Access to programs and data
We test how access is approved, provisioned, reviewed and removed across financially relevant systems.
Joiner, mover and leaver records · privileged-access logs · user access reviews · segregation-of-duties analysis
/ Sarbanes-Oxley · management testing
SOX ITGC testing assesses whether the technology controls supporting internal control over financial reporting are suitably designed and operated effectively. Aegentra performs independent or co-sourced management testing for Australian entities, with traceable workpapers, evidence-led conclusions and findings ready for review.
Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.
Direct answer
It is risk-based testing of the IT general controls that support financially relevant systems and automated controls. The work considers control design, then tests whether the control operated consistently across the period using evidence stronger than inquiry alone.
For Australian subsidiaries, this usually connects the local ERP, identity platform, financial interfaces and relevant service providers to a US parent’s ICFR programme. The parent’s materiality, risk assessment and control framework determine scope; a generic checklist does not.
/ Delivery team
The testing scope identifies the accountable lead, assigned testing responsibilities, reviewer responsibilities and the systems and periods covered.
Responsibility
Assigned role
How it is confirmed
Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.
Qualifications, professional credentials and formal training held across Aegentra’s delivery team.
Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.
NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.
Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.
The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.
The external auditor independently decides whether and how much to use work performed by management, internal audit or other testing providers.
What we test
Control names vary between groups. We test the risk the control addresses, the system and population it covers, and the evidence its operation leaves behind. Redundant controls are not added just to inflate a matrix.
We test how access is approved, provisioned, reviewed and removed across financially relevant systems.
Joiner, mover and leaver records · privileged-access logs · user access reviews · segregation-of-duties analysis
We trace production changes from request and approval through testing, migration and post-implementation evidence.
Change tickets · approvals · test results · deployment records · emergency-change reviews
We assess in-period implementations and material system changes that affect financial reporting.
Project governance · data migration reconciliations · user acceptance · go-live approvals · access separation
We test whether scheduled processing, failures, backups and incidents are monitored and resolved as designed.
Job-monitoring logs · exception tickets · backup results · restore tests · incident records
The workpaper standard
A testing result without its population, procedure and evidence trail is an opinion. Each workpaper connects the control objective to the exact work performed and the conclusion reached.
Illustrative format only — this is not a client result and does not contain fabricated testing metrics.
Illustrative workpaper
Control test record
Testing method
The nature, timing and extent of testing are adjusted to the control risk. A high-risk automated control and a low-risk manual review should not receive identical procedures simply because both appear once in a matrix.
Would the control, if performed by someone with the right authority and competence, prevent or detect the relevant financial-reporting risk?
Did the control operate as designed, by the right person, with enough consistent evidence across the period tested?
Inquiry is combined with observation, inspection or re-performance. Inquiry alone is not used to conclude that a control operated effectively.
Testing rhythm
Earlier testing produces a useful remediation window. It does not remove the need to consider the remaining period, changes in the control and the strength of evidence already obtained.
Scope and align
We align systems, controls, periods, populations and evidence expectations with group internal audit or management before testing begins.
Interim fieldwork
Walkthroughs and interim samples identify design gaps and operating exceptions while a control can still be corrected and re-performed.
Roll-forward
We assess changes, remaining-period evidence and the result of earlier testing to determine the additional roll-forward work required.
Report and close
Findings are discussed with accountable management, mapped to evidence and followed through remediation or formal acceptance.
Responsibility and boundary
| Party | Owns | Boundary |
|---|---|---|
| Management | The ICFR framework, control operation, evidence and the Section 404(a) assessment. | Management remains accountable even when testing is co-sourced or outsourced. |
| Aegentra | Management-side ITGC testing: scope alignment, walkthroughs, evidence testing, workpapers and findings. | We do not issue the Section 404(b) audit opinion and do not promise external-auditor reliance. |
| External auditor | The integrated audit and any Section 404(b) opinion, where applicable. | The external auditor independently decides whether and how much to use the work of others. |
What you receive
Who this is for
Need the controls designed or remediated first? That is a separate SOX ITGC readiness engagement. We separate implementation from testing where objectivity would otherwise be impaired.
Service facts
The control population, systems, period and testing model are agreed before fieldwork. That creates a fixed, reviewable scope and avoids an hourly engagement expanding around undefined evidence requests.
Primary sources
Official sources reviewed 14 August 2026. Engagement scope must still be aligned with your parent programme and external auditor.
Control selection, design and operating-effectiveness testing, evidence strength, interim timing and roll-forward procedures.
Competence, objectivity and the external auditor’s evaluation of work performed by internal audit or others.
Management responsibility and the annual assessment of internal control over financial reporting.
Frequently asked questions
Scope the testing
Bring the parent testing template, in-scope systems, reporting date and any previous findings. We will confirm the management-testing boundary, delivery model and fixed fee before fieldwork begins.
Fixed scope and fee · agreed before fieldwork
Book a scope review