← Crosswalk explorer

ESG Essentials SOX (Sarbanes-Oxley) Section 404

10 canonical controls in Keel’s library satisfy clauses of both ESG Essentials and SOX (Sarbanes-Oxley) Section 404. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don’t repeat.

10 shared controls ESG Essentials · 1.1: 40 in library SOX (Sarbanes-Oxley) Section 404 · Act of 2002 §404; COSO 2013 framework, 17 principles: 30 in library
Start free with ESG Essentials + SOX (Sarbanes-Oxley) Section 404 See all pairs

Controls that satisfy both

Canonical control ESG Essentials clauses SOX (Sarbanes-Oxley) Section 404 clauses
Information security policy
A board-approved information security policy set, reviewed at least annually and communicated to the workforce.
G.9 P12
Risk assessment & treatment
A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence.
G.6 P6, P7, P9
Third-party / vendor risk management
Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data.
G.7, E.7, S.6 P11, P15
Security awareness training
Ongoing security awareness training for all personnel, with completion tracking.
S.5 P4, P14
Management review
Leadership reviews management-system performance at planned intervals and drives improvement decisions.
G.14 P2, P16, P17
Nonconformity & corrective action (CAPA)
Nonconforming outputs are controlled; root causes are analyzed and corrective actions tracked to closure.
S.16 P17
Code of business conduct
A code of conduct - including conflicts of interest - acknowledged by staff.
G.2, G.4 P1, P5
Anti-corruption & bribery
Bribery and facilitation payments are prohibited, with training for relevant staff.
G.3 P1, P8
Whistleblower channel
A confidential, non-retaliatory channel to report misconduct.
G.5 P8, P14
Fraud risk assessment
A periodic assessment of how fraud could occur here - fraudulent reporting, misappropriation, corruption, and management override of controls - naming the specific schemes considered and the control responding to each.
G.3 P8

Clause identifiers (ESG Essentials and SOX (Sarbanes-Oxley) Section 404) are referenced factually for mapping. Keel is not affiliated with or endorsed by the bodies that publish these standards. Control descriptions are Keel’s own; a framework’s full authored control count is on its framework page.

Why this is one project, not two

On a crosswalk-native model, SOX (Sarbanes-Oxley) Section 404 mostly lights up controls you already built for ESG Essentials. You’re not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That’s the whole idea behind collect once, comply everywhere.