Skip to content

SOX control evidence: what auditors pull, and how to have it ready

Most SOX pain is not the controls themselves. It is producing the evidence that each one ran: the right document, the right approver, the right date, for every sample. Here is one control tested end to end.

Ademero Team6 min read

The Sarbanes-Oxley Act applies to companies with securities registered with the SEC. For a controller or an internal audit lead, SOX is mostly a document question: when the external auditor picks 25 transactions, can you produce, for each one, the document, the approval and the proof that the approval came first? This guide works through one control as an auditor tests it, then covers what the main sections of the law mean for your files.

The three sections that touch your documents

SectionWhat it saysWhat it means for your files
302The CEO and CFO certify each quarterly and annual report, including that disclosure controls workSub-certifications and close checklists signed by the people below them, kept with the period
404Management assesses internal control over financial reporting each year; for larger filers the auditor attests to itEvidence that each key control ran, for every sample the auditor selects
802Destroying, altering or falsifying records to obstruct an investigation is a crime; audit firms keep their workpapers for seven yearsNo deletions or edits that cannot be explained, and a way to stop disposal when a matter is open

SOX does not give one retention period for all of a company’s own financial records. The seven-year rule in Section 802 and the SEC’s rule apply to the audit firm’s records. Many companies choose seven years for the documents that support their financial statements as a matter of policy; set yours with counsel and write it down per document type.

One control, tested the way an auditor tests it

Take a typical accounts payable control, written in a control matrix like this (the amount is an example):

AP-04. Invoices of $25,000 or more are approved by the controller before payment. Approval is recorded in the AP system with the approver’s name and date.

The auditor asks for every invoice over $25,000 paid in the year, picks a sample, and for each one wants:

  1. The invoice itself, as received, with the vendor, number, date and amount readable.
  2. The approval: who approved it, and that this person is the controller or a named delegate.
  3. The timing: the approval date is before the payment date.
  4. Integrity: the invoice was not changed after it was approved, or if it was, the change is visible.
  5. The population: a complete list of the invoices over the threshold, so the sample is fair.

Where this goes wrong is rarely the approval. It is the evidence: an approval given by reply-all email, a PDF saved over with a corrected version, an invoice filed under the wrong vendor so it never appears in the list. A week of walkthrough meetings often comes down to pulling these five things by hand.

What makes the evidence fall out on its own

Auditor wantsSet it up so that
The invoiceEvery invoice is captured on arrival and indexed by vendor, number, date and amount
The approvalInvoices at or over the threshold route to the controller automatically, and the approval is recorded on the document, not in an inbox
The timingThe document history shows the approval step with its date and time, separate from the payment record
IntegrityChanges create a new version; earlier versions stay available
The populationA search by document type and amount range lists every invoice, and the results export to a spreadsheet
Content Central approval queue with two sample invoices waiting in an Invoice Approval process, showing date received, current member and next member
Sample data: invoices waiting in an approval queue, with the current and next approver shown. Each approval is recorded on the document’s history.

Segregation of duties lives in permissions

Auditors look for one person who can do two jobs that should be separate. In document terms, check these before the auditor does:

  • The person who enters or edits a vendor invoice cannot also approve it.
  • Nobody approves their own expense report.
  • Only a small, named group can delete financial documents or change their retention, and those actions are logged.
  • Shared logins are gone. An approval by “AP Clerk” proves nothing about who approved.
  • Substitutes for approvers on leave are set in advance and visible, not done by borrowing a password.

The close file, period by period

Section 302 certifications rest on a monthly and quarterly close. Keep one file per period with the same contents every time, so anyone can tell what is missing:

  • Account reconciliations with preparer and reviewer sign-off and dates.
  • Journal entries over your review threshold, with support and approval.
  • The close checklist and any sub-certifications from business unit and department heads.
  • Management review evidence: the report reviewed, by whom, what they asked and how it was resolved.

When a matter is open

Once litigation, an investigation or an SEC inquiry is reasonably expected, normal disposal of related records must stop. In practice that means being able to put specific documents, or every document for a vendor or a period, on hold so the retention schedule cannot remove them, and being able to show later when the hold started and who placed it.

Failures auditors actually write up

  • Approval evidence created after the payment, or with no date at all.
  • A control matrix that says “system enforced” when the routing can be skipped.
  • Incomplete populations because documents were filed inconsistently.
  • Retention schedules on paper that nobody applies, or records deleted with no record of why.
  • Broad delete rights in the document repository and no review of who has them.

Where Ademero fits

Content Central runs in the cloud or on your own servers, your choice. Approval workflows can route by amount, with deadlines, escalation, substitutes during absences and PIN approvals, and each step is recorded in the document’s version history. Check-out and check-in keep edits controlled, file changes create a new major version, and earlier versions can still be downloaded. Searches by document type and field values export to CSV or Excel for a sample population. Permissions are set per document type and field, sign-in can use Active Directory or SAML with MFA, the event log records sign-ins, views, downloads and deletions, and retention schedules with legal holds keep records exactly as long as your policy says. CapturePoint 6 reads invoices on your own PC, checks line-item math and sends finished documents to Content Central. Software does not make a company SOX compliant, but it can make the evidence a by-product of the work. See our compliance page.

Free live demo

See approvals, versions and the audit trail on your own invoices.

Book a free demo and we will show you around, answer your questions and run your real paperwork through it. No cost, no pressure.

  • A live tour of the products that fit your work
  • Your own documents, set up and shown working
  • Your workflow and process, mapped with you
  • Straight answers from people who build it
Engraved illustration: file boxes, a document scanner and a PC at a desk