SOX, without the spreadsheets.
Keep IT general controls audit-ready for financial reporting.
What is SOX?
The Sarbanes-Oxley Act requires US public companies to assess their internal control over financial reporting under Section 404. IT general controls — who can access financial systems, how changes reach production and how operations are run — are a core part of that assessment.
Who needs it
- US-listed companies and those preparing for an IPO
- Subsidiaries of US-listed groups
- Vendors whose systems are in their customers’ SOX scope
What SOX looks at
Access to programs and data
Provisioning, periodic access reviews, privileged access and segregation of duties.
Program change
Changes to financial systems are authorised, tested and approved before release.
Computer operations
Job scheduling, backups and incident handling for in-scope systems.
How Beviso gets you there
- ITGCs with automated evidence from identity providers, code hosting and ticketing
- Access review evidence with reviewer and timestamp
- Change evidence from pull requests and change tickets
9 SOX controls, ready on day one
These controls are loaded when you enable SOX, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
ITGC.AC.1
Logical Access — Provisioning and Deprovisioning
User access to financial systems is provisioned and deprovisioned following documented approval processes.
Evidence from
- Okta
- Google Workspace
- Microsoft Azure
- Salesforce
- AWS
- Rippling
ITGC.AC.2
Privileged Access Review
Privileged access to financial systems and infrastructure is reviewed periodically.
Evidence from
- Okta
- AWS
- GitHub
- Microsoft Azure
- HashiCorp Vault
ITGC.AC.3
Authentication Controls
Strong authentication including MFA is enforced for access to financial systems.
Evidence from
- Okta
- Duo
- Microsoft Azure
- Google Workspace
- 1Password
ITGC.CM.1
Change Management — Authorisation
Changes to financial systems follow a formal, authorised change management process.
Evidence from
- GitHub
- GitLab
- Jira
- ServiceNow
- Azure DevOps
ITGC.CM.2
Segregation of Duties in Change Process
Developers cannot deploy their own changes to production financial systems.
Evidence from
- GitHub
- GitLab
- Azure DevOps
ITGC.OPS.1
Job Scheduling and Monitoring
Automated financial processing jobs are scheduled, monitored, and exceptions are investigated.
Evidence from
- Datadog
- PagerDuty
- Splunk
- Grafana
ITGC.OPS.2
Backup and Recovery
Financial data is backed up and recovery procedures are tested.
Evidence from
- PagerDuty
- Datadog
- AWS
ITGC.AL.1
Audit Logging
System activity logs for financial systems are generated, retained, and reviewed.
Evidence from
- Datadog
- AWS
- Splunk
- Salesforce
- Okta
- HashiCorp Vault
ITGC.SEC.1
Vulnerability Management
Vulnerabilities in financial systems are identified and remediated on a risk-based timeline.
Evidence from
- Snyk
- Wiz
- Rapid7
- CrowdStrike
- SentinelOne
SOX questions
- We are not public. Why would SOX matter?
- If a public company relies on your service for financial reporting, its auditors may test your controls or ask for a SOC 1 report instead.
Often run alongside SOX
Start your SOX programme today.
Free while Beviso is in beta. No credit card required.
Get started free