Section 404 of the Sarbanes-Oxley Act requires every public company that files annual reports with the SEC to evaluate its internal controls over financial reporting and report the results each year, and for larger filers to have an independent auditor issue a separate opinion on those controls. The requirement makes the CEO and CFO personally accountable for the assessment, and officers who knowingly certify a noncompliant report face fines up to $1 million and up to 10 years in prison, rising to $5 million and 20 years for willful violations.1Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports
Which Companies Section 404 Applies To
Section 404 reaches any company filing annual reports with the SEC under the Securities Exchange Act. How much of the section applies depends on the company’s filer category, which the SEC sets by the market value of publicly held shares measured on the last business day of the second fiscal quarter.2U.S. Securities and Exchange Commission. Accelerated Filer and Large Accelerated Filer Definitions
- Large accelerated filers, with a public float of $700 million or more, carry the full Section 404 load: management assessment plus auditor attestation.
- Accelerated filers, with a public float between $75 million and $700 million, also owe both, though a separate revenue test (under $100 million) can pull some out of accelerated status.
- Non-accelerated filers, below $75 million, must complete the management assessment under Section 404(a) but are permanently exempt from the external auditor attestation under Section 404(b). Congress added that exemption through the Dodd-Frank Act.3U.S. Securities and Exchange Commission. Smaller Reporting Companies
Companies that recently went public get a separate on-ramp. An emerging growth company keeps that status for up to five fiscal years after its IPO and is exempt from the Section 404(b) auditor attestation during that window. The status ends sooner if annual revenue reaches $1.235 billion, the company issues more than $1 billion in non-convertible debt over three years, or it qualifies as a large accelerated filer.4U.S. Securities and Exchange Commission. Emerging Growth Companies The 404(a) management assessment still applies.
What Management Must Do Under Section 404(a)
Every annual report must contain an internal control report that says two things: management is responsible for establishing and maintaining adequate internal controls over financial reporting, and management has assessed whether those controls were effective as of fiscal year-end.5Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls
In practice, the CEO and CFO cannot delegate this away. They have to look at the control environment themselves, identify accounts and processes where errors or fraud could produce a material misstatement, and test whether the safeguards actually work. Revenue recognition, financial close, and access controls in accounting systems tend to draw the most attention.
A basic principle runs through the work: no single person should be able to initiate, approve, and conceal a transaction. When one employee records a payment and a different employee authorizes it, the structure creates a natural check. That separation shows up throughout a well-designed control environment, from journal entries to vendor payments to system access.
The assessment is not only annual. Under Exchange Act Rule 13a-15, the principal executive and financial officers must evaluate each quarter whether any change to internal controls has materially affected, or is reasonably likely to materially affect, the company’s financial reporting.6eCFR. 17 CFR 240.13a-15 – Controls and Procedures Those quarterly evaluations feed the disclosures on Form 10-Q.
What the Outside Auditor Must Do Under Section 404(b)
For companies that are not exempt, Section 404(b) adds an independent check. The outside auditor examines the internal controls and issues a separate opinion on whether they are effective. It is not a rubber stamp on management’s conclusion. The auditor runs an integrated audit, testing the financial statements and the underlying controls together, in the same engagement.7U.S. Securities and Exchange Commission. Study and Recommendations on Section 404(b) of the Sarbanes-Oxley Act of 2002
Auditors follow standards from the Public Company Accounting Oversight Board, which Congress created through the same law.8Public Company Accounting Oversight Board. Auditing Standards Under PCAOB Auditing Standard 2201, the auditor evaluates whether each control is properly designed and whether the people running it have the authority and qualifications to do so. Any disagreement with management’s assessment must go to the audit committee.9Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated With an Audit of Financial Statements
Auditors do not have to test every control from scratch. PCAOB standards let them use work performed by the company’s internal audit team, outside consultants, or other company personnel, but only after assessing the competence and objectivity of the people involved. For higher-risk controls, the auditor must do more of the testing personally, and walkthroughs of key processes are always the outside auditor’s own responsibility.9Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated With an Audit of Financial Statements
Material Weaknesses and Significant Deficiencies
When testing turns up a problem, it lands in one of two buckets, and the label drives what happens next.
