- What they do
- Assessor
- Which standards
- On the public register for SOX ICFR.
- Standards
- Pricing
- Not published
Framework Financial Services
SOX ICFR
Section 404 of the Sarbanes-Oxley Act requires management of a U.S. public company to assess and report each year on the effectiveness of internal control over financial reporting (ICFR), and, for accelerated and large accelerated filers, requires the company's external auditor to attest to that control environment under PCAOB Auditing Standard 2201.
Sections 302 and 906 add quarterly and annual certifications by the CEO and CFO. Most companies build their assessment on the COSO 2013 Internal Control Integrated Framework.
On paper, a company needs documented control narratives or matrices for each significant process, a risk assessment tying controls to financial statement assertions, evidence of management's testing, a formal evaluation of deficiencies, the management report included in the Form 10-K, and the sub-certification trail behind the 302 certifications.
Policies for financial close, journal entries, access, change management, and entity-level governance sit underneath all of it.
help
Who has to comply
SEC registrants filing annual reports. Section 404(a) management assessment applies to all filers after their first annual report. Section 404(b) auditor attestation applies to accelerated and large accelerated filers; non-accelerated filers and emerging growth companies are exempt from 404(b).
What the assessor asks to see
The auditor asks for the scoping and risk assessment, entity-level control documentation, process narratives and control matrices, IT general control documentation for in-scope systems, management's test plans and results, the deficiency evaluation and aggregation analysis, remediation status, service organization SOC 1 reports and complementary user entity controls, the financial close checklist and journal entry review evidence, and the certification and sub-certification trail.
Where the requirement sits: SOX 302, 404; 406 code of ethics; PCAOB AS 2201
AS 2201 amendments
The PCAOB lists a version of AS 2201 with amendments effective December 15, 2026, alongside the current standard effective for fiscal years beginning on or after December 15, 2024. Verify which version applies to a given audit year.
Assessors
Who assesses SOX ICFR
Management performs the 404(a) assessment. The 404(b) attestation must be issued by a public accounting firm registered with the PCAOB, applying AS 2201 as part of the integrated audit. Accredited by Public Company Accounting Oversight Board (registration and inspection of audit firms), under SEC oversight.
Public register of assessors: https://pcaobus.org/oversight/registration/registered-firms
- What they do
- Assessor
- Which standards
- On the public register for SOX ICFR.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for SOX ICFR.
- Standards
- Pricing
- Not published
- What they do
- Assessor
- Which standards
- On the public register for SOX ICFR.
- Standards
- Pricing
- Not published
Consultants
Who helps with SOX ICFR
A very large ecosystem of SOX advisory practices, internal audit co-sourcing firms, and GRC tool providers. Engagements typically cover scoping and risk assessment, control documentation, management testing, remediation tracking, and coordination with the external auditor; first-year public companies usually run a readiness project before their first 404(a) report.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a SOX ICFR consultant listing yet. Claim yours →
Software
Tools for SOX ICFR
Tools that name this framework in their own material.
Related reading
- Trends in Public Company Material Weaknesses: Insights from Recent SEC DataAnalysis of 8,000-plus filings showing which control areas fail most often and how rarely material weaknesses are remediated first time.Baker Tilly
- Material Weakness in Internal Controls: The Real ImpactsDistinguishes a deficiency from a significant deficiency and a material weakness, and sets out what disclosure of each actually costs a company.EisnerAmper
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SOX ICFR
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SOX ICFR
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.