Chapter 1
ITGC in SOX, SOC 1, and SOC 2 Audits
Why ITGC is different from application controls, and why financial auditors care about it. Comparing SOX (public-company financials), SOC 1 (financial-reporting relevance for user entities), and SOC 2 (Trust Services Criteria).
Key concepts
- ITGC = controls over IT infrastructure that support financial-reporting systems
- SOX 404: public-company compliance — external auditor tests ITGC annually
- SOC 1 = for user auditors of your customer (financial-relevance)
- SOC 2 = trust criteria (security, availability, processing integrity, confidentiality, privacy)
- Type I = point-in-time; Type II = over an audit period (min 6 months)
Hands-on practice
Day 18: ITGC evidence pack for SOC 1 audit →