The Institute of Internal Auditors has unveiled new guidance intended to help companies and auditors scope the IT general controls that should be included in their annual assessments of internal controls over financial reporting under Sarbanes-Oxley.

IT general controlsโ€”the controls that assure the proper operation of IT applications and automated controls and help protect data and programs from unauthorized changeโ€”comprise a substantial portion of internal and external auditorsโ€™ overall costs with Section 404. IIA leaders say assessing key IT general controls is critical, because failures can lead to material errors in financial statements, among other things.