Skip to main content

SOX compliance in Australia

By the Aegentra Security Team — NV1-cleared ISO 27001 practitioners · Published 25 July 2026

Australia has no Sarbanes-Oxley Act — yet Australian finance and IT teams are asked for SOX evidence every year. This guide explains how the obligation actually reaches an Australian entity, which IT controls get tested, and how SOX differs from the ISO 27001 and SOC 2 programs you may already run.

SOX applies to Australian companies through their US-listed parent. If your parent files with the SEC and your Australian entity is material to consolidated financial reporting, your IT general controls (ITGC) are in scope for the parent’s Section 404 assessment and are tested by its external auditor. Australia has no local SOX equivalent — the obligation flows down by contract and group policy, not by Australian law. In practice that means access, change and IT-operations controls over the systems that touch the numbers must be documented, operating, and evidenced every year.

Does SOX apply to Australian companies?

Directly, no. The Sarbanes-Oxley Act of 2002 is United States federal law. It binds issuers with securities registered on US exchanges and the auditors who examine them. There is no Australian equivalent — the Corporations Act imposes directors’ duties and financial-reporting obligations, and ASIC enforces them, but nothing in Australian law requires the Section 404 internal-control assessment that SOX demands.

Indirectly, constantly. Consolidated financial statements are exactly that — consolidated. When a US-listed parent asserts that its internal control over financial reporting is effective, the assertion covers the entities that are material to those statements, including Australian ones. The parent’s external auditor then tests controls at those entities. What arrives in your inbox is not a law but a group control matrix, a testing calendar, and a request list — and the consequence of failing it is a deficiency reported up to a US audit committee. Your obligation is defined by the parent’s scoping decisions, not by an Australian statute you can read, which is why the first conversation in any SOX program is with the parent’s SOX program office rather than your own IT team.

Who inherits the obligation in Australia

Four situations account for most Australian SOX exposure. The trigger is always a relationship with a US-listed entity — as a subsidiary, as an acquirer, as a listing candidate, or as a service provider.

The four ITGC domains an auditor tests

SOX splits into business-process controls (owned by finance) and IT general controls (owned by IT). ITGC is where technology teams live, and it reduces to four domains. Every one of them is tested by sampling: the auditor picks specific users, changes, or dates and asks you to prove the control operated for that item.

ITGC domainWhat the auditor tests
Access to programs and dataUser provisioning and de-provisioning, privileged access, periodic access reviews, segregation of duties, password and MFA configuration
Program change managementChange requests authorised, tested and approved before production; separation of development from production; emergency-change handling
Program developmentNew systems and major implementations follow a documented SDLC, with data-conversion and go-live approvals evidenced
Computer operationsJob scheduling and monitoring, incident handling, backup and restore testing, and third-party/cloud provider oversight

A first-year SOX ITGC program, step by step

  1. Confirm scope with the parent. Materiality is set at group level. Agree with the parent’s SOX PMO which of your entities, processes and systems are in scope before you build anything — scoping the wrong systems is the most expensive mistake in a first-year program.
  2. Map financial systems and their dependencies. Identify the applications that record, process or report financial transactions, then the infrastructure underneath them — identity provider, databases, hosting, integrations, and any outsourced provider that touches the data.
  3. Document the ITGC control set. Write the control descriptions the auditor will test against: who approves access, how changes reach production, how jobs are monitored, how backups are proven. Descriptions must match what actually happens, not the aspiration.
  4. Remediate the gaps. Typical first-year findings are the same everywhere: shared admin accounts, no periodic access review, developers with production write access, changes deployed without recorded approval, no evidence that backups restore.
  5. Evidence continuously, not in audit week. Auditors sample across the whole period. Controls that only operated in the month before fieldwork fail. Evidence collection has to run all year — this is where a live evidence engine pays for itself.
  6. Walk the auditor through it. Walkthroughs, sample selections, and exception handling. Deficiencies are graded — control deficiency, significant deficiency, or material weakness — and only the last is publicly disclosed, so early remediation matters.

This is exactly the sequence we run in a SOX ITGC readiness engagement for Australian subsidiaries and pre-IPO groups.

