| Engagement snapshot | |
|---|---|
| Client archetype | Indonesian manufacturing subsidiary of a US SEC-registrant multinational group |
| Service lines | IS audit and ITGC testing · SOX co-sourcing (IT scope) |
| Jurisdictions | United States (reporting regime) · Indonesia (fieldwork) |
| Engagement model | Co-sourced management testing for group internal audit |
| Duration band | Aligned to the group's annual SOX calendar |
| Frameworks | COSO 2013 · SEC Release 33-8810 · PCAOB AS 2201 and AS 1105 · 17 CFR 229.308 |
| Team shape | Partner-led; IS audit manager; IS auditors |
What was the challenge?
Management could not conclude on the subsidiary's automated controls until the IT general controls beneath them were tested. Group internal audit needed that evidence by application and ITGC domain, in group format.
| Challenge | Operational reality | Business risk |
|---|---|---|
| Undefined IT scope | ERP plus ancillary systems; no list of significant applications | A key control goes untested |
| Access and segregation of duties | Broad ERP roles; separate user stores in ancillary systems | One user can post and approve without detection |
| Change and operations | Transports, batch jobs and interfaces run by a small team | An unapproved change or failed job corrupts balances |
| Key reports (IPE) | Reviews rely on system-generated reports | A review performed on an incomplete report fails silently |
| Automated controls | Three-way match tolerances set in configuration | A tolerance changed without approval defeats the control |
How did JCSS Indonesia approach it?
We scoped from financially significant applications, then tested ITGC before automated controls.
Scope the IT footprint. We mapped systems and interfaces to the group's key controls under COSO 2013 Principle 11 and SEC Release 33-8810, which limits ITGC evaluation to the general controls other controls depend on. Artefact: application inventory.
Test ITGC by domain. We tested access, program changes, computer operations and program development by inquiry, observation, inspection and re-performance (AS 2201 .42–.45). Inquiry alone was never accepted (.50). Artefact: test scripts and access reconciliations.
Validate key reports. We tested source, parameters, logic, completeness and accuracy of each report supporting a control (AS 1105 .10). Artefact: IPE register.
Test automated controls and SoD. We inspected three-way match configuration and tolerances, re-performed with test transactions, and ran a segregation-of-duties conflict analysis. A configuration baseline lets later cycles test for change (AS 2201 .B28, benchmarking). Artefact: ITAC workpapers and SoD matrix.
Evaluate and aggregate deficiencies. We classified each exception against AS 2201 Appendix A, weighed compensating controls (.68) and combined related exceptions (.62). Artefact: deficiency evaluation memo; management owns the final classification.
Report and track remediation. We reported by application and domain for the Audit Committee pack. Artefact: deficiency log and remediation tracker, supporting the quarterly change evaluation in Rule 13a-15(d).
Why this approach: one process-level pass would have tested automated controls before ITGC were concluded, and pulled non-significant systems into scope. Testers stayed independent of control owners, so the external auditor can assess competence and objectivity (.18). Any reliance decision is the external auditor's.
How are IT control deficiencies classified?
Severity depends on whether there is a reasonable possibility of an undetected misstatement, and on its potential magnitude (AS 2201 .63).
| Class | AS 2201 definition (summary) | Paragraph | Illustrative IT example (not a finding) |
|---|---|---|---|
| Control deficiency | Design or operation of a control does not allow timely prevention or detection of misstatements | A3 | A leaver account disabled late, with a detective review in place |
| Significant deficiency | Less severe than a material weakness, yet merits attention by those overseeing financial reporting | A11 | Some changes to a significant application lack approval |
| Material weakness | Reasonable possibility that a material misstatement is not prevented or detected on a timely basis | A7 | Unrestricted production access with no change monitoring |
What were the results?
JCSS Indonesia delivered a complete IT SOX evidence file to group internal audit for management's year-end assessment.
| Result | What was delivered | What the client can now do |
|---|---|---|
| Defined IT scope | Application inventory with in/out rationale | Show why each system is in or out of scope |
| ITGC conclusions | A conclusion for each domain; every exception documented | Decide whether automated controls rest on effective ITGC |
| Tested key reports | IPE register for each in-scope report | Review controls on tested reports |
| Severity ranking | Deficiencies classified and aggregated in one memo | Present severity to the Audit Committee |
| Remediation | Tracker with owners, actions and retest status | Follow open items into the next quarter |
Which frameworks and regulations applied?
US rules govern the assessment; Indonesian law governs assurance and access evidence.
United States (governing regime)
- Sarbanes-Oxley Act 2002, Section 404 (15 U.S.C. 7262): management assessment and auditor attestation.
- 17 CFR 229.308 and 17 CFR 240.13a-15: management's report; quarterly changes.
- SEC Release 33-8810: management guidance.
- PCAOB AS 2201 and AS 1105: auditor standards.
- COSO Internal Control – Integrated Framework (2013): Principle 11.
Indonesia (fieldwork)
- UU 5/2011 on Akuntan Publik, Pasal 3: assurance reserved to public accountants.
- UU 27/2022 on Pelindungan Data Pribadi (personal data protection): handling of access evidence.
No tax treaty is engaged.
Key takeaways for CAEs and group controllers
- Scope IT from financially significant applications; each extra system adds ITGC testing no key control needs.
- Conclude ITGC before automated controls; an automated control is lower risk only when relevant ITGC are effective.
- Classify with AS 2201 Appendix A and aggregate related exceptions; the Audit Committee needs severity, not volume.
Frequently asked questions
Does SOX 404 apply to an Indonesian subsidiary of a US-listed group?
The obligation sits with the US registrant. Management assesses internal control over financial reporting for the consolidated statements under Section 404(a) and 17 CFR 240.13a-15(c), setting scope top-down and risk-based (SEC Release 33-8810). An Indonesian subsidiary is in scope where its accounts carry a reasonable risk of material misstatement.
Can JCSS Indonesia give an opinion on the subsidiary's internal controls?
No. Under UU 5/2011, Pasal 3(1) and (2), assurance services may be provided only by an Akuntan Publik (public accountant). JCSS Indonesia performs co-sourced management testing and reports test results. The external auditor's attestation under Section 404(b) is separate, and the auditor decides how far to use others' work (AS 2201 .16–.19).
Why test ITGC before automated application controls?
An automated control is generally lower risk if relevant IT general controls are effective (AS 2201 .47). If access or change controls fail, a correctly configured tolerance can be altered undetected. Testing ITGC first shows whether a configuration test of the automated control can stand alone.
Does UU 27/2022 affect access-control testing in Indonesia?
Yes. User listings and access logs contain employees' personal data. UU 27/2022 requires a controller to keep personal data confidential and prevent unauthorised access (Pasal 36, Pasal 39(1)). The two-year adjustment period under Pasal 74 ended on 17 Oct 2024. Confirm implementing rules with Indonesian counsel.
