Law · Financial reporting · United States

SOX ITGC: the IT general controls auditors test and how to pass

SOX ITGCs are the IT general controls that support financial reporting at US-listed companies under Sections 302 and 404 of the Sarbanes-Oxley Act. Auditors test three areas every year: access to programs and data, program changes, and computer operations, plus reliance on SOC 1 reports for outsourced systems.

Key takeaways

What you need to know about SOX ITGC

Annual testingControls are tested every year, with samples per control.
Access is the hotspotMost ITGC exceptions come from access provisioning, removal and reviews.
Changes need a trailAuthorisation, testing and approval before production.
Vendors via SOC 1Outsourced systems rely on SOC 1 reports and user controls.
Severity mattersA material weakness is disclosed publicly.

Who needs SOX ITGCs?

US-listed companies and the teams and providers that support their financial reporting.

US-listed companiesIssuers subject to Sections 302 and 404.
Pre-IPO companiesBuilding controls before listing.
Internal audit and ITOwning and testing the controls.
Service providersSupplying SOC 1 reports to listed customers.
Audit firmsTesting ITGCs in integrated audits.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What auditors test

What do SOX ITGCs cover?

SOX ITGCs cover who can access financially significant systems, how changes reach production, and how systems run and recover. Auditors test them so they can rely on application controls and system reports.

APD Access

Access to programs and data

Provisioning, removal, reviews, privileged access, SoD.

In QULDEX: Sampling per control
PC Change

Program changes

Authorise, test, approve, segregate.

In QULDEX: Change population per period
CO Operate

Computer operations

Jobs, backups, incidents.

In QULDEX: Operational evidence
SOC 1 Outsource

Service organisations

SOC 1 reports and CUECs.

In QULDEX: Reports tracked per vendor
Severity Evaluate

Deficiencies

Deficiency, significant deficiency, material weakness.

In QULDEX: Findings with severity
Control explorer

Which SOX ITGCs do auditors test?

These 18 controls and concepts carry most ITGC testing, grouped by area. Select any one to see what it asks for, typical evidence and how QULDEX handles it.

302/404SOX sections
AS 2201audit standard
3ITGC areas
1 yeartesting cycle

Showing up to 6 per group. Search, filter, or open a group to see all 18.

Access to programs and data 6

  1. APD-01User access provisioning

    New and changed access to in-scope systems is requested, approved and granted as approved.

    In QULDEXProvisioning tickets are sampled in the audit workspace.

    Typical evidence
    Approved tickets
    Maps to
    ISO 27001 A.5.18SOC 2 CC6.2

  2. APD-02User access removal

    Leavers' access is removed promptly.

    In QULDEXLeaver lists are matched to access removal automatically for sampling.

    Typical evidence
    HR leaver list, removal evidence
    Maps to
    ISO 27001 A.5.18

  3. APD-03Periodic user access reviews

    Business owners review access to financially significant applications, typically quarterly.

    In QULDEXReviews run as recurring tasks with sign-off and revocations tracked.

    Typical evidence
    Signed review, revocations
    Maps to
    SOC 2 CC6.3

  4. APD-04Privileged access

    Administrator and superuser access is restricted, approved and monitored.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Privileged user list, monitoring
    Maps to
    ISO 27001 A.8.2

  5. APD-05Segregation of duties

    Conflicting duties are separated or monitored with compensating controls.

    In QULDEXSoD conflicts are tracked with owners.

    Typical evidence
    SoD matrix

  6. APD-06Authentication

    Password and MFA settings meet policy for in-scope systems.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Configuration evidence
    Maps to
    ISO 27001 A.8.5

Program changes 5

  1. PC-01Change authorisation

    Changes to in-scope systems are authorised before development.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Change tickets
    Maps to
    ISO 27001 A.8.32

  2. PC-02Change testing

    Changes are tested and test results approved.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Test evidence

  3. PC-03Change approval for production

    Changes are approved before migration to production.

    In QULDEXChange population and samples are kept per period.

