SOX compliance for ITGC and §302/§404 readiness

Updated

SOX compliance work in IT centers on IT general controls (ITGC): the access, change, and operations controls behind Sarbanes-Oxley §302 and §404. Teams collect evidence that these controls operate, test them, evaluate any deficiencies, and produce the workpapers an external auditor reviews.

A full SOX program spans more than testing: defining reporting periods, scoping and materiality, a control register mapped to COSO 2013, sampling, validation of information produced by the entity (IPE), deficiency evaluation and aggregation, segregation-of-duties monitoring, reliance on service organizations via SOC 1 reports and complementary user-entity controls (CUECs), the §302 certification workflow, and auditor-ready workpapers.

What SOX requires from your IT organization

The Sarbanes-Oxley Act of 2002 makes executives personally accountable for financial reporting. Two sections drive nearly all of the IT work: §302, under which the CEO and CFO certify each quarter that disclosure controls are effective, and §404, which requires an annual management assessment of internal control over financial reporting (ICFR) — audited for accelerated filers.

Because financial reports are produced by systems, auditors test the IT general controls that keep those systems trustworthy. ITGCs are conventionally grouped into four domains: access to programs and data, program changes, program development, and computer operations. If ITGCs fail, the auditor cannot rely on application controls or system-generated reports, and substantive testing expands — which is why ITGC deficiencies are so expensive.

  • Access: user provisioning and deprovisioning, privileged access, periodic access reviews, segregation of duties.
  • Change: authorization, testing, and approval of changes to financially relevant systems, with the change-maker separated from the approver.
  • Operations: job scheduling and monitoring, incident handling, backup and recovery.
  • Information produced by the entity (IPE): any report used in a control must itself be shown complete and accurate.

Why SOX programs outgrow spreadsheets

A first-year program can survive in spreadsheets. It stops scaling the moment the in-scope system count grows: every quarter you re-collect user lists, change tickets, and job logs by hand; every screenshot has to be tied to the period it covers; and by the time the auditor samples, the person who pulled the evidence may be gone. The failure mode is rarely a missing control — it is evidence that cannot be traced, reproduced, or tied to a period.

This is why teams eventually move to purpose-built tooling. Good SOX software replaces the re-collection cycle with continuous, read-only evidence feeds, keeps an append-only record of who accepted what and when, and pre-assembles the workpapers — so the audit becomes a review of standing evidence instead of a quarterly scramble. The value is in the audit trail and reproducibility, not in the checklist.

Evidence vs estimates: what auditors actually test

The core discipline in any SOX program is that a control is either evidenced or it is a gap — there is no partial credit for intent. Some compliance dashboards will still display a readiness percentage when the underlying evidence is missing, but that number fails exactly where it matters, because an auditor tests the evidence, not the score. Treat any control without accepted, traceable evidence as unmet, and report anything you genuinely cannot measure as unmeasured rather than estimating around it.

What auditors actually test is provenance and reliability: where each artifact came from, the period it covers, who reviewed it, and whether it can be reproduced. Strong programs hold evidence with a clear chain of custody, re-verify it on a schedule, and can hand the auditor a bundle they can independently check. None of this substitutes for the external audit opinion — that remains the auditor's independent work — it simply makes reaching that opinion faster and less expensive.

How to evaluate SOX software

Whatever platform you choose, evaluate it against the failure modes that actually burn SOX teams:

  • Can it show where each piece of evidence came from, when, and who accepted it? (Traceability is what auditors test first.)
  • Does it handle IPE explicitly, or does every system-generated report become a finding?
  • Does deficiency evaluation support aggregation, or are deficiencies siloed per control?
  • Is tester independence and segregation of duties tracked structurally, or by convention?
  • Does it export workpapers in a form your audit firm will actually accept?
  • Does it tell you what it cannot measure — or does every dashboard read green?

Frequently asked questions

What is the difference between SOX §302 and §404?

§302 is the quarterly certification by the CEO and CFO that disclosure controls and procedures are effective. §404 is the annual management assessment of internal control over financial reporting, which for accelerated filers is also audited by the external auditor. §302 is a recurring attestation workflow; §404 is a full assessment program.

What are ITGCs in SOX compliance?

IT general controls are the controls over the systems that produce financial data, conventionally grouped into access to programs and data, program changes, program development, and computer operations. Auditors rely on ITGCs to trust application controls and system-generated reports.

Does SOX compliance software replace our external auditor?

No. Software prepares and organizes management's side of the program — evidence, testing, evaluation, certification records. The external audit opinion remains the auditor's independent work; good software makes that audit faster and less expensive, not unnecessary.

What is IPE and why does it matter in SOX?

Information produced by the entity (IPE) is any report or query output used within a control — an access listing, a change log, an exception report. Because the control relies on it, auditors require evidence that the IPE itself is complete and accurate; unvalidated IPE is a common source of findings.

Do SOX and SOC 2 evidence requirements overlap?

Substantially. SOX ITGC and the SOC 2 security criteria both cover access, change management, and operations, so much of the underlying evidence — access reviews, change approvals, provisioning records — is relevant to both. Many teams collect that evidence once and reuse it across the controls it legitimately supports.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.