We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. SOX ITGC compliance
SOX ITGC readiness, UAE

Under SOX your auditor gives an opinion on your controls. A statutory audit never did that.

PCAOB AS 2201 requires the auditor to express an opinion on the effectiveness of internal control over financial reporting. For a UAE subsidiary inside a US listed group, that changes what evidence looks like and what happens when a control fails.

Book a SOX ITGC readiness reviewSee what changes
SOX ITGC readiness for UAE subsidiaries
  • An opinionNot just reliance, a public conclusion
  • Top-downThe required approach to selecting controls
  • Material weaknessWhat a failed control can become
  • Location scopingWhy the UAE entity gets selected some years
The difference that catches people

A statutory audit tests controls to plan its work. SOX tests them to publish a verdict.

Teams that have been through a UAE statutory audit often assume SOX is the same requests with more paperwork. The purpose is different, and the difference shows up in how findings are treated.

  • In a statutory audit, a control weakness usually means the auditor does more substantive testing instead. The engagement absorbs it. Under SOX the auditor is expressing an opinion on the controls themselves, so a weakness cannot simply be worked around with more sampling.
  • A material weakness is defined by reasonable possibility of a material misstatement not being prevented or detected on a timely basis. It does not require that anything actually went wrong, which surprises people who expect to point at clean financial results as a defence.
  • Findings are cumulative. Multiple deficiencies affecting the same account, disclosure or component of internal control can collectively amount to a material weakness even where each one individually is less severe, so a list of small issues is not automatically a small problem.
  • And the timetable is unforgiving. Testing happens at an interim date with a roll-forward to year end, and the sufficiency of that roll-forward depends on the interim results, the length of the remaining period and whether things changed in between.
Ask us to assess your position
What SOX changes

Eight things a UAE finance and IT team should understand.

Most UAE organisations meeting SOX for the first time do so because a parent company listed in the United States, or because a US listed group acquired them. The requests look familiar and the standard behind them is materially different.

The auditor issues an opinion on controls

The stated objective is to express an opinion on the effectiveness of the company internal control over financial reporting. That is a separate conclusion from the financial statements opinion, and it is published, which changes the consequences of a control failing.

Top-down is the required approach

The auditor should use a top-down approach to select the controls to test. Testing starts at the financial statement level and works down to significant accounts, disclosures and assertions, which is why scoping arguments matter more than control counts.

Entity-level controls must be tested

The auditor must test those entity-level controls that are important to the conclusion about whether the company has effective internal control. Those sit at group level and they shape how much testing reaches individual locations such as a UAE entity.

ITGC effectiveness lowers the risk of automated controls

The standard states that an automated control would generally be expected to be lower risk if relevant information technology general controls are effective. That is the precise mechanism by which IT general controls carry weight in a financial audit.

Material weakness has a defined meaning

A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis. The threshold is possibility, not certainty.

Significant deficiency is the tier below

Less severe than a material weakness, yet important enough to merit attention by those responsible for oversight of financial reporting. Most ITGC findings land here, and a cluster of them in one area can aggregate into something more serious.

Your own work can reduce theirs, within limits

The auditor should evaluate the extent to which they will use the work of others to reduce their own work, judged on competence and objectivity. But as the risk associated with a control increases, the need for the auditor to perform their own work increases.

Location scoping explains the pattern you see

The auditor assesses the risk of material misstatement associated with each location or business unit, evaluates whether entity-level testing provides sufficient evidence, and varies the locations tested from year to year. That is why the UAE entity is in scope some years and not others.

Two regimes

Statutory audit ITGC against SOX ITGC.

The left column is what most UAE entities know. The right column is what arrives when a US listed parent enters the picture.
AspectUAE statutory auditSOX under AS 2201
Purpose of control testingInforms the audit approachSupports an opinion on controls
OutputNo separate control opinionA published opinion on effectiveness
Effect of a weaknessMore substantive testingPotential material weakness
Threshold languageProfessional judgementReasonable possibility of material misstatement
Approach to selecting controlsRisk basedTop-down, as required by the standard
Entity-level controlsConsideredMust be tested where important to the conclusion
Use of your internal audit workVariesPermitted, subject to competence and objectivity
Higher risk controlsVariesAuditor performs more of their own work
Location selectionGroup judgementRisk assessed and varied year to year
Evidence expectationSampledSampled, with roll-forward to year end
How we approach it

Four things that keep a first SOX year from producing findings.

