ITGC & SOX Advisory Services
Practical IT controls support to strengthen your SOX environment, resolve control issues, and reduce the burden on your internal teams.
IT general controls are critical to the systems supporting financial reporting, but maintaining them can become complicated as systems, access, processes, and audit requirements change.
Schmid CPA helps organizations design, assess, document, test, and improve ITGCs while working with control owners, management, internal audit, and other stakeholders to build a control environment that is both supportable and sustainable.
Access Management & Security
- Controls over user provisioning, access changes, terminations, privileged access, authentication, and other security-related processes.
User Access Reviews
- Design and improvement of periodic access reviews, including populations, reviewer responsibilities, evidence, exception identification, and follow-up.
Change Management
- Controls over system changes, approvals, testing, production migration, emergency changes, and segregation of responsibilities.
IT Operations
- Controls surrounding scheduled jobs, interfaces, backups, incident management, system monitoring, and other relevant IT operations processes.
Automated Controls & Key Reports
- Support with automated controls, system-generated reports, interfaces, configurations, and information used in the performance of controls.
SOX Documentation & Testing
- Walkthroughs, risk and control documentation, testing procedures, evidence requirements, deficiency evaluation support, and coordination with internal and external audit teams.
A control can address the right risk and still create problems if control owners do not understand what is required or if the evidence does not clearly demonstrate what was performed.
Schmid CPA helps organizations look beyond the control description to how the control actually operates.
That includes understanding who performs the control, what information they use, what they review, how exceptions are identified, what evidence is retained, and whether the process can operate consistently throughout the year.
The result should be a control that addresses the risk without creating unnecessary work every time it is tested.
Support may be appropriate when:
★ User access is not removed timely after termination
★ Privileged or administrative access is broader than intended
★ User access reviews are difficult to complete or evidence
★ Access populations are incomplete or difficult to validate
★ Segregation-of-duties conflicts require review or remediation
★ System changes lack consistent approval or testing evidence
★ Developers or administrators have inappropriate production access
★ Emergency changes are not consistently documented
★ Scheduled jobs or interfaces require stronger monitoring
★ Automated controls are not sufficiently understood or documented
★ System-generated reports require stronger control considerations
★ Control evidence does not demonstrate what the reviewer actually performed
★ Control owners interpret the same control differently
★ New systems need to be incorporated into the SOX environment
★ Internal or external audit identifies a control deficiency
Passing the next test is not necessarily the same thing as fixing the problem.
When an IT control deficiency is identified, Schmid CPA can help evaluate the underlying cause, determine whether the issue relates to control design, execution, evidence, system configuration, or process ownership, and develop practical remediation steps.
Depending on the issue, remediation may involve redesigning the control, changing the underlying process, improving system configuration, strengthening documentation, clarifying responsibilities, or introducing automation.
The objective is to address the underlying risk while creating a process that can continue operating after the immediate audit issue is closed.
SOX environments rarely remain static.
New ERP systems, acquisitions, organizational changes, new applications, changes in control ownership, and evolving audit expectations can all affect the IT control environment.
Schmid CPA can help organizations assess how these changes affect existing controls, identify new control requirements, update documentation, and prepare control owners for the resulting audit and compliance responsibilities.
IT controls often sit between several groups—IT, finance, internal audit, compliance, system owners, and external auditors.
Schmid CPA can work alongside these teams to help translate technical system processes into clear control requirements, resolve documentation and evidence issues, and keep remediation or testing efforts moving forward.
Support can range from an individual ITGC issue to broader assistance across the organization’s SOX IT controls environment.
Need help strengthening your ITGC or SOX environment?
Schedule a consultation to discuss your systems, controls, audit requirements, and current challenges.
