Skip to main content
FaizZab

Audit support

SOX ITGC Control Design & Testing Readiness

Prepare IT general controls to withstand SOX testing over the full reporting period.

The business problem

Why organizations bring this to us

ITGC deficiencies rarely come from missing controls. They come from a control that operated eleven times out of twelve, an access review with an incomplete population, or a change approved verbally and documented afterwards. Under SOX testing, those become deficiencies that can aggregate into something the audit committee has to discuss.

FaizZab prepares ITGCs to be tested: design that addresses the risk, populations that are complete and reconcilable, evidence produced at the time, and deficiency remediation that is verified rather than asserted.

Who this is for

  • Organizations within a SOX reporting environment preparing for ITGC testing.
  • Companies that received ITGC deficiencies in a prior cycle.
  • Businesses entering SOX scope for the first time following listing or acquisition.
  • Internal control functions needing IT-specific control design and evidence support.

Service scope

Engagement scope

Focused on the ITGC domains that carry the majority of deficiencies, prepared for testing over the full reporting period.

Logical access

Control design and evidence for user provisioning, modification, removal and periodic recertification across in-scope financially relevant systems.

Privileged access

Control over elevated and administrative access, including justification, approval, monitoring and periodic review with evidence of action taken.

Change management

Authorization, testing and approval controls across the complete change population, with defined handling for emergency changes.

IT operations

Job scheduling, batch processing, backup and recovery controls relevant to the integrity of financial reporting data.

Control design

Assess whether each ITGC as designed actually addresses the risk it is mapped to, and redesign where it does not.

Control testing readiness

Prepare populations, evidence and control owners so that testing by internal audit or external auditors proceeds without exceptions caused by preparation.

Evidence

Define the evidence standard per control - what artefact, produced by whom, when, retained where - so records exist for the whole period.

Remediation

Remediate identified deficiencies, establish the corrected control operating cleanly, and verify closure with evidence.

Methodology

The FaizZab approach

  1. Review scope and design

    Confirm in-scope systems and assess ITGC design against the risks they address.

  2. Establish populations

    Define and reconcile complete populations for access and change testing.

  3. Set evidence standards

    Define the evidence each control must produce and embed it into operation.

  4. Dry-run testing

    Test controls as an auditor would, before the auditor does.

  5. Remediate and verify

    Close deficiencies and verify a clean operating run.

What you receive

Key deliverables

  • ITGC scope and system relevance analysis
  • Control design assessment and redesign recommendations
  • Complete, reconciled population definitions for access and change
  • Evidence standard per control
  • Dry-run testing results with identified exceptions
  • Deficiency remediation plan and verified closure evidence

Outcome

ITGCs that are designed correctly, evidenced consistently and ready to be tested.

Commercial value

Why this service matters

Deficiencies aggregate

Individually minor ITGC deficiencies can combine into a significant issue. Preventing them is materially cheaper than explaining them.

Populations are the weak point

Incomplete populations undermine otherwise sound testing and are a frequent cause of exceptions.

Smoother external audit

Controls prepared for testing reduce audit effort, cost and management time.

Questions

Common questions

Do you sign off on internal control over financial reporting?

No. Management makes that assessment and external auditors form their own opinion. FaizZab supports control design, evidence and readiness.

Can you work alongside our external auditors?

Yes. We support management in preparing controls, populations and evidence, while independence between preparation and audit is preserved.

Related

Related services

View all services
Audit supportAVAILABLE NOW

IT Audit

Independent IT audit covering IT general controls, access controls, change management and IT operations, with structured evidence testing, findings and tracked remediation.

Explore this service
Audit supportAVAILABLE NOW

Internal Audit

Internal audit programme design and delivery - audit universe and planning, fieldwork, evidence, findings, corrective action and reporting, for management systems and business processes.

Explore this service
Attestation preparationAVAILABLE NOW

SOC 2 Type II Readiness

Preparation for a SOC 2 Type II examination - operating effectiveness programme, evidence calendar, recurring control execution, exception and deviation management, access and change evidence, and auditor evidence-pack preparation.

Explore this service
AdvisoryAVAILABLE NOW

GRC Advisory

Advisory support to design and integrate the GRC operating model - governance framework, compliance architecture, risk and control integration, obligation management, management reporting and evidence governance.

Explore this service

Important

FaizZab provides control design, readiness and remediation support. This service does not constitute a statutory audit, an opinion on internal control over financial reporting, or any form of statutory auditor engagement, and does not imply statutory auditor status.

Ready to move from intention to implementation?

Tell us your obligation, your timeline and where you are today. We will confirm whether this is the right engagement for you.