This course speaks directly to the importance of general controls (GC), application controls (AC) and spreadsheet controls as they relate to Sarbanes-Oxley (SOX) and also provides meaningful insight into the SOX IT Control Environment. SOX IT controls aim to guarantee that systems are accurate, holistic, and error-free, as this may affect financial reporting. In the initial years of SOX compliance, many felt that a material weakness could not result from a failure of any type of Information Technology (IT) control. The world has changed, and IT is no longer simply a back office function. IT is of strategic importance to internal control over financial reporting (ICFR), and it must be adequately evaluated from both a GC and AC level.

The Public Company Accounting Oversight Board (PCAOB) and Securities and Exchange Commission (SEC) guidance states technology controls should only be part of SOX 404 to the extent specific financial risks are addressed. This approach can significantly reduce the scope of IT controls required in the assessment.  Scoping decision is part of the entity's top-down risk assessment and can utilize a baselining approach.  However, to understand the aspects of how to scope and baseline information technology controls, the assessor must have a strong understanding of how technology controls impact internal controls over financial reporting.

NOTE: The Instructor has created 5 new segments on Sarbanes-Oxley Update - 20 Years Later:
Sarbanes-Oxley Update - 20 Years Later: Accounting Risk Assessment Considerations
Sarbanes-Oxley Update - 20 Years Later: Sourcing Emerging Risks Part 1
Sarbanes-Oxley Update - 20 Years Later: Evaluating Testing Processes
Sarbanes-Oxley Update - 20 Years Later: Sourcing Emerging Risks Part 2
Sarbanes-Oxley Update - 20 Years Later: Examining Fraud Risks

Learning Objectives
  • Identify controls to evaluate as it relates to Information Technology (IT) and Sarbanes-Oxley (SOX)
  • Explore the SOX IT Control Framework, and recognize how to approach IT evaluation
  • Explore IT Entity controls
  • Explore Application Controls (AC) vs. General Controls (GC)
  • Identify Information Technology General Controls (ITGC) that are specific to Financial Reporting (FR)
Last updated/reviewed: March 26, 2024
161 Reviews (561 ratings)

Reviews

5
Anonymous Author
The distinction between ITGCs and application controls is crucial for understanding SOX compliance requirements. Application controls like handling exceptions in financial systems ensure that individual applications, such as those used for financial reporting, function correctly and that any errors or inconsistencies are addressed promptly. By contrast, ITGCs are broader, focusing on the integrity of the IT environment as a whole, including system development, maintenance, and overall governance.

5
Member's Profile
Thank you for creating a great session with many examples. The bullets were a great help. I would like to take more classes.

4
Anonymous Author
Good introduction providing the basics and the various controls that make up of SOX

4
Anonymous Author
Great class, easy to follow content and relevant to my job. Time well spent.

3
Member's Profile
Info was good. Would have liked to see more robust handouts.

5
Member's Profile
the Excellent learning experience.

3
Anonymous Author
Material was fine. Since the course is a bit long and staff may need to take it in sections, I would just suggest mini quiz (just a couple of questions after each couple of section). I did take the review questions up front to gauge where I needed to focus the most in the training. Most people in our company do not have auditing, or sox in their toolkit.

5
Anonymous Author
The course is well structured and detailed. The one thing I like about online learning is how convenient it is. I can keep learning as long as I have a device with me. I really enjoyed this class and the format it was presented in. For me, I learn and retain much. I was surprised about how much information I learned about the course.

5
Anonymous Author
It is my first class for SOX. Lynn did great job by presenting clear distinctions between different areas/terms and straightforward examples. While, by no means, I understand all materials presented here 100% (I need to review a few more times in order to digest completely to be honest), thank you for widening my views & knowledge.

5
Member's Profile
Instructor was knowledgeable on the subject. I think this was a good overview but content could be updated, as the importance of IT controls is increasing in our highly-automated world. I think "real world" examples would make the course more relatable and interesting.

5
Anonymous Author
Liked the course and length of segments. No surprises. Instructor examples of main points were very helpful with retaining the differences between GC and AC as well as explanation for entity level controls. Especially appreciated the EUC control slides.

5
Member's Profile
The course provided relevant insight into the IT Control Environment. The information was delivered in a meaningful way and provided enough detail to explain the concept. Lynn continues to provide good courses with meaningful subject matter.

