that are designed to prevent fraud and material misstatements in the financial statements. The key point is scope. Not every internal control is a SOX control. A warehouse KPI review, a sales pipeline meeting or a customer NPS dashboard may matter to operations, but they are not SOX controls unless they directly support ICFR. SOX internal controls are the narrower set that matter to external financial reporting. 

Public companies rely on them because the Sarbanes-Oxley Act built management accountability into the reporting cycle. Section 302 requires CEO and CFO certifications in quarterly and annual reports. Section 404 requires management’s annual ICFR assessment and for companies subject to 404(b), auditor attestation. Section 906 is the separate certification under Title 18 with criminal provisions. PCAOB standards then govern how the auditor performs the integrated audit of ICFR and the financial statements. A simple example helps: a monthly account reconciliation for cash or deferred revenue can be a SOX control because it supports completeness, accuracy and cutoff in the general ledger. A monthly review of web traffic might be useful, but it usually is not a SOX control unless that metric feeds a material financial estimate or disclosure. 

The three buckets that make up a real SOX control environment

  • Entity-level controls set the tone and the guardrails. This bucket includes the code of conduct, audit committee oversight, fraud risk assessment, whistleblower procedures, close calendar governance and management review controls. Preventive examples include policy approvals and authority matrices. Detective examples include budget-to-actual reviews, quarterly balance sheet reviews and close analytics that surface unusual swings before filings go out. 

  • Process-level controls sit inside the actual transaction cycles: order to cash, procure to pay, payroll, inventory, treasury, tax and financial close. This is where reconciliations, journal entry approvals, three-way match, bank reconciliations, manual price override approvals and disclosure controls live. Some are preventive, like blocking an unapproved vendor payment. Others are detective, like a month-end reconciliation that catches an interface break after the fact. 

  • IT controls hold up the systems that process financial data. The core domains are access management, change management, computer operations and the application-level pieces that depend on them such as interface monitoring, audit trails, backups and segregation of duties. Preventive examples include approved provisioning, privileged access restrictions and SSO settings. Detective examples include access reviews, failed-job monitoring, backup restore tests and exception reports that confirm data moved completely from one system to another. 

How companies decide which SOX controls belong in scope

Good scoping starts at the top of the financial statements and works down. Management begins with significant accounts and disclosures, applies materiality, identifies relevant assertions such as occurrence, completeness, accuracy, cutoff, valuation and presentation, then maps those assertions to the processes, locations, systems, reports and people that could produce a material misstatement. That is the top-down approach in PCAOB AS 2201. Most companies anchor the overall framework in COSO and use COBIT to organize the IT side of the environment. Walkthroughs validate that the process narrative matches reality. The risk and control matrix then ties each risk to a control objective, a specific control activity and the evidence that proves it operated. 

Scoping discipline matters because the control universe gets large fast. In KPMG’s 2025 SOX survey, organizations averaged 546 key controls overall. Companies under $5 billion in revenue averaged about 320 total key controls, mid-sized companies averaged 629 and companies above $25 billion averaged 1,202. That is why strong teams narrow scope based on risk instead of trying to test every sensible control in the building. 

The full list of SOX controls by category with examples auditors expect to see

At the entity level, auditors usually expect to see tone at the top, audit committee oversight, close calendar governance, budget-to-actual review, policy approvals, whistleblower procedures and a fraud risk assessment. Management review controls live here too, but only when they operate at a level of precision that could catch a material misstatement. 

At the business process level, the common catalog includes reconciliations, three-way match, journal entry review, bank reconciliation, manual price override approval, inventory count controls, payroll master data review, tax provision review and disclosure controls around the quarter-end and year-end close. Some of these are preventive. Some are detectives. A good SOX program usually needs both. 

On the IT side, the reference list usually includes user provisioning and deprovisioning, privileged access review, password and SSO settings, segregation of duties, change tickets with approval and testing, batch or job monitoring, backup and restore testing, interface completeness checks, audit trail retention and incident response procedures that connect back to ICFR when financially relevant systems are affected. Then there are automated application controls such as three-way match logic, workflow approval routing, posting blocks, duplicate invoice checks and revenue recognition rules configured in the application itself. 

