M ManySignal

Compliance — SOX IT Controls

SOX IT General Controls — continuous monitoring for financial systems

SOX Section 404 and PCAOB AS 2201 require effective IT General Controls over financial reporting systems. ManySignal monitors privileged access to SAP, Oracle, and Workday financials — detecting unauthorised access, out-of-cycle configuration changes, and data export anomalies — with ITGC evidence for external auditors.

SOX ITGC domain coverage

Access Controls

Privileged access monitoring, quarterly access review evidence, segregation of duties violation detection, and deprovisioning verification for financial system users

Change Management

Unauthorised configuration changes to ERP systems outside approved change windows detected — financial system change control evidence for auditors

Computer Operations

Batch processing completion monitoring, backup execution verification, and financial system availability incident evidence

SOX IT controls — common questions

Which SOX sections relate to IT controls and cybersecurity?

SOX Section 302 requires CEOs and CFOs to certify the effectiveness of internal controls, including IT controls that protect financial data integrity. Section 404 requires annual assessment of internal control over financial reporting (ICFR). PCAOB AS 2201 governs external auditor assessment of ICFR. The IT General Controls (ITGCs) — access controls, change management, and operations controls — are the primary cybersecurity-adjacent controls assessed under SOX.

What IT General Controls does ManySignal address for SOX compliance?

ManySignal addresses three of the four ITGC domains: (1) Access Controls — monitoring privileged access to financial systems, flagging access outside approved roles, and detecting unauthorised modification of financial data; (2) Computer Operations — monitoring batch processing jobs, backup execution, and system availability for financial systems; (3) Change Management — monitoring unauthorised changes to ERP and financial application configurations outside approved change windows.

Which financial systems does ManySignal monitor for SOX controls?

ManySignal monitors access to SOX-relevant financial systems: SAP S/4HANA and ECC, Oracle Financials, Microsoft Dynamics 365 Finance, Workday Financials, and NetSuite. It monitors privileged access, configuration changes, and data export volumes. Journal entry anomalies — large manual journal entries, entries made at unusual times, or entries in unusual accounts — can be detected via integration with GL audit trails.

Can ManySignal help reduce the effort required for SOX ITGC testing?

Yes. SOX ITGC testing traditionally involves manual evidence collection — access review lists, change logs, and batch processing evidence. ManySignal automates the monitoring of these controls year-round, and generates evidence packages formatted for external auditor review. This reduces the quarterly and annual ITGC testing effort significantly and eliminates the risk of evidence gaps at testing time.

How does ManySignal support SOX compliance in cloud-hosted ERP environments?

Cloud ERP deployments (SAP S/4HANA Cloud, Oracle Fusion Cloud, Workday) shift some ITGC responsibilities to the SaaS provider under the shared responsibility model. ManySignal monitors the controls that remain the customer's responsibility: identity and access management (IAM) controls over ERP users, data export monitoring, and integration security between ERP and connected financial systems.

Automate SOX ITGC evidence collection

Connect your SAP, Oracle, or Workday environment. We'll demonstrate continuous access control monitoring and ITGC evidence package generation for your next external audit.