The short answer

Public company executives are accountable for IT general controls under Sarbanes-Oxley Section 404, yet many face audits without clarity on what is tested, what constitutes a deficiency, or who owns the outcome. This article explains what auditors examine, what delays sign-off, and how vCISO leadership provides the executive ownership needed to close this gap.

Public company executives face a recurring challenge: accountability for Sarbanes-Oxley IT general controls without a clear owner, sequence, or way of measuring progress. The result is delayed audit sign-off, material weaknesses disclosed in public filings, and friction between finance, IT, and external auditors. This article explains what auditors test, what constitutes a deficiency, and what adequate ownership looks like.

1What IT General Controls Are and Why They Matter

IT general controls are the foundational security and operational controls that support the reliability of financial reporting systems. Under Section 404 of the Sarbanes-Oxley Act, public companies must maintain effective internal control over financial reporting. When financial data is created, processed, or stored in IT systems, the controls that protect those systems become part of the internal control framework.

Auditors test IT general controls to determine whether they can rely on automated controls and application controls. If IT general controls are ineffective, auditors cannot rely on any automated process, forcing manual testing, expanding audit scope, and delaying sign-off. In severe cases, deficiencies are disclosed as material weaknesses in public filings, a signal to investors that financial data may be unreliable.

2What Auditors Test: The Five ITGC Domains

Auditors evaluate IT general controls across five domains. Each domain addresses a category of risk that could compromise the integrity of financial reporting systems.

Access Controls

Auditors test whether access to financial systems is restricted to authorized users, whether access is granted based on role, and whether access is removed when employment ends. They review user access reports, examine requests and approvals for access changes, and test whether privileged access is monitored. Deficiencies include former employees retaining access, excessive permissions granted to finance users, or lack of periodic access reviews.

Change Management

Change management controls ensure that modifications to financial systems are authorized, tested, and documented. Auditors review change tickets, test whether approvals are obtained before deployment, and verify that changes are tested in a separate environment. A deficiency exists when changes are deployed without approval, when testing is not documented, or when developers have access to production systems.

Computer Operations

Computer operations controls address system availability, backup integrity, and job scheduling. Auditors test whether backups are performed, whether backups are tested for recoverability, and whether batch jobs execute successfully. They review logs, test restoration procedures, and examine incident records. Deficiencies include failed batch jobs not investigated, backups not tested, or no documented disaster recovery plan.

Program Development and Acquisition

This domain covers the development and acquisition of new systems and major system enhancements. Auditors test whether requirements are documented, whether user acceptance testing is performed, and whether systems are approved before use. Deficiencies include systems deployed without business approval, inadequate testing documentation, or no separation between development and production environments.

System and Network Security

Security controls protect financial systems from unauthorized access and cyber threats. Auditors test whether firewalls are in place, whether systems are patched, whether intrusion detection is configured, and whether security incidents are investigated. They review vulnerability scan reports, patch logs, and incident response documentation. Deficiencies include unpatched systems, no vulnerability scanning, or security alerts not investigated.

3What Constitutes a Deficiency and What Delays Sign-Off

A deficiency exists when a control is not designed effectively or is not operating as designed. Auditors classify deficiencies by severity: a control deficiency is a shortcoming that does not rise to the level of a significant deficiency. A significant deficiency is important enough to merit attention by those charged with governance. A material weakness is a deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.

Material weaknesses must be disclosed in public filings. Significant deficiencies are reported to the audit committee but are not public. Even control deficiencies delay audit sign-off because auditors must expand testing when they cannot rely on IT general controls.

Common deficiencies that delay sign-off include: inadequate segregation of duties, where IT personnel have both development and production access; lack of evidence, where controls are performed but not documented; untimely execution, where access reviews occur but not quarterly as required; and scope gaps, where controls apply to some systems but not all systems in scope.

4Who Is Accountable and What Adequate Ownership Looks Like

The chief financial officer is ultimately accountable for internal control over financial reporting, including IT general controls. However, CFOs do not design, implement, or test these controls. IT teams execute the controls, but IT leadership typically reports to the COO or CEO, not the CFO. Internal audit tests the controls but does not own remediation. The result is accountability without authority and distributed ownership without a single point of coordination.

Adequate ownership requires an executive who understands both the compliance requirement and the technical substance, who can translate audit findings into actionable remediation, and who reports to the CFO or audit committee on readiness. This role sets the control objectives, defines what evidence is required, coordinates across IT and finance, and ensures that controls are tested before auditors arrive.

In organizations without a chief information security officer, or where the CISO reports outside the finance organization, virtual CISO leadership provides this executive ownership. The vCISO establishes the governance framework, defines the control environment, prepares the evidence package, and coordinates with external auditors.

5How IT General Controls Relate to Security Policy, Standards, and Awareness

IT general controls are the operational expression of security policy. A policy states the requirement; an IT general control is the mechanism that enforces it. For example, an access control policy may require that access be granted based on role and removed within 24 hours of termination. The IT general control is the documented process for requesting, approving, provisioning, and deprovisioning access, supported by logs and quarterly reviews.

Standards define how controls are implemented. A change management standard specifies the approval workflow, the environments required, the testing documentation, and the approval thresholds. Awareness ensures that IT personnel understand their responsibilities. Without documented policy and standards, auditors cannot determine whether a control is designed effectively. Without awareness, controls are inconsistently applied.

Sarbanes-Oxley does not prescribe specific policies or frameworks. It requires that controls be effective. However, auditors expect to see documented policies, standards that operationalize those policies, and evidence that personnel are trained. Organizations that lack this documentation face design deficiencies before auditors test a single control.

6Practical Next Steps for Public Company Leadership

CFOs and controllers preparing for Sarbanes-Oxley audits should take the following steps:

  • Confirm scope with external auditors. Identify which systems are in scope, which IT general control domains apply, and what evidence auditors will request. Document this in a scoping memorandum shared with IT leadership.
  • Assign executive ownership. Designate an individual accountable for IT general control readiness. This person should report to the CFO or audit committee and coordinate across IT, finance, and internal audit.
  • Document control objectives and procedures. For each IT general control domain, document the control objective, the procedure, the frequency, the responsible party, and the evidence retained. Use a control matrix reviewed quarterly.
  • Perform a readiness assessment. Test whether controls are operating as designed before auditors arrive. Identify deficiencies, remediate them, and document the remediation. Internal audit or an external advisor can perform this assessment.
  • Establish a continuous monitoring process. IT general controls are not annual events. Access reviews, change approvals, backup testing, and vulnerability scanning occur throughout the year. Implement a process to track completion and retain evidence.

Organizations that lack internal resources to establish this framework, or that face audit findings without a clear remediation path, benefit from interim executive leadership. A virtual CISO provides the strategy, governance, and audit coordination that closes the gap between accountability and execution, ensuring that IT general controls are ready when auditors test them.

If your organization is preparing for a Sarbanes-Oxley audit and lacks clarity on control ownership, evidence requirements, or remediation priorities, a confidential consultation can clarify your options. Heights Consulting Group provides virtual CISO leadership to public companies and pre-IPO organizations establishing IT general controls for the first time. To discuss your specific situation, contact the firm through the inquiry form on this site.

Related service: Security Policy, Standards and Awareness

Policies written to match how your organization actually operates, with the standards that make them workable and the training that makes them understood.

Read about Security Policy, Standards and Awareness