Regulation · US

SOX, without the spreadsheets.

Keep IT general controls audit-ready for financial reporting.

What is SOX?

The Sarbanes-Oxley Act requires US public companies to assess their internal control over financial reporting under Section 404. IT general controls — who can access financial systems, how changes reach production and how operations are run — are a core part of that assessment.

Who needs it

  • US-listed companies and those preparing for an IPO
  • Subsidiaries of US-listed groups
  • Vendors whose systems are in their customers’ SOX scope

What SOX looks at

Access to programs and data

Provisioning, periodic access reviews, privileged access and segregation of duties.

Program change

Changes to financial systems are authorised, tested and approved before release.

Computer operations

Job scheduling, backups and incident handling for in-scope systems.

How Beviso gets you there

  • ITGCs with automated evidence from identity providers, code hosting and ticketing
  • Access review evidence with reviewer and timestamp
  • Change evidence from pull requests and change tickets

9 SOX controls, ready on day one

These controls are loaded when you enable SOX, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

ITGC.AC.1

Logical Access — Provisioning and Deprovisioning

User access to financial systems is provisioned and deprovisioned following documented approval processes.

Evidence from

  • Okta
  • Google Workspace
  • Microsoft Azure
  • Salesforce
  • AWS
  • Rippling

ITGC.AC.2

Privileged Access Review

Privileged access to financial systems and infrastructure is reviewed periodically.

Evidence from

  • Okta
  • AWS
  • GitHub
  • Microsoft Azure
  • HashiCorp Vault

ITGC.AC.3

Authentication Controls

Strong authentication including MFA is enforced for access to financial systems.

Evidence from

  • Okta
  • Duo
  • Microsoft Azure
  • Google Workspace
  • 1Password

ITGC.CM.1

Change Management — Authorisation

Changes to financial systems follow a formal, authorised change management process.

Evidence from

  • GitHub
  • GitLab
  • Jira
  • ServiceNow
  • Azure DevOps

ITGC.CM.2

Segregation of Duties in Change Process

Developers cannot deploy their own changes to production financial systems.

Evidence from

  • GitHub
  • GitLab
  • Azure DevOps

ITGC.OPS.1

Job Scheduling and Monitoring

Automated financial processing jobs are scheduled, monitored, and exceptions are investigated.

Evidence from

  • Datadog
  • PagerDuty
  • Splunk
  • Grafana

ITGC.OPS.2

Backup and Recovery

Financial data is backed up and recovery procedures are tested.

Evidence from

  • PagerDuty
  • Datadog
  • AWS

ITGC.AL.1

Audit Logging

System activity logs for financial systems are generated, retained, and reviewed.

Evidence from

  • Datadog
  • AWS
  • Splunk
  • Salesforce
  • Okta
  • HashiCorp Vault

ITGC.SEC.1

Vulnerability Management

Vulnerabilities in financial systems are identified and remediated on a risk-based timeline.

Evidence from

  • Snyk
  • Wiz
  • Rapid7
  • CrowdStrike
  • SentinelOne

SOX questions

We are not public. Why would SOX matter?
If a public company relies on your service for financial reporting, its auditors may test your controls or ask for a SOC 1 report instead.

Start your SOX programme today.

Free while Beviso is in beta. No credit card required.

Get started free