
Raayzel Business Consulting
June 7, 2026
Corporate governance in 2026: what boards are getting wrong and why it matters to the CFO
June 19, 2026SOX compliance in 2026: what CFOs need to review before the next audit cycle
SOX Compliance | 6 min read | Raayzel Business Consulting
Sarbanes-Oxley compliance has been a fixture of corporate governance for over two decades. Yet the number of material weaknesses and significant deficiencies disclosed in annual filings has not declined materially. The controls are in place. The documentation exists. The auditors visit. And still, the same categories of deficiency appear year after year across publicly listed companies and their subsidiaries.
The reason is not complexity. It is that SOX compliance programmes are frequently designed around what passed last year rather than what the current control environment actually looks like. For CFOs and Finance Directors responsible for the Section 302 and 404 certifications, that is an exposure that no amount of documentation can adequately cover.
The certification responsibility is personal
Section 302 requires the CEO and CFO to personally certify the effectiveness of disclosure controls and procedures in each periodic report. Section 404 requires management’s assessment of internal control over financial reporting, supported by the external auditor’s attestation for accelerated filers. These are not administrative sign-offs. They carry direct legal accountability.
This accountability should sharpen the CFO’s interest in the quality of the underlying control environment, not merely the outputs of the annual testing programme. A controls environment that produces clean documentation but operates with undisclosed gaps is a greater legal and reputational risk than one that surfaces issues early and manages them transparently.
The five areas where deficiencies most commonly originate
Based on Raayzel’s advisory work and patterns observed across publicly available PCAOB inspection reports and SEC filings, the following five areas account for the majority of SOX deficiencies identified at significant companies:
- IT General Controls: Access management, change management, and computer operations remain the highest-frequency deficiency area. The shift to cloud infrastructure and hybrid IT environments has introduced new control gaps that legacy ITGC testing programmes do not adequately address.
- Period-end financial reporting: Manual journal entries, review controls, and the completeness of disclosures in complex accounting areas (revenue recognition, lease accounting, business combinations) remain high-risk.
- Segregation of duties: As finance teams operate with leaner headcount, compensating controls for SoD conflicts are frequently documented but not actually functioning as designed.
- Third-party service organisations: Reliance on SOC 1 reports without adequate assessment of the complementary user entity controls that sit with the organisation itself is a persistent gap.
- Control owner accountability: Controls are mapped to process owners who lack sufficient awareness of what the control requires, when it must be performed, and what constitutes adequate evidence.
What a pre-audit readiness review should examine
A SOX readiness review conducted in advance of the audit cycle should go beyond re-reading last year’s documentation. The focus should be on:
- Whether the risk assessment underlying the scoping decisions remains current, particularly where the business has undergone structural change, system implementations, or significant personnel transitions.
- Whether the design of key controls has kept pace with changes in the processes they are intended to mitigate.
- Whether control evidence is being generated and retained as a matter of routine operation, rather than being assembled retrospectively when testing begins.
- Whether management’s testing programme provides genuine independent assurance or whether it is functionally reproducing the evidence that will be provided to the external auditors.
A CFO who can answer these questions with confidence before the audit begins is in a materially stronger position than one who is relying on the external auditors to identify issues for the first time.
The relationship between SOX and broader internal control maturity
SOX compliance is a floor, not a ceiling. Organisations that treat it as a compliance exercise tend to have control environments that meet the minimum standard required to avoid a qualified opinion, without producing the operational and reporting reliability that strong internal controls are designed to deliver.
The CFOs and Finance Directors who derive the most value from their SOX programmes are those who use the discipline as a mechanism for building and maintaining genuine control maturity. That means integrating SOX scope with the broader internal audit plan, connecting the results of controls testing to operational risk reporting, and using deficiency patterns to identify systemic weaknesses rather than addressing individual findings in isolation.
Where Raayzel works in this space
Raayzel provides SOX advisory and controls remediation support to CFOs, Finance Directors, and their teams. Engagements range from pre-audit readiness reviews and deficiency remediation through to full SOX programme design for organisations approaching their first year of compliance. The work is execution-oriented and calibrated to the organisation’s specific risk profile, not templated.
Stay ahead of the governance and compliance agenda.
Sign up for free insights and resources from Raayzel Business Consulting: https://lp.constantcontactpages.com/sl/sBV4psC/insights




