A Sarbanes-Oxley compliance checklist turns the Sarbanes-Oxley Act (SOX) into the controls, tests and sign-offs a public company works through and shows its auditors. SOX is the US federal law passed in 2002 after the accounting scandals at Enron and WorldCom. It applies to companies that file periodic reports with the Securities and Exchange Commission (SEC).
Most of the checklist serves two sections of the law. Section 302 makes the CEO and CFO personally certify every quarterly and annual report. Section 404 requires management to assess internal control over financial reporting (ICFR) each year. Larger filers also need an auditor to attest to that assessment.
The stakes are personal. Under Section 906, an officer who willfully certifies a false report faces up to $5 million in fines and 20 years in prison (18 U.S.C. § 1350). This guide covers what goes on the checklist, when each task falls in the year, and how the downloadable template fits in.
Download your free Sarbanes-Oxley compliance checklist
A printable, fill-in checklist with sections for the standard being evidenced, the responsible owner and completion date, and findings with corrective actions. It closes with a log for unfinished items, a notes field, and signature and checked-by lines for sign-off.
Download templateKey takeaways
Section 302 makes the CEO and CFO personally certify every quarterly and annual report filed with the SEC.
Section 404 requires management to assess internal control over financial reporting each year, with auditor attestation for accelerated filers.
A Sarbanes-Oxley compliance checklist covers governance, process mapping, risk assessment, control testing, IT general controls and material weakness disclosure.
Audits most often fail on segregation of duties, IT access reviews, untested system changes and scattered control evidence.
Practice management software like Pabau gives healthcare practices inside a public company’s SOX scope role-based permissions and audit trails over billing.
What is the Sarbanes-Oxley Act and which companies must comply?
The Sarbanes-Oxley Act is the federal law that governs corporate governance, financial reporting and internal controls for public companies. It applies to every company that must file annual reports (Form 10-K) with the SEC, including any company whose securities trade on a US exchange.
SOX does not automatically apply to private companies, though some provisions (whistleblower protections and document destruction prohibitions) apply more broadly. If your company is publicly traded, SOX applies in full. That includes a foreign company with a US listing.
The Public Company Accounting Oversight Board (PCAOB), set up by SOX itself, writes the auditing standards that external auditors follow. The SEC enforces SOX and publishes guidance on putting it into practice. Knowing which sections apply to your company is the first step in building the checklist.
Key SOX sections every compliance team must know
SOX has 11 titles and dozens of sections. Six of them carry most of the compliance weight and audit risk, so they anchor the checklist.
Section 404 internal controls: Design and operating effectiveness
Section 404 is the heaviest part of SOX compliance. Your checklist has to answer two questions for every control. Is it designed to prevent or catch a misstatement, and does it work when tested?
- Identify financial reporting processes: Map every process cycle that affects financial reporting, including revenue, payroll, procurement, fixed assets, consolidation and period close.
- Assess control risk: For each process, document the assertion being managed (completeness, existence, accuracy or authorization) and its inherent risk level.
- Design preventive controls: Segregation of duties, authorization limits, reconciliation procedures, exception handling and system access controls.
- Test control operating effectiveness: Run walkthroughs in Q1, sample testing in Q2 and Q3, and year-end testing to confirm controls worked as designed.
- Document control testing: Record sample sizes, exceptions found, remediation applied and retesting results.
- Evaluate control deficiencies: Classify findings as control deficiencies, significant deficiencies or material weaknesses based on likelihood and impact.
- Disclose material weaknesses: Report any material weakness in the annual Form 10-K and to the audit committee.
IT general controls (ITGC): Access, change and monitoring
IT controls are a required part of any SOX program. PCAOB auditing standard AS 2201 expects auditors to assess the IT general controls that support ICFR. The common ITGC domains are below.
- Logical access controls: User provisioning, periodic access reviews and prompt removal of access for departing employees. Financial systems also need segregation of duties, so no user can both initiate and approve a payment.
- System change management: Change control procedures, testing before promotion to production, audit trails of changes, and separate development, test and production environments.
- Backup and recovery: Documented backup procedures, periodic restoration testing, offsite storage of backups, and recovery time and recovery point objectives.
- System monitoring: Log review procedures, intrusion detection, system uptime monitoring and incident response procedures.
- Configuration management: Change logs, patch management, hardware and software inventories, and authorized configuration baselines.
Section 302 CEO and CFO certification steps
Section 302 requires the CEO and CFO to personally certify that the financial statements are accurate and that internal controls are effective. The checklist has to show that the certification process is documented and defensible.
- Set the sign-off process: Name who reviews the financial statements, who evaluates internal control effectiveness and who approves the final certification wording.
- Document the ICFR assessment: Keep evidence that management evaluated both control design and operating effectiveness.
- Disclose material weaknesses: If a material weakness in ICFR is identified, the certification must disclose it.
- Certify every quarter: Section 302 certifications go in each Form 10-Q and in the annual Form 10-K.
- Confirm sign-off authority: Check that the certifying officers have direct knowledge of the financial data and controls they certify.
