SOX 404 / ICFR
What is SOX 404 / ICFR?
Sarbanes‑Oxley Act of 2002, Section 404 - Internal Control over Financial Reporting (ICFR), assessed and reported by management and audited in accordance with PCAOB Auditing Standard AS 2201 (revised 2020), based on the COSO Internal Control - Integrated Framework (2013).. It comprises 5 controls organised across 5 domains, and applies in the United States.
How SOX 404 / ICFR maps to other frameworks
All 5 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains SOX 404 / ICFR groups its controls into
Where SOX 404 / ICFR overlaps with the standards you already hold
What SOX 404 / ICFR means in your sector
What SOX 404 / ICFR means for your job
Questions people ask about SOX 404 / ICFR
What is SOX 404 / ICFR?
How many controls does SOX 404 / ICFR have?
Where does SOX 404 / ICFR apply?
How do I get started with SOX 404 / ICFR compliance?
Query SOX 404 / ICFR programmatically
SOX 404 / ICFR, its 5 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
SOX 404 / ICFR API reference and MCP config →How ready are you for SOX 404 / ICFR?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.