Skip to main content

SOX ITGC readiness for Australian entities

A US parent's filing obligation lands on your IT team as a control matrix nobody here wrote. We build the IT general controls behind it — access, change, development and operations — inside your own systems, and evidence them across the whole period so the auditor's testing has something to land on.

SOX is not Australian law. It still reaches you.

The Sarbanes-Oxley Act is United States federal law, and it arrives in Australia through ownership rather than jurisdiction. Your Australian entity is in scope when it is a subsidiary of a US-listed parent or SEC registrant and is material to the group’s consolidated financial statements, when you are preparing for a Nasdaq or NYSE listing, or when you are a foreign private issuer with US-listed ADRs. In each case the group’s obligation becomes your control matrix, usually with a deadline attached, and the external auditor tests the Australian systems as part of the group audit.

Sections 302 and 404 — what each one actually requires

Section 302 is a per-filing certification: the CEO and CFO personally certify, in every quarterly (Form 10-Q) and annual (Form 10-K) filing, that the financial statements are accurate and that they have designed and evaluated the disclosure controls behind them. Section 404 is an annual assessment of the control system itself. Section 404(a) requires management to assess and formally report on the effectiveness of internal control over financial reporting; Section 404(b) requires the company’s external auditor to independently attest to that assessment. Aegentra delivers readiness supporting the 404(a) assessment. Aegentra is not a PCAOB-registered firm and does not perform the 404(b) attestation.

The four ITGC domains we build

IT general controls sit underneath every automated control and every calculation inside a financially-significant application. If they fail, the auditor cannot rely on anything above them, and testing escalates from a sample to substantive work across the population. Four domains carry the weight. Access to programs and data covers provisioning and deprovisioning, periodic user access reviews, privileged and emergency access, and segregation of duties — it generates more findings than the other three combined. Program change covers whether changes to financial systems were requested, tested and approved before production, and whether a developer could deploy their own code. Program development covers implementations and migrations that touched a financial system during the period. Computer operations covers job scheduling and failure handling, backup and restoration, and incident management.

How a readiness engagement runs

Four phases, fixed scope and fixed price agreed after a scoping call. We start from the group SOX program office’s control matrix and materiality thresholds rather than a generic template, and produce an agreed list of in-scope systems and the controls each one carries. Gap assessment tests every in-scope control the way the external auditor will — design first, then whether it actually operated — and returns a gap register rated by how likely each gap is to become a deficiency. Remediation configures the controls inside your own Microsoft 365 tenant and financial systems. Then evidence: a control that works today is worthless if you cannot show it worked in March, so we set up capture through Aeges before the auditor asks for a sample.

SOX vs ISO 27001 vs SOC 2

These three are routinely confused, and scoping one as though it were another is the most expensive mistake in this area. The control work overlaps on access, change and operations, so mature ISO 27001 or SOC 2 evidence gives you a genuine head start — but SOX scopes tightly to the systems that touch the numbers and tests to financial-audit standards, which is a higher evidentiary bar than most ISMS internal audits apply.

What drives itSOX: US securities law · ISO 27001: voluntary certification · SOC 2: customer due diligence
Who tests itSOX: PCAOB-registered audit firm · ISO 27001: JAS-ANZ-accredited body · SOC 2: licensed CPA firm
ScopeSOX: systems touching the financials · ISO 27001: the whole ISMS you define · SOC 2: one service and its criteria
CadenceSOX: annual with interim testing · ISO 27001: three-year cycle plus surveillance · SOC 2: annual Type II period
You end up withSOX: a management assertion · ISO 27001: a certificate · SOC 2: an attestation report

Already built the controls and need someone independent to test them? That is SOX ITGC testing, a separate engagement — we never test controls we built. We also deliver ISO 27001 implementation and SOC 2 readiness separately, and map the control overlap so shared evidence is built once rather than three times. For background on how SOX reaches Australian subsidiaries, read SOX compliance in Australia.