Very few first year findings are about missing controls. Most are about evidence that exists somewhere but cannot be produced in the form an auditor can sample.

We work backwards from the evidence

For each control we ask what a sample of it looks like, where that evidence lives and how long it is retained. A control that operates perfectly but cannot be evidenced through to year end testing is treated by the auditor exactly as if it did not operate.

We scope with the top-down approach in mind

The auditor selects controls top down from significant accounts, disclosures and assertions. Understanding that route lets us focus effort on the systems that will actually be selected rather than documenting every system in the estate equally.

We position your work so it can be used

The auditor evaluates the extent to which the work of others can reduce their own, based on competence and objectivity. Work prepared with that in mind is far more likely to reduce the burden than work prepared purely for internal comfort.

We start before interim, not after

Findings identified at interim testing can be remediated with enough of the year remaining to demonstrate the new control operating. The same finding at year end usually cannot, which is the difference between a note and a reportable deficiency.

How an engagement runs

Four phases aligned to the audit calendar.

SOX work is not scheduled around your convenience. It is scheduled around interim testing and year end, and starting late is the most common reason a first year goes badly.
  1. 01
    Months 1 to 2

    Scope and control design

    Which systems are in scope because they support significant accounts and disclosures, and what the control design is for access, change and operations around them. Group entity-level controls are mapped so local testing does not duplicate them.

    • In scope systems identified against significant accounts
    • ITGC design documented for access, change and operations
    • Group entity-level control reliance mapped
    • Control owners named per control
  2. 02
    Months 3 to 4

    Evidence readiness

    Every control needs evidence that a sample can be drawn from and that shows the control operated, not merely that a policy exists. This is where most first year effort goes and where most first year findings come from.

    • Evidence source identified per control
    • Retention checked so samples can be produced
    • Population completeness demonstrable
    • Self testing performed on a sample basis
  3. 03
    Months 5 to 7

    Interim testing support

    Working through the auditor requests, with the understanding that as the risk associated with a control increases the auditor performs more of their own work rather than relying on yours. Findings identified here can still be remediated before year end.

    • Interim requests coordinated and answered
    • Findings triaged by severity
    • Remediation started with time to demonstrate operation
    • Communication line with the group SOX team established
  4. 04
    Months 8 to 10

    Roll-forward and year end

    The sufficiency of roll-forward procedures depends on the interim results, the length of the remaining period and the potential for subsequent changes. Changes made after interim testing therefore need to be surfaced rather than discovered.

    • Changes since interim testing documented
    • Roll-forward evidence prepared
    • Remediated controls evidenced as operating
    • Lessons captured for the following year
Where this comes up

Six situations we are asked to support.

The common thread is a UAE operation that has become part of a US listed reporting boundary, usually without much notice.

A UAE subsidiary acquired by a US listed group

The acquisition closes and the SOX calendar arrives with it. The first year is the hardest because control design, ownership and evidence all have to be established at once, usually alongside a systems integration.

A group preparing for a US listing

Readiness work ahead of a listing is considerably cheaper than remediation afterwards, because there is no auditor opinion at stake yet and no public disclosure consequence attached to a finding.

A regional entity selected for testing this year

Locations are risk assessed and varied year to year, so an entity that was out of scope last year can be in scope this year. Being ready in advance is the only response that works, because notice is often short.

An entity that had findings last year

Remediation has to be evidenced as operating, not merely implemented. That means the new control needs enough of the year behind it to produce a testable population, which is why remediation timing is a planning question.

A business relying heavily on automated controls

An automated control is generally expected to be lower risk where relevant IT general controls are effective. Where ITGCs are not effective, that reliance collapses and the testing burden shifts back onto manual procedures.

A team told their statutory audit evidence is not enough

It usually is not, because the purpose differs. Statutory control testing informs the audit approach, while SOX testing supports a published opinion, and the evidence expectations follow from that difference rather than from auditor preference.

Three positions

How UAE subsidiaries approach their first SOX year.

The middle column is the most common and it produces findings that were entirely avoidable, usually about evidence rather than about controls.
Control owners named
Prepared before interimYes
Reacting to requestsDuring testing
Assuming statutory experience covers itNo
Evidence located in advance
Prepared before interimYes
Reacting to requestsUnder time pressure
Assuming statutory experience covers itNo
Self testing performed
Prepared before interimYes
Reacting to requestsNo
Assuming statutory experience covers itNo
Findings surfaced early
Prepared before interimAt interim
Reacting to requestsAt year end
Assuming statutory experience covers itBy the auditor
Time to remediate and evidence
Prepared before interimAvailable
Reacting to requestsLimited
Assuming statutory experience covers itNone
Group coordination
Prepared before interimContinuous
Reacting to requestsEscalation driven
Assuming statutory experience covers itAbsent
Risk of a material weakness
Prepared before interimLow
Reacting to requestsModerate
Assuming statutory experience covers itElevated
Effort during year end
Prepared before interimManageable
Reacting to requestsHeavy
Assuming statutory experience covers itCrisis
Second year effort
Prepared before interimLower
Reacting to requestsSimilar
Assuming statutory experience covers itHigher
Position with the group
Prepared before interimReliable
Reacting to requestsWatched
Assuming statutory experience covers itA problem entity
Feature
Prepared before interim
Reacting to requests
Assuming statutory experience covers it
Control owners named
YesDuring testingNo
Evidence located in advance
YesUnder time pressureNo
Self testing performed
YesNoNo
Findings surfaced early
At interimAt year endBy the auditor
Time to remediate and evidence
AvailableLimitedNone
Group coordination
ContinuousEscalation drivenAbsent
Risk of a material weakness
LowModerateElevated
Effort during year end
ManageableHeavyCrisis
Second year effort
LowerSimilarHigher
Position with the group
ReliableWatchedA problem entity
What evidence actually means here

A control is only as good as the population an auditor can sample from.

Almost every first year finding we see is about evidence rather than about whether the control operates.

  • The population has to be complete and demonstrably so. An auditor selecting a sample needs confidence that the list it came from contains every instance, which means being able to explain how the list was produced and why nothing is missing from it.
  • Each item has to show the control operating, not merely that a policy exists. An approval workflow record with a requester, an approver, a date and an outcome is evidence. A policy document stating that approvals are required is not, however well written it is.
  • Retention has to reach year end testing. Logs rotated after thirty days cannot support a sample drawn in month nine, and this is discovered during testing rather than during design in a large proportion of first year programmes.
  • And the evidence has to be retrievable by somebody other than the person who built the system. Where retrieval depends on one engineer writing an ad hoc query, availability becomes a staffing risk in the middle of an audit timetable.
How an engagement runs

Five steps, aligned to the audit timetable rather than to ours.

Everything here is calendar driven. The value of starting early is entirely about having remediation time available later.
  1. 1

    Confirm scope with the group

    Which systems support significant accounts and disclosures, whether this entity is in scope for the current year, and which entity-level controls the group tests centrally. Locations are risk assessed and varied year to year, so this is confirmed rather than assumed.

  2. 2

    Document control design and name owners

    Access, change and operations controls around each in scope system, each with a named individual owner who knows they own it. Anonymous team ownership is the most reliable predictor of a control that nobody can evidence when asked.

  3. 3

    Establish the evidence position

    For each control, what the evidence is, where it lives, whether the population is complete and demonstrably so, and whether retention extends through year end testing. This step prevents more findings than any other.

  4. 4

    Self test before the auditor does

    Sampling your own controls the way the auditor will, so gaps are found while there is still time to remediate and to build a population showing the corrected control operating. Interim is the last comfortable moment for that.

  5. 5

    Support interim and roll-forward

    Coordinated responses to requests, changes since interim documented so roll-forward procedures hold, and remediated controls evidenced as operating. Then a short review capturing what to do differently in the following cycle.

Straight answers

What UAE teams ask about SOX ITGC.

The auditor objective under this standard is to express an opinion on the effectiveness of internal control over financial reporting. A statutory audit tests controls to inform its own approach. One produces a published verdict on your controls, the other does not.

A deficiency, or a combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis. Reasonable possibility is the operative phrase.

They can. Multiple deficiencies affecting the same account, disclosure, assertion or component of internal control can collectively constitute a material weakness even where each is individually less severe than one. Aggregation is assessed deliberately.

Because an automated control is generally expected to be lower risk where relevant IT general controls are effective. Effective ITGCs are what allow reliance on automated controls, and ineffective ones push the testing burden back onto manual procedures.

The auditor assesses the risk of material misstatement associated with each location or business unit, evaluates whether entity-level testing gives sufficient evidence, and varies the locations tested from year to year. Rotation is built into the approach.

Partly. The auditor evaluates the extent to which the work of others can reduce their own work, based on competence and objectivity. But as the risk associated with a control increases, the need for the auditor to perform their own work increases too.

The required method for selecting controls to test. It begins at the financial statement level and works down through significant accounts, disclosures and assertions to the controls that address them, which is why scoping discussions dominate early SOX work.

Yes. The auditor must test those entity-level controls that are important to the conclusion about whether the company has effective internal control. Strong entity-level controls can also reduce how much testing reaches individual locations.

Testing often happens at an interim date, with procedures covering the remaining period to year end. Sufficiency depends on the interim results, how long the remaining period is, and whether anything changed. Undisclosed mid year changes are the usual problem.

Not by itself. The material weakness definition turns on the reasonable possibility that a misstatement would not be prevented or detected on a timely basis, rather than on whether one actually occurred. Clean results do not demonstrate effective controls.

Evidence rather than control design. A control that operates but leaves no sampleable record, a population that cannot be shown to be complete, or logs that were rotated away before testing. All three are avoidable with preparation.

Before interim testing, with enough of the year remaining that any finding can be remediated and the corrected control can produce a testable population. Starting after interim usually means carrying the finding into the year end conclusion.

Group teams handle entity-level controls and coordination, but the controls operating in your systems are operated by your people and evidenced from your records. Central coordination reduces duplication rather than removing local responsibility.

Most of it, which is why the first year is disproportionately expensive. Control documentation, evidence sources, named owners and self testing routines all carry forward, and second year effort is typically much lower where the first year was done properly.

We scope by the number of in scope systems and whether this is a first year or a maintenance cycle. The free first step: pick one access control and try to produce evidence of it operating for a date six months ago. That test predicts your first year.

Less than is comfortable, because location selection is risk assessed and varied year to year. Entities that prepare in advance handle a short notice inclusion routinely, and entities that do not spend the first weeks assembling documentation rather than evidence.

They should, and it comes from the auditor risk assessment of each location or business unit. Asking early rather than waiting for the request is worth doing, because the answer determines how much preparation time you actually have.

A control operating across the organisation rather than in a single process, such as governance, policy, monitoring and communication. The auditor must test those important to the conclusion, and strong ones can reduce testing at individual locations.

The controls still need evidencing, and where a provider operates them you may be relying on their assurance report. Establishing which controls are yours and which are theirs, before testing starts, avoids a gap discovered at the worst moment.

Document it. Superseded controls may not require testing where the new controls achieve the related objectives, but the change and its timing have to be visible, since roll-forward sufficiency depends on knowing what changed after interim testing.

Substantially less, provided the first year established documentation, named owners, evidence sources and self testing. Where the first year was survived rather than built properly, the second year costs much the same as the first did.
First year readiness

Fifteen questions to answer before interim testing.

The evidence group is where first year SOX programmes are won or lost. A control that operates but cannot be evidenced is treated the same as one that does not operate.

Scope

  • Which systems support significant accounts?
    That defines ITGC scope.
  • Are we in scope this year?
    Locations vary year to year.
  • What does the group test centrally?
    Avoid duplicating it.
  • Which entity-level controls apply to us?
    They must be tested.
  • Have any systems changed mid year?
    Roll-forward depends on it.

Evidence

  • Can we evidence every access approval?
    Not just the policy.
  • Do change records tie to approvals?
    And to deployments.
  • Can we prove population completeness?
    A frequent challenge.
  • Are logs retained long enough?
    Through to year end testing.
  • Have we sampled ourselves first?
    Before the auditor does.

People and process

  • Does every control have a named owner?
    Not a team name.
  • Do owners know they own it?
    Frequently not.
  • Who coordinates with the group?
    A single point.
  • Is there time to remediate?
    Findings need operating evidence.
  • What happens when someone leaves?
    Ownership must transfer.
Related reading

The pages around this one.

IT general controls audit

The same controls, in the UAE statutory audit context.

Learn more

Access rights review

The control most often tested and most often failed.

Learn more

Audit readiness assessment

Finding the gaps before the auditor does.

Learn more
Next step

Pick one access control and produce evidence of it operating six months ago.

If that takes more than an hour, or the evidence no longer exists, you have found the finding your first SOX year would otherwise have found for you.

Book a SOX ITGC readiness reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

IT General Controls

What your external auditor tests, and the evidence they sample

Learn more

Access Rights Review

Certification that removes access, not one that gets approved

Learn more

Audit Readiness Assessment

Run the audit before the auditor does

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Privileged Access Audit

Every privileged path, not just the admin list

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Gap Assessment

Distance to a target you actually have to meet

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy