SOX Change Log Checker
Framework

SOX 404: what it asks of a production change

Section 404 asks management to assess internal control over financial reporting and the external auditor to report on it. The statute lists no change-management steps and sets no clock. The row held for it is one umbrella for IT general controls (access, change, operations); the change-management detail an auditor tests comes from COBIT BAI06 and BAI07, and the way the auditor tests it from PCAOB AS 2201. Ticking SOX 404 shows all three.

Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording. PCAOB AS 2201 is quoted as context about the audit, never as a reading of your rows.

The findings it sits behind

14 clauses cited
FindingClause
No independent approvalSOX 404 ITGC · COBIT BAI06.01 · AS 2201 ¶44-46
Approved after it shippedSOX 404 ITGC · COBIT BAI06.01 · COBIT BAI07.06 · AS 2201 ¶44-46
Automated author, no human approvalSOX 404 ITGC · COBIT BAI06.01 · COBIT BAI03.08
Deployed their own changeSOX 404 ITGC · COBIT DSS06.03 · COBIT BAI07.06
One person, three rolesSOX 404 ITGC · COBIT DSS06.03 · AS 2201 ¶39-42
Emergency, no approval afterSOX 404 ITGC · COBIT BAI06.02
Deployment with no matching changeSOX 404 ITGC · COBIT BAI06.03 · COBIT BAI10.03 · AS 2201 ¶22-27
No ticket referenceSOX 404 ITGC · COBIT BAI06.01 · COBIT BAI06.04
Approver not on the listSOX 404 ENT-5 delegation · SOX 404 ITGC · COBIT DSS06.03 · AS 2201 ¶39-42
No test evidenceSOX 404 ITGC · COBIT BAI07.05 · COBIT BAI03.08

Every SOX 404 / ICFR clause the checker cites · Every COBIT 2019 clause the checker cites · Every PCAOB AS 2201 clause the checker cites

Run the specimen Check your own change log