Skip to main content

/ Sarbanes-Oxley · management testing

Independent SOX ITGC testing in Australia.

SOX ITGC testing assesses whether the technology controls supporting internal control over financial reporting are suitably designed and operated effectively. Aegentra performs independent or co-sourced management testing for Australian entities, with traceable workpapers, evidence-led conclusions and findings ready for review.

Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Direct answer

What is SOX ITGC testing?

It is risk-based testing of the IT general controls that support financially relevant systems and automated controls. The work considers control design, then tests whether the control operated consistently across the period using evidence stronger than inquiry alone.

For Australian subsidiaries, this usually connects the local ERP, identity platform, financial interfaces and relevant service providers to a US parent’s ICFR programme. The parent’s materiality, risk assessment and control framework determine scope; a generic checklist does not.

/ Delivery team

Who will deliver your SOX ITGC testing?

The testing scope identifies the accountable lead, assigned testing responsibilities, reviewer responsibilities and the systems and periods covered.

ResponsibilityTesting accountability
Assigned roleEngagement lead and assigned tester
How it is confirmedThe people performing the work, their responsibilities and the agreed review trail are recorded before testing.
ResponsibilitySpecialist contribution
Assigned roleSystem or control specialist, where required
How it is confirmedThe specialist function is tied to the systems and controls in the agreed scope.
ResponsibilityReporting boundary
Assigned roleManagement and the external auditor retain their responsibilities
How it is confirmedAegentra provides management-side testing and does not issue the Section 404(b) audit opinion.

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

The people assigned to your engagement—and the experience and qualification evidence relevant to their roles—are confirmed in your proposal before work begins.

The external auditor independently decides whether and how much to use work performed by management, internal audit or other testing providers.

What we test

Four ITGC domains. Scoped to financial-reporting risk.

Control names vary between groups. We test the risk the control addresses, the system and population it covers, and the evidence its operation leaves behind. Redundant controls are not added just to inflate a matrix.

Access to programs and data

We test how access is approved, provisioned, reviewed and removed across financially relevant systems.

Joiner, mover and leaver records · privileged-access logs · user access reviews · segregation-of-duties analysis

Program change

We trace production changes from request and approval through testing, migration and post-implementation evidence.

Change tickets · approvals · test results · deployment records · emergency-change reviews

Program development

We assess in-period implementations and material system changes that affect financial reporting.

Project governance · data migration reconciliations · user acceptance · go-live approvals · access separation

Computer operations

We test whether scheduled processing, failures, backups and incidents are monitored and resolved as designed.

Job-monitoring logs · exception tickets · backup results · restore tests · incident records

The workpaper standard

A conclusion another reviewer can reconstruct.

A testing result without its population, procedure and evidence trail is an opinion. Each workpaper connects the control objective to the exact work performed and the conclusion reached.

Illustrative format only — this is not a client result and does not contain fabricated testing metrics.

Illustrative workpaper

Control test record

Review-ready structure
Control and objective
The exact control, frequency, owner and ICFR risk it addresses.
Population and selection
The complete population, its source, the selection method and the items tested.
Procedure performed
Inquiry, observation, inspection or re-performance — written so another reviewer can follow it.
Evidence examined
Named records, configurations, reports and approvals, including how report completeness and accuracy were considered.
Exceptions and conclusion
What differed from the control design, the evidence for that conclusion and the resulting deficiency assessment.
Review trail
Tester, reviewer, dates, review notes and closure status in one traceable record.

Testing method

Design, operation and evidence are separate questions.

The nature, timing and extent of testing are adjusted to the control risk. A high-risk automated control and a low-risk manual review should not receive identical procedures simply because both appear once in a matrix.

Design effectiveness

Would the control, if performed by someone with the right authority and competence, prevent or detect the relevant financial-reporting risk?

Operating effectiveness

Did the control operate as designed, by the right person, with enough consistent evidence across the period tested?

