GDPR Compliance Checklist: A Practical Guide

The UK GDPR and the EU GDPR set out comprehensive requirements for how organisations collect, use, store, and protect personal data. Both retain the substantive structure of the original EU GDPR following Brexit, with the UK version adapted for the UK's separate regulatory and enforcement context. For most organisations, GDPR compliance is not a single project with an end date but an ongoing discipline that needs to be embedded into how data is handled across every function.
5 min read time

The result was one of the most demanding pieces of governance legislation any public company faces. Section 404 in particular, which concerns internal control over financial reporting, is consistently cited as one of the most complex and expensive compliance obligations in public company life. That description is accurate. The requirement to document, test, and report publicly on internal controls over financial reporting is genuinely substantive work.

What the reputation sometimes obscures is that organisations that implement SOX compliance well often discover that the underlying discipline delivers something valuable beyond satisfying the legal requirement. This article explains what SOX actually requires, why it is as demanding as it is, and how the most effective organisations have made the programme work for them rather than against them.

The Legislative Background

SOX was signed into law in July 2002. Its primary purpose was restoring investor confidence in US public markets following a series of accounting frauds and governance failures. The Act covers a wide range of areas including auditor independence, corporate responsibility, enhanced financial disclosures, and analyst conflicts of interest.

For most governance practitioners, the most significant provisions are in Section 302, which requires senior executives to personally certify the accuracy of financial reports and the effectiveness of disclosure controls, and Section 404, which concerns the assessment and attestation of internal controls over financial reporting.

The personal accountability dimension of SOX was deliberate and significant. The officers who sign the certifications can be held personally liable for false or misleading statements. The Act created criminal penalties, not just regulatory sanctions, for intentional violations. This personal accountability, at the time a significant departure from how financial reporting responsibility had previously been framed, remains one of the Act's defining features.

What Section 404 Actually Requires

Section 404 operates through two provisions with different scope and different levels of assurance required.

Section 404(a) requires management to provide an annual assessment and report on the effectiveness of internal controls over financial reporting (ICFR). This is management's own evaluation, conducted using a recognised framework, with a conclusion stated publicly in the annual filing.

Section 404(b) requires an independent registered public accounting firm to separately assess and attest to management's evaluation. This is an external auditor's independent conclusion, not simply a review of management's work. The auditor must reach their own view on whether internal controls over financial reporting are effective.

Non-accelerated filers and smaller reporting companies are generally exempt from Section 404(b), though they remain subject to 404(a). This is a significant distinction: the external attestation requirement substantially increases both the cost and the rigour demanded.

The Scope of an ICFR Assessment

Determining what falls within the scope of an ICFR assessment is one of the first and most consequential decisions in a SOX programme.

The starting point is the financial statements. Every significant account, every material disclosure, and every accounting estimate needs to be considered. Working backwards from the financial statements, the assessment then identifies which business processes, systems, and transactions feed into those accounts and disclosures. Those processes become the in-scope population for control documentation and testing.

For most organisations, this means the in-scope area is broader than initially anticipated. Revenue recognition, procurement and accounts payable, payroll and compensation, treasury and cash management, fixed assets, financial close and consolidation, tax, and the IT general controls that support all of these, are typically all in scope. Each involves processes, systems, and human judgements that could, if improperly controlled, lead to material misstatement.

Entity-level controls, those that operate across the organisation rather than at the level of individual transactions, are also part of the assessment. The control environment, risk assessment processes, information and communication mechanisms, and monitoring activities that underpin the organisation's overall governance are assessed under the COSO Internal Control framework that both the SEC and PCAOB recognise as the appropriate basis for evaluation.

Documenting Key Controls

At the heart of the SOX programme is the identification, documentation, and testing of key controls: those controls that, if they failed, could result in a material misstatement going undetected.

Documentation precision matters significantly and is worth more attention than it often receives. A control described as "management reviews financial results monthly" is too vague to test meaningfully. Who specifically performs the review? What source data do they use? What specifically are they looking for? How do they evidence their review? What happens when an exception is identified?

A well-documented key control describes: the control objective, linking it explicitly to the relevant financial statement assertion (existence, completeness, valuation, rights and obligations, presentation and disclosure); the control description in enough detail to be testable; the control owner by role; the control type (preventive or detective, manual or automated); the frequency of performance; and the evidence the control produces.

This level of precision is not bureaucratic excess. It is what makes the testing of the control credible, what allows an external auditor to evaluate it, and what makes the control genuinely reproducible regardless of who performs it on a given day.

Testing Standards Under SOX

Testing key controls requires demonstrating both design effectiveness and operating effectiveness, a distinction that is foundational to the PCAOB's expectations under Auditing Standard 2201.