4
Anonymous Author
This was a good training. I have been working on IT SOX but still there were things I never knew and also information which explains why I do certain tests. Made me think if there is anything extra I should test in addition to current scope.

5
Anonymous Author
This is a wonderful training program catered to all the software professionals. This is a wonderful training program catered to all the software professionals.This is a wonderful training program catered to all the software professionals.

5
Member's Profile
Great concise course over Information Technology general controls and automated application controls. Great course for IT Auditors and determining the SOX guidance for an audit. I would recommend this course for entry level associates.

5
Anonymous Author
The course provides a great overview of the IT environment, ITGC, ITAC controls. This is great for non IT auditors to provide a baseline foundation to be able to understand and communicate effectively with your IT audit team

4
Anonymous Author
It was very well structured, well-paced and easy to follow training course. Structuring the course in segments as well as offering a continuous play option is perfect for any learning style. The examples given were good.

5
Member's Profile
Excellent overview for IT auditors - those with experience in the IT audit field will get a nice comprehensive course on IT audit from those; would be very informative for people thinking about entering IT audit field.

4
Anonymous Author
I was an auditor and now working in a private company. This course is very good for auditors and non-auditors. The course material is very good and helpful. The speaker is very knowledgable of the subject matter.

3
Member's Profile
This was most difficult course I have ever taken for a company. it was hard to focus in on the questions that might be asked during the final exam because of how much content is covered in the videos.

4
Member's Profile
I wish the course had some interactions with the information throughout the course. Short quizzes or question/answer type interactions would break up the lecture and keep listeners motivated.

4
Member's Profile
It was a good course covering a lot of material and subjects. This is a small nit but some of the background noise during the presentation was a little distracting, especially towards the end.

4
Anonymous Author
This was a detailed overview of ITGCs and application controls. The examples provided helped to give a good understanding of each type and the discussion on spreadsheets was very helpful.

4
Anonymous Author
Another informative course from Lynn Fountain, providing an overview of IT controls and Sox assessment considerations. Well-presented, moving at an appropriate pace, and insightful.

5
Member's Profile
Great course to understand KSOX process. This will help us to support the KSOX audit process to evaluate current system falls under KSOX control or not and remediate missing controls.

4
Anonymous Author
IT is an area I am not as familiar with. This webinar gives great examples in an easy to understand manner. It really generated some action items to consider for our program.

5
Member's Profile
this was a great refresher course; the way the topics were highlighted and then covered in greater detail was a good strategy to ensure understanding and retention. Thank you.

5
Member's Profile
This course helped me to better understand definitions of General Controls and Application Controls and what is typically considered to be in scope for Sarbanes Oxley (SOX).

3
Anonymous Author
This course material was not as straight forward as the other SOX courses I have taken by Lynn. I recommend taking notes during her listens and not rely on the powerpoints.

2
Anonymous Author
The videos were okay, if you know nothing about technology. The questions were oddly worded and vague. To someone who has participated in an IT audit, they were confusing.

5
Anonymous Author
Sarbanes-Oxley (SOX) Act was enacted in 2002 to enhance corporate governance and financial transparency. It mandates specific controls to safeguard financial reporting.

5
Member's Profile
Another awesome course! I think that anyone who has a sound understanding of COSO but is on shaky mental terms with COBIT should indulge their senses with this course.

5
Member's Profile
Clear and concise information, well organized and with good real life examples provided throughout the sessions. Logical order and nicely broken down by topic.

5
Anonymous Author
This was a great course provided by Lynn, it was very interesting, and she covered each of the various areas in great detail which made it easier to understand.

5
Anonymous Author
This course had good detailed information on IT controls for Sarbanes -Oxley. The slides were helpful but a little confusing. The presenter was very good.

4
Member's Profile
good high level primer on sox general controls. spreadsheet section did seem a bit short considering how much these are now used in reporting functions.

5
Member's Profile
This course was very challenging but educational. The instructor was effective in presenting the course. I will recommend this course to other auditors.

5
Member's Profile
Lynn provides an excellent program regarding ITGC. Examples provided as considerations for control design, framework and testing were extremely helpful!

4
Anonymous Author
All information was good and relevant. I suggest starting off with a humorous slide (if this allowed) to help set a positive tone from the beginning.

