Law · Financial reporting · United States
SOX ITGCs are the IT general controls that support financial reporting at US-listed companies under Sections 302 and 404 of the Sarbanes-Oxley Act. Auditors test three areas every year: access to programs and data, program changes, and computer operations, plus reliance on SOC 1 reports for outsourced systems.
US-listed companies and the teams and providers that support their financial reporting.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
SOX ITGCs cover who can access financially significant systems, how changes reach production, and how systems run and recover. Auditors test them so they can rely on application controls and system reports.
Provisioning, removal, reviews, privileged access, SoD.
In QULDEX: Sampling per controlAuthorise, test, approve, segregate.
In QULDEX: Change population per periodJobs, backups, incidents.
In QULDEX: Operational evidenceSOC 1 reports and CUECs.
In QULDEX: Reports tracked per vendorDeficiency, significant deficiency, material weakness.
In QULDEX: Findings with severityThese 18 controls and concepts carry most ITGC testing, grouped by area. Select any one to see what it asks for, typical evidence and how QULDEX handles it.
Showing up to 6 per group. Search, filter, or open a group to see all 18.
APD-01User access provisioningNew and changed access to in-scope systems is requested, approved and granted as approved.
In QULDEXProvisioning tickets are sampled in the audit workspace.
APD-02User access removalLeavers' access is removed promptly.
In QULDEXLeaver lists are matched to access removal automatically for sampling.
APD-03Periodic user access reviewsBusiness owners review access to financially significant applications, typically quarterly.
In QULDEXReviews run as recurring tasks with sign-off and revocations tracked.
APD-04Privileged accessAdministrator and superuser access is restricted, approved and monitored.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
APD-05Segregation of dutiesConflicting duties are separated or monitored with compensating controls.
In QULDEXSoD conflicts are tracked with owners.
APD-06AuthenticationPassword and MFA settings meet policy for in-scope systems.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
PC-01Change authorisationChanges to in-scope systems are authorised before development.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
PC-02Change testingChanges are tested and test results approved.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
PC-03Change approval for productionChanges are approved before migration to production.
In QULDEXChange population and samples are kept per period.
PC-04Developer access to productionDevelopers cannot move their own changes to production without control.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
PC-05Emergency changesEmergency changes are documented and approved after the fact.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
CO-01Job scheduling and monitoringBatch jobs and interfaces are scheduled, monitored and failures resolved.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
CO-02Backup and recoveryFinancial data is backed up and restores are tested.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
CO-03Incident and problem managementIT incidents affecting financial systems are tracked to resolution.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
AS 2201Integrated auditThe external auditor audits internal control over financial reporting alongside the financial statements.
In QULDEXAuditors get view-only, logged access to the evidence.
SOC 1Service organisation relianceVendor relianceControls at outsourced providers are covered by SOC 1 Type II reports and complementary user entity controls.
In QULDEXSOC 1 reports and CUECs are tracked per provider.
IPEInformation produced by the entityReports used in controls are complete and accurate.
In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.
DeficiencyDeficiency evaluationExceptions are classified as a deficiency, significant deficiency or material weakness.
In QULDEXExceptions become findings with severity and remediation.
Nothing matches that search.
Control IDs are QULDEX reference labels; your company's control matrix uses its own numbering. Summaries reflect common practice, not a rule list.
Scope the systems that matter to financial reporting, document the controls, test them through the year, fix exceptions and support the external audit. The cycle repeats every year.
Identify applications, databases and infrastructure supporting significant accounts.
Control descriptions, owners, frequency and test steps.
Map CUECs for each outsourced system.
Interim and year-end testing with samples.
Classify deficiencies and fix before year-end.
Durations are QULDEX planning ranges for one annual cycle.
Auditors ask for these records each year.
| Document | Area | Where it lives in QULDEX |
|---|---|---|
| In-scope system list | Scoping | Risk register |
| ITGC control matrix | All | Control library |
| User access review sign-offs | APD-03 | Evidence vault |
| Provisioning and removal samples | APD-01, APD-02 | Evidence vault |
| Change populations and samples | PC-01–PC-05 | Evidence vault |
| Backup and restore evidence | CO-02 | Evidence vault |
| SOC 1 reports and CUEC mapping | SOC 1 | Vendor register |
| Deficiency evaluation | Deficiency | CAPA automation |
Control IDs are QULDEX reference labels.
A first-year programme typically takes 3 to 6 months to set up; after that, testing runs through the year. The number of in-scope systems and how automated access and change evidence is drive the effort.
Bars compare relative effort across an annual cycle.
Check these eight things first. Nothing you enter leaves this page.
Access and change controls overlap heavily with SOC 2 and ISO 27001, so one control set can serve SOX testing and security certifications.
| SOX ITGC area | SOC 2 | ISO 27001:2022 | COBIT 2019 | Shared evidence |
|---|---|---|---|---|
| User access provisioning | CC6.2 | A.5.18 | DSS05.04 | Access tickets |
| Access reviews | CC6.3 | A.5.18 | DSS05.04 | Review sign-offs |
| Privileged access | CC6.1 | A.8.2 | DSS05.04 | Admin lists |
| Change management | CC8.1 | A.8.32 | BAI06 | Change samples |
| Backup and recovery | A1.2 | A.8.13 | DSS04 | Restore tests |
| Job monitoring | CC7.1 | A.8.6 | DSS01 | Job logs |
Indicative mapping for planning.
QULDEX is SOX ITGC testing and audit management software built from EGV Group's audit delivery, used by control owners, internal audit and the external auditors who rely on their work. Pick your role to see who does what.
For IT and business owners of SOX controls.
For internal audit and SOX programme teams.
For audit firms performing integrated audits.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →IT general controls over the systems that support financial reporting at US-listed companies. They cover access to programs and data, program changes, program development and computer operations, and auditors test them under PCAOB AS 2201.
Mainly access (provisioning, removal, reviews, privileged access, segregation of duties), change management (authorisation, testing, approval, segregation) and computer operations (jobs, backups, incidents).
A material weakness is a deficiency that creates a reasonable possibility of a material misstatement not being prevented or detected on time, and it must be disclosed. A significant deficiency is less severe but important enough to tell the audit committee.
Yes. A SOC 1 Type II report on an outsourced provider lets auditors rely on its controls, provided you operate the complementary user entity controls (CUECs) it lists.
Quarterly is the most common practice for financially significant applications, though frequency depends on risk and your auditor's expectations.
How many samples auditors look at for each control frequency.
blog.quldex.comA file-naming scheme auditors can follow.
blog.quldex.comHow auditors grade findings.
blog.quldex.comHow SOC reports cover gaps between periods.
Reviewed by
Answer a short readiness check and get a gap summary by ITGC area. No sales call needed to see the result.