SOX Change Log Checker
Clause text

PCAOB AS 2201: the clauses the checker cites

The 3 PCAOB AS 2201 clauses behind the findings, each with the evidence an auditor asks for where it is held.

Quoted as context: what the external auditor plans and tests under this standard. It describes the audit, not the rows you pasted.

3 clauses

AS 2201 ¶22-27 Entity-level controls and the period-end process, including IT general controls

What the external auditor does under this standard (context, not a reading of your rows):

Entity-level controls, period-end. Requirements include (a) evaluate Entity-Level Controls including control environment, risk assessment, monitoring, information, communication, COSO components, (b) evaluate the Period-End Financial Reporting Process including procedures used to enter transactions, initiate, authorise, record, process, report period-end financial information, (c) consider IT general controls, IT application controls, (d) consider management override, tone at the top, governance, ethics, (e) document evaluation including significant findings, conclusions, (f) determine extent, nature of further testing based on entity-level conclusions.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: PCAOB AS 2201
AS 2201 ¶39-42 Walkthroughs and the selection of controls to test

What the external auditor does under this standard (context, not a reading of your rows):

Walkthroughs, selection, design effectiveness. Requirements include (a) perform Walkthroughs of significant transaction flows to confirm understanding of controls, identify control points, (b) Selecting Controls to Test focused on controls that sufficiently address the risk of misstatement to each relevant assertion, (c) evaluate Design Effectiveness via inquiry, observation, walkthrough, inspection, (d) determine whether the company's controls if operating as prescribed by persons possessing necessary authority, competence would satisfy the company's control objectives, (e) document understanding, selection rationale, design conclusions, (f) update design conclusions as controls or processes change.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: PCAOB AS 2201
AS 2201 ¶44-46 Testing controls across the period: nature, timing and extent

What the external auditor does under this standard (context, not a reading of your rows):

Operating effectiveness. Requirements include (a) test Operating Effectiveness of controls that are sufficiently important to address assertion-level risk, (b) determine Nature of Tests including inquiry, observation, inspection of relevant documentation, reperformance, (c) determine Timing of Tests including interim, roll-forward, period-end procedures, (d) determine Extent of tests including sample size, selection method, considering frequency, control type, reliance on automation, (e) use evidence from other parties including internal audit, management testing where appropriate per AS 2605, (f) document tests, results, conclusions including sample selection, (g) consider IT general controls reliance for automated controls.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: PCAOB AS 2201