By the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Published 25 July 2026
Australia has no Sarbanes-Oxley Act — yet Australian finance and IT teams are asked for SOX evidence every year. This guide explains how the obligation actually reaches an Australian entity, which IT controls get tested, and how SOX differs from the ISO 27001 and SOC 2 programs you may already run.
SOX applies to Australian companies through their US-listed parent. If your parent files with the SEC and your Australian entity is material to consolidated financial reporting, your IT general controls (ITGC) are in scope for the parent’s Section 404 assessment and are tested by its external auditor. Australia has no local SOX equivalent — the obligation flows down by contract and group policy, not by Australian law. In practice that means access, change and IT-operations controls over the systems that touch the numbers must be documented, operating, and evidenced every year.
Directly, no. The Sarbanes-Oxley Act of 2002 is United States federal law. It binds issuers with securities registered on US exchanges and the auditors who examine them. There is no Australian equivalent — the Corporations Act imposes directors’ duties and financial-reporting obligations, and ASIC enforces them, but nothing in Australian law requires the Section 404 internal-control assessment that SOX demands.
Indirectly, constantly. Consolidated financial statements are exactly that — consolidated. When a US-listed parent asserts that its internal control over financial reporting is effective, the assertion covers the entities that are material to those statements, including Australian ones. The parent’s external auditor then tests controls at those entities. What arrives in your inbox is not a law but a group control matrix, a testing calendar, and a request list — and the consequence of failing it is a deficiency reported up to a US audit committee. Your obligation is defined by the parent’s scoping decisions, not by an Australian statute you can read, which is why the first conversation in any SOX program is with the parent’s SOX program office rather than your own IT team.
Four situations account for most Australian SOX exposure. The trigger is always a relationship with a US-listed entity — as a subsidiary, as an acquirer, as a listing candidate, or as a service provider.
SOX splits into business-process controls (owned by finance) and IT general controls (owned by IT). ITGC is where technology teams live, and it reduces to four domains. Every one of them is tested by sampling: the auditor picks specific users, changes, or dates and asks you to prove the control operated for that item.
| ITGC domain | What the auditor tests |
|---|---|
| Access to programs and data | User provisioning and de-provisioning, privileged access, periodic access reviews, segregation of duties, password and MFA configuration |
| Program change management | Change requests authorised, tested and approved before production; separation of development from production; emergency-change handling |
| Program development | New systems and major implementations follow a documented SDLC, with data-conversion and go-live approvals evidenced |
| Computer operations | Job scheduling and monitoring, incident handling, backup and restore testing, and third-party/cloud provider oversight |
This is exactly the sequence we run in a SOX ITGC readiness engagement for Australian subsidiaries and pre-IPO groups.
These three get conflated, and treating one as a substitute for another is a fast way to fail an audit. The controls overlap heavily — access, change and operations appear in all three — so a mature ISO 27001 or SOC 2 program gives you a real head start, and evidence can be reused wherever it is valid. But the objective, the scope and the testing bar are different in each.
| SOX ITGC | ISO 27001 | SOC 2 | |
|---|---|---|---|
| Status | Mandatory under US law | Voluntary certification | Voluntary attestation |
| Objective | Reliable financial reporting | Confidentiality, integrity, availability | Security of a service |
| Scope | Financial systems only | Whole ISMS you define | The service and its criteria |
| Who tests | External financial auditor (PCAOB-registered) | Accredited certification body | Licensed CPA firm |
| Cycle | Annually | Three-year cycle with surveillance | Annual report period |
| Output | Management assertion + auditor opinion | Certificate | Restricted-use report |
If you hold ISO 27001 already, the efficient play is to map your Annex A controls to the ITGC matrix, reuse the evidence that genuinely covers a SOX control, and treat the remainder as net-new work. We run that mapping as the opening step of a SOX ITGC readiness engagement, and we build the ISMS itself under ISO 27001 consulting and implementation. If your buyers are asking for SOC 2 rather than an ISO certificate, that is a separate readiness program with its own criteria.
First-year findings are remarkably consistent across Australian subsidiaries, and almost none of them are exotic. They are the ordinary consequences of a small IT team that has never been sampled by a financial auditor.
Not directly. The Sarbanes-Oxley Act is US federal law and binds companies listed on US exchanges. It reaches Australian companies through the group: if your parent is US-listed and your Australian entity is material to consolidated financial reporting, your controls form part of the parent’s Section 404 assessment and are tested by its external auditor. Australia has no local SOX statute — the obligation arrives via group policy and intercompany agreements, not the Corporations Act.
IT general controls are the controls over the IT environment that financial applications depend on — access to programs and data, program change management, program development, and computer operations. If ITGC is unreliable, the auditor cannot rely on any automated control or system-generated report inside the financial process, so the whole audit becomes substantive and expensive. That is why ITGC failures cascade.
No, and conflating them is a common and costly error. SOX is mandatory US law about the reliability of financial reporting, scoped narrowly to financial systems, and tested annually by your external financial auditor. SOC 2 is a voluntary AICPA attestation about the security of a service, driven by customer demand, and issued by a CPA firm to reassure your buyers. Different objective, different scope, different audience — many groups need both.
No, but it helps considerably. Access control, change management, operations and vendor management appear in both frameworks, so a mature ISMS typically covers a large share of the ITGC control set and gives you evidence habits that transfer. What does not transfer is scoping and testing: SOX scope is set by financial materiality, and the evidence bar is a financial-audit standard. The ITGC still have to be scoped, remediated and evidenced specifically for SOX.
Sooner than most expect. Underwriters and diligence teams ask about internal control readiness before the listing, and newly public companies face management’s assessment obligations quickly after — with only limited transitional relief depending on filer status. Practically, companies targeting a US listing start the ITGC program a year or more ahead so the first assessment is not also the first time controls have operated.
The most serious grade of deficiency: a control deficiency, or combination of them, such that there is a reasonable possibility a material misstatement of the financial statements would not be prevented or detected on a timely basis. Material weaknesses are disclosed publicly by the parent, which is why groups invest heavily in closing significant deficiencies before year-end.
The parent’s external auditor cannot build the controls it will test — that independence line is absolute. Australian entities typically engage a separate firm to run readiness and remediation. Aegentra delivers SOX ITGC readiness for Australian subsidiaries and pre-IPO groups: scoping with the parent’s PMO, control design and remediation in your Microsoft 365 and cloud stack, and continuous evidence collection through the Aeges risk engine.
SOX request list landed on your desk? We scope with your parent’s SOX program office, remediate the ITGC gaps in your own stack, and evidence every control across the whole period — see SOX ITGC readiness. More field notes are on the Aegentra Insights hub.