AegentraNew Zealand

Govern / New Zealand

SOX and ITGC readiness

Aegentra helps teams prepare IT general controls and supporting evidence for a SOX-related programme. For New Zealand operations within a US-listed or pre-IPO group, scope should follow the group’s financial-reporting risks and auditor requirements.

On this page

Start with the boundary

Define the work that is needed.

For finance, IT and programme teams establishing controls or resolving readiness gaps before the agreed assurance process.

  • Relevant systems and interfaces supporting financial reporting
  • Access administration and privileged-access controls
  • Change-management and IT-operations controls
  • Control ownership, evidence design and remediation planning

Keep the responsibilities distinct

Readiness consulting is not an external audit opinion or a determination that SOX applies to every NZ company. Management and the appointed auditors retain their responsibilities; legal applicability requires appropriate advice.

What the engagement can produce

Useful outputs, agreed in advance.

  • A scoped ITGC readiness and gap assessment
  • A control/evidence responsibility map
  • Prioritised remediation actions
  • Preparation for agreed testing and auditor discussions

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A group uses an application for financial reporting but cannot reproduce a complete user-access population. The problem is not just an incomplete review checklist: the source, completeness and ownership of the population must be established.

Questions for the first discussion

  • Which financial-reporting processes and systems are in scope?
  • What criteria and testing expectations has the group agreed?
  • Which controls require design work and which already operate?

Before you begin

Your questions, answered.

Is SOX readiness the same as independent ITGC testing?

No. Readiness helps design and improve controls and evidence. Testing evaluates defined controls against agreed criteria and a period or date. We distinguish those responsibilities and assess conflicts before assigning an independent testing scope.

What can be included in sox and itgc readiness?

The agreed scope can include relevant systems and interfaces supporting financial reporting; access administration and privileged-access controls; change-management and IT-operations controls; control ownership, evidence design and remediation planning. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which financial-reporting processes and systems are in scope? What criteria and testing expectations has the group agreed? Which controls require design work and which already operate? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.