11 min read

SOX IT General Controls: A Complete Guide

A detailed guide to Sarbanes-Oxley IT general controls covering access management, change management, computer operations, and program development.

CISAPractice|

IT General Controls (ITGCs) are foundational to Sarbanes-Oxley (SOX) compliance. These controls ensure that technology supporting financial reporting operates reliably, securely, and as intended. For CISA professionals working in public companies or their service providers, mastering ITGC auditing is a core competency.

What Are IT General Controls?

ITGCs are controls that apply to all systems, applications, and data across an organization's IT environment. They create the foundation upon which application-level controls depend. If ITGCs are deficient, the reliability of application controls that depend on them cannot be assured, potentially leading to material weakness findings.

The Four ITGC Domains

Access to Programs and Data

Access controls ensure that only authorized individuals can access systems, applications, and data relevant to financial reporting. Key control activities include:

  • User Access Provisioning: Formal processes for granting access based on job requirements and appropriate approvals
  • User Access Modification: Timely updates to access rights when roles change
  • User Access Termination: Prompt removal of access when employees leave the organization or change roles
  • Periodic Access Reviews: Regular reviews of user access rights to verify continued appropriateness
  • Privileged Access Management: Enhanced controls over administrative and elevated access accounts
  • Authentication Controls: Password policies, multi-factor authentication, and session management

Program Change Management

Change management controls ensure that modifications to applications and systems are authorized, tested, and properly implemented. Key controls include:

  • Change Request and Approval: Formal change request processes with appropriate authorization
  • Testing and Validation: Testing in non-production environments before deployment to production
  • Segregation of Duties: Separation between developers and those who promote changes to production
  • Emergency Change Procedures: Defined processes for emergency changes with after-the-fact review and approval

Program Development

Program development controls ensure that new applications and significant system modifications are properly designed, developed, tested, and implemented. This includes project management oversight, requirements documentation, user acceptance testing, and data conversion validation.

Computer Operations

Operations controls ensure that systems operate reliably and that data is properly processed and stored. Key areas include:

  • Job Scheduling: Automated batch processing controls with monitoring for failures
  • Backup and Recovery: Regular data backups with tested restoration procedures
  • Incident Management: Processes for identifying, responding to, and resolving operational issues
  • Environmental Controls: Physical security, power management, and climate controls for computing facilities

Scoping ITGCs

Not all systems require ITGC testing. Scoping identifies the applications and infrastructure components that support financially significant processes. Start with financial statement assertions, identify supporting business processes, determine the applications used in those processes, and then identify the infrastructure (databases, operating systems, networks) supporting those applications.

Common ITGC Deficiencies

  • Excessive or inappropriate access privileges, particularly for terminated employees
  • Inadequate segregation of duties in the change management process
  • Missing or incomplete access reviews
  • Insufficient testing documentation for application changes
  • Shared or generic privileged accounts without adequate monitoring

Testing Approach

ITGC testing typically involves a combination of inquiry, observation, inspection of documentation, and reperformance. For Type II testing, auditors select samples from the audit period and verify that controls operated consistently. The sample size depends on the frequency of the control activity and the overall control environment.

Strong ITGC knowledge is essential for CISA professionals, particularly those working in financial services, public accounting, or any organization subject to SOX requirements. The principles apply broadly to IT control assurance across all regulatory frameworks.

Related Tags

Technical Deep DiveSOXIT General ControlsCompliance

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free