Sarbanes-Oxley 404 IT Testing Methodology
Best Practices for Sarbanes-Oxley Section 404 Testing
Use the high-level diagram in this guide to test your company’s Sarbanes-Oxley Section 404 IT general control set.
According to this sample, in order to define the company’s Sarbanes-Oxley Section 404 scope, IT management will work closely with the business (process owners/control owners and their delegates) to identify and evaluate the in-scope financial processes. Various applications, systems and platforms will be in scope, though this list may change from year to year. As part of the annual planning process, IT management will review the IT general controls in the context of the business process.