Blog

SOX 404 vs 302: Which Sections Apply to You

Subscribe now to join the Risk Register community:

Most conversations about SOX compliance collapse everything into "Section 404" and move on.

That works until someone asks the CFO why the quarterly certifications are a separate obligation from the year-end ICFR assessment, or until internal audit presents a deficiency that affects one and not the other. Sections 302 and 404 cover different ground. The compliance calendars are different, the responsible parties are different, and the consequences for failures are different.

Section 302 Runs Quarterly; Section 404 Runs Annually

Section 302 of the Sarbanes-Oxley Act (SOX) requires the CEO and CFO to personally certify each quarterly and annual SEC filing. Specifically, they must certify that they have reviewed the report, that it does not contain material misstatements, that the financial statements fairly present the company's financial condition, and that they have disclosed to the audit committee and external auditors any significant deficiencies, material weaknesses, or fraud involving management.

Section 302 certifications happen four times a year, on every 10-Q and 10-K. That cadence matters for internal audit because deficiencies that surface mid-year must be disclosed in the next quarterly certification, not held until year-end. A material weakness identified in Q2 has to be reflected in the Q2 10-Q certification. There's no waiting for the annual ICFR assessment. Not every company faces both clocks equally, and filer status is what determines which one applies to you. Whether your company faces 404(b) specifically turns on a classification most teams haven't examined closely since they first went public.

Section 404 operates on a different clock and a different depth of obligation. Section 404(a) requires management to assess the effectiveness of the company's internal controls over financial reporting (ICFR) as of the fiscal year-end and include that assessment in the annual report. Section 404(b) requires the company's external auditor to independently attest to management's assessment. Both are annual, tied to the 10-K filing. The PCAOB's Auditing Standard AS 2201 governs the external auditor's work under 404(b), setting detailed requirements for the auditor's evaluation of management's assessment and independent testing of ICFR.

Does Your Company Actually Face 404(b)?

The 404(b) external auditor attestation requirement applies to large accelerated filers and accelerated filers. Non-accelerated filers face only 404(a), and since the SEC's 2020 amendments to the filer definitions that group is bigger than the old $75 million public float line suggests: a company with under $100 million in annual revenue and a public float under $700 million is now non-accelerated too. Emerging Growth Companies (EGCs) under the JOBS Act of 2012 are exempt from 404(b) for up to five years after their IPO, or until they lose EGC status, whichever comes first.

For internal audit, that distinction affects the depth of documentation required. When the external auditor must attest, the testing has to be built for external review, with evidence that supports a second set of professional eyes. When 404(b) doesn't apply, management's assessment still needs to be supportable, but the standard is management's own judgment rather than an auditor's attestation. The two are not the same bar, and audit plans should reflect which bar you're writing to. Whichever bar applies, both sections share the same vocabulary for what a control failure looks like, and that shared vocabulary is where the next piece of the analysis starts.

The Deficiency Classification Hierarchy Runs Through Both Sections

Both 302 and 404 reference the same three-level deficiency hierarchy: control deficiency, significant deficiency, and material weakness. A control deficiency exists when a control doesn't prevent or detect misstatements on a timely basis. A significant deficiency is a deficiency or combination of deficiencies important enough to merit attention by those charged with governance. A material weakness is a deficiency or combination of deficiencies where there is a reasonable possibility that a material misstatement could occur and not be prevented or detected in time.

Material weaknesses require public disclosure in the annual 10-K and, under 302, must be disclosed to the audit committee and external auditors in the period they are identified, not held until year-end. Year after year, the categories that show up most often in material weakness disclosures are the same ones: income tax accounting, revenue recognition, and the financial close and consolidation process. Each runs directly through processes that internal audit reviews, and the quarterly clock turns a slow finding in one of them into a certification problem fast. Understanding what that quarterly clock actually demands of internal audit's process is the next piece.

302 Certifications Create a Real-Time Pressure Test for Internal Audit's Work

Because Section 302 certifications happen quarterly, internal audit's findings don't sit in a holding pattern waiting for the year-end assessment. A significant deficiency or material weakness that surfaces during a Q3 internal audit engagement has to be evaluated and disclosed within that quarter's reporting cycle. The CEO and CFO are personally certifying that they've disclosed all of that information to the audit committee.

