SOX Documentation Examples: Narratives, Matrices, and Testing Logs

Sarbanes-Oxley compliance is built on a specific set of documents: written process narratives, workflow flowcharts, a risk and control matrix, testing logs with supporting evidence, IT general control records, officer certifications, and reports classifying any control failures. Below are SOX documentation examples for each of these categories, with what auditors expect to see inside them and the federal rules that govern how long you have to keep them. Section 404 of the Act requires every annual report to include management’s assessment of whether internal controls over financial reporting work effectively, and that assessment is only as good as the paperwork behind it.1Office of the Law Revision Counsel. United States Code Title 15 Section 7262 – Management Assessment of Internal Controls

Who Produces This Documentation

The rules apply to companies that file periodic reports with the SEC under the Securities Exchange Act of 1934.2Legal Information Institute. Sarbanes-Oxley Act All of them must produce documentation supporting management’s Section 404(a) assessment. Accelerated filers, generally those with $100 million or more in revenues, face a second layer: their outside auditor must independently evaluate that documentation and issue its own opinion under 404(b).3U.S. Securities and Exchange Commission. Smaller Reporting Companies Non-accelerated filers and emerging growth companies are permanently exempt from the 404(b) auditor attestation but still must complete the management assessment and its supporting documentation.1Office of the Law Revision Counsel. United States Code Title 15 Section 7262 – Management Assessment of Internal Controls Private companies fall outside SOX entirely.

Process Narratives

A process narrative is a written, step-by-step description of how the company handles a financial process from beginning to end. Two of the most common examples cover the Procure-to-Pay and Order-to-Cash cycles.

A Procure-to-Pay narrative walks through everything from the initial purchase request to the final payment. It names the specific roles at each stage: the purchasing agent who approves a vendor, the receiving clerk who confirms delivery, the accounts payable employee who matches the invoice to the purchase order. An Order-to-Cash narrative covers the customer side, describing how orders are received, how credit limits are checked, and when revenue is recorded in the accounting system.

Good narratives state how often each task happens (daily posting versus month-end reconciliation, for instance) and identify where automated controls in the software block unauthorized transactions from moving forward without approval. The test is whether someone unfamiliar with the process could read the narrative and understand exactly who does what, when they do it, and what prevents mistakes.

Workflow Flowcharts

Flowcharts translate the narratives into visual maps that show how financial data moves through the organization. A typical SOX flowchart tracks a transaction from its origin to its final posting in the general ledger, using standardized symbols: rectangles for actions, diamonds for decision points where someone must approve or reject, and clear start and end markers that define the boundaries of the process.

Their value is in exposing gaps. Auditors look at the visual flow and can immediately spot places where a control might be missing or where one person handles too many steps in a chain.

Segregation of Duties Records

That last point, one person handling too many steps, is what segregation of duties documentation addresses. The records define role boundaries: who prepares journal entries, who approves them, and who reconciles the accounts afterward. The same split applies to procurement (vendor setup, approval, and payment kept separate) and payroll (calculation, approval, and disbursement kept separate).

Documentation for segregation of duties typically consists of role-based access control configurations in the ERP and IT systems, not a policy manual sitting on a shelf. The records need to show that system permissions actually enforce the separation. Auditors also expect evidence that management conducts regular access reviews before the external audit, confirming the segregation is current rather than set up once and forgotten.p>

Risk and Control Matrix

The Risk and Control Matrix, usually called a RACM, is the central document that ties every identified financial risk to the specific control designed to address it. It is organized as a grid, with columns for a control ID, a risk statement describing what could go wrong, and a detailed description of the control activity itself.

Specificity is what makes a RACM entry useful. For a journal entry review control, the matrix should state that a manager must approve all manual adjustments above a set dollar threshold before they post. Vague descriptions are exactly what auditors flag as deficient. Each entry also states how often the control runs (daily, weekly, quarterly) and classifies it as preventive (stops the error before it happens) or detective (catches the error after the fact, like a monthly reconciliation). Both types belong in the matrix, across every significant account and process.

Choosing Which Controls Belong in the Matrix

Not every control the company operates qualifies as a “key control” that demands full documentation and testing. PCAOB Auditing Standard 2201 directs auditors to use a top-down approach, starting at the financial statement level and working down to significant accounts, focusing on the areas with the greatest risk of material misstatement.4Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting Management should apply the same logic. A low-risk account warrants lighter documentation than one with a history of adjustments or judgment-heavy estimates.

Entity-level controls get evaluated first: the audit committee’s oversight role, a whistleblower hotline, and a code of conduct. If those are weak, auditors test more heavily at the process level, which drives up the documentation burden everywhere else.

Testing Logs and Supporting Evidence

A control that is beautifully documented but never actually performed is worse than useless. Testing logs are the proof that a control operated as designed throughout the reporting period. Common examples include:

  • Bank reconciliation reports signed by a reviewing manager.
  • System-generated exception reports listing transactions that deviated from the rules, with notes on how each exception was resolved.
  • Screenshots showing that automated controls blocked unauthorized actions.
  • Physical inventory count sheets, approval records, and timestamped system logs.

