Instructor for this course
more

This course speaks directly to the importance of general controls (GC), application controls (AC) and spreadsheet controls as they relate to Sarbanes-Oxley (SOX).  In the initial years of SOX compliance, many felt that a material weakness could not result from a failure of any type of Information Technology (IT) control. The world has changed, and IT is no longer simply a back office function. IT is of strategic importance to internal control over financial reporting (ICFR), and it must be adequately evaluated from both a GC and AC level.

The Public Company Accounting Oversight Board (PCAOB) and Securities and Exchange Commission (SEC) guidance states technology controls should only be part of SOX 404 to the extent specific financial risks are addressed. This approach can significantly reduce the scope of IT controls required in the assessment.  Scoping decision is part of the entity's top-down risk assessment and can utilize a baselining approach.  However, to understand the aspects of how to scope and baseline information technology controls, the assessor must have a strong understanding of how technology controls impact internal controls over financial reporting.

Learning Objectives

  • Identify controls to evaluate as it relates to Information Technology (IT) and Sarbanes-Oxley (SOX)
  • Explore the IT Control Framework, and recognize how to approach IT evaluation
  • Explore IT Entity controls
  • Explore Application Controls (AC) vs. General Controls (GC)
  • Identify Information Technology General Controls (ITGC) that are specific to Financial Reporting (FR)
Last updated/reviewed: November 18, 2019

Included In Certifications

This course is included in the following Certification Programs:

17 CoursesSarbanes-Oxley (SOX) Certification

  1. Sarbanes Oxley (SOX) Overview
  2. SOX: Authoritative Bodies
  3. Sarbanes-Oxley (SOX) Standards - Evolution
  4. Information Technology General Controls Primer
  5. COSO 2013 Overview
  6. Sarbanes-Oxley (SOX) Section 404
  7. Sarbanes-Oxley Section 302: ICFR
  8. Sarbanes-Oxley (SOX) And Fraud Sections
  9. Sarbanes-Oxley (SOX) - Top Down Risk Assessment Part 1
  10. Sarbanes-Oxley (SOX) - Top Down Risk Assessment Part 2
  11. Sarbanes-Oxley (SOX) - Entity Level Controls
  12. Sarbanes-Oxley (SOX) Identifying and Documenting Controls
  13. Sarbanes-Oxley (SOX) Testing
  14. Sarbanes-Oxley (SOX) - Information Technology Controls
  15. Sarbanes-Oxley (SOX) - Assessing Material Impact
  16. XBRL - Connection to SOX 302/404 and Critical Roles
  17. Tools For Sarbanes-Oxley Compliance