Evidence strength

Inquiry is combined with observation, inspection or re-performance. Inquiry alone is not used to conclude that a control operated effectively.

Testing rhythm

Interim first. Roll-forward to the reporting date.

Earlier testing produces a useful remediation window. It does not remove the need to consider the remaining period, changes in the control and the strength of evidence already obtained.

Scope and align

Start with the parent programme and the financial-reporting risk.

We align systems, controls, periods, populations and evidence expectations with group internal audit or management before testing begins.

Interim fieldwork

Test early enough to leave a real remediation window.

Walkthroughs and interim samples identify design gaps and operating exceptions while a control can still be corrected and re-performed.

Roll-forward

Cover the period between interim testing and the reporting date.

We assess changes, remaining-period evidence and the result of earlier testing to determine the additional roll-forward work required.

Report and close

Make every conclusion reviewable and every action owned.

Findings are discussed with accountable management, mapped to evidence and followed through remediation or formal acceptance.

Responsibility and boundary

Management tests. The external auditor decides what they can use.

PartyOwnsBoundary
ManagementThe ICFR framework, control operation, evidence and the Section 404(a) assessment.Management remains accountable even when testing is co-sourced or outsourced.
AegentraManagement-side ITGC testing: scope alignment, walkthroughs, evidence testing, workpapers and findings.We do not issue the Section 404(b) audit opinion and do not promise external-auditor reliance.
External auditorThe integrated audit and any Section 404(b) opinion, where applicable.The external auditor independently decides whether and how much to use the work of others.

What you receive

A complete testing file, not a findings slide.

  • Agreed scope, control list, testing period and evidence request
  • A traceable workpaper for every control tested
  • Design and operating-effectiveness conclusions
  • Exceptions and findings mapped to the relevant control and evidence
  • Management-ready findings register and remediation priorities
  • Roll-forward and re-performance records where included in scope

Who this is for

The testing deadline is local, even when the programme is global.

  • An Australian entity is inside a US-listed parent’s SOX scope
  • Group internal audit needs local or specialist testing capacity
  • A pre-IPO programme needs management testing before its first reporting cycle
  • A previous ITGC finding needs independent re-performance
  • Control owners cannot provide sufficiently objective testing of their own work

Need the controls designed or remediated first? That is a separate SOX ITGC readiness engagement. We separate implementation from testing where objectivity would otherwise be impaired.

Service facts

Scope before fee. Evidence before conclusion.

The control population, systems, period and testing model are agreed before fieldwork. That creates a fixed, reviewable scope and avoids an hourly engagement expanding around undefined evidence requests.

What this service is
Independent or co-sourced management testing supporting the Section 404(a) assessment
What it is not
A Section 404(b) audit opinion — that is issued by a PCAOB-registered public accounting firm
Framework
Sarbanes-Oxley Act Sections 302 and 404; ITGCs over financial reporting systems
Who it is for
Australian subsidiaries of US-listed parents, pre-IPO groups, and SEC registrants
Domains tested
Access to programs and data, program change, program development, computer operations
Engagement models
Independent testing, co-sourced internal audit, mock ITGC audit, deficiency remediation
Testing approach
Design and operating effectiveness, sampled across the full period
Deliverables
Scope and test plan, control workpapers, exceptions, conclusions, findings and remediation priorities
Timing
Interim testing plus year-end roll-forward
Fee
Fixed fee agreed after a scoping call
Delivery
Remote-first, Australia-wide; onsite available

Primary sources

What this page relies on.

Official sources reviewed 14 August 2026. Engagement scope must still be aligned with your parent programme and external auditor.

Frequently asked questions

Clear answers before the scope call.

Scope the testing

Send the control matrix. We will map the testing effort.

Bring the parent testing template, in-scope systems, reporting date and any previous findings. We will confirm the management-testing boundary, delivery model and fixed fee before fieldwork begins.

Fixed scope and fee · agreed before fieldwork

Book a scope review