    Typical evidence
    Approval evidence

  4. PC-04Developer access to production

    Developers cannot move their own changes to production without control.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Access lists
    Maps to
    ISO 27001 A.8.31

  5. PC-05Emergency changes

    Emergency changes are documented and approved after the fact.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Emergency change log

Computer operations 3

  1. CO-01Job scheduling and monitoring

    Batch jobs and interfaces are scheduled, monitored and failures resolved.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Job logs

  2. CO-02Backup and recovery

    Financial data is backed up and restores are tested.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Backup logs, restore tests
    Maps to
    ISO 27001 A.8.13

  3. CO-03Incident and problem management

    IT incidents affecting financial systems are tracked to resolution.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Incident tickets

Audit and evaluation 4

  1. AS 2201Integrated audit

    The external auditor audits internal control over financial reporting alongside the financial statements.

    In QULDEXAuditors get view-only, logged access to the evidence.

    Typical evidence
    Auditor requests

  2. SOC 1Service organisation relianceVendor reliance

    Controls at outsourced providers are covered by SOC 1 Type II reports and complementary user entity controls.

    In QULDEXSOC 1 reports and CUECs are tracked per provider.

    Typical evidence
    SOC 1 reports, CUEC mapping

  3. IPEInformation produced by the entity

    Reports used in controls are complete and accurate.

    In QULDEXQULDEX tracks this control with an owner, test steps, samples and evidence each period, so testing rolls forward instead of starting over.

    Typical evidence
    Report validation

  4. DeficiencyDeficiency evaluation

    Exceptions are classified as a deficiency, significant deficiency or material weakness.

    In QULDEXExceptions become findings with severity and remediation.

    Typical evidence
    Deficiency log

Control IDs are QULDEX reference labels; your company's control matrix uses its own numbering. Summaries reflect common practice, not a rule list.

Annual cycle

How do you run a SOX ITGC programme?

Scope the systems that matter to financial reporting, document the controls, test them through the year, fix exceptions and support the external audit. The cycle repeats every year.

  1. Scope in-scope systems

    Identify applications, databases and infrastructure supporting significant accounts.

  2. Document the control matrix

    Control descriptions, owners, frequency and test steps.

  3. Collect SOC 1 reports

    Map CUECs for each outsourced system.

  4. Test controls

    Interim and year-end testing with samples.

  5. Remediate exceptions

    Classify deficiencies and fix before year-end.

  6. Support the external audit

    Q1–Q3Interim testing
    Q4Roll-forward and year-end
    AfterManagement assessment and audit opinion

Durations are QULDEX planning ranges for one annual cycle.

Records to keep

Which documents does SOX ITGC testing need?

Auditors ask for these records each year.

DocumentAreaWhere it lives in QULDEX
In-scope system listScopingRisk register
ITGC control matrixAllControl library
User access review sign-offsAPD-03Evidence vault
Provisioning and removal samplesAPD-01, APD-02Evidence vault
Change populations and samplesPC-01–PC-05Evidence vault
Backup and restore evidenceCO-02Evidence vault
SOC 1 reports and CUEC mappingSOC 1Vendor register
Deficiency evaluationDeficiencyCAPA automation

Control IDs are QULDEX reference labels.

Time and cost

How much effort does SOX ITGC take?

A first-year programme typically takes 3 to 6 months to set up; after that, testing runs through the year. The number of in-scope systems and how automated access and change evidence is drive the effort.

Where the time goes

Scoping2–4 wk
Control matrix3–6 wk
SOC 1 mapping2–4 wk
TestingOngoing
RemediationOngoing

Bars compare relative effort across an annual cycle.

What changes the effort

  • In-scope systems: each adds access and change testing
  • Automation: system-generated populations save sampling time
  • Outsourcing: SOC 1 gaps need compensating controls
  • Prior-year findings: repeat exceptions raise severity
  • Existing SOC 2 or ISO 27001: access and change evidence overlaps
Readiness check · 2 minutes

How ready are your SOX ITGCs?

