standard
SOX / PCAOB (ICFR)
SOX 404 / PCAOB AS 2201 — ICFR control taxonomy
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- sox
- authority
- mandatory
Details
- authority
- mandatory
- version
- SOX §302/§404 (2002), PCAOB AS 2201
- publicationDate
- 2002-07-30
- amendmentState
- current SEC/PCAOB requirements
- effectiveDate
- Not provided
- source_url
- Not provided
- reviewed_at
- Not provided
- note
- Illustrative ICFR control taxonomy: SOX §404 and PCAOB AS 2201 publish no universal control list — controls are defined by each registrant's own risk assessment.
- propositions
Source
No record-specific source URL is provided.
Connections
- ITGC-CM — Program change management — changes to applications, databases, and infrastructure are requested, authorized, tested, approved, and migrated to production by appropriate personnel with segregation between development and production. belongs_to SOX / PCAOB (ICFR)
- PLC-PHYS — Physical safeguards / custody controls — controls over physical custody of assets, inventory counts, and safeguarding of negotiable instruments and records. belongs_to SOX / PCAOB (ICFR)
- PLC-IPE — Information Produced by the Entity (IPE) / completeness and accuracy — controls over the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting. belongs_to SOX / PCAOB (ICFR)
- PLC-SOD — Segregation of duties — incompatible duties (authorization, recording, custody, reconciliation) are divided among different people to reduce the risk of error or fraud. belongs_to SOX / PCAOB (ICFR)
- PLC-INTF — Interface controls — controls ensuring data transferred between systems and across interfaces is complete, accurate, and processed only once (reconciliation of record counts/control totals, error handling). belongs_to SOX / PCAOB (ICFR)
- PLC-EXCEPTION — Exception and edit-report controls — review and timely resolution of system-generated exception, error, and edit reports. belongs_to SOX / PCAOB (ICFR)
- ELC-MON — Monitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies. belongs_to SOX / PCAOB (ICFR)
- ITGC-OPS — Computer operations — job scheduling and batch processing, backup and recovery, incident/problem management, and monitoring of system processing and availability. belongs_to SOX / PCAOB (ICFR)
- PLC-INPUT — Input controls — edit/validation checks, completeness checks, and field/format controls that ensure data entered into systems is complete, accurate, and valid. belongs_to SOX / PCAOB (ICFR)
- PLC-RECON — Reconciliations — account and subledger-to-general-ledger reconciliations performed completely and accurately, with timely review, approval, and resolution of reconciling items. belongs_to SOX / PCAOB (ICFR)
- ELC-IC — Information & Communication — quality of financial reporting information, internal communication of control responsibilities, and external communication channels (including whistleblower/ethics hotline). belongs_to SOX / PCAOB (ICFR)
- ITGC-AC — Access to programs and data — logical and physical access security: authentication, authorization, user provisioning/deprovisioning, periodic access recertification, privileged/administrative access, and segregation of duties enforced via access. belongs_to SOX / PCAOB (ICFR)
- ELC-MGMT-OVR — Anti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates. belongs_to SOX / PCAOB (ICFR)
- ELC-PERFR — Period-End Financial Reporting Process — controls over the close process, consolidation, journal entries, estimates, and preparation of financial statements and disclosures. belongs_to SOX / PCAOB (ICFR)
- ELC-RA — Risk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control. belongs_to SOX / PCAOB (ICFR)
- PLC-MRC — Management review controls — reviews of financial information, account analyses, budget-to-actual variances, estimates, and reconciliations performed at an appropriate level of precision with documented investigation and resolution of items. belongs_to SOX / PCAOB (ICFR)
- PLC-AUTH — Authorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed. belongs_to SOX / PCAOB (ICFR)
- ELC-CE — Control Environment — tone at the top, integrity and ethical values, code of conduct, board/audit committee oversight, organizational structure, assignment of authority and responsibility, commitment to competence, HR policies. belongs_to SOX / PCAOB (ICFR)
- ITGC-DEV — Program development / SDLC — new systems and significant implementations are designed, developed, tested, approved, and converted/migrated in accordance with management's specifications. belongs_to SOX / PCAOB (ICFR)
- PLC-CALC — Automated processing / configurable controls — system-enforced calculations, three-way matches, tolerance checks, and configurable application controls operating as designed. belongs_to SOX / PCAOB (ICFR)
- ELC-CA — Control Activities (entity-level) — policies and procedures, period-end financial reporting process oversight, and entity-wide control activities including technology general controls policies. belongs_to SOX / PCAOB (ICFR)