Article

Changing the perspective: Turning SOX 404(b) uncertainty into enterprise value

Regulatory relief does not equal risk relief

July 29, 2026

As regulators consider potential changes to the Sarbanes-Oxley Act (SOX) section 404(b) guidelines for independent external audits, many organizations are understandably focused on compliance costs and expected savings. While that perspective is important, it may not be the most crucial consideration for leaders responsible for SOX oversight and governance. Regardless of how the regulatory discussion unfolds, organizations will continue to face financial reporting risk, cybersecurity threats and artificial intelligence governance concerns, among other challenges.

The underlying risk profile of the business does not decrease because regulatory thresholds for attestation requirements change.

Instead, the responsibility for the mitigation of risk to acceptable levels begins to shift. Investor confidence, board governance and auditor reliance on controls remain critical.

RSM perspective

Organizations should avoid confusing regulatory relief with risk relief. Regardless of how the SOX 404(b) discussion evolves, management remains accountable for understanding, monitoring and mitigating risk across the enterprise. The risk didn't retire. The responsibility didn't retire. The only thing being debated is the mechanism used to validate controls.

An opportunity to elevate internal audit

The question for leaders is no longer “How do we maintain compliance?” Rather, it’s “How do we use the capabilities created through compliance activities to address the risks that matter most to the business?”

In addition, as boards become increasingly concerned about cyberthreats, AI governance, technology transformation, operational resilience and third-party risk, many company leaders are asking a similar question: What could internal audit accomplish if it reclaimed even a portion of the capacity currently devoted to compliance activities?

RSM perspective

Many company leaders have long recognized that some of the organization's most significant risks live outside the financial reporting process. This discussion creates an opportunity to revisit where internal audit resources can create the greatest value.

Organizations increasingly want assurance over:

  • Cybersecurity programs
  • AI governance
  • Strategic suppliers
  • Technology implementations
  • Data privacy programs
  • Operational resilience

These are not merely audit topics. They are enterprise value topics.

From compliance function to growth enabler

Since SOX was enacted in 2002, internal audit has shifted toward a compliance-heavy mandate, while the ecosystem of business risks has evolved and expanded. Internal audit remains one of the few functions capable of independently assessing risk across the entire enterprise, evaluating technology, operations, cybersecurity, data, regulatory compliance, governance and strategic initiatives through a common lens.

That capability is becoming increasingly valuable.

RSM perspective

The most effective internal audit functions don't simply validate controls. They help organizations understand risk, improve decision making and increase confidence in strategic initiatives. In fact, internal audit became one of the organization's most important enterprise intelligence functions, possessing the unique ability to provide independent insight across technology, operations, cyber, compliance and governance. Few functions possess that enterprise-wide perspective.

Board members of complex businesses are increasingly asking:

  • Are we managing AI responsibly?
  • How resilient are our critical operations?
  • Can we trust our technology-enabled processes?
  • What risks could disrupt future growth?

These conversations are far more strategic than compliance alone.

The next generation of internal audit function looks different

The most forward-looking organizations are already evaluating how internal audit can become a broader risk and value function. Most advanced organizations consider reallocating capacity and evaluating skills first. Many organizations may soon have an opportunity to redistribute internal audit resources. These are not merely audit topics. They are enterprise value topics.

The internal audit function of the future is asking questions like:

  • Which risks currently receive insufficient attention?
  • What risk domains deserve increased coverage?
  • How should plans evolve over the next five years?

In other words, if you recovered half of the resources currently devoted to SOX, what new risks would immediately move into your audit plan? Also, how would that affect talent? The future internal audit function will bring more value to the most pressing risks to the business.

RSM perspective

The future of internal audit is not about performing fewer compliance exercises. It's about delivering more meaningful insight into the risks that shape enterprise performance.

Potential growth areas include not only cybersecurity and AI governance, but also data and analytics, third-party risk, technology assurance and privacy, and global compliance.

Preparing for technology-driven risk

Technology is changing how organizations operate, and critical business processes increasingly rely on automation, advanced analytics, intelligent workflows and AI-enabled decision making. That creates both opportunity and risk. This situation represents one of the most significant emerging responsibilities for internal audit leaders.

RSM perspective

The future challenge for internal audit isn't simply understanding controls. It is understanding the controls surrounding increasingly autonomous systems. As organizations automate more decisions, you must ask—who validates the controls surrounding those decisions? As organizations increasingly rely on automation and AI-enabled processes, the need for strong governance and independent assurance becomes more important, not less.

Questions audit committees should be asking right now

Regardless of regulatory outcomes, boards should consider several strategic questions:

  • Are we spending our resources on the highest-risk areas?
  • What risks could materially affect enterprise value?
  • How confident are we in our AI governance capabilities?
  • Where are we most exposed to technology-driven disruption?
  • Are we adequately addressing third-party and operational risk?

RSM perspective

Audit committees should not be asking whether they can spend less on assurance. They should be asking whether assurance resources are focused on the risks that matter most.

IPO readiness and the new internal audit opportunity

While much attention has focused on public companies that may experience regulatory relief, another important audience exists: Organizations preparing for or considering the public markets. For these organizations, outsourced and co-sourced internal audit models may provide access to specialized capabilities without requiring significant in-house investment.

Question: If the path to public company readiness becomes more flexible, how should companies build scalable governance and assurance capabilities?

RSM perspective

For many companies approaching the public markets, the challenge isn't compliance. It's building a governance and risk framework capable of supporting future growth. Organizations preparing an initial public offering should view internal audit as a capability that scales with the business—not simply a compliance requirement to satisfy regulatory expectations.

A defining opportunity for internal audit leaders

The discussion surrounding SOX 404(b) often focuses on compliance. That perspective may be too narrow. The larger opportunity is the transformation of internal audit itself. Organizations that simply view change as an opportunity to reduce costs may capture short-term savings. However, organizations that view change as an opportunity to expand internal audit reach may create long-term enterprise value.

The organizations that benefit most from regulatory change will use this opportunity to rethink how internal audit contributes to enterprise value. The future of internal audit is not necessarily smaller; it may be broader, more specialized, more technology-enabled and more strategically aligned to enterprise growth than at any point in its history.

Closing thought

The real opportunity with a potential SOX 404(b) shift is reclaiming capacity and reinvesting it into the risks, opportunities and strategic priorities that will define the next decade of business performance. The future of internal audit will be measured less by the number of controls tested and more by its ability to help organizations navigate uncertainty, manage emerging risk and create confidence in critical business decisions.

RSM perspective

If redesigning the internal audit function today, start with the risks most likely to disrupt growth, damage trust or affect enterprise value, then build the audit plan from those priorities.

AI TECHNOLOGY SOLUTIONS

Intelligent risk management technology solutions to improve speed and consistency

Risk teams often rely on multiple tools that weren’t designed to work together. As a result, controls and workflows remain fragmented, making it harder to understand the risk posture and act quickly.

RSM’s intelligent risk management technology solutions help bring that work into a more coordinated environment. Built on practitioner experience and embedded into RSM delivery, they help reduce manual effort, improve consistency, and provide a clearer view of priorities. The ecosystem is modular by design, so you can begin with the areas of greatest need and expand over time. RSM manages the architecture, integration, and orchestration needed to help teams work together more effectively.