Check these eight things first. Nothing you enter leaves this page.

ScopeIs the list of in-scope systems agreed with the auditor?
APD-01Is every access grant approved before it is given?
APD-02Is leavers' access removed promptly?
APD-03Are user access reviews done and signed each quarter?
PC-03Are changes approved before production?
PC-04Are developers kept from deploying their own changes?
SOC 1Do you have SOC 1 reports for outsourced systems?
DeficiencyAre exceptions classified and remediated?
Crosswalk

How SOX ITGCs map to SOC 2, ISO 27001 and COBIT

Access and change controls overlap heavily with SOC 2 and ISO 27001, so one control set can serve SOX testing and security certifications.

ITGC crosswalk

SOX ITGC areaSOC 2ISO 27001:2022COBIT 2019Shared evidence
User access provisioningCC6.2A.5.18DSS05.04Access tickets
Access reviewsCC6.3A.5.18DSS05.04Review sign-offs
Privileged accessCC6.1A.8.2DSS05.04Admin lists
Change managementCC8.1A.8.32BAI06Change samples
Backup and recoveryA1.2A.8.13DSS04Restore tests
Job monitoringCC7.1A.8.6DSS01Job logs

Indicative mapping for planning.

Where QULDEX fits

How QULDEX runs SOX ITGC testing from scoping to audit opinion

QULDEX is SOX ITGC testing and audit management software built from EGV Group's audit delivery, used by control owners, internal audit and the external auditors who rely on their work. Pick your role to see who does what.

For IT and business owners of SOX controls.

  1. ScopeAgree in-scope systemsSystem list linked to accounts
  2. EvidenceProvide populationsPopulations and samples per period
  3. ReviewsSign access reviewsRecurring review tasks
  4. TestFix exceptionsExceptions into CAPA
  5. VendorsMap SOC 1 CUECsSOC 1 register
  6. OpinionSupport year-endRoll-forward evidence
Without one systemWith QULDEX
Access reviews chased by emailRecurring review tasks with sign-off
Samples rebuilt every yearPopulations kept per period
SOC 1 gaps found at year-endCUECs mapped up front
SOX and SOC 2 tested twiceOne control set mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

SOX ITGC questions people ask

What are SOX ITGCs?

IT general controls over the systems that support financial reporting at US-listed companies. They cover access to programs and data, program changes, program development and computer operations, and auditors test them under PCAOB AS 2201.

Which ITGC areas do auditors test?

Mainly access (provisioning, removal, reviews, privileged access, segregation of duties), change management (authorisation, testing, approval, segregation) and computer operations (jobs, backups, incidents).

What is the difference between a significant deficiency and a material weakness?

A material weakness is a deficiency that creates a reasonable possibility of a material misstatement not being prevented or detected on time, and it must be disclosed. A significant deficiency is less severe but important enough to tell the audit committee.

Do SOC 1 reports help with SOX?

Yes. A SOC 1 Type II report on an outsourced provider lets auditors rely on its controls, provided you operate the complementary user entity controls (CUECs) it lists.

How often should user access reviews be done for SOX?

Quarterly is the most common practice for financially significant applications, though frequency depends on risk and your auditor's expectations.

Sources

References

  1. Sarbanes-Oxley Act of 2002, Sections 302 and 404. sec.gov
  2. PCAOB Auditing Standard AS 2201. pcaobus.org
  3. COSO Internal Control – Integrated Framework (2013). coso.org
  4. AICPA SOC 1 guide. aicpa-cima.com

Reviewed by

Swati Chaturvedi

Framework reviewer · QULDEX

Reviewed this page against SOX Sections 302 and 404, PCAOB AS 2201 and common ITGC testing practice.

Page history
  • : Page first built: ITGC control explorer, annual cycle, readiness check and crosswalk

Find your ITGC exceptions before the auditor does

Answer a short readiness check and get a gap summary by ITGC area. No sales call needed to see the result.

Schedule
Book a Demo