Where SOX programs usually get stuck: evidence, reports, spreadsheets and SOC 1 reliance

The hardest part of SOX is rarely writing the control. It is proving the control actually operated. For a management review control, a signature alone is weak. A revenue fluctuation review needs the threshold used, the comparison performed, the exceptions investigated, the questions asked and the support retained. PCAOB guidance is blunt here: verifying sign-off by itself provides little or no evidence. Precision matters. A review of total company revenue is less precise than a review by product, region or contract type. That is why management review controls often look fine on paper and still fail testing. 

Report completeness and accuracy is the next trap. If a control uses a report then the team needs to show the report source, parameters, population completeness, logic, any manual filters and why the report ties back to the system of record. PCAOB said about 17% of audits inspected in the 2021 and 2022 cycles had deficiencies where the auditor did not sufficiently test the accuracy and completeness of company-produced information or external-source information. In KPMG’s 2025 survey, 55% of organizations still said IPE and completeness and accuracy issues caused moderate challenges and 61% to 70% of organizations tested key reports every year depending on revenue size. 

SOC 1 reliance has its own rules. A SOC 1 report covers controls at a service organization that are relevant to user entities’ ICFR, but it does not erase the customer’s work. Complementary user entity controls still have to exist and operate on your side. If the payroll processor assumes you restrict HR master data changes or review exception reports, that remains your control. Spreadsheet and end-user computing controls are similar. The file needs a clear owner, version control, locked formulas, access restrictions, evidence of change review and a way to show that key tabs and logic were not altered outside the approved process. 

How SOX control testing works from walkthroughs to deficiency ratings

When people talk about SOX control testing, SOX controls testing or SOX compliance testing, they usually mean the same sequence. First comes design effectiveness: if the control worked exactly as described, could it prevent or detect a material misstatement? Then implementation: does the control actually exist and is the right person performing it? Then operating effectiveness: did it work consistently during the period? Test methods include inquiry, inspection, observation and reperformance, with sample sizes based on frequency and risk. Walkthroughs often happen early. Retesting happens after remediation if a control failed earlier in the year. Management may do this work directly, internal audit may lead it, some companies co-source it and external auditors perform their own testing for reliance and for the integrated audit opinion. 

Deficiency ratings turn on likelihood and magnitude. A control deficiency exists when the design or operation of a control does not let management prevent or detect misstatements on time. A significant deficiency is less severe than a material weakness but still important enough for audit committee attention. A material weakness exists when there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on time. One late approval on a low-risk reconciliation with a precise compensating review may stay a simple deficiency. Ineffective access provisioning across a core financial application is different because it can affect multiple assertions, multiple processes and a large transaction population. PCAOB also treats a material restatement as an indicator of material weakness, though SEC staff has said not every restatement automatically means one exists. In the real world the consequences are public: the SEC’s January 17, 2025 action against Singularity cited eight years of ineffective ICFR and unremediated material weaknesses, while a 2026 amended filing by Core Scientific tied a material weakness in accounting controls to multi-period restatements. 

Why IT changes, AI workflows and cyber incidents can quietly break a SOX control

A control can stay perfectly documented and still break the moment the technology around it changes. AI-assisted journal entry preparation can introduce accuracy risk if the reviewer only checks the final entry and not the source logic. AI-based anomaly detection can be useful, but someone still needs to define escalation thresholds, review false positives and keep evidence of what was investigated. COSO’s 2026 guidance on internal control over generative AI is a sign that this has moved from experiment to control design. That lines up with KPMG’s May 2026 survey, which found half of US companies were already planning multi-agent AI systems in finance and named cyber threats and accuracy of AI-generated outputs as leading concerns. 