SOX vs ISO 27001 vs SOC 2

These three get conflated, and treating one as a substitute for another is a fast way to fail an audit. The controls overlap heavily — access, change and operations appear in all three — so a mature ISO 27001 or SOC 2 program gives you a real head start, and evidence can be reused wherever it is valid. But the objective, the scope and the testing bar are different in each.

SOX ITGCISO 27001SOC 2
StatusMandatory under US lawVoluntary certificationVoluntary attestation
ObjectiveReliable financial reportingConfidentiality, integrity, availabilitySecurity of a service
ScopeFinancial systems onlyWhole ISMS you defineThe service and its criteria
Who testsExternal financial auditor (PCAOB-registered)Accredited certification bodyLicensed CPA firm
CycleAnnuallyThree-year cycle with surveillanceAnnual report period
OutputManagement assertion + auditor opinionCertificateRestricted-use report

If you hold ISO 27001 already, the efficient play is to map your Annex A controls to the ITGC matrix, reuse the evidence that genuinely covers a SOX control, and treat the remainder as net-new work. We run that mapping as the opening step of a SOX ITGC readiness engagement, and we build the ISMS itself under ISO 27001 consulting and implementation. If your buyers are asking for SOC 2 rather than an ISO certificate, that is a separate readiness program with its own criteria.

Where Australian entities usually fail

First-year findings are remarkably consistent across Australian subsidiaries, and almost none of them are exotic. They are the ordinary consequences of a small IT team that has never been sampled by a financial auditor.

Frequently asked questions

Does SOX apply to Australian companies?

Not directly. The Sarbanes-Oxley Act is US federal law and binds companies listed on US exchanges. It reaches Australian companies through the group: if your parent is US-listed and your Australian entity is material to consolidated financial reporting, your controls form part of the parent’s Section 404 assessment and are tested by its external auditor. Australia has no local SOX statute — the obligation arrives via group policy and intercompany agreements, not the Corporations Act.

What is ITGC and why does it matter for SOX?

IT general controls are the controls over the IT environment that financial applications depend on — access to programs and data, program change management, program development, and computer operations. If ITGC is unreliable, the auditor cannot rely on any automated control or system-generated report inside the financial process, so the whole audit becomes substantive and expensive. That is why ITGC failures cascade.

Is SOX the same as SOC 2?

No, and conflating them is a common and costly error. SOX is mandatory US law about the reliability of financial reporting, scoped narrowly to financial systems, and tested annually by your external financial auditor. SOC 2 is a voluntary AICPA attestation about the security of a service, driven by customer demand, and issued by a CPA firm to reassure your buyers. Different objective, different scope, different audience — many groups need both.

Does ISO 27001 certification satisfy SOX?

No, but it helps considerably. Access control, change management, operations and vendor management appear in both frameworks, so a mature ISMS typically covers a large share of the ITGC control set and gives you evidence habits that transfer. What does not transfer is scoping and testing: SOX scope is set by financial materiality, and the evidence bar is a financial-audit standard. The ITGC still have to be scoped, remediated and evidenced specifically for SOX.

When does a pre-IPO company need to be SOX ready?

Sooner than most expect. Underwriters and diligence teams ask about internal control readiness before the listing, and newly public companies face management’s assessment obligations quickly after — with only limited transitional relief depending on filer status. Practically, companies targeting a US listing start the ITGC program a year or more ahead so the first assessment is not also the first time controls have operated.

What is a material weakness?

The most serious grade of deficiency: a control deficiency, or combination of them, such that there is a reasonable possibility a material misstatement of the financial statements would not be prevented or detected on a timely basis. Material weaknesses are disclosed publicly by the parent, which is why groups invest heavily in closing significant deficiencies before year-end.

Who can help with SOX in Australia?

The parent’s external auditor cannot build the controls it will test — that independence line is absolute. Australian entities typically engage a separate firm to run readiness and remediation. Aegentra delivers SOX ITGC readiness for Australian subsidiaries and pre-IPO groups: scoping with the parent’s PMO, control design and remediation in your Microsoft 365 and cloud stack, and continuous evidence collection through the Aeges risk engine.

SOX request list landed on your desk? We scope with your parent’s SOX program office, remediate the ITGC gaps in your own stack, and evidence every control across the whole period — see SOX ITGC readiness. More field notes are on the Aegentra Insights hub.