Measuring the pervasiveness of IT general controls: A model and empirical validation

Michel Benaroch · International Journal of Accounting Information Systems · 2025

Auditing IT general controls (ITGC) for Sarbanes-Oxley (SOX) compliance is challenging because all ITGCs are presumed to be pervasive and in need of detailed testing. However, some ITGCs are more pervasive than others and have a greater impact on financial reporting. We developed a network model of ITGCs embedded in a system of enterprise information systems (IS) processes and used network centrality metrics to score the pervasiveness of an ITGC based on its connectivity and its implied disruptive influence on the information flow needed for the IS process system to function as intended. We tested our pervasiveness scores by examining the equity market reactions to revelations of specific ITGC deficiencies that led to cyber incidents (e.g., data breaches, cyberattacks). We found a direct relationship between ITGC pervasiveness and equity market reactions, suggesting that equity market participants attach greater value-relevance to more pervasive ITGCs. Our pervasiveness scores also explained equity market reactions better than the “priority” scores senior IT auditors assign to testing (auditing) specific ITGCs based on their importance to SOX compliance. Our findings are robust and hold for 17-day event windows and for the pre- and post-SOX periods.

Read the paper · More papers on PaperTik