IT General Controls Audits Getting it Right
Rigorous evaluation of Logical Access (IAM), Change Management (SDLC), Computer Operations (Backup & Batch Jobs), and Program Development under SOX Section 404, PCAOB standards, COBIT, and SSAE 18 SOC 1/2.
Request ITGC / SOX Audit
Receive audit scoping & sample matrix in 4 hours
6 Core Pillars of IT General Controls (ITGC) Auditing
Our certified CISA auditors and former Big-4 consultants evaluate IT governance, IAM, and change management to guarantee painless statutory audits.
Logical Access & IAM (AC)
Auditing user onboarding/offboarding workflows, quarterly user access reviews (UAR), Segregation of Duties (SoD) conflicts, and privileged superuser (PAM) session monitoring.
- User provisioning & timely de-provisioning
- Quarterly User Access Review (UAR) sign-offs
- Segregation of Duties (SoD) matrix checks
Change Management (CM)
Evaluating change authorization tickets (Jira/ServiceNow), environment segregation (Dev/Stage/Prod), peer code reviews, UAT approvals, and emergency change logs.
- Dev-to-Prod environment segregation
- Formal UAT & business owner sign-offs
- Emergency change retrospective audits
Computer Operations (CO)
Auditing automated database backups, quarterly disaster recovery (DR) restoration drills, batch job scheduling failure alerts, and incident escalation logs.
- Daily backup logs & immutable storage
- Disaster recovery restoration drill testing
- Critical batch job alerting & monitoring
Program Development (PD)
Validating new ERP/Core application implementations, data conversion integrity checks, reconciliation scripts, and legacy data archiving procedures.
- New system implementation controls
- Data conversion & migration reconciliation
- SDLC methodology security compliance
Third-Party SOC 1/2 Review
Analyzing vendor SSAE 18 SOC 1 Type II and SOC 2 reports (AWS, Salesforce, SAP), and auditing internal Complementary User Entity Controls (CUECs).
- Vendor SOC 1 Type II qualification checks
- Complementary User Entity Controls (CUEC)
- SaaS application access risk mapping
Audit Defense & Certification
Delivering complete Design of Controls (DoC) and Operating Effectiveness (OE) testing workpapers, deficiency remediation plans, and defending results before statutory auditors.
- PCAOB-compliant audit workpapers
- Big-4 external auditor liaison support
- Official ITGC Compliance Attestation
5-Stage ITGC & SOX 404 Audit Roadmap
Our certified CISA lead auditors follow a structured, evidence-based testing methodology aligned with PCAOB standards.
ICFR & ERP Infrastructure Mapping
Identifying all financially significant applications (SAP, Oracle, NetSuite), supporting databases, operating systems, and active directory domains in SOX scope.
Process Walkthroughs & RCM Alignment
Interviewing process owners, inspecting control narratives, and validating Risk and Control Matrices (RCM) to verify adequate control design.
Evidence Sampling & Ticket Validation
Executing statistical sample selections (25/45/60 rule) across user access requests, change tickets, backup logs, and validating supporting evidence.
Deficiency Scoring & Compensating Controls
Classifying findings as Control Deficiencies (CD), Significant Deficiencies (SD), or Material Weaknesses (MW) and assisting engineering teams with rapid remediation.
Board-Ready SAR & External Audit Defense
Delivering final ITGC testing workpapers, executive summaries for the Audit Committee, and defending results directly with your statutory financial auditors.
Frequently Asked Questions
Key details on ITGC domains, SOX 404 requirements, and sample testing rules.