40 Reviews (144 ratings)Reviews

5
Anonymous Author
Liked the course and length of segments. No surprises. Instructor examples of main points were very helpful with retaining the differences between GC and AC as well as explanation for entity level controls. Especially appreciated the EUC control slides.
5
Member's Profile
Great concise course over Information Technology general controls and automated application controls. Great course for IT Auditors and determining the SOX guidance for an audit. I would recommend this course for entry level associates.
5
Anonymous Author
The course provides a great overview of the IT environment, ITGC, ITAC controls. This is great for non IT auditors to provide a baseline foundation to be able to understand and communicate effectively with your IT audit team
4
Anonymous Author
I was an auditor and now working in a private company. This course is very good for auditors and non-auditors. The course material is very good and helpful. The speaker is very knowledgable of the subject matter.
4
Anonymous Author
This was a detailed overview of ITGCs and application controls. The examples provided helped to give a good understanding of each type and the discussion on spreadsheets was very helpful.
4
Anonymous Author
Another informative course from Lynn Fountain, providing an overview of IT controls and Sox assessment considerations. Well-presented, moving at an appropriate pace, and insightful.
4
Anonymous Author
IT is an area I am not as familiar with. This webinar gives great examples in an easy to understand manner. It really generated some action items to consider for our program.
5
Member's Profile
This course helped me to better understand definitions of General Controls and Application Controls and what is typically considered to be in scope for Sarbanes Oxley (SOX).
5
Member's Profile
Another awesome course! I think that anyone who has a sound understanding of COSO but is on shaky mental terms with COBIT should indulge their senses with this course.
5
Member's Profile
This course was very challenging but educational. The instructor was effective in presenting the course. I will recommend this course to other auditors.
4
Anonymous Author
This is a clear overview of ITGCs, application and spreadsheet controls - easy to follow by people even with little or no background in IT.
5
Member's Profile
I liked the IT control categories. I think these were easy to follow. I am preparing to work for a public company so this was very helpful.
5
Anonymous Author
Clear distinction between general and application controls. It was useful to add Spreadsheet controls, as these these are often ignored
2
Anonymous Author
Rather than have your whole lesson written in the slides, why not have fewer slides with main points and speak on them freely.
3
Anonymous Author
Although this course had a lot of useful information, it was difficult to follow at times. Still an overall good course.
4
Anonymous Author
This course was giving a good understanding about IT general control, application controls and spreadsheet controls.
5
Member's Profile
I enjoyed this course very much.Surprisingly I found some of the questions tricky.Excellent overall delivery by Lynn.
4
Member's Profile
The course was informative and helpful in providing a deeper understanding into specifics regarding ITGC controls.
4
Anonymous Author
This is a great course for those new to SOX concepts, or for those who have forgotten what they learned in college.
Member's Profile
This course covers a lot of information. It provides a good distinction between general controls and ITGC's.
4
Anonymous Author
I liked that the exam covered the key points in the course material, sometimes these aren't in synch.
5
Member's Profile
Great course specially regarding the differences between application controls and general controls.
5
Anonymous Author
This course was excellent and provided important information that I will utilize in the future.
5
Member's Profile
Great class. Covered a lot of topics but the instructor was organized and easy to follow.
5
Member's Profile
The course title describes its content well. The instructor provides a very clear message.
4
Member's Profile
A lot of information that is useful. Was a little hard to follow at some points.
5
Anonymous Author
Sarbanes-Oxley (SOX) - Information Technology Controls is an excellent course.
5
Anonymous Author
IT is not a favorite of mine, but I was kept engaged during the entire course
4
Member's Profile
Great overview. Good explanation about different types of controls.
4
Member's Profile
Little complex but good learning of IT Sox testing and applications
4
Anonymous Author
Course provides extensive overview of all types of IT controls.
4
Member's Profile
Helpful information - a new area for me and I learnt something!
4
Anonymous Author
It was very useful for me to understand a link between IT GC.
4
Anonymous Author
Good to refresh memory of ITGC and other IT related controls
4
Member's Profile
This course was not as dynamic as some of the other courses.
5
Anonymous Author
Super thorough deck with complete breakdown of SOX Controls
4
Anonymous Author
Good information provided
4
Anonymous Author
excellent review SOX Act
5
Anonymous Author
Excellent course.
4
Anonymous Author
Good.

Prerequisites

Course Complexity: Intermediate

No Advanced Preparation or Prerequisites are needed for this course, but completion of the instructor's previous webinars on Sarbanes-Oxley (SOX) may be helpful.

Education Provider Information

Company:
Illumeo, Inc., 75 East Santa Clara St., Suite 1215, San Jose, CA 95113
Contact:
For more information regarding this course, including complaint and cancellation policies, please contact our offices at (408) 400- 3993 or send an e-mail to .
Course Syllabus
INTRODUCTION and OVERVIEW
  6:39Introduction to Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls
General Controls, Applications Controls, and Sprea
  6:16IT and SOX
  3:56Identifying Technical Controls to Evaluate
  9:02IT Controls Framework
  12:24Technology Entity Controls
  10:26Application Vs. General Controls
  10:36ITGC Specific to FR
  6:21SDLC
  8:30Application Controls
  9:53IT Baselining
CONCLUSION
  8:53Spreadsheets
Continuous Play
  1:32:57Sarbanes-Oxley General Controls, Applications Controls and Spreadsheet Controls
SUPPORTING MATERIALS
  PDFSlides: Sarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls
  PDFSarbanes-Oxley (SOX) General Controls, Applications Controls, and Spreadsheet Controls Glossary/Index
REVIEW and TEST
  quizREVIEW QUESTIONS
 examFINAL EXAM