Client Snapshot
A leading US-based global leader in CRM, marketing automation, and customer experience platforms, with a robust SaaS ecosystem supporting marketing, sales, customer service, and operations. As its technology environment evolved across multiple enterprise applications and interconnected systems, maintaining a consistent and effective IT control environment became increasingly complex. This created a growing need for greater assurance over technology controls and their effectiveness across critical business processes. The organization engaged Pierag for IT SOX internal audit co-sourcing and risk-based control testing to support its critical audit requirements.
The Challenge
- A complex, highly integrated SaaS environment required a comprehensive assessment of the IT control landscape from a SOX perspective.
- Critical ITGCs and application controls across access, operations, change management, and key business processes required robust risk-based testing.
- Existing control documentation and testing processes needed greater consistency and alignment ahead of critical audit milestones.
- The scale and complexity of the environment required stronger coordination and proactive risk visibility to support audit readiness.
Our Approach
- Mapped the IT landscape from a SOX perspective through detailed process walkthroughs with key stakeholders.
- Applied a risk-based testing methodology to focus assessment efforts on critical controls and business processes.
- Maintained regular touchpoints with internal audit leadership to enable timely issue identification and resolution. Aligned testing and documentation practices to support consistency, accountability, and audit requirements.
Results Delivered
- Refined the SOX control documentation across RCMs, test scripts, control descriptions, attribute checklists, and evidence trackers.
- Completed ITGC testing across User Access Management, Computer Operations, and Change Management.
- Performed point-in-time testing of key IT Application Controls across P2P, H2R, Fixed Assets, and other critical processes.
- Established structured audit workpapers, test sheets, and observation logs, with updates captured in audit tools.
Impact
The engagement strengthened the client’s overall IT control environment by improving the consistency of control documentation, testing practices, and audit alignment. A risk-prioritized approach provided greater visibility into the control landscape and supported stronger audit readiness, while embedded testing efficiencies and best practices created a more scalable foundation for future compliance cycles.