SOX ITGC evidence your external auditor won't kick back
IT General Controls underpin every financial statement assertion a public company makes. GRXForce's AI Evidence Agent keeps access, change, and operations evidence audit-ready across every quarter, drafting the workpaper as each control is tested, not just at year end.
What is SOX ITGC?
Section 404 of the Sarbanes-Oxley Act requires public companies to assess and report on internal controls over financial reporting. IT General Controls (ITGC) are the technology-layer controls, access management, change management, and IT operations, that financial applications and data depend on. External auditors test ITGCs every year as part of the broader internal controls audit, and weaknesses here can cascade into every financial application that relies on them.
What it takes, at a glance
- Access controls over financial systems: provisioning, review, and timely de-provisioning
- Change management controls proving changes to financial systems were authorized and tested
- IT operations controls: backups, job scheduling, and incident management for financial data
- Segregation of duties enforced and evidenced across financial system access
- Evidence retained and organized for the external auditor's ITGC walkthroughs and testing
Your readiness checklist
- Inventory every system in-scope for financial reporting and map its ITGC owner
- Implement quarterly access reviews with sign-off, not just annual
- Enforce segregation of duties and document where compensating controls apply
- Require and evidence approval + testing for every change to in-scope systems
- Organize evidence by control and quarter so auditor walkthroughs don't become a fire drill
How the timeline actually breaks down
Where most programs actually stand
An ITGC gap assessment checks whether access, change, and operations controls over in-scope financial systems would hold up under external audit testing today. GRXForce's assessment flags the gaps that most commonly become audit findings.
Check My SOX ITGC ReadinessWhat auditors actually expect to see
- Quarterly access review sign-offs for every in-scope financial system
- Change tickets showing request, approval, testing, and deployment for financial applications
- Segregation-of-duties matrices with any conflicts and their compensating controls documented
- Backup and job-scheduling logs for systems that process financial data
- Termination logs showing access removed within policy timelines
Where programs like yours lose time
- Running access reviews annually when quarterly is what most auditors expect
- Change tickets that show a deployment happened but not that it was approved first
- Segregation-of-duties conflicts nobody documented a compensating control for
- Treating ITGC as an IT-only problem instead of a joint IT and finance responsibility
- Scrambling to assemble a year of evidence in the weeks before the audit instead of collecting it continuously
How SOX ITGC compares
| Framework | Type | Typical timeline | Renewal | Best for |
|---|---|---|---|---|
| ISO 27001:2022 | Certification | 6-12 months typical | 3-year cycle + annual surveillance | Any company selling globally, especially outside the US |
| SOC 2 Type II | Attestation (CPA report) | 3-12 month observation window | Annual Type II report | SaaS companies selling to US enterprise customers |
| GDPR | Regulation | Ongoing, no certificate | Continuous | Anyone processing EU residents' personal data |
| DPDPA 2023 | Regulation | Ongoing, no certificate | Continuous | Anyone processing Indian residents' digital personal data |
| HITRUST CSF | Certification | 6-18 months by tier | 1-2 year cycle by tier | Healthcare and health-tech handling PHI |
| NIST CSF | Voluntary framework | Ongoing, self-assessed | Continuous | US federal contractors and critical infrastructure |
| PCI DSS | Industry mandate | 3-6 months typical | Annual (ROC or SAQ) | Anyone storing, processing or transmitting card data |
| SOX ITGC | Regulatory (internal controls) | Ongoing, tested annually | Annual audit cycle | US public companies and their auditors |
| HIPAA | Regulation | Ongoing, no certificate | Continuous | US healthcare providers, payers and business associates |
Run it yourself, or hand us the programme
See exactly how GRXForce runs a SOX ITGC control test: the AI Evidence Agent discovers and reviews the evidence and drafts the workpaper, you make the final call.
See It Run in the Audit Engine →Frequently asked
Does SOX ITGC apply to private companies?
SOX itself applies to US public companies, but private companies preparing for an IPO, or that are subsidiaries of a public parent, often need to build ITGC evidence well ahead of listing.
How is ITGC different from a SOC 2 report?
ITGC specifically supports the financial statement audit and is tested by your external auditor as part of the SOX 404 assessment; SOC 2 is a separate attestation aimed at customers. The underlying access and change controls overlap substantially, which GRXForce cross-maps.
What's the biggest source of ITGC audit findings?
Access management, stale accounts, missing quarterly reviews, and segregation-of-duties conflicts without documented compensating controls account for most findings we see.
Also covered: ISO 27001:2022 SOC 2 Type II GDPR DPDPA 2023 HITRUST CSF NIST CSF PCI DSS HIPAA
Find My Gaps
3 minutes. No sales pitch. Get a preliminary SOX ITGC readiness score.