IT Audit Software Consulting
IT audit software is the category of tools internal audit and IT risk teams use to plan, execute, and document technology-focused audits — most centrally, the IT general controls (ITGCs) that underpin SOX Section 404 reliance on application controls. That includes access review and recertification workflows, change-management testing, control-testing workpapers, and issue-tracking through remediation. For a SOX programme, IT audit software is not optional tooling layered on top of the ERP — it is the system of record an external auditor will expect to see when they ask how access provisioning, segregation of duties, and configuration change control were tested during the fiscal year.
Why ITGCs are the load-bearing wall of a SOX audit
PCAOB AS 2201 directs auditors to evaluate whether a company's controls over financial reporting are designed and operating effectively, and it explicitly requires the auditor to test the IT general controls that support automated application controls before they can rely on those application controls. If access to post a journal entry, change a vendor bank account, or override a three-way match is not properly restricted and logged, an auditor cannot trust that the application control enforcing segregation of duties is operating as designed — no matter how well the ERP is configured. This is why ITGC testing (access provisioning and deprovisioning, periodic access recertification, change management for financially relevant configuration, and backup/recovery) sits upstream of nearly every other control test in a SOX walkthrough.
IT audit software exists to make that testing repeatable and evidenced rather than reconstructed each cycle from email threads and spreadsheet extracts. A mature IT audit tool maintains a control library mapped to COSO 2013 components, schedules recurring test procedures (quarterly access reviews, change-ticket sampling), stores workpapers with reviewer sign-off, and tracks deficiencies from identification through management's remediation plan and retest. Without it, IT audit teams typically rebuild the same evidence trail manually every quarter, which is both labor-intensive and a common source of testing gaps an external auditor will flag.
Core capabilities that separate audit-grade tools from generic ITSM
General-purpose IT service management (ITSM) platforms track tickets; they were not built to prove control operation to a PCAOB-registered auditor. Audit-grade IT audit software adds a few specific capabilities: risk-based audit planning that ties individual test procedures back to a documented risk assessment, sampling methodology support (statistical or judgmental, with the rationale preserved), workpaper templates with mandatory reviewer sign-off before a test can be marked complete, and an audit trail on the workpapers themselves — who changed what test conclusion, and when, matters when the auditor questions a prior-period result.
Integration with the ERP and identity systems is the second differentiator. Tools that can pull user-access data, role assignments, and change logs directly from SAP, Oracle, Dynamics 365, or the identity provider (Okta, Entra ID) reduce the manual export-and-reconcile work that introduces both delay and error into quarterly testing cycles. Tools that rely entirely on manual data upload push that reconciliation burden onto the IT audit team every single testing period, which scales poorly once an organization has more than one or two in-scope ERP instances.
Where IT audit software fits relative to GRC and access-governance tools
IT audit software, GRC (governance, risk, and compliance) platforms, and identity/access-governance tools overlap but answer different questions. GRC platforms (ServiceNow GRC, Archer, MetricStream) are typically the enterprise system of record for the full risk and control matrix across all SOX-in-scope processes, not just IT. Identity governance tools (SailPoint, Saviynt) automate access certification and SoD conflict detection at the identity layer. IT audit software is often the layer that plans and documents the testing itself — sometimes standalone (AuditBoard, Workiva, TeamMate+), sometimes a module inside a broader GRC suite.
The practical decision for most IT audit teams is not which single tool covers everything, but which combination avoids duplicate data entry. A common pattern is an access-governance tool feeding certification results into the audit-management platform's workpapers automatically, rather than an auditor re-keying the same access review conclusion into two systems. Evaluating IT audit software in isolation from the identity and ERP layer it has to pull evidence from is the most common cause of a tool selection that looks good in a demo and creates rework in production.
What actually differentiates the options
- ·Native connectors (or a documented API) to the in-scope ERP(s) and identity provider, so access and change-log evidence can be pulled rather than manually exported each quarter.