Design effectiveness asks: if this control operates as described, would it prevent or detect material misstatements in the relevant assertion? A control can be well documented and formally approved but still fail design assessment if its logic does not genuinely address the risk. A mitigating control that only operates after a material misstatement has already occurred is not an effective preventive control, regardless of how well it is designed.

Operating effectiveness asks: has this control actually been applied consistently, as described, throughout the period under assessment? This requires evidence. Evidence for a manual control might be approval signatures, system logs, review documentation, or reconciliation records. Evidence for an automated control depends primarily on the reliability of the IT general control environment within which it operates.

Sample sizes for operating effectiveness testing are prescribed by the PCAOB's guidance and reflect the frequency of the control. A control that operates daily over a twelve-month assessment period has a population of approximately 250 occurrences. PCAOB guidance indicates minimum samples in the range of 25 items for high-frequency controls. Sampling fewer items without justification creates an independence risk.

Walkthroughs, where the tester traces a specific transaction from initiation through to its reflection in the financial statements, identifying each key control as it is encountered, are expected for significant processes and provide both design assessment evidence and the understanding needed to plan operating effectiveness testing.

IT General Controls

Automated controls are only as reliable as the IT environment in which they operate. A perfectly designed automated approval threshold is not effective if the system it runs on has inadequate access controls, allowing the logic to be overridden, or inadequate change controls, allowing the parameters to be modified without proper authorisation.

IT general controls (ITGCs) govern the reliability of the IT environment and are assessed as part of every SOX programme. The main categories are access management (who can access systems and data, and are those accesses appropriate), change management (how system changes are authorised, developed, tested, and deployed), and operations (how IT systems are monitored and maintained to ensure reliable operation).

ITGCs are often where organisations underestimate the scope of a SOX programme. A comprehensive list of financially significant systems, applications, databases, and infrastructure components, and the associated ITGC assessment for each, is typically more extensive than initially anticipated.

Deficiency Classification and Reporting

When testing identifies a control problem, the severity of that problem determines the response and the disclosure requirements.

A control deficiency exists where a control is not present or not operating in a way that allows timely prevention or detection of misstatements. Not every control deficiency is serious, and the assessment of severity involves judgment about the magnitude of potential misstatement and the likelihood that it would occur and remain undetected.

A significant deficiency is a control deficiency, or combination of deficiencies, that is less severe than a material weakness but important enough to require the attention of those responsible for oversight. Significant deficiencies must be communicated to the audit committee and external auditors but are not required to be disclosed publicly in the annual report.

A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting that creates a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected and corrected on a timely basis. Material weaknesses must be disclosed in the annual report. Their existence means management cannot conclude that internal controls are effective.

Identifying a material weakness is not, in itself, a catastrophe. Organisations that identify and disclose material weaknesses transparently, with a clear remediation plan, are demonstrating governance integrity. What creates far greater regulatory and reputational risk is a material weakness that existed and was not identified, because nobody was looking rigorously.

Where the Genuine Value Lies

Organisations that implement SOX compliance well frequently find that the underlying discipline creates value that extends beyond the regulatory requirement.

Financial process rigour improves because documentation and testing standards expose weaknesses in process design that management had not previously examined systematically. Errors and irregularities that might have reached the financial statements before being discovered are caught at the control level.

The documented control environment provides a foundation for other compliance requirements. SOC 2 audits, ISO 27001, and internal audit programmes all benefit from the systematic control documentation a SOX programme produces.

Audit efficiency improves over time. An external audit team that can rely on a strong, well-tested internal control environment needs to perform less substantive testing. The cost of the annual audit, while never trivial for a public company, is directly influenced by the quality of the internal control programme that supports it.

And the disciplines of continuous documentation maintenance, testing on a rigorous evidentiary basis, and transparent reporting of deficiencies, are exactly the disciplines that make an organisation more governable and its financial reporting more trustworthy over time.

Making SOX Work Year-Round

The organisations that manage SOX most effectively treat it as a continuous programme rather than an annual filing preparation exercise.

That means maintaining control documentation as processes, systems, and people change, not catching up at year-end. It means spreading testing across the year rather than compressing it into the quarter before the filing deadline. It means reviewing significant changes, system implementations, acquisitions, and organisational restructuring for their ICFR implications as they happen, not in retrospect.

A SOX programme that only becomes active in the fourth quarter produces three predictable outcomes: testing that is too compressed to be thorough, surprises close to filing that there is insufficient time to remediate, and a pattern of annual stress that makes the programme unsustainable as a long-term governance discipline.

The organisations that describe SOX as an advantage rather than a burden are almost uniformly the ones that have made it continuous.

Related Reading

References

Next Steps

Would your data protection stand up if the regulator came knocking?

Join 150+ organisations who’ve already made calQrisk their competitive edge.
Book a Demo