SOX ITGC control testing
IT general control testing across access, change and operations for in-scope financial applications.
Typically run by Internal Audit / SOX Compliance
Loading AuditFlow…
Finance
Banks, NBFCs, insurers, fintechs, payment processors and capital markets firms.
The job you're hiring this for
Evidencing ITGC and access controls for SOX or an RBI IS Audit, with quarterly access recertification that actually gets completed.
Every one carries weighted questions, auditor guidance and clause references — ready to run, or to edit into your own house standard.
IT general control testing across access, change and operations for in-scope financial applications.
Typically run by Internal Audit / SOX Compliance
Walks the twelve PCI DSS v4.0 requirements against the cardholder data environment, sized for an SAQ-D style review.
Typically run by Security / Compliance Lead
IS audit against the RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices for regulated entities.
Typically run by IS Auditor (CISA/DISA)
Branch-level controls covering cash, KYC documentation, account opening, dormant accounts and physical security.
Typically run by Internal Auditor / Concurrent Auditor
File-level review of customer identification, beneficial ownership, risk categorisation and periodic updation for a sample of accounts.
Typically run by Compliance Officer / Concurrent Auditor
Reviews scenario coverage, data completeness and the quality of alert disposition through to suspicious transaction reporting.
Typically run by AML Compliance / Principal Officer
Tests list currency, rescreening coverage, match quality and the discipline around discounting a potential match.
Typically run by AML / Sanctions Compliance
Credit audit of sanctioned loan files covering appraisal quality, delegated authority, security creation and end use of funds.
Typically run by Credit Audit / Internal Auditor
Tests asset classification against the date of default, borrower-level application, income reversal and provisioning adequacy.
Typically run by Internal Audit / Credit Monitoring
Reviews front, mid and back office separation, limit discipline, deal capture integrity and independent confirmation and valuation.
Typically run by Internal Audit / Market Risk
Tests whether complaints from every channel are captured, resolved substantively within turnaround, and drive systemic fixes.
Typically run by Nodal Officer / Compliance
Reviews whether products sold matched the customer's profile, what was disclosed before sale, and whether incentives cut across suitability.
Typically run by Compliance / Business Assurance
Regulatory governance review of outsourcing arrangements — materiality, approval, contractual rights, concentration and tested exit.
Typically run by Compliance / Vendor Governance
Tests the completeness of the entry population and whether preparation, approval and support hold up on high-risk manual entries.
Typically run by Financial Controller / Internal Audit
Tests the SoD matrix against actual role assignments in the core banking system, including compensating controls at small branches.
Typically run by IS Audit / Internal Audit
Reviews the completeness of the related party register and whether transactions had prior approval, arm's length pricing and correct disclosure.
Typically run by Internal Audit / Company Secretary
Each of these has a real control library in the product — questions map to specific clauses, so gap analysis shows you what is genuinely unevidenced.
Card-brand mandated controls for anyone storing, processing or transmitting card data.
12 controls mapped
The international standard for information security management systems.
23 controls mapped
Business continuity management — impact analysis, strategies and tested plans.
12 controls mapped
Internal control over financial reporting for US-listed companies and their subsidiaries.
20 controls mapped
Reserve Bank of India requirements for IT governance, cyber resilience and outsourcing.
16 controls mapped
India's personal data protection law, with consent and breach-notice obligations.
19 controls mapped
EU privacy regulation applying to any organisation processing EU residents' data.
16 controls mapped
Not hypotheticals. These are the findings that recur in financial services, and every one of them is a question in at least one of the 16 templates above.
Templates, findings and AI prompts use your sector's terms, not generic audit language.
Pick one of the 16 templates above, walk the site with your phone, and see the finished report before you get back to your desk.