Practitioner Track · Outline + Hands-on Labs

ITGC + SOC 2 Type II — Audit Practitioner Track

IT General Controls for SOX, SOC 1, and SOC 2 audits

IT General Controls (ITGC) are the backbone of every financial-audit assurance — SOX, SOC 1, SOC 2. This outline covers all 4 ITGC domains, testing methodology, evidence collection, and the SOC 2 Type II difference. Hands-on labs live in the 22-Day GRC Simulation.

5 chapters· ~9 hours reading· 4 matching hands-on labs

Course outline

Chapter 1

ITGC in SOX, SOC 1, and SOC 2 Audits

Why ITGC is different from application controls, and why financial auditors care about it. Comparing SOX (public-company financials), SOC 1 (financial-reporting relevance for user entities), and SOC 2 (Trust Services Criteria).

Key concepts

  • ITGC = controls over IT infrastructure that support financial-reporting systems
  • SOX 404: public-company compliance — external auditor tests ITGC annually
  • SOC 1 = for user auditors of your customer (financial-relevance)
  • SOC 2 = trust criteria (security, availability, processing integrity, confidentiality, privacy)
  • Type I = point-in-time; Type II = over an audit period (min 6 months)

Chapter 2

Access Management + Segregation of Duties

The most tested ITGC domain. Provisioning, deprovisioning, periodic access reviews, privileged access, and the SoD matrix.

Key concepts

  • Provisioning: request → approval → grant → notify
  • Deprovisioning: MUST happen within defined SLA (usually 24h) of role change
  • Access review: quarterly cadence for financial systems, semi-annual for others
  • SoD conflicts: cannot post + approve, cannot create + pay, cannot request + approve
  • Privileged access: PAM tools, session recording, break-glass procedures

Chapter 3

Change Management + IT Operations Controls

Change management (standard vs emergency vs pre-approved), backup + restore, incident management, batch job monitoring, and the evidence chain.

Key concepts

  • Standard change: ticket → approval → test → deploy → post-check
  • Emergency change: pre-approved playbook + post-hoc notification
  • Change vs incident distinction — audit failures often confuse these
  • Backup: RPO / RTO / test frequency / offsite storage
  • Restoration testing: MUST happen at least annually

Chapter 4

Design vs Operating Effectiveness Testing

The two-part test in every ITGC audit. Design: is the control appropriate for the risk? Operating: does it work every time? Evidence collection strategies, sample sizes, deficiency categorisation.

Key concepts

  • Design effectiveness: reviewed against control objective + risk
  • Operating effectiveness: sample-based testing across audit period
  • Sample sizes: SOC 2 usually 15-25 per control for population < 250
  • Deficiency: minor, significant, material weakness
  • Deviation: a single control failure — must analyse root cause

Chapter 5

SOC 2 Type II Readiness Workflow

The step-by-step path to a SOC 2 Type II report: scoping, gap assessment, remediation, audit period, evidence collection, auditor selection, and the report itself.

Key concepts

  • Trust Services Criteria: Security (mandatory), plus optional Availability, Processing Integrity, Confidentiality, Privacy
  • Audit period: minimum 6 months, typically 12 months
  • Bridge letter: covers gap between last report and current date
  • Common issues: incomplete access reviews, missing vendor risk assessments, undocumented emergency changes
  • Report distribution: NDA required, auditor's report tied to a specific date range

Ready for the workshop?

The 22-Day GRC Practical Simulation is where you actually produce the deliverables — scope statements, SoAs, control tests, evidence packs. Full access is included with the 22-Day Program enrolment or Cohort 2026 candidature.