Frameworks

SOX IT general controls, tested all year.

ITGCs fail quietly between tests. TruOps checks the controls behind financial reporting continuously and keeps the evidence dated.

SOX ITGC · readinessevidence current
SOX ITGC · coverage by ITGC domain
Access to programs & datapartial · 63%
Program changessatisfied · 96%
Program developmentsatisfied · 95%
Computer operationssatisfied · 93%
The same work also counts toward
COBIT43% · partials shown
SOC 277% · partials shown
NIST CSF51% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The Sarbanes-Oxley Act of 2002 requires U.S. public companies to maintain and assess internal control over financial reporting (Section 404). IT general controls (ITGCs) are the IT controls that support it, commonly grouped into access to programs and data, program changes, program development, and computer operations. Many companies use the COSO Internal Control framework and, for IT, COBIT.

This page is for you if
  • Access reviews and change tickets are still sampled in a scramble each quarter
  • ITGCs passed last year and silently drifted
  • External audit wants evidence across the period, not a week of screenshots
Law
Sarbanes-Oxley Act of 2002, Section 404
Applies to
U.S. public companies
ITGC domains
Access · change · development · operations
Common frameworks
COSO · COBIT

The ITGC domains

DomainTypical controls
Access to programs and dataProvisioning, periodic access reviews, privileged access, terminations
Program changesChange approval, testing, segregation of duties, emergency changes
Program developmentSystem development lifecycle controls for new systems
Computer operationsJob scheduling, backups, incident handling

The actual challenge

SOX ITGCs fail between tests. The classic findings (joiner-mover-leaver, privileged access, unapproved changes) are already sitting in Entra ID, Okta, and the pipeline, unread.

  • IUC/IPE debates eat the testing window because evidence was assembled late.
  • The same access control is tested for SOX and for SOC 2, twice.
  • Management review is a slide of green dots.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts SOX ITGC from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.
Quarterly access-review workbooksExported, filtered, signed, filed. Drift between quarters is invisible.Identity connectors check access and MFA on a cadence. Exceptions become findings before testing, not after.

How TruOps helps with SOX ITGC

Pick SOX ITGC as your anchor, or map it to the framework you already run. TruOps keeps SOX ITGC's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your SOX ITGC assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

Access reviews and change approvals are the classic SOX findings. With identity and code tools connected, TruOps checks them on a schedule and surfaces exceptions before testing, not after.

If this is your situation

Connect Entra ID or Okta in a demo and pick one ITGC. TruOps will show a timestamped check instead of a screenshot, and how that same control counts toward SOC 2.

How TruOps helps

Anchor or map
Run SOX ITGC as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your SOX ITGC assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

What are IT general controls?

Controls over the IT environment that support the reliability of financial systems: access, program changes, program development, and computer operations.

Can TruOps replace SOX testing by auditors?

No. External auditors still test and opine. TruOps keeps controls monitored and evidence organized for them.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.