The proposed changes to SOX 404(b)
Recent proposals by the U.S. Securities and Exchange Commission (SEC) could result in one of the most significant changes to the Sarbanes-Oxley (SOX) compliance landscape in many years. The proposals seek to amend the SEC filer status framework and, if adopted, would substantially reduce the number of companies subject to the external auditor attestation requirements of SOX Section 404(b). While the proposals remain under consultation and have not yet been finalised, they have generated significant discussion among boards, audit committees and management teams globally.
For Irish organisations listed on U.S. exchanges, or those considering future access to U.S. capital markets, the proposed changes could materially alter the compliance burden associated with SOX programmes. Under the proposals, many companies that are currently required to obtain an independent auditor's opinion on the effectiveness of Internal Control over Financial Reporting (ICFR) under SOX 404(b) may become exempt from that requirement. However, the requirement for management to establish, maintain and annually assess the effectiveness of ICFR under SOX 404(a) would remain unchanged.
Why the distinction between SOX 404(a) and 404(b) matters
This distinction is important. While a reduction in external attestation requirements may lower compliance costs and reduce testing effort, it does not reduce management's accountability for maintaining an effective control environment. Boards, management teams and audit committees would continue to be responsible for identifying control deficiencies, remediating weaknesses, supporting CEO and CFO certifications, and maintaining investor confidence in the integrity of financial reporting.
For many Irish companies, the practical implications extend beyond compliance. Internal audit functions, which have often dedicated significant resources to supporting SOX 404(b) requirements, may have an opportunity to redirect capacity towards broader enterprise risks such as cybersecurity, artificial intelligence governance, operational resilience, third-party risk management and technology transformation. Equally, for organisations considering an IPO or future access to U.S. capital markets, internal audit can play a pivotal role in building the governance, risk management and control frameworks needed to support public company readiness. While the proposed SEC reforms include a potential five-year exemption from the SOX 404(b) auditor attestation requirement for newly public companies, management's responsibility for maintaining effective internal control over financial reporting would remain. As a result, organisations would still need to invest in scalable control frameworks, governance structures, documentation standards and assurance capabilities to ensure they are prepared for future compliance obligations and sustained stakeholder scrutiny, they would just have more time to get this done.
Looking beyond compliance
Against this backdrop, our colleagues in the United States explore why organisations should avoid viewing potential changes to SOX 404(b) solely through a compliance lens. Instead, they suggest that organisations should consider how any reduction in compliance burden could be leveraged to enhance risk oversight, strengthen governance and expand the strategic contribution of internal audit.
Regulatory relief does not equal risk relief
As regulators consider potential changes to the Sarbanes-Oxley Act (SOX) section 404(b) guidelines for independent external audits, many organisations are understandably focused on compliance costs and expected savings. While that perspective is important, it may not be the most crucial consideration for leaders responsible for SOX oversight and governance. Regardless of how the regulatory discussion unfolds, organisations will continue to face financial reporting risk, cybersecurity threats and artificial intelligence governance concerns, among other challenges.
The underlying risk profile of the business does not decrease because regulatory thresholds for attestation requirements change.
Instead, the responsibility for the mitigation of risk to acceptable levels begins to shift. Investor confidence, board governance and auditor reliance on controls remain critical.
Organisations should avoid confusing regulatory relief with risk relief. Regardless of how the SOX 404(b) discussion evolves, management remains accountable for understanding, monitoring and mitigating risk across the enterprise. The risk didn't retire. The responsibility didn't retire. The only thing being debated is the mechanism used to validate controls.
An opportunity to elevate internal audit
The question for leaders is no longer “How do we maintain compliance?” Rather, it’s “How do we use the capabilities created through compliance activities to address the risks that matter most to the business?”
In addition, as boards become increasingly concerned about cyberthreats, AI governance, technology transformation, operational resilience and third-party risk, many company leaders are asking a similar question: What could internal audit accomplish if it reclaimed even a portion of the capacity currently devoted to compliance activities?
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
Organisations increasingly want assurance over:
- Cybersecurity programs
- AI governance
- Strategic suppliers
- Technology implementations
- Data privacy programmes
- Operational resilience
These are not merely audit topics. They are enterprise value topics.
From compliance function to growth enabler
Since SOX was enacted in 2002, internal audit has shifted toward a compliance-heavy mandate, while the ecosystem of business risks has evolved and expanded. Internal audit remains one of the few functions capable of independently assessing risk across the entire enterprise, evaluating technology, operations, cybersecurity, data, regulatory compliance, governance and strategic initiatives through a common lens.
That capability is becoming increasingly valuable.
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
Board members of complex businesses are increasingly asking:
- Are we managing AI responsibly?
- How resilient are our critical operations?
- Can we trust our technology-enabled processes?
- What risks could disrupt future growth?
These conversations are far more strategic than compliance alone.
The next generation of internal audit function looks different
The most forward-looking organisations are already evaluating how internal audit can become a broader risk and value function. Most advanced organisations consider reallocating capacity and evaluating skills first. Many organisations may soon have an opportunity to redistribute internal audit resources. These are not merely audit topics. They are enterprise value topics.
The internal audit function of the future is asking questions like:
- Which risks currently receive insufficient attention?
- What risk domains deserve increased coverage?
- How should plans evolve over the next five years?
In other words, if you recovered half of the resources currently devoted to SOX, what new risks would immediately move into your audit plan? Also, how would that affect talent? The future internal audit function will bring more value to the most pressing risks to the business.
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
Potential growth areas include not only cybersecurity and AI governance, but also data and analytics, third-party risk, technology assurance and privacy, and global compliance.
Preparing for technology-driven risk
Technology is changing how organisations operate, and critical business processes increasingly rely on automation, advanced analytics, intelligent workflows and AI-enabled decision making. That creates both opportunity and risk. This situation represents one of the most significant emerging responsibilities for internal audit leaders.
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
Questions audit committees should be asking right now
Regardless of regulatory outcomes, boards should consider several strategic questions:
- Are we spending our resources on the highest-risk areas?
- What risks could materially affect enterprise value?
- How confident are we in our AI governance capabilities?
- Where are we most exposed to technology-driven disruption?
- Are we adequately addressing third-party and operational risk?
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
IPO readiness and the new internal audit opportunity
While much attention has focused on public companies that may experience regulatory relief, another important audience exists: Organisations preparing for or considering the public markets. For these organisations, outsourced and co-sourced internal audit models may provide access to specialized capabilities without requiring significant in-house investment.
Question: If the path to public company readiness becomes more flexible, how should companies build scalable governance and assurance capabilities?
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.
A defining opportunity for internal audit leaders
The discussion surrounding SOX 404(b) often focuses on compliance. That perspective may be too narrow. The larger opportunity is the transformation of internal audit itself. Organisations that simply view change as an opportunity to reduce costs may capture short-term savings. However, organisations that view change as an opportunity to expand internal audit reach may create long-term enterprise value.
The organisations that benefit most from regulatory change will use this opportunity to rethink how internal audit contributes to enterprise value. The future of internal audit is not necessarily smaller; it may be broader, more specialized, more technology-enabled and more strategically aligned to enterprise growth than at any point in its history.
Key takeaway
The real opportunity with a potential SOX 404(b) shift is reclaiming capacity and reinvesting it into the risks, opportunities and strategic priorities that will define the next decade of business performance. The future of internal audit will be measured less by the number of controls tested and more by its ability to help organisations navigate uncertainty, manage emerging risk and create confidence in critical business decisions.
If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.