SOX 404 and ICFR and PCAOB AS 2201: what it asks of an approval matrix
For a listed company: the entity-level controls an ICFR programme carries, the delegation of authority among them, and the fraud controls over journals and management override. PCAOB AS 2201 is quoted beside it for the auditor's side of the same work.
Quoted when the company is listed and SOX 404 is in scope.
Named, not quoted, beside it: the SEC rules on internal control over financial reporting beyond what SOX 404 carries; the ASX Corporate Governance Principles and Recommendations.
Approval families anchored here
36SOX 404 and ICFR: every clause cited, quoted
7 of the 19 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
SOX ENT-2 Audit Committee OversightThe audit committee oversees ICFR, financial reporting, and external auditor independence with documented charter and meeting cadence.
Where matrices usually fall short: Audit Committee charter not refreshed when responsibilities change; Executive sessions with external auditor and internal audit not consistently held; Committee not evidencing review of significant estimates and judgments; Pre-approval policy for non-audit services not consistently followed; Minutes do not document challenge of management or follow-up on prior items
Source: SOX 404 and ICFR
SOX ENT-5 Delegation of AuthorityBoard-approved delegation of authority matrix defines approval limits for commitments, expenditures, and contracts.
Where matrices usually fall short: Delegation of authority not reconciled to system approval limits across ERP and banking; Re-delegation in absence of approver not documented or not time-bound; Out-of-policy approvals not escalated or remediated; Authority matrix not refreshed when roles and reporting lines change; Compensating controls not documented when the approver is unavailable
Source: SOX 404 and ICFR
SOX FRAUD-1 Fraud Risk AssessmentAnnual fraud risk assessment identifies schemes, considers incentives/pressures, opportunities, and rationalizations.
Where matrices usually fall short: Fraud risk assessment treated as a checkbox rather than a tailored exercise; Schemes not mapped to specific accounts, assertions, and processes; Anti-fraud programs not linked to identified scheme risks; Assessment not refreshed when business model or incentives change; Output not communicated to process owners or the Audit Committee
Source: SOX 404 and ICFR
SOX FRAUD-2 Management Override ControlsControls mitigate management override risk including independent review of top-side journal entries and unusual transactions.
Where matrices usually fall short: Top-side and topside-only entries not separately identified and reviewed; Manual journal entries posted by management without independent review; Late entries near period close not subject to enhanced scrutiny; Compensating controls not documented when normal segregation fails; Reports used to identify override risk are IPE without ITGC testing
Source: SOX 404 and ICFR
SOX FRAUD-3 Journal Entry Review and ApprovalManual journal entries are reviewed and approved by someone other than the preparer with supporting documentation.
Where matrices usually fall short: Risk-based criteria for entry selection not defined or not refreshed; Same user posts and approves entries below threshold, breaking segregation; Support documentation not consistently attached for manual entries; Review of high-risk entries evidenced only by signature without documented inquiry; Recurring or templated entries not periodically validated for continued validity
Source: SOX 404 and ICFR
SOX FRAUD-4 Conflict of Interest DisclosureAnnual conflict of interest disclosures are obtained from directors, officers, and key employees.
Where matrices usually fall short: Disclosure population incomplete for contractors, board, and acquired entity staff; Disclosed conflicts not adjudicated or mitigated with documented plans; Annual refresh not reconciled to current employee and contractor lists; Related party disclosures not reconciled to vendor and customer master data; Walkthroughs of the conflict disclosure process not refreshed annually
Source: SOX 404 and ICFR
SOX SOX404-3 Business Process Controls (Revenue, Procurement, HR, Inventory)Per SOX 404: business process controls including Revenue + Procure-to-Pay + HR/Payroll + Inventory + Treasury + each tied to financial statement assertions.
Source: SOX 404 and ICFR
PCAOB AS 2201: every clause cited, quoted
3 of the 8 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. The evidence guidance for these rows is not held, and the page says so on each.
AS 2201 ASTWO-3 Entity-Level Controls and Period-End Financial Reporting ProcessPer PCAOB AS 2201 paragraphs 4, 22-27, 5: entity-level controls + period-end. Requirements include (a) evaluate Entity-Level Controls including control environment + risk assessment + monitoring + information + communication + COSO components + (b) evaluate the Period-End Financial Reporting Process including procedures used to enter transactions + initiate + authorise + record + process + report period-end financial information + (c) consider IT general controls + IT application controls + (d) consider management override + tone at the top + governance + ethics + (e) document evaluation including significant findings + conclusions + (f) determine extent + nature of further testing based on entity-level conclusions.
Source: PCAOB AS 2201
AS 2201 ASTWO-4 Walkthroughs, Control Selection, Design Effectiveness TestingPer PCAOB AS 2201 paragraphs 7, 8-9, 39, 42: walkthroughs + selection + design effectiveness. Requirements include (a) perform Walkthroughs of significant transaction flows to confirm understanding of controls + identify control points + (b) Selecting Controls to Test focused on controls that sufficiently address the risk of misstatement to each relevant assertion + (c) evaluate Design Effectiveness via inquiry + observation + walkthrough + inspection + (d) determine whether the company's controls if operating as prescribed by persons possessing necessary authority + competence would satisfy the company's control objectives + (e) document understanding + selection rationale + design conclusions + (f) update design conclusions as controls or processes change.
Source: PCAOB AS 2201
AS 2201 ASTWO-7 Deficiency Evaluation, Material Weakness, and CommunicationPer PCAOB AS 2201 paragraphs 62-69: deficiency evaluation + classification + communication. Requirements include (a) evaluate Deficiencies including severity considering likelihood + potential magnitude + compensating controls + (b) classify deficiencies as deficiency + significant deficiency + material weakness per AS 2201 definitions + (c) determine Material Weakness existence based on likelihood and magnitude of potential misstatement + (d) Communicate Deficiencies to management and audit committee + (e) communicate material weaknesses in writing to management + audit committee + (f) document evaluation including severity factors + classification + communication + (g) consider aggregated impact of deficiencies + remediation status + management response.
Source: PCAOB AS 2201