SOX Financial Reporting Compliance Checklist

Last updated: 2026-04-08 — ComplianceStack Editorial Team

18 items
Progress 0 of 18 reviewed

SOX Sections 302, 404, and 906 impose overlapping obligations on public company financial reporting — and the consequences of non-compliance include criminal prosecution, SEC enforcement, and shareholder litigation. The average cost of a financial restatement for a mid-cap public company exceeds $2.5 million in direct costs alone, before accounting for market cap loss. This checklist covers the 18 financial reporting requirements that define a defensible SOX program, from quarterly certifications through annual ICFR assessments.

Priority Legend:
● Critical ● High ● Medium ● Ongoing

SOX Compliance Checklist for Financial Reporting

1

Establish a Disclosure Committee with documented charter and membership

Critical 3-5 days to establish, quarterly meetings

The Disclosure Committee is responsible for reviewing all SEC filings, earnings releases, and other public disclosures for accuracy and completeness. Membership should include CFO, General Counsel, Controller, IR Director, and key business unit heads. Document the committee charter, meeting schedule, and voting procedures. Meeting minutes must be retained as evidence of the CEO/CFO certification process.

SOX Section 302; SEC Release No. 33-8124; SEC Release No. 33-8238
2

Implement disclosure controls and procedures (DC&P) over all SEC filings

Critical 1-2 weeks to design, quarterly evaluation

DC&P covers the processes that ensure information required to be disclosed in SEC reports is recorded, processed, summarized, and reported within the time periods specified. The CFO and CEO must separately evaluate DC&P effectiveness each quarter. Document the evaluation, including what information was reviewed, who participated, and the conclusion reached.

SOX Section 302; SEC Rule 13a-15(e); SEC Release No. 33-8238
3

Execute Section 302 certifications with full supporting sub-certification chain

Critical 2-3 days per filing

CEOs and CFOs certify quarterly and annually that: (1) the filing contains no material misstatements or omissions; (2) financial statements fairly present financial condition; (3) they are responsible for establishing and maintaining DC&P and ICFR; (4) they have disclosed all significant deficiencies and material weaknesses to the Audit Committee. Support each certification with sub-certifications from process owners. False certifications carry criminal penalties up to 20 years.

SOX Section 302; SOX Section 906; 18 U.S.C. § 1350
4

Complete Section 404(a) management assessment of ICFR and include in annual 10-K

Critical 2-4 weeks for assessment, 1-2 days for disclosure

Management must assess ICFR effectiveness as of fiscal year-end and include that assessment in Item 9A of the 10-K. The assessment must identify the framework used (COSO 2013), state the scope of the evaluation, disclose any material weaknesses identified, and conclude on overall ICFR effectiveness. The SEC has brought enforcement actions for vague or unsupported ICFR conclusions.

SOX Section 404(a); SEC Rule 13a-15(d); SEC Release No. 33-8238
5

Coordinate Section 404(b) external auditor attestation (accelerated filers)

Critical Coordinated with external audit

Accelerated filers (public float ≥ $75 million) must have their external auditor attest to and report on management's ICFR assessment. Non-accelerated filers are exempt. Engage your auditor early in Q3 to align on scope, testing approach, and timeline. Material weaknesses identified by the auditor that management did not identify independently signal a deficiency in the management assessment process itself.

SOX Section 404(b); PCAOB AS 2201; SEC Rule 12b-2
6

Maintain a continuous disclosure monitoring process for 8-K triggering events

Critical Ongoing monitoring

Current report triggers include: material definitive agreements, bankruptcy, amendments to code of ethics, departure of directors/officers, amendments to charter/bylaws, and unregistered securities sales. Review the complete list of 8-K triggers (Form 8-K general instructions) at least annually and assign a business owner responsible for monitoring each category. Most 8-K events must be filed within four business days.

SEC Form 8-K General Instructions; Regulation FD (17 CFR 243)
7

Establish and test a financial restatement protocol

High 2-3 days to document, annual tabletop

Document the process your company will follow if a restatement becomes necessary: materiality assessment, engagement of external counsel, Audit Committee notification, SEC filing procedures (NT 10-K/10-Q, then amended filing), and investor communication. Test the protocol annually in tabletop exercises. Companies without a documented protocol make longer, more costly restatements.

