• Manufacturing
  • ITGC
  • SOX
  • US / Indonesia

IT SOX Controls Testing for a US-Listed Group's Indonesian Subsidiary

A US-listed multinational needed IT general control and automated-control evidence from its Indonesian manufacturing subsidiary for management's SOX 404(a) assessment. JCSS Indonesia scoped the financially significant applications, tested ITGC and key automated controls under COSO 2013, and classified deficiencies against PCAOB AS 2201 definitions. Group internal audit received a severity-ranked IT evidence file. JCSS Indonesia issued no opinion.

Engagement snapshot
Client archetypeIndonesian manufacturing subsidiary of a US SEC-registrant multinational group
Service linesIS audit and ITGC testing · SOX co-sourcing (IT scope)
JurisdictionsUnited States (reporting regime) · Indonesia (fieldwork)
Engagement modelCo-sourced management testing for group internal audit
Duration bandAligned to the group's annual SOX calendar
FrameworksCOSO 2013 · SEC Release 33-8810 · PCAOB AS 2201 and AS 1105 · 17 CFR 229.308
Team shapePartner-led; IS audit manager; IS auditors

What was the challenge?

Management could not conclude on the subsidiary's automated controls until the IT general controls beneath them were tested. Group internal audit needed that evidence by application and ITGC domain, in group format.

ChallengeOperational realityBusiness risk
Undefined IT scopeERP plus ancillary systems; no list of significant applicationsA key control goes untested
Access and segregation of dutiesBroad ERP roles; separate user stores in ancillary systemsOne user can post and approve without detection
Change and operationsTransports, batch jobs and interfaces run by a small teamAn unapproved change or failed job corrupts balances
Key reports (IPE)Reviews rely on system-generated reportsA review performed on an incomplete report fails silently
Automated controlsThree-way match tolerances set in configurationA tolerance changed without approval defeats the control

How did JCSS Indonesia approach it?

We scoped from financially significant applications, then tested ITGC before automated controls.

  1. Scope the IT footprint. We mapped systems and interfaces to the group's key controls under COSO 2013 Principle 11 and SEC Release 33-8810, which limits ITGC evaluation to the general controls other controls depend on. Artefact: application inventory.

  2. Test ITGC by domain. We tested access, program changes, computer operations and program development by inquiry, observation, inspection and re-performance (AS 2201 .42–.45). Inquiry alone was never accepted (.50). Artefact: test scripts and access reconciliations.

  3. Validate key reports. We tested source, parameters, logic, completeness and accuracy of each report supporting a control (AS 1105 .10). Artefact: IPE register.

  4. Test automated controls and SoD. We inspected three-way match configuration and tolerances, re-performed with test transactions, and ran a segregation-of-duties conflict analysis. A configuration baseline lets later cycles test for change (AS 2201 .B28, benchmarking). Artefact: ITAC workpapers and SoD matrix.

  5. Evaluate and aggregate deficiencies. We classified each exception against AS 2201 Appendix A, weighed compensating controls (.68) and combined related exceptions (.62). Artefact: deficiency evaluation memo; management owns the final classification.

  6. Report and track remediation. We reported by application and domain for the Audit Committee pack. Artefact: deficiency log and remediation tracker, supporting the quarterly change evaluation in Rule 13a-15(d).

Why this approach: one process-level pass would have tested automated controls before ITGC were concluded, and pulled non-significant systems into scope. Testers stayed independent of control owners, so the external auditor can assess competence and objectivity (.18). Any reliance decision is the external auditor's.

How are IT control deficiencies classified?

Severity depends on whether there is a reasonable possibility of an undetected misstatement, and on its potential magnitude (AS 2201 .63).

ClassAS 2201 definition (summary)ParagraphIllustrative IT example (not a finding)
Control deficiencyDesign or operation of a control does not allow timely prevention or detection of misstatementsA3A leaver account disabled late, with a detective review in place
Significant deficiencyLess severe than a material weakness, yet merits attention by those overseeing financial reportingA11Some changes to a significant application lack approval
Material weaknessReasonable possibility that a material misstatement is not prevented or detected on a timely basisA7Unrestricted production access with no change monitoring

What were the results?

JCSS Indonesia delivered a complete IT SOX evidence file to group internal audit for management's year-end assessment.

ResultWhat was deliveredWhat the client can now do
Defined IT scopeApplication inventory with in/out rationaleShow why each system is in or out of scope
ITGC conclusionsA conclusion for each domain; every exception documentedDecide whether automated controls rest on effective ITGC
Tested key reportsIPE register for each in-scope reportReview controls on tested reports
Severity rankingDeficiencies classified and aggregated in one memoPresent severity to the Audit Committee
RemediationTracker with owners, actions and retest statusFollow open items into the next quarter

Which frameworks and regulations applied?

US rules govern the assessment; Indonesian law governs assurance and access evidence.

United States (governing regime)

Indonesia (fieldwork)

No tax treaty is engaged.

Key takeaways for CAEs and group controllers

  • Scope IT from financially significant applications; each extra system adds ITGC testing no key control needs.
  • Conclude ITGC before automated controls; an automated control is lower risk only when relevant ITGC are effective.
  • Classify with AS 2201 Appendix A and aggregate related exceptions; the Audit Committee needs severity, not volume.

Frequently asked questions

Does SOX 404 apply to an Indonesian subsidiary of a US-listed group?

The obligation sits with the US registrant. Management assesses internal control over financial reporting for the consolidated statements under Section 404(a) and 17 CFR 240.13a-15(c), setting scope top-down and risk-based (SEC Release 33-8810). An Indonesian subsidiary is in scope where its accounts carry a reasonable risk of material misstatement.

Can JCSS Indonesia give an opinion on the subsidiary's internal controls?

No. Under UU 5/2011, Pasal 3(1) and (2), assurance services may be provided only by an Akuntan Publik (public accountant). JCSS Indonesia performs co-sourced management testing and reports test results. The external auditor's attestation under Section 404(b) is separate, and the auditor decides how far to use others' work (AS 2201 .16–.19).

Why test ITGC before automated application controls?

An automated control is generally lower risk if relevant IT general controls are effective (AS 2201 .47). If access or change controls fail, a correctly configured tolerance can be altered undetected. Testing ITGC first shows whether a configuration test of the automated control can stand alone.

Does UU 27/2022 affect access-control testing in Indonesia?

Yes. User listings and access logs contain employees' personal data. UU 27/2022 requires a controller to keep personal data confidential and prevent unauthorised access (Pasal 36, Pasal 39(1)). The two-year adjustment period under Pasal 74 ended on 17 Oct 2024. Confirm implementing rules with Indonesian counsel.

How this case study was prepared: anonymised, based on the engagement record; regulations as in force at 02 Oct 2026; not legal or tax advice.

Client details are anonymised and the engagement is described with client confidentiality preserved. Last reviewed: 02 Oct 2026. Reviewed by: Managing Partner.