SSBJ Internal Controls: J-SOX Does Not Cover This
In a Japanese listed company, a revenue figure passes through a machine. It comes out of a system with access controls, it is reviewed by someone who did not enter it, it is approved by someone senior to both, and every one of those steps leaves a record that an audit firm will pull a sample from.
The electricity consumption figure for the same group is usually maintained by two people in a sustainability team, in a workbook that lives on a shared drive, assembled from emails sent by plant managers.
From the fiscal year ending March 2027, both numbers go into the same document, the annual securities report. A year after that, the second one gets an assurance opinion attached to it. The control system around it has to arrive in between, and Japan’s existing internal control regime will not deliver it.
The regime that does not extend
Japan’s internal control report under the Financial Instruments and Exchange Act, the one everyone calls J-SOX, is an instrument about financial reporting. Sustainability information is not inside it, and the Financial Services Agency’s working group did not put it there.
The working group’s final report, published on 8 January 2026, builds sustainability assurance as a separate regime with its own standards and its own registration system. Internal control reporting appears in the document twice, both times in footnotes. The relevant one records a member’s view that companies should build a governance structure covering sustainability information regardless of whether it falls within internal control reporting.
Read that footnote as what it is. Nobody is proposing to extend J-SOX. Somebody in the room noticed that the controls are needed anyway.
Where the scrutiny arrives from instead
It arrives through assurance, and the FSA has been specific about the shape of it.
Assurance on SSBJ-based sustainability information in the annual securities report will be performed under standards aligned with the international ones: ISSA 5000 from the IAASB, ISQM 1, and IESSA from the IESBA. Assurance providers will be registered, and both audit firms and non-audit-firm providers may register if they meet the requirements. The Japanese standards themselves are to be deliberated by the Business Accounting Council (FSA working group report, 8 January 2026).
The timing is fixed and has been for a while. Prime-listed companies with average market capitalisation of ¥3 trillion or more disclose for the fiscal year ending March 2027, ¥1 trillion and above from 2028, ¥500 billion and above from 2029. Assurance begins one fiscal year after mandatory disclosure for each tier. The level is limited assurance, with no move to reasonable assurance under consideration, and the scope for the first two years is governance, risk management, and Scope 1 and 2 (FSA roadmap; English roadmap). We have written elsewhere about why that one-year gap is not a free year.
What a practitioner actually looks at
ISSA 5000 is the standard the Japanese one will be aligned with, so its structure tells you what will be asked.
Before designing any procedure, the practitioner obtains an understanding of five components of the entity’s internal control as they relate to preparing the sustainability information: the control environment, the entity’s risk assessment process, the entity’s process for monitoring the system of internal control, the information system and communication, and control activities. Under limited assurance that understanding comes through inquiry (IAASB webinar, planning and risk assessment).
Inquiry sounds mild. It means somebody sits with your team and asks how the information system works: how you identify which sustainability information gets reported, how external information is recorded, processed, corrected and incorporated, and how the methods, assumptions and data sources behind estimates are identified and changed. They then evaluate whether that system appropriately supports the preparation of the information (same source).
There is also a procedure that runs at both assurance levels. The practitioner reconciles the sustainability information to the underlying records, then asks about material adjustments (same source). If the published number cannot be walked back to a meter reading, an invoice, or a supplier submission, that is where the engagement slows down.
Control points, by scope
Scope 1. The hard part is completeness rather than accuracy. Fuel and process emissions come from invoices and meters that mostly exist. The question is whether every entity that should be in the number is in it, and the answer is now set by the consolidation schedule rather than by which sites the sustainability team can reach. That reconciliation is its own piece of work and it belongs in the control design, with a documented owner and a sign-off.
Scope 2. This is where factor version control decides the number. Japan’s Ministry of the Environment publishes per-utility electricity emission factors under the SHK scheme, and the FY2024 figures were published on 9 January 2026. A control here records which published year’s factor was applied to which reporting period, who approved the change, and when the calculation was re-run. Groups that switch factor vintages mid-preparation and do not log it produce a number nobody can reproduce six months later.
Scope 3. It sits outside the first two years of mandatory assurance scope, which is exactly why it is worth building the controls now rather than later. Scope 3 is where the estimates live, and estimates carry their own requirements: the method, the assumptions, the data source, and a justification for any change from last year. The data problems in the Scope 3 categories do not resolve themselves during the grace period.
What transfers from J-SOX, and what you are choosing
The J-SOX machinery does not apply here, so borrowing from it is a design decision rather than a compliance requirement. Four pieces of it transfer cleanly.
Segregation of preparer, reviewer and approver, so that no single person both produces a figure and signs it off. Evidence retention with a record of who entered what, from which source, and when. Change control over formulas, emission factors and activity-data definitions, so a changed number has a reason attached. And documented judgements, since a materiality assessment or a Scope 3 category inclusion decision is a judgement that an assurance provider will ask the basis for.
None of this is exotic. It is the same discipline finance has run for years, applied to a dataset that has never had it, in a company where the two teams often do not share a system.
The practical argument for reusing the finance controls is that your audit firm already understands them. A control designed to be legible to an auditor is legible to an assurance practitioner, and the same evidence store answers both conversations.
What to do in the next two quarters
Take one Scope 1 site and one Scope 2 contract and walk each number from the published report back to its source document. Note every hand it passed through and every place the trail goes cold. That exercise usually finds the same three things: a plant that emails a total with no working, a factor whose vintage nobody recorded, and a reviewer who cannot say what they checked.
Then write the control down before you build any tooling. Who enters, who reviews, who approves, what evidence gets kept, and how long. A control that exists only as a habit does not survive its first inquiry, because the person answering describes what they usually do, and usually is not a control.
The first tier has one disclosure year before assurance starts. That year is the build window, and it started in April.
Check where you stand. The free SSBJ readiness check takes about three minutes and scores the dimensions an assurance provider will actually test: socious.io/ssbj-check.
Socious Report takes one dataset into AI-drafted CSRD, SSBJ and ISSB reports, then adds an independent Socious Verify credential.