SEC Staff Accounting Bulletins (SAB 99, SAB 108); ASC 250-10
8

Implement and evaluate controls over non-GAAP financial measures

High 1-2 days per filing

Non-GAAP measures (Adjusted EBITDA, free cash flow, etc.) are subject to SEC Regulation G and Compliance & Disclosure Interpretations. Controls must ensure: (1) reconciliation to the most directly comparable GAAP measure; (2) equal or greater prominence for GAAP measures; (3) no presentation of non-GAAP per share liquidity measures. Include non-GAAP controls in your DC&P evaluation.

Regulation G (17 CFR 244); SEC Non-GAAP C&DIs (updated 2018)
9

Maintain controls over earnings guidance and forward-looking statements

High 1-2 days per guidance release

Earnings guidance and forward-looking statements must include meaningful cautionary language referencing actual risks that could cause results to differ (not boilerplate). The Disclosure Committee should review all guidance for accuracy and completeness. Document the basis for guidance assumptions, including sensitivity analysis for key variables. Maintain records of guidance approval.

Securities Act Section 27A; Exchange Act Section 21E; Regulation FD
10

Conduct quarterly management review of significant estimates and judgments

High 1-2 days per quarter

Significant accounting estimates (goodwill impairment, revenue recognition, pension assumptions, loss contingencies, stock-based compensation) require documented management review at each period end. Review should assess whether assumptions remain appropriate given current conditions, whether the estimate falls within a reasonable range, and whether disclosure adequately explains the sensitivity of the estimate.

ASC 250-10; SEC Release SAB 99; PCAOB AS 2110
11

Document legal entity reconciliation and intercompany elimination controls

High 3-5 days to document, ongoing quarterly

Consolidation controls are a frequent source of material misstatement. For each legal entity, document the trial balance review process, the intercompany elimination process, and the controls over foreign currency translation. Validate that eliminations are complete (no intercompany balances remaining) and that translation rates are applied consistently.

ASC 810; ASC 830; PCAOB AS 2201.25
12

Establish tax provision review controls and coordinate with external tax advisors

High 1-2 weeks per quarter

The tax provision is consistently one of the most complex estimates on the income statement. Controls must cover: current and deferred tax calculations, uncertain tax positions (ASC 740-10), valuation allowances, effective tax rate analysis, and schedule M adjustments. Significant changes in tax law (like TCJA or Pillar Two) require immediate reassessment of existing controls.

ASC 740; FIN 48 / ASC 740-10; PCAOB AS 2201.25
13

Implement controls over related-party transaction identification and disclosure

Medium 1-2 days per quarter

All related-party transactions must be identified, evaluated for disclosure, and approved through the appropriate approval process. Controls should require all officers and directors to certify related-party relationships at least annually. Related-party transactions that are material or unusual must be disclosed in the notes. The Audit Committee must review all related-party transactions under most governance frameworks.

ASC 850; Item 404 of Regulation S-K; SOX Section 402
14

Review debt covenant compliance and disclose going concern considerations

Medium Monthly monitoring

Debt covenant compliance must be monitored continuously, not just at reporting dates. Establish a covenant tracker updated by Treasury monthly with threshold alerts. If a covenant violation is probable within 12 months, assess going concern disclosure requirements under ASC 205-40. Failure to disclose probable covenant violations is a material misstatement.

ASC 470-10; ASC 205-40; SEC Release No. 33-9144
15

Maintain a comprehensive subsequent events review through filing date

Medium 2-3 days before each filing

Events between fiscal year-end and the filing date must be evaluated for recognition or disclosure under ASC 855. Assign a process owner responsible for collecting subsequent event information from all business units. Establish a cutoff procedure — typically two to three business days before filing — for receiving subsequent event information. Document the review and retain evidence.

ASC 855 (Subsequent Events); AU-C Section 560
16

Validate XBRL/iXBRL tagging against financial statements before SEC filing

Medium 1-2 days per filing

Inline XBRL is required for all domestic registrants filing 10-K, 10-Q, and 8-K financial statements. Controls must verify that XBRL tags match the face of the financial statements, that custom tags are used only when no standard tag exists, and that the iXBRL viewer renders correctly. XBRL errors trigger SEC comment letters and can delay acceptance of filings.

