SOX Change Log Checker
Clause text

SOX 404 / ICFR: the clauses the checker cites

The 2 SOX 404 / ICFR clauses behind the findings, each with the evidence an auditor asks for where it is held.

Our statement of each clause, read against the copy we hold and cited to it; it is not the instrument's verbatim wording.

2 clauses

SOX 404 ITGC IT General Controls (ITGC) - Access, Change, Operations

ITGC including access management, change management, computer operations, program development, backup, recovery.

The evidence an auditor asks for here is the change-management evidence under COBIT BAI06 and BAI07, which shows with SOX 404.
Source: SOX 404 / ICFR
SOX 404 ENT-5 delegation Delegation of Authority

Board-approved delegation of authority matrix defines approval limits for commitments, expenditures, and contracts.

Evidence an auditor expects: DOA policy; Board resolutions; Approval evidence for transactions above thresholds; System configuration
Where it usually falls short: Delegation of authority not reconciled to system approval limits across ERP and banking; Re-delegation in absence of approver not documented or not time-bound
Source: SOX 404 / ICFR