AegentraNew Zealand

Internal audit / New Zealand

SOX ITGC testing

Aegentra provides scoped IT general controls testing for teams supporting a SOX programme. We agree criteria, populations, evidence and the testing period, then document results and exceptions for the responsible management and assurance stakeholders.

On this page

Start with the boundary

Define the work that is needed.

For internal-audit, finance and IT teams needing defined testing support across systems relevant to financial reporting.

  • Control criteria, period and system boundary
  • Population completeness and sampling approach
  • Access, change and IT-operations control testing
  • Exceptions, conclusions and agreed follow-up

Keep the responsibilities distinct

This service does not issue a statutory audit opinion or replace management’s assessment and the appointed external auditor’s work. Testing independence and any prior readiness involvement are assessed before assignment.

What the engagement can produce

Useful outputs, agreed in advance.

  • A testing plan and evidence request
  • Workpapers linking tests to criteria and evidence
  • A clearly reported exception and results register
  • Agreed follow-up or retesting scope

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A change-control test cannot rely only on tickets selected by the control owner. The population and selection basis need to be understood before concluding what the sample demonstrates.

Questions for the first discussion

  • Which controls and testing period have been agreed?
  • How will the evidence populations be produced and validated?
  • Who will evaluate exceptions and make the final assurance decisions?

Before you begin

Your questions, answered.

Will your work automatically be accepted by our external auditor?

No. The appointed auditor decides how it may use another party’s work under the applicable standards and circumstances. Agree scope, competence, documentation and independence expectations with the relevant stakeholders before testing begins.

What can be included in sox itgc testing?

The agreed scope can include control criteria, period and system boundary; population completeness and sampling approach; access, change and IT-operations control testing; exceptions, conclusions and agreed follow-up. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which controls and testing period have been agreed? How will the evidence populations be produced and validated? Who will evaluate exceptions and make the final assurance decisions? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.