SEC Rule 405 of Regulation S-T; SEC Release No. 33-10514
17

Conduct annual Regulation FD training for officers, employees, and IR staff

Medium 1 day annually

Regulation FD prohibits selective disclosure of material nonpublic information. Train all personnel who interact with investors, analysts, or journalists on what constitutes material information, how to respond to inquiries about non-public topics, and how to escalate potential FD issues. Document training attendance. Companies have paid multi-million dollar SEC penalties for individual employee Reg FD violations.

Regulation FD (17 CFR 243.100-.103); SEC Guidance (Aug 2000)
18

Archive all SEC filings, supporting documentation, and communication for seven years

Ongoing Policy: 2 days; ongoing compliance

SOX Section 802 makes it a federal crime to knowingly alter, destroy, or conceal documents relevant to an SEC investigation. Maintain a document retention policy with a seven-year minimum for all audit-related records, financial statements, certifications, sub-certifications, and correspondence with external auditors. Ensure litigation hold procedures can be activated within 24 hours.

SOX Section 802; 18 U.S.C. § 1519; SEC Rule 17a-4

See How Your Financial Reporting Scores on SOX

Run a free gap analysis to find out which items you have covered and where the risks are.

Gap Analyzer →   Training Tracker →

Common Mistakes That Trigger Enforcement

Treating the Section 302 certification as a formality signed by the CFO alone without a sub-certification chain
If a material misstatement is later discovered, the absence of sub-certifications shifts all liability to the CFO and CEO personally. A sub-certification chain creates accountability throughout the organization and provides evidence of a genuine review process.
Using boilerplate cautionary language in forward-looking statements
The PSLRA safe harbor only protects forward-looking statements accompanied by meaningful cautionary statements identifying important factors that could cause actual results to differ materially. Generic boilerplate does not qualify. Courts have denied safe harbor protection to companies using identical risk factor language across multiple years without updating for changed circumstances.
Disclosing non-GAAP metrics without equal or greater prominence for GAAP measures
SEC Regulation G and C&DI guidance require the most directly comparable GAAP measure to be disclosed with equal or greater prominence than any non-GAAP measure. The SEC has issued comment letters and required restatements for improper non-GAAP presentations.
Not updating the Disclosure Committee charter when the CFO or General Counsel changes
The effectiveness of DC&P depends on the committee functioning as designed. If the charter names individuals rather than roles, a leadership change can leave the committee without a proper quorum or designated chair, undermining the certification process.
Filing 8-Ks late because the triggering event was not recognized as a disclosure obligation
Most 8-K events require filing within four business days. Late filings result in loss of S-3 shelf registration eligibility, SEC comment letters, and potential enforcement action. Companies have paid multi-million dollar penalties for systematic 8-K late filing patterns.

Frequently Asked Questions

What is the difference between SOX Section 302 and Section 404?

Section 302 requires CEOs and CFOs to certify quarterly that they have reviewed the filing, it does not contain material misstatements, the financial statements fairly present the company's condition, and they are responsible for establishing and evaluating disclosure controls and procedures. Section 404 requires annual management assessment of internal control over financial reporting effectiveness, and for accelerated filers, an external auditor attestation. The 302 certification covers DC&P quarterly; the 404 assessment covers ICFR annually.

Who is required to sign SOX Section 302 certifications?

Section 302 certifications must be signed by the principal executive officer (CEO) and the principal financial officer (CFO) of the company. This cannot be delegated to anyone else, including the Chief Accounting Officer or Controller. If the CEO or CFO role is temporarily vacant, the acting or interim CEO/CFO must sign. Foreign private issuers filing on Form 20-F face equivalent requirements under Exchange Act Rules 13a-14 and 15d-14.

What are the criminal penalties for false SOX certifications?

Under SOX Section 906, any officer who certifies a periodic report knowing it does not comport with all requirements of the securities laws faces up to 10 years imprisonment and $1 million in fines. If the officer willfully certifies a false report, the penalty increases to up to 20 years imprisonment and $5 million in fines. Under Section 1107, retaliating against a whistleblower carries up to 10 years imprisonment. These are personal criminal penalties — they cannot be indemnified by the company.

✉ Save This Checklist

Enter your email and we'll send you a clean copy — plus updates when requirements change.

We also offer a free personalized gap analysis for your specific situation.

Related Resources