5
Anonymous Author
Excellent overview of SOX IT Controls for non-IT auditors. Very informative, presentation was efficient and engaging. Another great course by Lynn.

5
Anonymous Author
Good course. Explained very well. I like the explanation of each topic in so easy way that it is understood to everyone. Thank you for this effort.

4
Anonymous Author
Good information, helpful. Informative. Learning and interesting. Time Length can be reduced. Liked the course. SDLC was helpful and informative

4
Anonymous Author
This is a clear overview of ITGCs, application and spreadsheet controls - easy to follow by people even with little or no background in IT.

5
Member's Profile
I liked the IT control categories. I think these were easy to follow. I am preparing to work for a public company so this was very helpful.

4
Anonymous Author
A good overview of various elements of IT for SOX including ITGC, Technology Entity Level Controls, Application Controls and Spreadsheets.

5
Member's Profile
Background on this topic is something I needed very much as my familiarity was lacking, but the field is becoming more important over time

5
Anonymous Author
Clear distinction between general and application controls. It was useful to add Spreadsheet controls, as these these are often ignored

4
Member's Profile
Gave a good overview of SOX related to ITGC. Would have like to gone into more detail on application controls. Overall, good course.

4
Member's Profile
It's a lomg course. A part A and Part B with separate finals might be better for those who need to take this in multiple sittings.

2
Anonymous Author
Rather than have your whole lesson written in the slides, why not have fewer slides with main points and speak on them freely.

5
Member's Profile
The course gave me the understanding of ITs role in KSOX and the processes that need to be put in place all through the cycle

5
Anonymous Author
Deep dive into controls for our IT applications. This applies to everything we do today given the everything is electronic.

4
Member's Profile
would be helpful if the course had examples related to how organizations establish, work with and monitor various controls.

4
Anonymous Author
Low resolution of video made it hard to see visuals, and the speed at which content was covered made it hard to take notes.

3
Anonymous Author
Although this course had a lot of useful information, it was difficult to follow at times. Still an overall good course.

4
Anonymous Author
This course was giving a good understanding about IT general control, application controls and spreadsheet controls.

5
Anonymous Author
this is a great overview of IT controls. The trainer made an effort by using common language to explain the concepts.

4
Anonymous Author
The instructor was clear and offered practical applications of the controls. The reference materials were also helpful.

5
Member's Profile
This course was effective and easily disgestible. Easy to follow, the continuous play video feature was useful as well.

5
Member's Profile
Very informative! Got good knowledge on Sox. Trainer explained everything very well. Thanks for providing this course.

3
Anonymous Author
The training was very monotonous. May be including some real life examples with question/answer in between would help.

5
Anonymous Author
I like that it was simple to understand. opportunity for improvement will be more real to life examples or scenarios.

5
Member's Profile
I enjoyed this course very much.Surprisingly I found some of the questions tricky.Excellent overall delivery by Lynn.

4
Member's Profile
Training was excellent with good interaction.Knowledge sharing is good. Recording facility is excellent for revising.

5
Anonymous Author
This course was more interesting and had information that took extra time to listen to and watch. But a great course.

4
Member's Profile
The course was as advertised. It gave a basic understanding of IT and Application controls that are part of SOX 404.

5
Member's Profile
Like everything. Very informative videos. Easy to understand and learn. Truly appreciate the tutor.

4
Member's Profile
The course was informative and helpful in providing a deeper understanding into specifics regarding ITGC controls.

4
Anonymous Author
This is a great course for those new to SOX concepts, or for those who have forgotten what they learned in college.

4
Anonymous Author
The training is just like a refresher courseNothing surprised me. New auditors will gain a lot from this training.

5
Member's Profile
Comprehensive course on how to apporach to IT controls over Sarbanes Oxley. Quite noisy at the end of video though

5
Anonymous Author
great course and lynn explained the Sarbanes-Oxley (SOX) - Information Technology Controls in a very detailed way

3
Anonymous Author
content was adequate for the topics pertaining to SOX compliance. Dividing into separate topics is a good idea.

5
Member's Profile
Good overview covering the distinction of application and general controls, as well as IT controls for SOX 404

Member's Profile
This course covers a lot of information. It provides a good distinction between general controls and ITGC's.

