SOX ITGC
SOX IT General Controls (ITGC) Checklist
An ITGC checklist for access, change, and IT operations supporting SOX 404 / ICFR.
- Estimated time
- Ongoing / 3–6 Months to Mature
- Audience
- Public-Company IT, Finance, and Internal Audit
- Last updated
Operational reference for ITGCs. External auditors opine on ICFR; this is not a PCAOB audit.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: In-Scope Systems
Phase 2: Access
Phase 3: Change & Ops
Phase 4: Testing
FAQ
ITGC vs application controls?+–
ITGCs are access, change, and operations. Application controls are business-process automations in the app.
Does SOC 2 replace SOX ITGC?+–
No. SOX is about ICFR. SOC 2 is Trust Services. Overlap exists but audiences differ.
What is IPE?+–
Information produced by the entity—reports used in controls that must be complete and accurate.
Who tests?+–
Management, internal audit, and external auditors each have a role.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer