Skip to main content
Framework library
Framework module · sox-icfr

Sarbanes-Oxley ICFR

The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.

SOX Sections 302 and 404; PCAOB AS 2201 · U.S. Securities and Exchange Commission — Release 33-8238 · published 2003-06-05

Standing today
Directory entry

00Answer

from the registry record
What is Sarbanes-Oxley ICFR?
The US public-company regime for management assessment and, where applicable, independent audit of internal control over financial reporting. SOX does not prescribe one universal IT-control catalog, and registry tracking is not an audit opinion.
Who does Sarbanes-Oxley ICFR apply to?
Sarbanes-Oxley ICFR applies to public companies, financial reporting, audit firms, US, per U.S. Securities and Exchange Commission — Release 33-8238.
What is the current version of Sarbanes-Oxley ICFR?
The current edition is SOX Sections 302 and 404; PCAOB AS 2201, issued by U.S. Securities and Exchange Commission — Release 33-8238 and published 2003-06-05. Source: https://www.sec.gov/rule-release/33-8238.
What does an assessment under Sarbanes-Oxley ICFR require?
No control catalog has been ingested for Sarbanes-Oxley ICFR yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Sarbanes-Oxley ICFR is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; SOX applicability, issuer scoping, ICFR risks and controls, testing, deficiency evaluation, and auditor procedures are not ingested or implemented as a distinct module.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Management assessment of ICFR · Disclosure controls and procedures · Integrated audit of ICFR · Deficiency evaluation and reporting · IT general controls as scoped to financial reporting
Applies to
public companies · financial reporting · audit firms · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30
Pending change
PCAOB and SEC-approved amendments to AS 2201 paragraph .09 and new paragraph .99 become effective on 2026-12-15. They affect the auditor standard, not the statutory text of SOX.Expected: 2026-12-15

03Version ledger

1 edition
SOX Sections 302 and 404; PCAOB AS 2201Current edition2003-06-05

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to public companies · SOX requires management and auditor assessment of internal control over financial reporting but does not prescribe one IT-control catalog. COBIT 2019 is licensed governance guidance often used to design and map IT general controls; neither this record nor COBIT is a SOX certification.

  2. Also applies to public companies · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.

  3. SEC Cybersecurity Disclosure RulesRelease Nos. 33-11216; 34-97989

    Also applies to public companies · What a public company must tell investors: a material cybersecurity incident on Form 8-K Item 1.05 within four business days, and its risk-management and board oversight annually under Reg S-K Item 106.

  4. Commonly assessed together · Generally accepted government auditing standards for financial audits, attestation engagements, reviews, and performance audits. They govern auditor and audit-organization quality; they do not certify the entity being audited.

Sarbanes-Oxley ICFR | ControlFrame