IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

SOX 404 — IT general controls

25 scoped preparation workpapers and 50 evidence review actions

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
SOX-ITGC-SYSTEMSWINDOWS / WIN-INVENTORY-COVERAGE-001Host inventory can support reconciliation of financially relevant systems. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-ACCESS-LEAVEADSEC / AD-LIFECYCLE-001Stale enabled accounts can identify lifecycle exceptions; HR departure reconciliation remains manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-ACCESS-PRIVADSEC / AD-PRIV-001Directory privileged groups support review of scoped infrastructure administration. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-ACCESS-PRIVENTRA / ENTRA-ROLE-001Directory role assignments support review of scoped cloud administration. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-ACCESS-REVIEWENTRA / ENTRA-GUEST-001Enabled guest inventory supports access review where the tenant supports financial reporting. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-OPS-RECOVERYBACKUP / VEEAM-JOB-001Job status supports backup-operation review but does not prove restoration or financial-data completeness. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SOX-ITGC-OPS-RECOVERYBACKUP / VEEAM-REPO-001Repository observations support backup protection review; recovery testing remains manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Original ITAF workpapers for IT controls relevant to financial reporting. Management selects a suitable recognized ICFR framework and agrees financial scope with its auditor. This is not a bundled COSO/COBIT catalog, a complete ICFR assessment, or an audit opinion. Control design and sampling are risk-based, not a prescribed universal SOX checklist. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.