TL;DR: Identity governance and SOX compliance diverge because IT buys IGA for provisioning efficiency while audit needs entitlement-level evidence, complete application coverage, and auditor-reperformable control proof, according to SafePaaS. When audit is absent at scoping, coverage and reporting follow IT priorities instead of the SOX-in-scope application list, creating a structural compliance gap.
NHIMG editorial — based on content published by SafePaaS: Identity governance and SOX compliance coverage gaps
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: What breaks when audit is left out of IGA scoping for SOX?
A: The control boundary becomes an IT convenience boundary, so financially relevant applications and entitlements may never be governed, reviewed, or evidenced.
Q: When should organisations prioritise SOX coverage over IGA workflow automation?
A: Prioritise SOX coverage whenever an IGA programme touches financially relevant systems, because automation without complete population coverage can hide control gaps.
Q: How do you know if identity governance evidence will withstand SOX testing?
A: Evidence is defensible when access, approval, certification, SoD analysis, and remediation can be traced across the full control period without manual reconstruction.
Practitioner guidance
- Align IGA scope to the SOX application list Map every application currently onboarded in the IGA platform against the formal SOX in-scope list, then document the delta as a remediation backlog.
- Include audit in access-governance design reviews Bring SOX Program Leads and Internal Audit into certification design, evidence requirements, and onboarding prioritisation before any new scope is approved.
- Require entitlement-level evidence for financial systems Replace role-only reviews with entitlement detail that shows what the access can actually do in journals, payables, liabilities, and approval paths.
What's in the full article
SafePaaS's full analysis covers the operational detail this post intentionally leaves for the source:
- A practical comparison of IT-driven IGA objectives versus SOX evidence requirements for control owners.
- Detailed examples of entitlement-level access evidence that auditors expect during reperformance.
- A step-by-step gap analysis method for comparing current IGA onboarding against the SOX in-scope application list.
- Guidance on extending governance to missing applications without replacing the existing platform.
👉 Read SafePaaS's analysis of SOX coverage gaps in identity governance →
SOX identity governance gaps: what happens when audit is absent?
Explore further
Audit exclusion at scoping is the real control failure. The problem is not that IGA platforms cannot automate identity workflows. The failure is that the people who must prove SOX control effectiveness are often not present when application coverage and certification rules are defined. That means the control boundary is set by operational convenience, not financial risk. The practitioner conclusion is simple: if audit was absent at scoping, compliance coverage was never truly established.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Another 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which shows how quickly hidden access becomes a governance problem.
A question worth separating out:
Q: Who should own identity governance decisions for SOX compliance?
A: Ownership should be shared across IAM, SOX Program Leads, Internal Audit, and the relevant control owners for financial systems. IAM can operate the platform, but audit defines the evidence standard and SOX defines the risk boundary. If those functions are separated, coverage decisions will favour operational efficiency over control effectiveness.
👉 Read our full editorial: SOX identity governance breaks when audit is left out of scoping