Guides / SOX Compliance
SOX process flowcharts: a complete guide for finance & audit teams
A SOX process flowchart is a visual map of a financially significant business process — order-to-cash, procure-to-pay, financial close — that shows every step, role, and control point an external auditor needs to test under Sarbanes-Oxley Section 404. It pairs with a written narrative and a risk-and-control matrix to form the core SOX documentation set.
What is a SOX process narrative?
A SOX process narrative is a written description of how a financially significant process flows from initiation to recording in the general ledger. It names every actor, every system, every key input and output, and — critically — every control that mitigates a risk of material misstatement.
Most companies pair the narrative with a flowchart because PCAOB AS 2201 requires auditors to "obtain an understanding of the flow of transactions" — and a one-page swimlane diagram communicates that flow faster than ten pages of prose.
Narrative vs. flowchart vs. risk-and-control matrix (RCM)
The three artifacts answer different audit questions:
- Narrative — answers "What happens?" Plain-English description of the process.
- Flowchart — answers "Who does what, and where do controls sit?" Visual, swimlane-by-role.
- Risk-and-control matrix — answers "Which risks are mitigated, by which controls, tested how?" A structured table with control IDs.
Auditors expect all three to reconcile. If the narrative mentions a manager approval that doesn't appear in the flowchart or the RCM, that's a finding waiting to happen.
Key controls vs. non-key controls
Not every control is in scope for SOX. A key control is one that, by itself or in combination with others, addresses a risk of material misstatement to the financial statements. Auditors test these every year.
On the flowchart, mark key controls distinctly — a colored box, a "K" annotation, or the control ID from your RCM (e.g., RTR-04). Non-key controls can be shown in a muted style or omitted from the audit version of the diagram.
Walkthrough documentation requirements
A walkthrough is the auditor's step-by-step trace of a single transaction through the process. PCAOB AS 2201.37 requires auditors to perform at least one walkthrough per major class of transactions per year.
Your flowchart supports the walkthrough by giving the auditor the map. For each key control, you'll typically need:
- The control description and frequency
- The control owner (matches the swimlane in the diagram)
- Evidence: who reviewed, when, what document or screenshot
- Exception handling — what happens if the control fails
The top-down, risk-based approach
PCAOB AS 2201 mandates a top-down approach: start with financial statement assertions, identify accounts that could be materially misstated, work down to the processes feeding those accounts, then to the controls within those processes.
Your flowchart sits at the bottom of that hierarchy. Each diagram should be tagged with the in-scope account (e.g., Revenue, Inventory) and the assertions it addresses (existence, completeness, accuracy, cut-off, valuation).
SOX flowchart symbols & swimlane conventions
Stick to standard flowchart shapes — auditors don't want a BPMN 2.0 primer:
- Rectangle — a process step or activity
- Diamond — a decision point (always show both branches)
- Parallelogram — an input or output document
- Cylinder — a system or database (ERP, AP system, etc.)
- Highlighted rectangle with control ID — a key control
Use swimlanes for roles (AR Clerk, AR Manager, Controller, IT) and label every transition between lanes as a handoff.
Example: revenue recognition process flow
A typical SOX-grade order-to-cash flowchart includes these key controls:
- OTC-01 — Credit limit check before order release (system control)
- OTC-02 — Three-way match: PO, receiving doc, invoice (preventive)
- OTC-03 — Revenue cut-off review at period-end (detective)
- OTC-04 — Management review of revenue accruals (detective)
- OTC-05 — Segregation of duties: order entry vs. invoicing vs. cash application
Each control gets its own labeled box in the flowchart, anchored in the role's swimlane and linked to the underlying evidence in your RCM.
Common SOX audit findings tied to documentation
- Flowchart and narrative describe different process steps
- Key controls in the RCM don't appear in the flowchart
- No documented exception path for failed controls
- Diagram is undated — auditor can't tell which period it represents
- Segregation of duties violations visible in swimlanes but unflagged
- System-generated reports referenced but never marked as IPE (Information Produced by the Entity)
Downloadable SOX flowchart templates
Querychart users start from a spreadsheet template — columns for Step #, Role, Action, System, Control ID, Decision Outcome — and generate the swimlane flowchart automatically. When a control changes, you update the row and the diagram refreshes. No manual redrawing, no drift between narrative and visual.
Frequently asked questions
Does SOX require a flowchart, a narrative, or both?
SOX itself doesn't mandate a specific format — PCAOB AS 2201 requires that auditors understand the flow of transactions and identify controls. In practice, most public companies use all three artifacts together: a narrative for the prose, a flowchart for the visual, and a risk-and-control matrix for the structured test plan.
How often should SOX flowcharts be updated?
At minimum annually, and any time a key process or system changes. Most teams refresh diagrams during the Q1 scoping cycle and re-walk them with control owners before interim testing.
What's the difference between a SOX flowchart and a SOC 2 flowchart?
SOX flowcharts focus on financially significant processes and controls over financial reporting (ICFR). SOC 2 flowcharts focus on the Trust Service Criteria — security, availability, processing integrity, confidentiality, privacy — and typically cover IT processes like change management, access provisioning, and incident response. The diagramming techniques are identical; the scope and control IDs differ.
Do auditors prefer Visio or another tool for SOX flowcharts?
Auditors don't care about the tool — they care about clarity, completeness, and traceability to the RCM. Visio, Lucidchart, Miro, and spreadsheet-driven tools like Querychart all produce acceptable diagrams. The advantage of spreadsheet-driven generation is that the diagram can never drift from the underlying control list.
How detailed should a SOX process flowchart be?
Keep one flowchart per major process (one for OTC, one for P2P, one for financial close) at 15–30 boxes. If you need more detail, create child diagrams for sub-processes (e.g., 'Cash application' as a child of OTC). Mixing high-level overview boxes with detailed sub-steps in one diagram is the most common mistake.
Can I generate these diagrams from a spreadsheet?
Yes. Querychart turns a structured spreadsheet (one row per step, with role, action, and decision columns) into a connected swimlane flowchart automatically. When the process changes, you edit the row and the diagram updates — no manual redrawing.
Generate your SOX process flowchart from a spreadsheet in Querychart →