Delegation of Authority Matrix Validator
Regime

SOX 404 and ICFR and PCAOB AS 2201: what it asks of an approval matrix

For a listed company: the entity-level controls an ICFR programme carries, the delegation of authority among them, and the fraud controls over journals and management override. PCAOB AS 2201 is quoted beside it for the auditor's side of the same work.

Quoted when the company is listed and SOX 404 is in scope.

Named, not quoted, beside it: the SEC rules on internal control over financial reporting beyond what SOX 404 carries; the ASX Corporate Governance Principles and Recommendations.

Approval families anchored here

36
FamilyClause
Purchase ordersSOX ENT-5 · SOX SOX404-3
Invoices with no purchase orderSOX ENT-5 · SOX SOX404-3
Capital expenditureSOX ENT-5 · SOX SOX404-3
Leases and rental commitmentsSOX ENT-5 · SOX SOX404-3
Spend over budget and budget transfersSOX ENT-5 · SOX SOX404-3
Payment run releaseSOX ENT-5 · SOX SOX404-3
Urgent and manual paymentsSOX ENT-5 · SOX SOX404-3
Bank account opening and changesSOX ENT-5 · SOX SOX404-3
Vendor master data changeSOX ENT-5 · SOX FRAUD-1
Employee expense claimsSOX ENT-5 · SOX SOX404-3
Payroll releaseSOX ENT-5 · SOX SOX404-3
Customer and sales contractsSOX ENT-5
Supplier contractsSOX ENT-5
Contracts signed for the companySOX ENT-5
Confidentiality agreementsSOX ENT-5
Guarantees, indemnities and letters of creditSOX ENT-2 · SOX ENT-5
Journal entriesSOX FRAUD-2 · SOX FRAUD-3 · AS 2201 ASTWO-3
Accruals and prepaymentsSOX FRAUD-3 · SOX SOX404-3 · AS 2201 ASTWO-3
Provisions and reservesSOX FRAUD-3 · SOX SOX404-3 · AS 2201 ASTWO-3
Write-offsSOX FRAUD-3 · SOX SOX404-3 · AS 2201 ASTWO-3
Reconciliation sign-offSOX FRAUD-3 · SOX SOX404-3 · AS 2201 ASTWO-3
FX, hedging and treasury dealsSOX FRAUD-3 · SOX SOX404-3 · AS 2201 ASTWO-3
Price and price list changesSOX ENT-5 · SOX SOX404-3
Discounts and rebatesSOX ENT-5 · SOX SOX404-3
Credit notesSOX ENT-5 · SOX SOX404-3
Customer refundsSOX ENT-5 · SOX SOX404-3
Customer credit limitsSOX ENT-5 · SOX SOX404-3
New hires and headcountSOX SOX404-3
Pay changesSOX SOX404-3
Terminations and severanceSOX SOX404-3
Bonuses and incentivesSOX SOX404-3
Acquisitions, disposals and borrowingSOX ENT-2 · SOX ENT-5
Related-party transactionsSOX ENT-2 · SOX FRAUD-4
Donations, sponsorships, gifts and hospitalitySOX ENT-2 · SOX ENT-5
Litigation and claim settlementsSOX ENT-2 · SOX ENT-5
Changes to the delegation of authoritySOX ENT-5

SOX 404 and ICFR: every clause cited, quoted

7 of the 19 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

SOX ENT-2 Audit Committee Oversight

The audit committee oversees ICFR, financial reporting, and external auditor independence with documented charter and meeting cadence.

What an auditor asks to see: Audit committee charter; Independence assessments; Meeting minutes; Agendas; Executive session records; Auditor communications
Where matrices usually fall short: Audit Committee charter not refreshed when responsibilities change; Executive sessions with external auditor and internal audit not consistently held; Committee not evidencing review of significant estimates and judgments; Pre-approval policy for non-audit services not consistently followed; Minutes do not document challenge of management or follow-up on prior items
Source: SOX 404 and ICFR
SOX ENT-5 Delegation of Authority

Board-approved delegation of authority matrix defines approval limits for commitments, expenditures, and contracts.

What an auditor asks to see: DOA policy; Board resolutions; Approval evidence for transactions above thresholds; System configuration
Where matrices usually fall short: Delegation of authority not reconciled to system approval limits across ERP and banking; Re-delegation in absence of approver not documented or not time-bound; Out-of-policy approvals not escalated or remediated; Authority matrix not refreshed when roles and reporting lines change; Compensating controls not documented when the approver is unavailable
Source: SOX 404 and ICFR
SOX FRAUD-1 Fraud Risk Assessment

Annual fraud risk assessment identifies schemes, considers incentives/pressures, opportunities, and rationalizations.