- ·Configurable control library mapped to COSO 2013 components and, where relevant, PCAOB AS 2201 language, so control descriptions match what an external auditor expects to see.
- ·Workpaper-level audit trail — reviewer sign-off, timestamped conclusion changes, and version history — since testing conclusions themselves get questioned in a PCAOB inspection.
- ·Deficiency and remediation tracking that links a control exception to a documented management action plan and a retest date, not just an open issue log.
- ·Support for both statistical and judgmental sampling methodologies with the rationale captured in the workpaper, not just the sample result.
- ·Role-based access within the tool itself that separates preparer and reviewer functions — an IT audit tool with no internal segregation of duties is an awkward credibility gap during your own SOX walkthrough.
Requirement, control, evidence
| Requirement | Control | Evidence |
|---|---|---|
| External auditor reliance on automated application controls (PCAOB AS 2201) | Documented ITGC testing covering access provisioning, change management, and computer operations for each in-scope system. | ITGC workpapers with test procedures, sample selections, and reviewer sign-off stored in the audit software's system of record. |
| Access must be restricted to authorized users consistent with job duties (supports ICFR) | Quarterly user access recertification performed by system and process owners. | Recertification campaign results exported or synced from the identity/access tool into the audit workpaper, with exceptions tracked to closure. |
| Configuration changes to financially relevant systems must be authorized and tested before deployment | Change-ticket sampling comparing a population of production changes against approved change requests. | Sample testing workpaper showing ticket ID, requester, approver, and deployment date reconciled to the change management system log. |
| Identified control deficiencies must be evaluated and remediated on a tracked timeline | Issue and remediation tracking workflow linking each deficiency to a management action plan and retest. | Issue log with severity rating, remediation owner, target date, and closure evidence attached in the audit platform. |
What this actually costs
| Cost driver | Low | High | What moves it |
|---|---|---|---|
| IT audit software licensing (platform + connector modules) | $25,000/yr | $120,000/yr | Scales with number of named users, number of connected systems, and whether the vendor charges per in-scope entity. |
| Implementation and ERP/identity integration build-out | $20,000 | $90,000 | Higher when connecting multiple ERP instances or legacy systems without a native connector, requiring custom API work. |
| Ongoing ITGC testing labor (internal audit or co-source) | $40,000/yr | $200,000/yr | Driven by number of in-scope applications, testing frequency, and whether work is performed internally or by a co-source provider. |
- · Ranges assume a mid-market to large-enterprise environment with one to three in-scope ERP instances; more entities or platforms trend toward the high end.
- · Figures are illustrative estimates based on typical engagement patterns, not vendor quotes or pricing commitments from any specific software provider.
- · Labor estimates reflect testing effort only and exclude remediation project costs, which are covered separately under ERP configuration remediation.
A representative scenario
A hypothetical financial services company with two ERP instances (a legacy on-premise platform and a newer cloud ERP acquired through a merger) is preparing for its second year of 404(b) testing. In year one, ITGC evidence was assembled manually — access lists exported to spreadsheets, change tickets pulled from three different systems and reconciled by hand. The external auditor's year-one management letter noted inconsistent evidence formatting and two instances where sample selections could not be re-traced to source data. In year two, the internal audit team implements IT audit software with API connectors to both ERPs and the identity provider, standardizes the control library against COSO 2013, and enforces reviewer sign-off before any test conclusion is finalized. This kind of consolidation — collapsing manual, multi-system evidence gathering into a single connected workpaper environment after a first-year audit surfaces evidence-quality issues — is a common trigger for IT audit software adoption and is described here as illustrative, not as a specific client engagement.
Common questions
No specific software is required by SOX or PCAOB AS 2201 — the requirement is that ITGC testing be performed and evidenced in a way an auditor can independently verify. In practice, most organizations past a certain scale adopt dedicated IT audit software because spreadsheet-based evidence collection does not hold up well under repeated audit cycles or PCAOB inspection scrutiny.
Book an assessment
Get a scoping call on it audit software for your organisation's platform and entity structure.
Book an Assessment →