A Guide for Management by Internal Controls Practitioners
SARBANES-OXLEY SECTION 404:
A Guide for Management by Internal Controls Practitioners
The Institute of Internal Auditors
2nd Edition, January 2008
Table of Contents
About the Second Edition...........................................................................................................iii How to Use This Guide .............................................................................................................. iv Introduction................................................................................................................................. 1 Summary for the CEO and CFO ................................................................................................. 3 A. Section 404: Rules or Principles ............................................................................................ 9 B. C. Revisiting the Principles of Internal Control ...................................................................... 11 The COSO Framework ....................................................................................................... 15 What Constitutes an Effective System of Internal Control as it Relates to the Requirements of Section 404?............................................................................................. 18
D. Who Is Responsible for Internal Controls? ......................................................................... 19 E. F. What Is the Scope of Management’s Assessment of the System of Internal Control Over Financial Reporting?.................................................................................................. 21 Defining the Detailed Scope for Section 404 ....................................................................... 25 1) 2) 3) 4) 5) 6) 7) Using a Top-down and Risk-based Approach to Defining the Scope .......................... 25 The Detailed Process for