Each piece of evidence connects a specific control to a specific date, person, and outcome. Auditors are not looking for perfection. They are looking for consistent execution. A control performed 49 out of 52 weeks with documented reasons for the three gaps tells a stronger story than a control with no evidence at all.

IT General Control Records

IT general controls protect the technology environment that financial reporting runs on. The documentation splits into a few standard categories.

Access control records are the most heavily tested. They include user access request forms showing manager approval for each grant of access to financial systems, periodic access review reports where managers confirm current users still need their permissions, and evidence of prompt removal when employees leave or change roles. Password policy configurations, firewall logs, and records of administrative access to sensitive servers fill out the file.

Change management documentation tracks every modification to financial software, from the initial request through development, testing, and approval before implementation. The records must show that no change went live without being tested and signed off, because an unauthorized code change could corrupt financial data without anyone noticing until audit time.

Third-Party and Cloud Provider Documentation

When a cloud provider or SaaS vendor handles systems that touch financial reporting, the company’s own SOX obligation does not transfer to the vendor. The standard practice is to obtain a SOC 1 Type 2 report from the provider. Prepared under AICPA attestation standards, these reports cover the service organization’s internal controls relevant to clients’ financial reporting and include an independent auditor’s opinion on whether the controls operated effectively during the review period. If a provider cannot produce a SOC 1 Type 2 report, the company must implement and document its own compensating controls to fill the gap.

Deficiency Classification Documentation

SOX documentation must also account for what happens when controls fail. PCAOB Auditing Standard 2201 defines three tiers, and the distinction between them has real consequences.4Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting

  • A deficiency exists when a control is missing or does not work well enough for employees to catch or prevent misstatements during normal work.
  • A significant deficiency is a deficiency, or combination of deficiencies, serious enough to warrant the attention of those overseeing financial reporting, but not severe enough to qualify as a material weakness.
  • A material weakness is a deficiency where there is a reasonable possibility that a material misstatement in the financial statements would not be caught or prevented in time.

A material weakness must be publicly disclosed in the annual report and produces an adverse opinion on internal controls in an integrated audit. Material changes to internal controls, including newly discovered weaknesses, also must be reported in current filings on Form 8-K.5U.S. Securities and Exchange Commission. Form 8-K Significant deficiencies are communicated to management and the audit committee but do not automatically trigger public disclosure. Classifying a problem correctly shapes both the documentation and the urgency of remediation.

Section 302 Officer Certifications

The CEO and CFO must personally certify each quarterly and annual report. The certification states that the signing officer has reviewed the report, that it contains no material misstatements, and that the financial statements fairly present the company’s financial condition.6Office of the Law Revision Counsel. United States Code Title 15 Section 7241 – Corporate Responsibility for Financial Reports

The certification goes further. The signing officers must confirm they are responsible for establishing and maintaining the company’s internal controls, that they have evaluated those controls within 90 days of the report, and that they have disclosed any significant deficiencies or material weaknesses to the auditors and the audit committee.6Office of the Law Revision Counsel. United States Code Title 15 Section 7241 – Corporate Responsibility for Financial Reports They must also disclose any fraud involving employees who play a significant role in the control environment.

How Long You Have to Keep All of It

Federal law sets the retention floor. The statute requires accountants who audit SEC-reporting companies to maintain audit workpapers for at least five years from the end of the fiscal period the audit concluded.7Office of the Law Revision Counsel. United States Code Title 18 Section 1520 – Destruction of Corporate Audit Records Using its rulemaking authority under the same section, the SEC extended that to seven years for all records relevant to an audit or review, including workpapers, memoranda, correspondence, and electronic records containing conclusions, opinions, analyses, or financial data related to the engagement.8U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews

Seven years is the number that matters in practice. Records must be kept in formats that prevent unauthorized alteration or deletion, and they must be readily accessible for at least the first two years. Companies using electronic storage should maintain detailed audit logs tracking any access to or modification of stored records. The scope goes beyond final workpapers to include documents inconsistent with the auditor’s final conclusions, so long as they relate to a significant matter.8U.S. Securities and Exchange Commission. Retention of Records Relevant to Audits and Reviews

What Missing or Falsified Documentation Costs

Under Section 906, a CEO or CFO who certifies a financial report knowing it does not comply with the law faces up to $1 million in fines, up to 10 years in prison, or both. If the false certification is willful rather than merely knowing, the penalties rise to $5 million in fines and up to 20 years in prison.9Office of the Law Revision Counsel. United States Code Title 18 Section 1350 – Failure of Corporate Officers to Certify Financial Reports

Destroying or tampering with documentation carries an equally severe penalty. Anyone who alters, destroys, or falsifies records with the intent to obstruct a federal investigation faces up to 20 years in federal prison.10Office of the Law Revision Counsel. United States Code Title 18 Section 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations The provision does not require an existing subpoena. Destroying records in anticipation of an investigation is enough.