5
Anonymous Author
This course helped me understand the financial impact of IT changes and and how to allign with KSOX controls.

4
Member's Profile
Some questions were vague in order provide a answer. This was helpful though and did cover alot of topics.

5
Member's Profile
It was really good knowledge on knowing about the process and software applications in Information Technology

4
Member's Profile
It was good course with lot of clarity, information and simple language for lay man to understand the SOX.

3
Anonymous Author
A bit long and it should have been a more informative on the key elements as well as the testing material.

5
Anonymous Author
I've used illumeo for years to complete my CPEs. I've never had a problem with the material or the exams.

3
Member's Profile
The course was complete and efficient. The presenter was extremely bland, not a good fit to lecturing.

5
Anonymous Author
Course is very helpful and easy to understand .Thank you for providing such course details information

5
Anonymous Author
There are some good tactics presented in this class regarding risk assessment linking to IT controls.

5
Member's Profile
Informative course where you get know about the Sarbanes-Oxley (SOX) - Information Technology Controls

4
Anonymous Author
I liked that the exam covered the key points in the course material, sometimes these aren't in synch.

5
Anonymous Author
Good course on IT general controls and distinction between general controls and application controls

5
Member's Profile
Great course specially regarding the differences between application controls and general controls.

4
Anonymous Author
This course is most helpful if you're new to IT related internal controls over financial reporting.

5
Anonymous Author
Good overview for auditors when defining ITGCs and where they fit into the overall SOX environment.

4
Anonymous Author
The course was very well formatted and easily absorbed for the student, could have been more visual

5
Anonymous Author
Good informative course and liked the concept of the instructor explaining all concepts in detail.

5
Member's Profile
very good content. well thougth out good depth of topics. logical flow of material. good review

5
Anonymous Author
This course was excellent and provided important information that I will utilize in the future.

5
Anonymous Author
Great learning experience and strongly I will recommend this course to my collegues to complete

5
Anonymous Author
I learned a ton from this course on the importance of financial controls as it pertains to SOX

5
Anonymous Author
Several aspects of IT controls were amplified and explained better than I have heard before.

5
Member's Profile
Great class. Covered a lot of topics but the instructor was organized and easy to follow.

4
Anonymous Author
I liked how the instructor was clear and easy to understand the concerts she was explaining

4
Anonymous Author
Nice overview of ITGCs with a clear breakdown of general, entity, and application controls.

5
Member's Profile
The course title describes its content well. The instructor provides a very clear message.

5
Member's Profile
Good course overall, registration process is bit lengthy, but videos are very informative.

5
Anonymous Author
I gained a lot of knowledge from this course and deeper understanding of ITCGs and ITAC's

5
Anonymous Author
Nice introduction to IT general controls and application controls. Good examples given.

3
Member's Profile
Better narration of lesson and better graphics to help students retain the information

4
Member's Profile
I liked the content but there were not enough specific examples on how SOX is applied.

4
Anonymous Author
Good content but not all the terminology in the quiz was fully covered in the slides.

3
Anonymous Author
Lengthy but informative. Could be simplified further or make it easier to relate to.

5
Anonymous Author
great material for learning or keep current with SOX as well as getting CPE credits.

5
Anonymous Author
This was a challenging course but informative as I needed to brush up on IT skills.

5
Anonymous Author
As someone with zero SOX experience, this was a great intro to IT Controls for SOX.

4
Member's Profile
A lot of information that is useful. Was a little hard to follow at some points.

4
Anonymous Author
The course was very understanding and useful .Thankyou for the great information.

5
Anonymous Author
Great course re: IT and SOX. Very thorough in describing the controls framework

4
Anonymous Author
This course clarify the importance of applications and general controls in SOX.

5
Member's Profile
This was a good in depth course that covers the main IT controls related to SOX

5
Anonymous Author
Sarbanes-Oxley (SOX) - Information Technology Controls is an excellent course.

5
Anonymous Author
IT is not a favorite of mine, but I was kept engaged during the entire course

5
Member's Profile
i didn't know what is SOX but I supported SOX request. good to learn SOX.

