After a SOX compliance review, test the assumptions behind each control conclusion before treating a clean opinion as evidence that the business is sound, and before any remediation plan or certification is signed. The opinion confirms that the machinery producing the numbers worked. Whether the numbers describe the business the board believes it is running is a separate question, and the review does not answer it.
A SOX compliance review is the annual Section 404 assessment of internal control over financial reporting, made by management and, for larger public companies, attested by an external auditor.
What a SOX compliance review delivers
Section 404 of the Sarbanes-Oxley Act requires management to assess and report each year on the effectiveness of internal control over financial reporting. The SEC's 2003 final rule set the terms: management selects a recognised control framework, documents the key controls over significant accounts and disclosures, tests whether they are designed and operating effectively, and states a conclusion. For accelerated filers, the external auditor then issues its own opinion on the same controls.
That auditor opinion follows PCAOB AS 2201, which integrates the controls audit with the financial statement audit and classifies every finding into three tiers. A deficiency is a control that does not prevent or detect misstatements as intended. A significant deficiency merits the attention of those overseeing financial reporting. A material weakness creates a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. One material weakness is enough to make an effective conclusion impossible.

The discipline has genuine value. Control documentation forces process owners to state who approves what, and against which evidence. Reconciliations happen on schedule because someone will test them. Segregation of duties, system access, and journal entry review stop being informal habits and become documented obligations. Prior-year deficiencies get tracked to closure, and the audit committee receives a signed opinion it can point to.
The review also gives management, internal audit, and the external auditor a shared vocabulary for severity, which makes it one of the more rigorous exercises within organisational governance. As with a governance audit, the output is graded and defensible. A clean opinion is real evidence. It is evidence about the controls, not about the business the controls report on.
What it leaves unexamined
The review tests whether controls operate as documented. It does not test whether the documented design addresses the transactions that matter most, or whether the judgments those controls process are honest representations of the business. Scope is set top-down from management's own risk assessment, so controls over accounts judged not significant are never tested. The standard offers reasonable assurance, not absolute assurance, and says so.
The review also treats management's judgments as inputs. A control over a valuation checks that the estimate was reviewed and approved, not whether the estimate is right. A control over a transaction checks that it was recorded under policy, not why the business wanted it recorded that way. Every control conclusion carries assumptions that the testing does not reach.
| What the SOX review concluded | What it assumed | Gap to test |
|---|---|---|
| Controls over significant accounts are operating effectively | The accounts scoped out as low risk contain nothing that could mislead a reader of the statements | Which balances or structures sit outside scope, and why they were judged immaterial |
| Transactions were recorded in line with the approved accounting policy | A transaction booked correctly under policy is a transaction with a legitimate business purpose | What each large or unusual transaction type is actually for, and who would object if it were disclosed |
| No material weakness identified | Absence of a detected failure means absence of a material problem | What evidence would have surfaced a weakness if one existed, and whether anyone looked for it |
The last row is not hypothetical. Rice and Weber (2012) studied firms that later restated financial statements because of misstatements linked to control weaknesses. Only 32.4 percent had reported a material weakness in their SOX 404 reports during the period the misstatements were live. The opinion is frequently clean at exactly the moment the problem exists.
This is the ground where governance and compliance part company. Compliance asks whether the process ran. Governance asks what the organisation is relying on, and whether that reliance is earned. A SOX opinion answers the first question well and is routinely quoted as though it answered the second.
Write down the control conclusion your certification depends on most and ask whether it tested the substance of the transactions or only that the process ran. Start the Walk →
When the gap cost Lehman Brothers the truth about its leverage
Ernst & Young's opinion on Lehman Brothers' internal control over financial reporting, as of 30 November 2007, stated that the firm maintained effective internal control over financial reporting. On that same date, according to the court-appointed examiner, Lehman had $38.6 billion of Repo 105 transactions outstanding: short-term repurchase agreements booked as sales, which removed securities from the balance sheet just before quarter-end and brought them back shortly after.
Usage rose to $49.1 billion at the end of the first quarter of 2008 and $50.38 billion at the end of the second. The Valukas examiner's report found that no US law firm would provide the true sale opinion the accounting required, so Lehman relied on an English-law opinion from Linklaters written for its London broker-dealer. The transactions had an accounting policy, volume limits it breached at every quarter-end, and a legal opinion. What they lacked was a purpose anyone was asked to defend.
On 16 May 2008, Matthew Lee, a senior vice president in Lehman's finance division, sent a letter to senior management raising balance sheet concerns. On 12 June he told Ernst & Young about the $50 billion of Repo 105. The next day, Ernst & Young met the audit committee and did not mention it, although the committee had asked to be told of every allegation.
The examiner found that former Lehman directors were, without exception, unaware of the Repo 105 programme. Lehman filed for bankruptcy on 15 September 2008.
The examiner concluded that colorable claims existed against four senior officers, and a colorable claim of professional malpractice against Ernst & Young. Like most governance failures, the structures were all present. The controls processed the transactions correctly. The question of what the transactions were for never entered the test.
One step before the certification
Before the chief executive and chief financial officer sign the next quarterly certification, and before a remediation plan for any deficiency goes to the audit committee, each material control conclusion needs a second question: what is this finding being taken to prove? The same question applies after an internal audit, where severity ratings carry the same untested judgment.
The five steps of the Universal Decision-Making Method fit here without new machinery. Frame the decision the opinion is being used for: signing the certification or taking a remediation item to the board. Name the Tentative Elements: the transactions, estimates, and structures the conclusion covers. Surface the assumptions each conclusion takes as given, starting with scope and purpose.
Then decide what counts as Sufficient Certainty for each critical assumption, in proportion to the weight the certification places on it. Finally, Implement and Monitor: name the signal that would reopen a conclusion before next year's testing cycle, such as a transaction type that spikes at quarter-end or an allegation the auditor has not relayed. Environmental certification needs the same discipline: the work after an ISO 14001 audit is naming the operating changes that reopen an aspect rating before the next surveillance visit.
Remediation deserves the same scrutiny. Fixing the control that failed assumes the control was the problem. A SOX review tells a board that its financial reporting machinery ran as designed. Deciding whether to rely on what that machinery produced is a separate judgment, and it belongs to the people who sign.
You could close every SOX deficiency and still leave the assumption that the controls cover the right risks untested.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.