The Institute of Internal Auditors has unveiled new guidance intended to help companies and auditors scope the IT general controls that should be included in their annual assessments of internal controls over financial reporting under Sarbanes-Oxley.



