What is SOX and what are ITGCs?
The Sarbanes-Oxley Act (SOX) was passed by the US Congress in 2002 after the Enron and WorldCom accounting scandals. Its Section 404 requires management to assess and confirm annually the effectiveness of internal control over financial reporting (ICFR), with an independent auditor — for larger companies — issuing its own opinion on it. Section 302 adds personal CEO and CFO accountability for the accuracy of reports, and auditors are overseen by the PCAOB.
Because financial data is created and processed in IT systems, the reliability of financial statements depends on controls over those systems. ITGCs (IT General Controls) are the foundation: general controls over the IT environment that automated application controls (for example three-way invoice matching) and system-generated reports rely on. If ITGCs are ineffective — for example a developer can single-handedly change production code — the auditor cannot rely on any automated control operating in that system.
Who is it for?
SOX applies to all companies listed on US exchanges (NYSE, Nasdaq) and registered with the SEC — including foreign private issuers and, in practice, their significant subsidiaries worldwide. A Polish or European subsidiary of a US-listed group often has to maintain ITGCs locally because its systems feed the group’s consolidated financial statements.
The requirements also reach private companies indirectly: businesses preparing for a US IPO implement SOX ahead of time, and service providers (SaaS, IT outsourcing, payroll, hosting) serving SOX-regulated customers are asked for SOC 1 / ISAE 3402 reports, in which an independent auditor examines the provider’s controls relevant to customers’ financial reporting. Solid ITGCs are therefore also a sales asset for B2B vendors targeting listed companies.
The four ITGC domains
ITGCs are traditionally grouped into four domains covering every layer of financially relevant systems: application, database, operating system and infrastructure. The scope is set by the "in-scope" systems — those that create, process or store data flowing into the financial statements.
- Access to programs and data — approval-based access provisioning and revocation, periodic access reviews, privileged account control, authentication and MFA, segregation of duties (SoD).
- Change management — every production change tested and approved before deployment, separated environments, version control, a supervised emergency change path.
- Program development — a project methodology with gates, user acceptance testing (UAT), data migration control with reconciliation, formal go-live approval.
- IT operations — backups with monitoring and restore testing, oversight of batch jobs and interfaces, incident, vulnerability and patch management, business continuity.
- The common denominator: every control must leave evidence (a ticket, a report, a dated approval) that the auditor can examine on a sample spanning the whole year.
What does an ITGC audit look like?
ITGCs carry no certificate — they are tested every year as part of the financial statement audit. The auditor’s IT team first confirms the scope (which systems feed the statements), then tests controls in two steps: design and implementation, and operating effectiveness on samples spanning the audit period — for example 25 random production changes or new accounts, demanding the full evidence trail each time.
Exceptions are classified by severity: from a plain deficiency, through a significant deficiency reported to the audit committee, up to a material weakness — publicly disclosed in the annual report and typically damaging investor confidence. Ineffective ITGCs force the auditor to expand costly substantive testing: data the systems cannot be trusted to protect must be verified manually. That is why companies test ITGCs internally during the year and fix deviations before the external auditor finds them.
How long does it take and what does it cost?
Building a working ITGC program from scratch typically takes 6 to 12 months: scoping the systems, writing the risk and control matrix (RCM), implementing missing processes (access reviews, a formal change path, backup monitoring) and — most importantly — letting the controls run for several months so evidence exists for the auditor to test. Companies preparing for an IPO usually start at least a year before listing.
The cost depends on the number of in-scope systems, the degree of automation and the maturity of IT processes. It comprises IT team time to operate controls and produce evidence, optional advisory support, tooling (ITSM, identity management, evidence automation) and audit fees. The biggest savings come from limiting the number of in-scope systems, automating evidence collection and keeping data tidy — an ITGC audit where evidence is available on demand can cost half the team-hours of one firefought ad hoc.
How does Guardiso help?
Guardiso organises your ITGC program — from the control matrix to evidence ready for auditor sampling — and keeps controls operating all year, not just before the audit.
- ITGCs across all four domains (access, change, development, operations) seeded automatically when you enable the standard — with descriptions, statuses and owners.
- A maturity self-assessment that surfaces control gaps before the financial auditor finds them.
- Evidence collected per control: access reviews, change approvals, backup reports — in one place, with history spanning the whole audit period.
- Recurring tasks that police periodic controls (quarterly access reviews, restore tests, privileged account reviews).
- A risk register linked to controls — a natural foundation for the risk and control matrix (RCM).
- An auditor portal: the IT audit team gets controlled access to evidence without files being emailed around.
- Cross-mapping to ISO 27001, SOC 2 and other standards — the same access, change and operations controls satisfy the requirements of multiple frameworks at once.