What an auditor asks to see: Fraud risk methodology; Fraud risk register; Control mapping; Mitigation plans
Where matrices usually fall short: Fraud risk assessment treated as a checkbox rather than a tailored exercise; Schemes not mapped to specific accounts, assertions, and processes; Anti-fraud programs not linked to identified scheme risks; Assessment not refreshed when business model or incentives change; Output not communicated to process owners or the Audit Committee
Source: SOX 404 and ICFR
SOX FRAUD-2 Management Override Controls

Controls mitigate management override risk including independent review of top-side journal entries and unusual transactions.

What an auditor asks to see: Override risk policy; Top-side JE review; Audit committee review of estimates; Related party transactions
Where matrices usually fall short: Top-side and topside-only entries not separately identified and reviewed; Manual journal entries posted by management without independent review; Late entries near period close not subject to enhanced scrutiny; Compensating controls not documented when normal segregation fails; Reports used to identify override risk are IPE without ITGC testing
Source: SOX 404 and ICFR
SOX FRAUD-3 Journal Entry Review and Approval

Manual journal entries are reviewed and approved by someone other than the preparer with supporting documentation.

What an auditor asks to see: JE policy; Approval matrix; Approved JEs with support; Exception reports
Where matrices usually fall short: Risk-based criteria for entry selection not defined or not refreshed; Same user posts and approves entries below threshold, breaking segregation; Support documentation not consistently attached for manual entries; Review of high-risk entries evidenced only by signature without documented inquiry; Recurring or templated entries not periodically validated for continued validity
Source: SOX 404 and ICFR
SOX FRAUD-4 Conflict of Interest Disclosure

Annual conflict of interest disclosures are obtained from directors, officers, and key employees.

What an auditor asks to see: COI policy; Completed disclosures; Review and resolution log
Where matrices usually fall short: Disclosure population incomplete for contractors, board, and acquired entity staff; Disclosed conflicts not adjudicated or mitigated with documented plans; Annual refresh not reconciled to current employee and contractor lists; Related party disclosures not reconciled to vendor and customer master data; Walkthroughs of the conflict disclosure process not refreshed annually
Source: SOX 404 and ICFR
SOX SOX404-3 Business Process Controls (Revenue, Procurement, HR, Inventory)

Per SOX 404: business process controls including Revenue + Procure-to-Pay + HR/Payroll + Inventory + Treasury + each tied to financial statement assertions.

What an auditor asks to see: evidence guidance not held for this clause
Source: SOX 404 and ICFR

PCAOB AS 2201: every clause cited, quoted

3 of the 8 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim. The evidence guidance for these rows is not held, and the page says so on each.

AS 2201 ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process

Per PCAOB AS 2201 paragraphs 4, 22-27, 5: entity-level controls + period-end. Requirements include (a) evaluate Entity-Level Controls including control environment + risk assessment + monitoring + information + communication + COSO components + (b) evaluate the Period-End Financial Reporting Process including procedures used to enter transactions + initiate + authorise + record + process + report period-end financial information + (c) consider IT general controls + IT application controls + (d) consider management override + tone at the top + governance + ethics + (e) document evaluation including significant findings + conclusions + (f) determine extent + nature of further testing based on entity-level conclusions.

What an auditor asks to see: evidence guidance not held for this clause
Source: PCAOB AS 2201
AS 2201 ASTWO-4 Walkthroughs, Control Selection, Design Effectiveness Testing

Per PCAOB AS 2201 paragraphs 7, 8-9, 39, 42: walkthroughs + selection + design effectiveness. Requirements include (a) perform Walkthroughs of significant transaction flows to confirm understanding of controls + identify control points + (b) Selecting Controls to Test focused on controls that sufficiently address the risk of misstatement to each relevant assertion + (c) evaluate Design Effectiveness via inquiry + observation + walkthrough + inspection + (d) determine whether the company's controls if operating as prescribed by persons possessing necessary authority + competence would satisfy the company's control objectives + (e) document understanding + selection rationale + design conclusions + (f) update design conclusions as controls or processes change.

What an auditor asks to see: evidence guidance not held for this clause
Source: PCAOB AS 2201
AS 2201 ASTWO-7 Deficiency Evaluation, Material Weakness, and Communication

Per PCAOB AS 2201 paragraphs 62-69: deficiency evaluation + classification + communication. Requirements include (a) evaluate Deficiencies including severity considering likelihood + potential magnitude + compensating controls + (b) classify deficiencies as deficiency + significant deficiency + material weakness per AS 2201 definitions + (c) determine Material Weakness existence based on likelihood and magnitude of potential misstatement + (d) Communicate Deficiencies to management and audit committee + (e) communicate material weaknesses in writing to management + audit committee + (f) document evaluation including severity factors + classification + communication + (g) consider aggregated impact of deficiencies + remediation status + management response.

What an auditor asks to see: evidence guidance not held for this clause
Source: PCAOB AS 2201