Finance Index

What is SOX compliance in accounts payable, and which controls are in scope?

Reference guide to SOX compliance accounts payable, including control design, audit evidence, risk points, finance procedures, and compliance review.

SOX (the Sarbanes-Oxley Act) requires public companies to maintain and assess effective internal control over financial reporting. In AP, that means the controls protecting payables accuracy and completeness - invoice approval per a delegation of authority, three-way matching, AP-to-GL reconciliation, segregation of duties, and access controls over the AP system - must be designed well, operating, and evidenced.

At a Glance

Aspect Short Answer Why It Matters
SOX compliance in accounts payable SOX (the Sarbanes-Oxley Act) requires public companies to maintain and assess effective internal control over financial reporting. Keeps evidence clear and reduces control risk.
Audit evidence Two sections do the work. Keeps evidence clear and reduces control risk.
Related terms A key control is one whose failure could allow a material misstatement to reach the financial statements - invoice approval per the DOA, three-way matching, the AP-to-GL reconciliation, and the access/SoD controls that protect them are the usual AP key controls. Keeps evidence clear and reduces control risk.
Management's assessment vs 404(a) is management's own conclusion that ICFR is effective, supported by its testing; 404(b) is the external auditor's independent opinion on the same controls. Keeps evidence clear and reduces control risk.
A SOX control narrative A control narrative describes how a process works end to end; the RCM maps each financial-reporting risk in the process to the control(s) that address it, capturing the control owner, frequency, type (preventive/detective, manual/automated), assertion covered, and evidence. Keeps evidence clear and reduces control risk.

Which SOX sections apply to AP, and does SOX apply to private companies?

Two sections do the work. Section 302 requires the CEO and CFO to personally certify the financial statements and the controls behind them every quarter - which is why weak AP controls become a personal exposure for the CFO. Section 404 requires management to assess internal control over financial reporting (404(a)) and, for larger public companies, the external auditor to attest to it (404(b)); newer public companies often qualify for an emerging-growth-company exemption from 404(b) for up to five years. SOX itself binds public companies, but private companies meet equivalent expectations through lender covenants, investor and acquirer diligence, and the simple fact that fraud and misstatement risk don't depend on filing status.

What is a key control vs a non-key control in AP?

A key control is one whose failure could allow a material misstatement to reach the financial statements - invoice approval per the DOA, three-way matching, the AP-to-GL reconciliation, and the access/SoD controls that protect them are the usual AP key controls. Non-key controls add operational value but aren't relied on to prevent material misstatement, so they receive lighter testing. The discipline of "key control rationalization" - keeping the key set small and meaningful rather than declaring thirty AP controls key - is what keeps a SOX program testable; an over-engineered control set is itself a red flag of a program that hasn't been thought through.

What is management's assessment vs the auditor's opinion on internal controls (404(a) vs 404(b))?

404(a) is management's own conclusion that ICFR is effective, supported by its testing; 404(b) is the external auditor's independent opinion on the same controls. Both can reach "effective" or identify deficiencies, and they're separate evaluations - management can't outsource its 404(a) responsibility to the auditor.

What is a SOX control narrative and a risk-control matrix (rcm) for AP?

A control narrative describes how a process works end to end; the RCM maps each financial-reporting risk in the process to the control(s) that address it, capturing the control owner, frequency, type (preventive/detective, manual/automated), assertion covered, and evidence. The RCM is the backbone document testers and auditors work from.

How do I write a control description that testers can actually test?

State the who, what, when, and how-evidenced precisely: who performs it, what they examine, how often, what threshold or criteria triggers action, and what record it leaves. "The controller reviews large invoices" is untestable; "the controller reviews and signs off on all invoices over $50K before payment, evidenced by approval in the AP system" is.

How many SOX key controls should an AP process have - are 30 controls a red flag?

Most well-rationalized AP processes land in the low-to-mid single digits of key controls. Thirty key controls usually signals that operational and key controls have been conflated - it inflates testing cost and obscures which controls actually matter. Auditors increasingly push for fewer, well-designed key controls over many redundant ones.

What does "operating effectiveness" vs "design effectiveness" mean for an approval control?

Design effectiveness asks whether the control, if it operates as described, would prevent or detect the risk. Operating effectiveness asks whether it actually operated that way over the period. A control can be well-designed but fail in operation (people skipped it) or operate consistently but be poorly designed (it wouldn't catch the risk anyway) - auditors test both.

What is a SOC 1 report and do we need one from our AP automation vendor for SOX?

A SOC 1 (specifically a SOC 1 Type II) reports on the controls at a service organization that are relevant to its customers' financial reporting, tested over a period by an independent auditor. If your AP automation runs financially significant controls, your auditors will want the vendor's SOC 1 to rely on those controls - and will check for complementary user entity controls (CUECs) you must perform on your side.

Stampli perspective

Stampli's position is that accounts payable controls should live in the daily workflow, not in after-the-fact cleanup. When invoice capture, coding, approvals, vendor communication, and audit evidence stay together, finance teams can move faster without losing visibility or accountability.