SOX ITGC

SOX ITGC evidence your external auditor won't kick back

IT General Controls underpin every financial statement assertion a public company makes. GRXForce's AI Evidence Agent keeps access, change, and operations evidence audit-ready across every quarter, drafting the workpaper as each control is tested, not just at year end.

Overview

What is SOX ITGC?

Section 404 of the Sarbanes-Oxley Act requires public companies to assess and report on internal controls over financial reporting. IT General Controls (ITGC) are the technology-layer controls, access management, change management, and IT operations, that financial applications and data depend on. External auditors test ITGCs every year as part of the broader internal controls audit, and weaknesses here can cascade into every financial application that relies on them.

Requirements

What it takes, at a glance

  • Access controls over financial systems: provisioning, review, and timely de-provisioning
  • Change management controls proving changes to financial systems were authorized and tested
  • IT operations controls: backups, job scheduling, and incident management for financial data
  • Segregation of duties enforced and evidenced across financial system access
  • Evidence retained and organized for the external auditor's ITGC walkthroughs and testing
Checklist

Your readiness checklist

  • Inventory every system in-scope for financial reporting and map its ITGC owner
  • Implement quarterly access reviews with sign-off, not just annual
  • Enforce segregation of duties and document where compensating controls apply
  • Require and evidence approval + testing for every change to in-scope systems
  • Organize evidence by control and quarter so auditor walkthroughs don't become a fire drill
Implementation roadmap

How the timeline actually breaks down

Weeks 1-2ScopingIdentify every system that's in-scope for financial reporting and assign ITGC owners.
Weeks 3-6Control designBuild or formalize access, change, and operations controls for in-scope systems.
Ongoing quarterlyEvidence cadenceAccess reviews, change approvals, and operations evidence collected every quarter, not just at year end.
AnnualExternal audit supportOrganized evidence and control narratives ready for the auditor's ITGC walkthroughs.
Gap assessment

Where most programs actually stand

An ITGC gap assessment checks whether access, change, and operations controls over in-scope financial systems would hold up under external audit testing today. GRXForce's assessment flags the gaps that most commonly become audit findings.

Check My SOX ITGC Readiness
Evidence

What auditors actually expect to see

  • Quarterly access review sign-offs for every in-scope financial system
  • Change tickets showing request, approval, testing, and deployment for financial applications
  • Segregation-of-duties matrices with any conflicts and their compensating controls documented
  • Backup and job-scheduling logs for systems that process financial data
  • Termination logs showing access removed within policy timelines
Common mistakes

Where programs like yours lose time

  • Running access reviews annually when quarterly is what most auditors expect
  • Change tickets that show a deployment happened but not that it was approved first
  • Segregation-of-duties conflicts nobody documented a compensating control for
  • Treating ITGC as an IT-only problem instead of a joint IT and finance responsibility
  • Scrambling to assemble a year of evidence in the weeks before the audit instead of collecting it continuously
Compare frameworks

How SOX ITGC compares

FrameworkTypeTypical timelineRenewalBest for
ISO 27001:2022Certification6-12 months typical3-year cycle + annual surveillanceAny company selling globally, especially outside the US
SOC 2 Type IIAttestation (CPA report)3-12 month observation windowAnnual Type II reportSaaS companies selling to US enterprise customers
GDPRRegulationOngoing, no certificateContinuousAnyone processing EU residents' personal data
DPDPA 2023RegulationOngoing, no certificateContinuousAnyone processing Indian residents' digital personal data
HITRUST CSFCertification6-18 months by tier1-2 year cycle by tierHealthcare and health-tech handling PHI
NIST CSFVoluntary frameworkOngoing, self-assessedContinuousUS federal contractors and critical infrastructure
PCI DSSIndustry mandate3-6 months typicalAnnual (ROC or SAQ)Anyone storing, processing or transmitting card data
SOX ITGCRegulatory (internal controls)Ongoing, tested annuallyAnnual audit cycleUS public companies and their auditors
HIPAARegulationOngoing, no certificateContinuousUS healthcare providers, payers and business associates
Two ways to get there

Run it yourself, or hand us the programme

Run it yourself, the platform Controls pre-mapped to SOX ITGC, an AI Evidence Agent that discovers and reviews evidence and drafts the workpaper for every control, and a human sign-off trail your auditor can inspect line by line. Explore the platform →
Hand it over, managed services A named compliance lead runs your entire SOX ITGC programme: gap analysis, policies, evidence, auditor liaison, and surveillance after the milestone. Get it handled →

See exactly how GRXForce runs a SOX ITGC control test: the AI Evidence Agent discovers and reviews the evidence and drafts the workpaper, you make the final call.

See It Run in the Audit Engine →
FAQ

Frequently asked

Does SOX ITGC apply to private companies?

SOX itself applies to US public companies, but private companies preparing for an IPO, or that are subsidiaries of a public parent, often need to build ITGC evidence well ahead of listing.

How is ITGC different from a SOC 2 report?

ITGC specifically supports the financial statement audit and is tested by your external auditor as part of the SOX 404 assessment; SOC 2 is a separate attestation aimed at customers. The underlying access and change controls overlap substantially, which GRXForce cross-maps.

What's the biggest source of ITGC audit findings?

Access management, stale accounts, missing quarterly reviews, and segregation-of-duties conflicts without documented compensating controls account for most findings we see.

Also covered: ISO 27001:2022 SOC 2 Type II GDPR DPDPA 2023 HITRUST CSF NIST CSF PCI DSS HIPAA

Find My Gaps

3 minutes. No sales pitch. Get a preliminary SOX ITGC readiness score.