5
Anonymous Author
Very good course of Sarbanes - Oxley (SOX) Information Technology Controls.

5
Member's Profile
The course is a very useful and good experience for understanding the SOX

5
Anonymous Author
very helpful. I love the way it is explained. It is so handy to understand.

4
Member's Profile
I like the overall pace of the course & clarity of key concepts presented.

3
Member's Profile
Course is very much OK and easy to follow, nothing else to be added here.

4
Anonymous Author
Very informative. I would highly recommend this course for non-auditors.

5
Member's Profile
Content in the course is very informative. It covered all aspects of SOX.

4
Member's Profile
It is a really good and helpful course. It has appropriate information.

3
Anonymous Author
Materials were easy to follow and relevant information was provided.

4
Anonymous Author
this was so hard for me because I'm not in IT. Thanks for experience.

5
Anonymous Author
Great and organized documents. Easy to follow. Instructor was great

5
Member's Profile
Concepts should be more simplified. Found little vague to understand

4
Member's Profile
Great overview. Good explanation about different types of controls.

4
Member's Profile
Little complex but good learning of IT Sox testing and applications

4
Anonymous Author
Great overview of entity level controls and process level controls!

3
Member's Profile
missing some important information that are crucial for the quiz.

4
Member's Profile
This is very informative. All IT staff must go thru this training.

4
Anonymous Author
The course contains plenty of information on application controls

5
Anonymous Author
It's Good to learn about the systems which we work on daily basis

5
Anonymous Author
great challenging questions. Instructor was great and thorough.

4
Anonymous Author
Course provides extensive overview of all types of IT controls.

4
Member's Profile
Helpful information - a new area for me and I learnt something!

4
Anonymous Author
Enter a short review and let others know about this Course.

4
Anonymous Author
It was very useful for me to understand a link between IT GC.

4
Anonymous Author
Good to refresh memory of ITGC and other IT related controls

4
Member's Profile
This course was not as dynamic as some of the other courses.

5
Anonymous Author
Super thorough deck with complete breakdown of SOX Controls

4
Anonymous Author
Good training - including content and flow of the material.

5
Anonymous Author
nofreeadsfrommenofreeadsfrommenofreeadsfrommenofreeadsfromme

4
Member's Profile
Great review of general vs application controls. Thank you!

5
Anonymous Author
The Course was good, I learned a lot about the SOX controls

2
Member's Profile
it was quite difficult for me to understand this subject.

5
Anonymous Author
I thought the approach was interesting and informative!

5
Anonymous Author
it really helpful to improve our awareness of security.

5
Anonymous Author
New experience and knowledgeable information shared.

4
Member's Profile
I liked the detailed explanation about AC, GC and EC

4
Anonymous Author
Well explained and more interesting than I expected

3
Anonymous Author
Course was as expected and CPE's seem appropriate

4
Anonymous Author
Good information provided

4
Anonymous Author
excellent review SOX Act

5
Anonymous Author
Excellent course.

4
Anonymous Author
Good.

Prerequisites
Course Complexity: Intermediate

No Advanced Preparation or Prerequisites are needed for this course, but completion of the instructor's previous webinars on Sarbanes-Oxley (SOX) may be helpful.

Education Provider Information
Company: Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA 95113
Contact: For more information regarding this course, including complaint and cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to .
Course Questions and Answers(2 Questions)
User picture

I have completed my final exam and unable to see my answers, how many are right or wrong. How many attempts are allowed for final exam?

Member's Profile

System does not allow to show the answers detail. However there is no limits to attempt the final exam until you passed.

Instructor for this course
Course Syllabus
INTRODUCTION and OVERVIEW
  Introduction to Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls6:39
General Controls, Applications Controls, and Sprea
  IT and SOX6:16
  Identifying Technical Controls to Evaluate 3:56
  IT Controls Framework 9:02
  Technology Entity Controls 12:24
  Application Vs. General Controls 10:26
  ITGC Specific to FR10:36
  SDLC6:22
  Application Controls 8:31
  IT Baselining 9:54
CONCLUSION
  Spreadsheets 8:53
Continuous Play
  Sarbanes-Oxley General Controls, Applications Controls and Spreadsheet Controls 1:32:58
SUPPORTING MATERIALS
  Slides: Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet ControlsPDF
  Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls Glossary/IndexPDF
REVIEW and TEST
  REVIEW QUESTIONSquiz
 FINAL EXAMexam