ERP and cloud migrations create quieter failures. Automated controls may need re-benchmarking after configuration changes. Interfaces may need to be revalidated after a new API or middleware layer goes live. Role redesign in a SaaS ERP can blow up segregation of duties if finance and IT do not revisit permissions. Deloitte’s 2026 cloud ERP guidance makes the point well: transformation is a chance to modernize controls over data mapping, validation, segregation of duties and audit trails, but only if those controls stay integrated from planning through post-deployment. We see teams wait until UAT is nearly done, then discover that the report used in a review control changed fields, the approval workflow lost an audit trail or a cloud vendor now owns part of the evidence chain. 

Cyber incidents can do the same thing from the outside. If an intrusion corrupts data, interrupts logging or forces emergency access changes, the ICFR risk assessment has changed whether or not the quarterly close calendar admits it yet. The SEC’s cyber rules and staff guidance both push registrants to assess these risks on an ongoing basis and to think about outsourced functions, operational disruption and the quality of disclosure. In practice that means incident response is not just a security playbook. It may trigger control redesign for backups, journal entry approvals, interface monitoring, disclosure committee workflows and human review over reconstructed data. 

What strong SOX programs deliver beyond compliance

Strong programs do more than pass testing. They shorten the close because owners know what evidence is needed the first time. They reduce audit surprises because finance, IT and audit are working from the same risk map. They improve governance because the audit committee gets cleaner issue tracking and clearer severity calls. They support investor confidence because reliable reporting is the point of the whole exercise. They also make IPO prep, acquisitions, ERP changes and post-close remediation far less chaotic. If you want a practical benchmark, KPMG’s 2025 survey found 68% of organizations described their programs as maturing and showed just how different the control footprint can be by size. Good programs are not the ones with the most controls. They are the ones where every key control has a clear owner, a clean evidence trail and a path to remediation when something breaks. That is the same discipline we build into our SOX 404 workflow and our compliance reporting and audit trail capabilities. 

See how we keep control owners, evidence and testing in sync

If you are mapping SOX controls or cleaning up testing season, get in touch to see how we can help your finance, IT and audit teams keep evidence, owners, reviews and remediation in one shared workflow at TeamSync.

Found this useful? Share it.

Share

On this page

  • Why SOX controls stay under the microscope
  • What SOX controls actually are and why public companies rely on them
  • The three buckets that make up a real SOX control environment
  • How companies decide which SOX controls belong in scope
  • The full list of SOX controls by category with examples auditors expect to see
  • Where SOX programs usually get stuck: evidence, reports, spreadsheets and SOC 1 reliance
  • How SOX control testing works from walkthroughs to deficiency ratings
  • Why IT changes, AI workflows and cyber incidents can quietly break a SOX control
  • What strong SOX programs deliver beyond compliance
  • See how we keep control owners, evidence and testing in sync

Related articles

  • Healthcare Compliance Officer: Role, Responsibilities, and What They Actually Need
    GeneralHealthcare Compliance Officer: Role, Responsibilities, and What They Actually Need5 min read
  • SOX Compliance: Requirements, Controls, and What Auditors Actually Ask For
    GeneralSOX Compliance: Requirements, Controls, and What Auditors Actually Ask For5 min read
  • Compliance Risk Management: Frameworks, Governance, and How to Actually Run It
    GeneralCompliance Risk Management: Frameworks, Governance, and How to Actually Run It5 min read
← PreviousSOX Compliance: Requirements, Controls, and What Auditors Actually Ask ForGeneralNext →Compliance Risk Management: Frameworks, Governance, and How to Actually Run ItGeneral

Keep reading

More insights from the TeamSync team

Healthcare Compliance Officer: Role, Responsibilities, and What They Actually Need
General5 min read

Healthcare Compliance Officer: Role, Responsibilities, and What They Actually Need

TT
TeamSync TeamAugust 31, 2026
Read more →
SOX Compliance: Requirements, Controls, and What Auditors Actually Ask For
General5 min read

SOX Compliance: Requirements, Controls, and What Auditors Actually Ask For

TT
TeamSync TeamAugust 31, 2026
Read more →
Compliance Risk Management: Frameworks, Governance, and How to Actually Run It
General5 min read

Compliance Risk Management: Frameworks, Governance, and How to Actually Run It

TT
TeamSync TeamAugust 27, 2026
Read more →