- A significant deficiency is a control gap less severe than a material weakness but still important enough to warrant the attention of those overseeing financial reporting.
- A material weakness is a gap where there is a reasonable possibility that a material misstatement in the financial statements would not be prevented or detected in time.10Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements
A material weakness has to be disclosed in the annual report, and management cannot conclude that internal controls are effective when one exists. Concealing a material weakness is itself a violation. The SEC has charged executives for doing exactly that.11U.S. Securities and Exchange Commission. SEC Charges Company CEO and Former CFO With Hiding Internal Controls Deficiencies and Violating Sarbanes-Oxley Requirements
Disclosure is only the start. The company has to redesign or strengthen the failed control, test the fix over a period long enough to show it works, and disclose the remediation in a later filing. Under Item 308 of Regulation S-K, any material change to internal controls must be reported in the next quarterly or annual report, and where the change responds to a material weakness, the company should describe the original problem so the disclosure isn’t misleading.12U.S. Securities and Exchange Commission. Management’s Report on Internal Control Over Financial Reporting and Disclosure in Exchange Act Periodic Reports Under PCAOB Auditing Standard 6115, the outside auditor can separately test the redesigned controls and issue an opinion on whether the weakness still exists.13Public Company Accounting Oversight Board. AS 6115 – Reporting on Whether a Previously Reported Material Weakness Continues to Exist
How and When to File
The internal control report is not a standalone filing. It goes into the annual report on Form 10-K, alongside the financial statements and the auditor’s opinion, submitted through EDGAR.14U.S. Securities and Exchange Commission. Submit Filings
Deadlines track filer status. Large accelerated filers must file the 10-K within 60 days of fiscal year-end, accelerated filers within 75 days, and non-accelerated filers within 90 days. Those deadlines cover the whole report, so the assessment and any auditor attestation have to be finished with time to spare.
After the first management report on internal controls, the company also has to disclose in each Form 10-Q any change to those controls that has materially affected, or is reasonably likely to materially affect, financial reporting.15eCFR. 17 CFR 229.308 – Item 308 Internal Control Over Financial Reporting
What Compliance Costs
The work is expensive, and the costs are sticky. A 2025 GAO report found that companies subject to both Sections 404(a) and 404(b) spend roughly 19 percent more on compliance than exempt peers.16U.S. Government Accountability Office. Sarbanes-Oxley Act – Compliance Costs Internal compliance costs averaged around $1 million to $1.3 million for companies with $1 billion to $10 billion in revenue and roughly $1.8 million for companies above $10 billion.
External audit fees are harder to isolate because auditors don’t typically break out the 404(b) share of a total audit fee. The GAO looked at 98 companies moving into 404(b) coverage and saw a median audit fee increase of $219,000, about 13 percent, in the year they became subject to the requirement.16U.S. Government Accountability Office. Sarbanes-Oxley Act – Compliance Costs That bump tapered the next year without vanishing. First-year costs are always the heaviest because the documentation infrastructure has to be built from scratch; costs tend to flatten by year two.
Penalties for Getting It Wrong
Consequences run on two tracks: SEC civil enforcement and federal criminal prosecution.
On the civil side, the SEC can bring actions against companies and individual officers for failing to maintain adequate internal controls or misrepresenting their state. In one case, the SEC charged a CEO and former CFO with hiding internal control deficiencies. The CFO paid a $23,000 penalty, was barred for five years from serving as an officer or director of a public company, and was suspended for at least five years from practicing as an accountant before the SEC.11U.S. Securities and Exchange Commission. SEC Charges Company CEO and Former CFO With Hiding Internal Controls Deficiencies and Violating Sarbanes-Oxley Requirements The professional bar often bites harder than the fine.
The criminal side is steeper. Under 18 U.S.C. ยง 1350, a CEO or CFO who knowingly certifies a periodic report that doesn’t comply with the law faces up to $1 million in fines and up to 10 years in prison. Willful certification pushes the maximums to $5 million and 20 years.1Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports The line between “knowing” and “willful” is where defense lawyers earn their fees; the practical point is that signing off on controls you know are broken can put you in prison.
A company with repeated Section 404 failures also risks SEC investigation, restatement of prior results, and delisting by its stock exchange, though delisting typically follows sustained noncompliance rather than a single bad year.