Instiq
Chapter 4 · IT governance & internal control·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

4.3J-SOX (the internal control reporting system)

Key points

Covers the internal control reporting system (J-SOX) under the Financial Instruments and Exchange Act—the mechanism in which management self-assesses the effectiveness of internal control over financial reporting, prepares and submits an internal control report, and an auditor audits it—building the judgment to diagnose scope narrowing (a top-down, risk-based approach) and deficiency classification (a material weakness that should be disclosed).

The internal control reporting system (J-SOX), under the Financial Instruments and Exchange Act, requires the management of a listed company to self-assess "whether its own internal control over financial reporting functions effectively" and to disclose the result as an internal control report. An external auditor (audit firm) then audits whether that report is fairly stated. Systems auditors and IT auditors are involved in this system because, in an era when much of financial reporting is processed by IT systems, IT controls determine the reliability of financial reporting. Grounded in the J-SOX framework, reasonable scope narrowing, and the classification of deficiencies by severity, this section builds the viewpoint from which an auditor decides "where to focus the evaluation."

4.3.1The J-SOX framework

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.