Scrutineer.ai

Scrutineer · By framework

SOX compliance software for Section 404 controls, ITGC testing and evidence

SOX compliance lives or dies on evidence. Sarbanes-Oxley Section 404 asks you to show that internal control over financial reporting was designed well and actually operated, and the IT general controls behind your financial systems (access, change management and operations) are where most findings come from. The controls usually exist. Proving they ran, every quarter, without a manual scramble, is the hard part.

Scrutineer maps your ITGCs and process-level controls to the SOX control objectives you are testing, pulls the supporting evidence from your identity, cloud and ticketing systems, and tracks each test and remediation item to close. Control owners see what is due, gaps surface while there is still time to fix them, and your external auditor gets an organized, current evidence package instead of a folder of screenshots. Scrutineer is readiness and decision support: your independent registered public accounting firm audits ICFR and issues the opinion.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with SOX compliance

ITGCs mapped, not guessed

Access, change management and IT operations controls are mapped to the Section 404 objectives they support, so you can see coverage across every in-scope financial system rather than reconstructing it in a spreadsheet.

Evidence pulled every period

User access reviews, change approvals and job-failure logs are collected automatically as they happen, so quarterly testing draws on a continuous record instead of a backfill.

Deficiencies caught early

When a control misses a period or evidence goes stale, Scrutineer flags it and tracks remediation to close, so a control gap does not become a significant deficiency in the audit.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps ITGCs and process controls to Section 404 objectives
  • Collects access, change and operations evidence automatically
  • Tracks control testing by period with named owners
  • Flags missed control executions and stale evidence
  • Prioritizes remediation before the external audit
  • Produces an organized evidence package for your auditor
SOX COMPLIANCE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Good questions

Questions about SOX compliance

SOX compliance software maps the internal controls over financial reporting required by Sarbanes-Oxley Section 404, collects the evidence that proves each control operated, and tracks testing and remediation. It replaces the spreadsheets and screenshot folders most teams use to prepare for the ICFR audit.
No tool can. Scrutineer keeps your controls mapped, your evidence current and your deficiencies tracked to close, which is what readiness means. Management still asserts on ICFR and an independent registered public accounting firm performs the audit. Scrutineer is not legal or accounting advice.
The three domains auditors focus on: logical access (provisioning, deprovisioning and periodic access reviews), change management (approvals, testing and segregation of duties in your deployment pipeline), and IT operations (backups, job monitoring and incident handling) for the systems in your financial reporting scope.
SOX 404 compliance means satisfying Section 404 of the Sarbanes-Oxley Act, which covers internal control over financial reporting. Section 404(a) requires management to assess ICFR effectiveness and report the conclusion in the annual report. Section 404(b) requires the company's independent PCAOB-registered auditor to attest to that assessment. In practice the work is documenting your controls, testing that they operated across the year, and evidencing both.
Who has to sign. 404(a) is management's own assessment of ICFR and applies to essentially every SEC reporting company. 404(b) adds an independent auditor attestation on top, and it only applies to accelerated and large accelerated filers. Non-accelerated filers were permanently exempted from 404(b) by the Dodd-Frank Act in 2010, and SEC amendments adopted March 12, 2020 pulled more low-revenue smaller reporting companies out of accelerated filer status as well. Emerging growth companies are generally exempt from 404(b) for up to five years after IPO. The distinction decides whether you are budgeting for an internal assessment or an external audit.
Accelerated filers, meaning a public float of $75 million to under $700 million, and large accelerated filers at $700 million or more. Below those thresholds a non-accelerated filer still owes the 404(a) management assessment but not the auditor attestation. Filer status is recalculated, so a company can cross into 404(b) after a good year, which is the moment thin control documentation becomes expensive. Confirm your own status with your counsel or auditor; the thresholds interact with smaller reporting company and emerging growth company rules.
They divide into entity-level controls, business process controls over significant accounts, and IT general controls over the systems those processes run on. The ITGC layer is where most software-driven companies concentrate: access to programs and data, change management, and computer operations. An ITGC failure is serious out of proportion to its size, because if change control is broken the auditor cannot rely on any automated control or report from that system.
SOX is a law that obliges a public company to assess its own internal control over financial reporting. SOC 1 is a voluntary examination a service organization commissions so that its customers can rely on its controls. They meet in the middle: when a public company outsources something that touches its numbers, the SOC 1 report from that provider becomes part of how the company supports its own SOX 404 assessment.
Not on its own, and this is a common misreading. A SOC 1 gives management and its auditors evidence about controls at one service organization for one period. Management still has to assess the controls it operates itself, confirm the report period covers its own year, obtain a bridge letter for any gap, and implement the complementary user entity controls the report assumes. A SOC 1 is an input to a SOX assessment, not a substitute for one.
Any third party performing a process that affects your financial statements: payroll processing, billing and receivables, claims administration, loan servicing, fund administration, benefit plan recordkeeping, and increasingly cloud platforms that calculate or hold financial data. If the provider could cause a misstatement in your books, its controls are in scope for your assessment and you should be collecting its SOC 1 annually.
Yes, and the overlap is larger than most teams assume. Logical access, change management and IT operations are the same IT general controls in all three programs, and they are usually the majority of the testing burden. What differs is the layer above: SOX adds process controls over financial reporting, SOC 1 adds control objectives you write yourself, and SOC 2 adds the Trust Services Criteria. One evidence base can serve all three.
Testing is proving a control operated throughout the period, not that it exists today. Testers select a sample from the whole year and examine the artifact behind each item: the approval on a change ticket, the reviewer sign-off on an access review, the resolution of a failed job. Because it is period-based, evidence assembled in the weeks before fieldwork is the most common source of exceptions. Continuous collection is what makes a sample easy to satisfy.

Keep reading

Guides that go deeper on SOX and IT general controls

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification