SOX readiness
Works out whether the auditor attestation actually applies to you, then weights the plan by where first-year programmes fail β which is not where the effort usually goes.
Filer status is derived, not asked
Attestation follows accelerated status; status follows public float measured on the last business day of your second fiscal quarter. Leave these blank and the tool says so rather than guessing.
Ordered by weight, heaviest first
The weights are not evenly spread. IT general controls and evidence of operation carry 45% between them, because that is where first-year programmes fail β process documentation, which absorbs most of the effort, carries 15%.
Access, change management and the controls around the systems the numbers come from. The most common source of first-year material weaknesses, and the most commonly under-resourced - a failure here is pervasive by construction, because a system you cannot rely on contaminates everything it produced.
A control that genuinely happens and leaves no trace fails testing exactly as hard as one that never happened. This is the cheapest gap to close and the one usually found in the first week of testing rather than the first month of planning.
The catch-all review that is meant to detect what the process controls miss, performed at a level that would not catch a material misstatement. It is designed when nobody wants to design a real control, and it is tested harder than anything else on the list.
Walkthroughs, flows, and a matrix that ties each control to the risk it addresses. Necessary, visible, and the part most readiness projects spend disproportionate time on because it is the most comfortable.
Which accounts, locations and processes are in scope, and why. Done badly it produces either an unaffordable programme or one that misses a material account - and scoping is the decision your auditor will re-perform first.
Tone, board oversight, whistleblowing, the control environment. Cheap to document and genuinely load-bearing: weak entity-level controls raise the bar on everything below them.
Whether the things you already know are broken have owners and dates. Carrying a known gap into year end unremediated is a different conversation from discovering one.
A planning tool. It sizes the work remaining; it does not and cannot tell you whether your ICFR will be effective at year end.
The attestation can arrive without anything about the company changing
Most readiness tools begin by asking whether SOX 404(b) applies to you, which assumes the answer to the question people most often get wrong. The auditorβs attestation follows accelerated filer status, and accelerated filer status follows public float measured on one specific day β the last business day of your second fiscal quarter. That means it can arrive because the share price moved in a quarter nobody was watching it, with revenue, headcount and operations all unchanged. And the year it arrives is the year the programme has to already exist.
The 2020 amendments to Rule 12b-2 run the other way and are less well understood. An issuer under the revenue ceiling, with float under the testβs own float ceiling, falls out of accelerated status on the revenue test β and the attestation goes with it. That is the expensive half of the change in both directions: the savings surprise people on the way out, and the cost surprises them on the way back.
The second thing this tool does differently is refuse to score your chance of passing. Internal control over financial reporting at year end is effective or it is not. There is no partial credit, no eighty percent, and no number that honestly expresses a likelihood. What a percentage can honestly express is how much work is left β and that number is only useful if the weights reflect where programmes actually fail, which is not where the effort usually goes.
Effort concentrates on process documentation, because documentation is the comfortable part: it is visible, it is finishable, and it can be done by the people already in the room. Failures concentrate somewhere else. They concentrate in IT general controls, owned by a team that has never been asked about control objectives and whose failures contaminate everything downstream. They concentrate in evidence, where controls that genuinely happen leave no trace and fail testing anyway. And they concentrate in the precision of management review controls β the catch-all review, designed when nobody wanted to design a real control, tested against a question nobody asked internally first.
What this tool does not do
The filer status half is derived from the text of Rule 12b-2 and is as reliable as the float and revenue figures you put in - float is measured on the last business day of your second fiscal quarter, not today and not at year end, and using the wrong date is the commonest way to get a wrong answer out of it. The readiness half is a weighted self-assessment. It is only as good as your own honesty about where each area has got to, and it deliberately does not produce a chance of passing, because ICFR at year end is effective or it is not and no percentage can express that.
- Any conclusion about whether your ICFR is or will be effective - that is a determination management makes and an auditor tests
- Scoping: which accounts, locations and processes are material to you, which is the decision your auditor re-performs first
- Reading your control matrix, your walkthroughs, or any of your documentation
- Whether a specific deficiency is a material weakness - the severity tool covers that framework separately
- COSO framework mapping, or whether your entity-level controls satisfy the seventeen principles
- ITGC testing itself: access reviews, change management, or anything about your specific systems
- The SEC's disclosure controls and procedures requirement under Rule 13a-15(e), which is a related but separate evaluation
- Cost, staffing or auditor fee estimates for the programme
Frequently asked questions
Does SOX 404(b) apply to us?
The tool derives it rather than asking. The auditor's attestation on internal control reaches accelerated and large accelerated filers, and that status turns on public float measured on the last business day of your second fiscal quarter β with a lower exit threshold than entry, so last year's status is an input to this year's. An emerging growth company is outside 404(b) for as long as it stays one, whatever its filer status.
Can the attestation go away?
Yes, and this is the half of the 2020 amendments to Rule 12b-2 that nobody notices. An issuer with revenue under $100m and float under $700m is a smaller reporting company on the revenue test, which excludes it from accelerated status β and the attestation goes with it. Note the float ceiling on that test: above $700m of float, low revenue buys nothing at all.
Why is the score labelled work remaining rather than readiness?
Because ICFR at year end is binary. It is effective or it is not; there is no eighty percent effective, and a tool that implies otherwise is telling you something that cannot be true. The percentage here sizes the programme β it is a project management number, weighted by where failures actually happen, and it is deliberately not a probability of passing.
Why do IT general controls carry the heaviest weight?
Because an ITGC deficiency is pervasive by construction. If the system that produces a number cannot be relied on, no control over that number can be either β so a gap in access management or change control does not stay contained to IT, it contaminates every process control that uses system-generated data. It is the most common source of first-year material weaknesses and the most commonly under-resourced part of a readiness plan.
We know our controls operate. Is documenting the evidence really worth it?
A control that genuinely operates and leaves no trace fails testing exactly as hard as one that never operated. The asymmetry is timing: an initial, a date and a saved report cost almost nothing prospectively, and there is no honest way to create them retrospectively. By the time testing starts, the periods you needed evidence for have already passed.
What is wrong with a management review control?
Nothing, if it has demonstrable precision. The question a tester asks is what size of error the review would have caught β and a monthly look at a variance report with no threshold, no record of what was investigated and no evidence of what the reviewer concluded has no answer to that. It is the control that gets designed when nobody wants to design a real one, and a well documented imprecise review is easier for a tester to find than an undocumented one.