• 1000

The Sarbanes-Oxley Act as a federal law is valid for American and foreign companies as well as subsidiaries whose assets are traded on the American stock market or publicly offered in the US. With recent trends in global mergers and acquisitions and companies seeking to be traded on a US exchange, the need for global SOX 404 compliance services has increased, and KPMG has responded to the demand by developing the German SOX Center of Competence.

The SOX Center of Competence consists of a group of professionals with knowledge and experience in delivering SOX related services to both national and global organizations. Our global SOX methodology has been created on the basis of the SEC's Interpretive Guidance for management and has been adopted by our member firms who can work seamlessly on cross-border engagements to provide a consistent approach and delivery of our services. Our SOX CoC can help organizations with the following professional services.

Our SOX services include but are not limited to the services below:

SOX Strategy & Transformation

Determination of the right ICOFR strategy for the organization.  Touches on the importance of strong entity level controls and the risk assessment process, as well as discussion around the economic decision for level of auditor reliance.

SOX Implementation

KPMG supports in SOX implementation including training, development of a SOX Strategy, risk assessment, walkthroughs, documentation of processes and controls, gap analysis and remediation activities.

SOX Documentation

Assistance in documenting SOX processes and controls in Narrative/Flowchart formats and Risk and Control Matrix (RCM) and testing templates. All decisions regarding controls and process design are made by the client.

SOX Testing

KPMG supports the client in planning, risk assessment, designing and executing effective testing strategy, determining the nature and timing of Testing, the Sampling Strategy and performing TOD and TOE testing and managing test results. 


KPMG performs an independence assessment based on PCAOB AS No. 2201 (AS  5) in preparation for an IPO, aligned with the KPMG Audit Methodology.

Quick Check

KPMG assesses the readiness of the client’s ICOFR/controls program to determine how mature the client’s SOX program is.

IPO Readiness

KPMG can help clients develop a seamless strategy for going public – from evaluation, to offering, to Post-IPO operations.

Project Management Support

KPMG provides support for overseeing management’s SOX program from design and planning to execution.

SOX Program Maturity/ Cost of Control
(including SOX Health check and CPAM)

Assessing the maturity of your ICOFR program and considering the total cost of control as a driver toward a more “healthy” program.

In each of these services, KPMG professionals work closely with clients to establish compliance programs, transfer knowledge and provide training to support a successful SOX 404 compliance program.  

The SOX CoC is able to bring value to organizations through our integrated network of professionals. 

  • Through our ONE Audit strategy in Germany, we provide an integrated approach for our delivery of SOX Services through close collaboration with our Attestation Team.
  • We operate as a reliable partner prepared for different interests and issues, as we are able to present far-reaching and interdisciplinary solutions within KPMG through collaboration with other service lines to provide specialist expertise for optimal solutions.
  • Collaboration with our KPMG US teams for knowledge sharing and training materials to provide a 'one-firm' approach and set a global quality standard for SOX delivery to our clients