That creates a genuine forcing function for timely conclusions. Picture the finding that's been sitting in draft since July because the process owner keeps rescheduling the closing meeting. The 10-Q certification date doesn't reschedule with it. Draft findings that sit unresolved for two months aren't just a process problem. They create a gap between what internal audit knows and what the certifying officers can truthfully represent.

Internal audit functions that run efficient issue-to-conclusion timelines are providing real protection for the certifications, whether they frame it that way or not. The next section covers the criminal dimension most internal audit conversations skip past entirely.

Section 906 Adds Criminal Liability on Top of Civil Exposure

Neither 302 nor 404 exists in isolation. Section 906 of SOX establishes criminal penalties for false certifications. Knowingly submitting a false certification can result in fines up to $1 million and up to 10 years in prison. Willfully submitting a false certification carries fines up to $5 million and up to 20 years in prison. Section 906 is a criminal statute, so those cases are brought by the Department of Justice, while the SEC pursues its own false-certification actions under Section 302.

The theory in both is the same: material misstatements that flowed through control failures the certifying officers should have known about. Internal audit's role in keeping the CEO and CFO accurately informed is not a formality in that context. That criminal and civil exposure is exactly why the next question matters: how do 302 and 404 work together in the audit plan itself?

What Does the 302-and-404 Combination Mean for Your Audit Plan?

The practical implication for internal audit is that 302 and 404 together create a year-round obligation, not just a year-end project. The 404 assessment sets the annual framework: which controls are in scope, how they're documented, and how the risk of material misstatement is evaluated across financial reporting processes. The 302 certifications create quarterly checkpoints where control failures have to surface and be disclosed, not deferred.

Audit plans built around a Q4-heavy testing calendar miss this dynamic. Controls tested only once a year, in the months before year-end, don't support the quarterly certification cycle. The question worth asking when scoping the annual plan: are we testing frequently enough to support accurate certifications all year, not just the annual assessment? The answer to that question gets more consequential when you look at what happens to companies that arrive on a public exchange before they've had to ask it at all.

The NYSE Proposal Would Leave Newly Listed Companies With Neither 404(b) Nor Internal Audit

The NYSE has asked the SEC to stretch the transition period for its internal audit listing requirement from one year to five. The filing is SR-NYSE-2026-37, published in the Federal Register on August 18, 2026, and we submitted a comment letter asking the Commission to disapprove it. The reason ties straight back to everything above.

The Exchange's central argument is that internal audit only supplements Sections 404(a) and 404(b), so deferring it costs investors nothing. For the companies this rule actually reaches, that argument doesn't hold. There's no management report under 404(a) in the first annual report after an IPO. EGCs are exempt from 404(b) for up to five years. Put those side by side and a newly listed EGC could spend five years with no auditor attestation on ICFR, no internal audit function, and in year one no management assessment either. The 302 certifications keep coming every quarter the whole time, signed by a CEO and CFO with no independent check behind them.

Recent KPMG and PwC reviews of IPO filings put the share of new registrants disclosing at least one material weakness at close to half, and we walk through both studies in the letter. Those are the companies the proposal would let run without an internal audit function until year five. A company that arrives on the exchange carrying an unremediated material weakness is the strongest case for internal audit in year one, not the weakest.

Section 303A.07(c) already lets a listed company source the function from a third party, and a large share of the first-year work can now be automated with practitioner review on top. Our AI-enabled internal audit services run segregation-of-duties testing across key systems and controls testing at a fixed price, so a company that listed last quarter can have a charter, a risk assessment, and a sized audit plan well inside twelve months. The cost picture the Exchange describes isn't the one newly public companies actually face. Full stop.

Sections 302 and 404 only protect anyone when someone independent is testing between certifications. If your team is working through how to structure SOX testing to support both the quarterly 302 certifications and the annual 404 assessment, reach out to our SOX compliance and advisory practice and we'll walk through what a testing calendar that supports both looks like.

The next quarterly certification is closer than it looks.

Subscribe now to join the Risk Register community: