Under SOX your auditor gives an opinion on your controls. A statutory audit never did that.
PCAOB AS 2201 requires the auditor to express an opinion on the effectiveness of internal control over financial reporting. For a UAE subsidiary inside a US listed group, that changes what evidence looks like and what happens when a control fails.

- An opinionNot just reliance, a public conclusion
- Top-downThe required approach to selecting controls
- Material weaknessWhat a failed control can become
- Location scopingWhy the UAE entity gets selected some years
A statutory audit tests controls to plan its work. SOX tests them to publish a verdict.
Teams that have been through a UAE statutory audit often assume SOX is the same requests with more paperwork. The purpose is different, and the difference shows up in how findings are treated.
- In a statutory audit, a control weakness usually means the auditor does more substantive testing instead. The engagement absorbs it. Under SOX the auditor is expressing an opinion on the controls themselves, so a weakness cannot simply be worked around with more sampling.
- A material weakness is defined by reasonable possibility of a material misstatement not being prevented or detected on a timely basis. It does not require that anything actually went wrong, which surprises people who expect to point at clean financial results as a defence.
- Findings are cumulative. Multiple deficiencies affecting the same account, disclosure or component of internal control can collectively amount to a material weakness even where each one individually is less severe, so a list of small issues is not automatically a small problem.
- And the timetable is unforgiving. Testing happens at an interim date with a roll-forward to year end, and the sufficiency of that roll-forward depends on the interim results, the length of the remaining period and whether things changed in between.
Eight things a UAE finance and IT team should understand.
The auditor issues an opinion on controls
The stated objective is to express an opinion on the effectiveness of the company internal control over financial reporting. That is a separate conclusion from the financial statements opinion, and it is published, which changes the consequences of a control failing.
Top-down is the required approach
The auditor should use a top-down approach to select the controls to test. Testing starts at the financial statement level and works down to significant accounts, disclosures and assertions, which is why scoping arguments matter more than control counts.
Entity-level controls must be tested
The auditor must test those entity-level controls that are important to the conclusion about whether the company has effective internal control. Those sit at group level and they shape how much testing reaches individual locations such as a UAE entity.
ITGC effectiveness lowers the risk of automated controls
The standard states that an automated control would generally be expected to be lower risk if relevant information technology general controls are effective. That is the precise mechanism by which IT general controls carry weight in a financial audit.
Material weakness has a defined meaning
A deficiency, or combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis. The threshold is possibility, not certainty.
Significant deficiency is the tier below
Less severe than a material weakness, yet important enough to merit attention by those responsible for oversight of financial reporting. Most ITGC findings land here, and a cluster of them in one area can aggregate into something more serious.
Your own work can reduce theirs, within limits
The auditor should evaluate the extent to which they will use the work of others to reduce their own work, judged on competence and objectivity. But as the risk associated with a control increases, the need for the auditor to perform their own work increases.
Location scoping explains the pattern you see
The auditor assesses the risk of material misstatement associated with each location or business unit, evaluates whether entity-level testing provides sufficient evidence, and varies the locations tested from year to year. That is why the UAE entity is in scope some years and not others.
Statutory audit ITGC against SOX ITGC.
| Aspect | UAE statutory audit | SOX under AS 2201 | |
|---|---|---|---|
| Purpose of control testing | Informs the audit approach | Supports an opinion on controls | |
| Output | No separate control opinion | A published opinion on effectiveness | |
| Effect of a weakness | More substantive testing | Potential material weakness | |
| Threshold language | Professional judgement | Reasonable possibility of material misstatement | |
| Approach to selecting controls | Risk based | Top-down, as required by the standard | |
| Entity-level controls | Considered | Must be tested where important to the conclusion | |
| Use of your internal audit work | Varies | Permitted, subject to competence and objectivity | |
| Higher risk controls | Varies | Auditor performs more of their own work | |
| Location selection | Group judgement | Risk assessed and varied year to year | |
| Evidence expectation | Sampled | Sampled, with roll-forward to year end |
Four things that keep a first SOX year from producing findings.
We work backwards from the evidence
For each control we ask what a sample of it looks like, where that evidence lives and how long it is retained. A control that operates perfectly but cannot be evidenced through to year end testing is treated by the auditor exactly as if it did not operate.
We scope with the top-down approach in mind
The auditor selects controls top down from significant accounts, disclosures and assertions. Understanding that route lets us focus effort on the systems that will actually be selected rather than documenting every system in the estate equally.
We position your work so it can be used
The auditor evaluates the extent to which the work of others can reduce their own, based on competence and objectivity. Work prepared with that in mind is far more likely to reduce the burden than work prepared purely for internal comfort.
We start before interim, not after
Findings identified at interim testing can be remediated with enough of the year remaining to demonstrate the new control operating. The same finding at year end usually cannot, which is the difference between a note and a reportable deficiency.
Four phases aligned to the audit calendar.
- 01Months 1 to 2
Scope and control design
Which systems are in scope because they support significant accounts and disclosures, and what the control design is for access, change and operations around them. Group entity-level controls are mapped so local testing does not duplicate them.
- In scope systems identified against significant accounts
- ITGC design documented for access, change and operations
- Group entity-level control reliance mapped
- Control owners named per control
- 02Months 3 to 4
Evidence readiness
Every control needs evidence that a sample can be drawn from and that shows the control operated, not merely that a policy exists. This is where most first year effort goes and where most first year findings come from.
- Evidence source identified per control
- Retention checked so samples can be produced
- Population completeness demonstrable
- Self testing performed on a sample basis
- 03Months 5 to 7
Interim testing support
Working through the auditor requests, with the understanding that as the risk associated with a control increases the auditor performs more of their own work rather than relying on yours. Findings identified here can still be remediated before year end.
- Interim requests coordinated and answered
- Findings triaged by severity
- Remediation started with time to demonstrate operation
- Communication line with the group SOX team established
- 04Months 8 to 10
Roll-forward and year end
The sufficiency of roll-forward procedures depends on the interim results, the length of the remaining period and the potential for subsequent changes. Changes made after interim testing therefore need to be surfaced rather than discovered.
- Changes since interim testing documented
- Roll-forward evidence prepared
- Remediated controls evidenced as operating
- Lessons captured for the following year
Six situations we are asked to support.
A UAE subsidiary acquired by a US listed group
The acquisition closes and the SOX calendar arrives with it. The first year is the hardest because control design, ownership and evidence all have to be established at once, usually alongside a systems integration.
A group preparing for a US listing
Readiness work ahead of a listing is considerably cheaper than remediation afterwards, because there is no auditor opinion at stake yet and no public disclosure consequence attached to a finding.
A regional entity selected for testing this year
Locations are risk assessed and varied year to year, so an entity that was out of scope last year can be in scope this year. Being ready in advance is the only response that works, because notice is often short.
An entity that had findings last year
Remediation has to be evidenced as operating, not merely implemented. That means the new control needs enough of the year behind it to produce a testable population, which is why remediation timing is a planning question.
A business relying heavily on automated controls
An automated control is generally expected to be lower risk where relevant IT general controls are effective. Where ITGCs are not effective, that reliance collapses and the testing burden shifts back onto manual procedures.
A team told their statutory audit evidence is not enough
It usually is not, because the purpose differs. Statutory control testing informs the audit approach, while SOX testing supports a published opinion, and the evidence expectations follow from that difference rather than from auditor preference.
How UAE subsidiaries approach their first SOX year.
| Feature | Prepared before interim | Reacting to requests | Assuming statutory experience covers it |
|---|---|---|---|
Control owners named | Yes | During testing | No |
Evidence located in advance | Yes | Under time pressure | No |
Self testing performed | Yes | No | No |
Findings surfaced early | At interim | At year end | By the auditor |
Time to remediate and evidence | Available | Limited | None |
Group coordination | Continuous | Escalation driven | Absent |
Risk of a material weakness | Low | Moderate | Elevated |
Effort during year end | Manageable | Heavy | Crisis |
Second year effort | Lower | Similar | Higher |
Position with the group | Reliable | Watched | A problem entity |
A control is only as good as the population an auditor can sample from.
Almost every first year finding we see is about evidence rather than about whether the control operates.
- The population has to be complete and demonstrably so. An auditor selecting a sample needs confidence that the list it came from contains every instance, which means being able to explain how the list was produced and why nothing is missing from it.
- Each item has to show the control operating, not merely that a policy exists. An approval workflow record with a requester, an approver, a date and an outcome is evidence. A policy document stating that approvals are required is not, however well written it is.
- Retention has to reach year end testing. Logs rotated after thirty days cannot support a sample drawn in month nine, and this is discovered during testing rather than during design in a large proportion of first year programmes.
- And the evidence has to be retrievable by somebody other than the person who built the system. Where retrieval depends on one engineer writing an ad hoc query, availability becomes a staffing risk in the middle of an audit timetable.
Five steps, aligned to the audit timetable rather than to ours.
- 1
Confirm scope with the group
Which systems support significant accounts and disclosures, whether this entity is in scope for the current year, and which entity-level controls the group tests centrally. Locations are risk assessed and varied year to year, so this is confirmed rather than assumed.
- 2
Document control design and name owners
Access, change and operations controls around each in scope system, each with a named individual owner who knows they own it. Anonymous team ownership is the most reliable predictor of a control that nobody can evidence when asked.
- 3
Establish the evidence position
For each control, what the evidence is, where it lives, whether the population is complete and demonstrably so, and whether retention extends through year end testing. This step prevents more findings than any other.
- 4
Self test before the auditor does
Sampling your own controls the way the auditor will, so gaps are found while there is still time to remediate and to build a population showing the corrected control operating. Interim is the last comfortable moment for that.
- 5
Support interim and roll-forward
Coordinated responses to requests, changes since interim documented so roll-forward procedures hold, and remediated controls evidenced as operating. Then a short review capturing what to do differently in the following cycle.
What UAE teams ask about SOX ITGC.
Fifteen questions to answer before interim testing.
Scope
- Which systems support significant accounts?That defines ITGC scope.
- Are we in scope this year?Locations vary year to year.
- What does the group test centrally?Avoid duplicating it.
- Which entity-level controls apply to us?They must be tested.
- Have any systems changed mid year?Roll-forward depends on it.
Evidence
- Can we evidence every access approval?Not just the policy.
- Do change records tie to approvals?And to deployments.
- Can we prove population completeness?A frequent challenge.
- Are logs retained long enough?Through to year end testing.
- Have we sampled ourselves first?Before the auditor does.
People and process
- Does every control have a named owner?Not a team name.
- Do owners know they own it?Frequently not.
- Who coordinates with the group?A single point.
- Is there time to remediate?Findings need operating evidence.
- What happens when someone leaves?Ownership must transfer.
Pick one access control and produce evidence of it operating six months ago.
If that takes more than an hour, or the evidence no longer exists, you have found the finding your first SOX year would otherwise have found for you.
Related Services
Explore more solutions that work great with this service
IT General Controls
What your external auditor tests, and the evidence they sample
Access Rights Review
Certification that removes access, not one that gets approved
Audit Readiness Assessment
Run the audit before the auditor does
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Privileged Access Audit
Every privileged path, not just the admin list
IT Risk Assessment
A short register with an owner against every risk
Gap Assessment
Distance to a target you actually have to meet
Compliance as a Service
Keeping the position true between assessments