Regulation

SOX / PCAOB (ICFR)

SOX 404 / PCAOB AS 2201 — ICFR control taxonomy

21 requirements · 19 connected unified controls

Open SOX / PCAOB (ICFR) in the map
Version
SOX §302/§404 (2002), PCAOB AS 2201
Published
2002-07-30
Amendments
current SEC/PCAOB requirements

Illustrative ICFR control taxonomy: SOX §404 and PCAOB AS 2201 publish no universal control list — controls are defined by each registrant's own risk assessment.

Requirements and control mappings

“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.

Entity-Level Controls (COSO-aligned)

RequirementUnified control and mapping
ELC-CEControl Environment — tone at the top, integrity and ethical values, code of conduct, board/audit committee oversight, organizational structure, assignment of authority and responsibility, commitment to competence, HR policies.
UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culturePartial

Remaining requirement: also spans board oversight, organizational structure, competence, and HR policy elements

ELC-RARisk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control.
UC-RISK-06 — Perform periodic enterprise risk assessmentsPartial

Remaining requirement: objective-setting, fraud, and change aspects covered by dedicated unified controls

ELC-CAControl Activities (entity-level) — policies and procedures, period-end financial reporting process oversight, and entity-wide control activities including technology general controls policies.
ELC-ICInformation & Communication — quality of financial reporting information, internal communication of control responsibilities, and external communication channels (including whistleblower/ethics hotline).
UC-TRAIN-04 — Communicate control responsibilities and reporting channelsPartial

Remaining requirement: quality financial-reporting information prong and general external communication only partially addressed

ELC-MONMonitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies.
ELC-PERFRPeriod-End Financial Reporting Process — controls over the close process, consolidation, journal entries, estimates, and preparation of financial statements and disclosures.
ELC-MGMT-OVRAnti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates.

IT General Controls

Process-Level / Business-Process Controls

RequirementUnified control and mapping
PLC-SODSegregation of duties — incompatible duties (authorization, recording, custody, reconciliation) are divided among different people to reduce the risk of error or fraud.
PLC-MRCManagement review controls — reviews of financial information, account analyses, budget-to-actual variances, estimates, and reconciliations performed at an appropriate level of precision with documented investigation and resolution of items.
PLC-RECONReconciliations — account and subledger-to-general-ledger reconciliations performed completely and accurately, with timely review, approval, and resolution of reconciling items.
PLC-IPEInformation Produced by the Entity (IPE) / completeness and accuracy — controls over the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting.
PLC-AUTHAuthorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed.
PLC-INTFInterface controls — controls ensuring data transferred between systems and across interfaces is complete, accurate, and processed only once (reconciliation of record counts/control totals, error handling).
PLC-INPUTInput controls — edit/validation checks, completeness checks, and field/format controls that ensure data entered into systems is complete, accurate, and valid.
PLC-CALCAutomated processing / configurable controls — system-enforced calculations, three-way matches, tolerance checks, and configurable application controls operating as designed.
PLC-EXCEPTIONException and edit-report controls — review and timely resolution of system-generated exception, error, and edit reports.
PLC-PHYSPhysical safeguards / custody controls — controls over physical custody of assets, inventory counts, and safeguarding of negotiable instruments and records.