404(a) · United States

If 404(b) Goes Away: What Management Still Has to Do Under 404(a)

5 min read

The SEC’s proposal would take many companies outside the Section 404(b) auditor attestation. It would not change management’s own assessment under Section 404(a). This article sets out what that assessment still requires.

What the proposal would change

On 19 May 2026 the SEC proposed a restructuring of the filer status framework (Release Nos. 33-11419; 34-105515). The proposal would raise the public float threshold for large accelerated filer status from $700 million to $2 billion, collapse the filer categories into two principal ones — large accelerated filer and non-accelerated filer — and give newly public companies a five-year on-ramp before large accelerated filer status, and with it the attestation, can apply.

Under the proposal, only large accelerated filers would remain subject to the auditor attestation under Section 404(b) of the Sarbanes-Oxley Act. On the SEC’s own estimate, 80.8% of reporting companies would be non-accelerated filers.

Status. This is a proposal, not a rule. The comment period closed on 20 July 2026. At the date of this article it has not been adopted, and it may be adopted as proposed, adopted in modified form, re-proposed or withdrawn. Confirm the current position before acting on it.

What Section 404(a) still requires

Section 404(b) is the auditor’s obligation. Section 404(a) is management’s, and the proposal leaves it untouched. Every reporting company would still have to include in its annual report a management report on internal control over financial reporting that, under Item 308(a) of Regulation S-K:

  • states management’s responsibility for establishing and maintaining adequate ICFR;
  • identifies the framework used to evaluate it — for almost every filer, COSO 2013;
  • concludes whether ICFR was effective as of the last day of the fiscal year; and
  • discloses any material weakness. If one exists at year-end, ICFR cannot be concluded effective.

The quarterly Section 302 certifications and the Section 906 certification continue unchanged, as does the Item 308(c) disclosure of material changes in ICFR each quarter.

None of this was ever derivative of the auditor’s work. In an integrated audit, AS 2201.75(c) requires the auditor to obtain management’s written representation that it did not use the auditor’s procedures as part of the basis for its own assessment. Management’s conclusion has always had to stand on management’s own evaluation. The SEC’s 2007 interpretive guidance for management (Release No. 33-8810) remains the reference point for how that evaluation can be performed.

Where auditor-shaped programmes fall short

For many accelerated filers, the external audit has quietly acted as the quality-control layer on management’s programme. The auditor’s walkthroughs find documentation gaps. Their testing finds controls that do not operate. Their sample sizes and evidence requests set the standard the programme works to.

Take the attestation away and that layer goes with it. The common weaknesses then become management’s alone to find:

  • Scoping inherited, not reasoned. Significant accounts, locations and key controls selected years ago to match the auditor’s plan, with no current rationale on file.
  • Testing designed for reliance, not for a conclusion. Management testing sized and timed around what the auditor would re-perform, rather than around what management needs to support its own conclusion.
  • Deficiency evaluation deferred. Severity assessments that waited for the auditor’s view, with no documented reasoning on magnitude, likelihood, aggregation or compensating controls.
  • Management review controls without precision. Reviews evidenced by a signature but not by what was reviewed, against what threshold, and what was followed up.

There is also a practical consequence. The financial statement auditor will still assess control risk and perform substantive procedures. A programme that degrades once attestation ends is likely to mean a heavier substantive audit, not a lighter one — and a higher risk that an error reaches the financial statements.

Building management’s own methodology

The right response is to keep the programme and replace the external benchmark with an internal one. That means a written methodology that management owns, covering:

  • Scoping — a top-down, risk-based scoping memo refreshed each year: significant accounts and disclosures, relevant assertions, locations and systems, with exclusions explained.
  • Risk assessment and key control selection — what could go wrong for each assertion, and the control that addresses it, with the reasoning recorded.
  • Testing approach — who tests, when, over what population and with what sample, including interim testing and roll-forward, with testers independent of the control.
  • Deficiency evaluation — a consistent basis for severity, individually and in aggregate, applied as deficiencies arise rather than at year-end.
  • Remediation — root cause, owner, date, and validation over a sufficient operating period before a deficiency is treated as closed.
  • The annual conclusion — an assessment memo that records the reasoning, not just the result, signed by the officers who certify.

The test for each element is simple: would it withstand re-performance by a sceptical reviewer? From the point the attestation ends, nothing else will check it.

Evidence and audit committee reporting

Two disciplines matter more once the auditor’s opinion is gone.

Evidence retention. Management’s conclusion is only as defensible as the evidence behind it. Retain contemporaneous evidence of each control’s operation and each test performed, in a form another reviewer could follow. Evidence reconstructed at year-end rarely survives scrutiny.

Audit committee oversight. The audit committee loses the auditor’s independent ICFR opinion as an input to its oversight. It should expect, in its place, regular reporting from management on programme status, testing results, open deficiencies with their severity reasoning, and remediation progress — and should be able to see how management reached its conclusion.

The proposal may change before it is adopted. The responsibility it leaves behind will not. Companies likely to fall outside 404(b) are better placed deciding now how management’s own assessment will be performed, evidenced and overseen, rather than discovering the gap in the first year without an auditor’s report.

Sources

  • SEC Release Nos. 33-11419; 34-105515 (19 May 2026), proposed rule, and SEC fact sheet — sec.gov
  • Sarbanes-Oxley Act of 2002, §§302, 404, 906; Regulation S-K Item 308
  • PCAOB AS 2201, paragraph .75(c) — pcaobus.org
  • SEC Release No. 33-8810 (2007), Commission Guidance Regarding Management’s Report on Internal Control Over Financial Reporting

This article is general information, current as at its publication date. It is not legal, accounting or audit advice.

Have an ICFR issue to discuss?

Start a conversation