Common SOX control failures and how to fix them
Four control failures come up in SOX audits more often than the rest.
- Weak segregation of duties: The same user can initiate and approve a transaction.
- Loose IT change control: System changes go live without testing or documentation.
- Skipped access reviews: Former employees keep access to financial systems.
- Scattered evidence: Design and testing records sit across emails and spreadsheets.
Each fix starts with a named control owner, a test on a set schedule and one place to store the evidence. Compliance management software can hold that evidence, run the testing workflow and track each remediation on a single audit trail.
Where healthcare practices fall inside SOX scope
A private practice doesn’t file with the SEC, but it can still sit inside SOX scope. That happens when a publicly traded company owns the practice and consolidates its results into the group’s financial statements. The parent’s Section 404 assessment can then reach down to the practice’s billing and payment processes.
At practice level, the controls that matter usually sit in the revenue cycle.
- Who can post, edit, discount or refund a patient invoice
- How card and cash takings are reconciled to the bank each day
- How write-offs are approved and recorded
- Who has access to the billing system, and how quickly leavers lose it
Access reviews for billing systems overlap with the access checks in a HIPAA risk assessment, so one review can often feed both.
The clinical record follows the same logic. A practice that already applies EHR security basics to access, logging and backups has much of the ITGC groundwork in place.
Ongoing SOX compliance monitoring
SOX compliance doesn’t end after the audit. Finance and audit teams should review the checklist and test a sample of key controls every quarter. They should also watch for new risks as the business changes. The timeline below shows how that work spreads across a typical calendar year.

When your organization acquires a subsidiary or launches a new financial system, expand the checklist to cover the new processes and controls.
How Pabau keeps practice-level financial controls audit-ready
In many practices, billing controls live in people’s heads. One login might take a payment, apply a discount and issue a refund, and the only record is a spreadsheet updated at month-end. That setup is hard to defend when a parent company’s auditors ask for evidence.
Practice management software like Pabau puts payments, invoicing and reporting in one system with role-based permissions. You assign each team member an access level, so you decide who can view, edit or export financial and patient records. A full audit trail logs every action with a time stamp.
Pabau also integrates with Xero, so reconciliations start from the same data your team recorded at the front desk. Digital forms with signatures give control owners a dated place to record their sign-offs.
Book a demo to see how Pabau’s compliance and digital forms tools help audit and finance teams document controls ahead of each SOX cycle.
Keep practice billing controls audit-ready
Pabau’s role-based permissions and audit trails show who took, edited or refunded each payment. Your team spends less time rebuilding evidence before every SOX review.
Conclusion
Start where auditors find the most failures. Map your financial processes and name an owner for every key control. Then test on a quarterly schedule, so the year-end assessment confirms results you already have.
The trade-off is effort now against remediation later. A deficiency found in Q2 can be fixed and retested before year-end. The same deficiency found during the Form 10-K cycle may have to be disclosed as a material weakness.
If your practice sits inside a public parent’s SOX scope, bring billing permissions and payment records into one system before the auditors ask. Book a demo to see how Pabau gives your practice an audit trail for every payment, refund and discount.
Continue your research
Need one place for control evidence? Compliance management software keeps audit trails, access levels and documentation together.
Running an access review? HIPAA risk assessment guide walks through the six steps and the nine HHS elements.
Auditing records as well as controls? Medical chart audit guide explains how to check that documentation matches what was done and billed.
Setting a retention policy? How long to keep medical records sets out retention rules by state.
Frequently asked questions
What is the difference between SOX Section 302 and Section 404?
Section 302 requires the CEO and CFO to personally certify the accuracy of financial statements and the effectiveness of disclosure controls. Section 404 requires management to assess and report on internal control over financial reporting (ICFR) as of year-end. Section 404(b) also requires external auditors to attest to that assessment, for large accelerated and accelerated filers only.
Does SOX apply to private companies?
SOX applies to companies whose securities trade on a US exchange and that file periodic reports with the SEC (Forms 10-K and 10-Q). Private companies are generally exempt unless they are required to file with the SEC. A private subsidiary of a public company can still fall inside its parent’s ICFR assessment. Some SOX provisions, such as whistleblower protection and document destruction prohibitions, apply more broadly.
What are the penalties for SOX non-compliance?
Penalties range from SEC civil enforcement actions and audit findings to criminal prosecution under Section 906. An officer who willfully certifies a false financial report faces up to 20 years in prison and $5 million in fines, per 18 U.S.C. § 1350(c). Regulatory findings also damage a company’s reputation and investor confidence.
How often is a SOX audit required?
Public companies file an annual report on Form 10-K with the SEC, and most face an external audit of each fiscal year. Large accelerated and accelerated filers also need Section 404(b) auditor attestation. Some companies run interim testing in Q2 and Q3, but the formal annual audit is the compliance requirement.
What counts as a material weakness under SOX?
A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting. It creates a reasonable possibility that a material misstatement of the annual or interim financial statements won’t be prevented or detected in time. Material weaknesses must be disclosed in management’s SOX certification and in the annual Form 10-K.