Case Study — Fortune 500 Enterprise SaaS Company

Testing 100% of ITGC SOX Controls
With 70% Less Manual Effort

A Fortune 500 enterprise SaaS company re-engineered its SOX IT general controls program; moving from sample-based, spreadsheet-driven testing to AI-assisted, full-population validation with a complete evidence trail.

−70%
manual testing time
+15%
testing accuracy
100%
ITGC controls tested
~180
controls across 22 systems
The Challenge

The control population grew. The testing model didn’t.

The company's SOX program covered roughly 180 IT general controls spanning cloud ERP, the identity provider, source-control and CI/CD pipelines, cloud infrastructure, databases, and the ticketing system used to authorize changes and access. Each quarter, internal audit and SOX teams pulled access listings, change tickets, and job logs by hand, reconciled them in spreadsheets, and tested judgmental samples of 25 to 40 items per control. Sampling left blind spots across tens of thousands of access changes; manual reconciliation was slow and error-prone, with stale extracts and transposition errors driving rework; and evidence stored as thousands of screenshots took days to reproduce when the external auditor asked how a conclusion was reached.

The Torvia AI Solution

Existing test plans, run against complete populations.

Torvia connected read-only to the in-scope systems, pulled complete populations directly from source, executed the defined test steps, and generated review-ready workpapers with evidence linked to each attribute; all under a human-in-the-loop model where auditors review and approve every output. Rather than replacing the SOX methodology, Torvia was mapped onto it: existing control descriptions, risk ratings, and test plans were configured as Torvia test procedures across all four ITGC domains. Because every tested attribute links back to its origin, conclusions are reproducible on demand, and testers begin each cycle with a prioritized exception list instead of a backlog of evidence to assemble.

Controls at a Glance

Every gap closed with an owned, tested control.

Access to programs & data
Full-population access reviews, provisioning/deprovisioning vs. HR terminations, privileged-access and SoD analysis
Automated
Program changes
Every production deployment reconciled to an approved change ticket; unauthorized and after-the-fact changes detected
Automated
Program development
Approvals, testing sign-off, and go-live authorization evidenced for each in-scope project
Automated
Computer operations
Batch-job success/failure and remediation testing, backup completion, incident-to-resolution tracing over complete logs
Automated
We used to spend most of the cycle just assembling evidence. Now the population is already reconciled and the exceptions are waiting for us on day one. We test more controls, more completely, in a fraction of the time; and when the auditors ask how we got there, we can show them exactly.
— Director of Internal Audit & SOX Compliance
The Results

More coverage, less effort, stronger auditor reliance.

70% less manual testing time

Measured as total tester and reviewer hours against in-scope ITGC controls versus the prior cycle on a like-for-like basis.

15% better testing accuracy

Deterministic extraction and repeatable test logic cut tester exceptions, review notes, and auditor-identified manual errors.

Full-population coverage

Access, change, and operations controls moved from judgmental samples to full- or expanded-population testing.

Built for audit scrutiny

Human-in-the-loop review, source-linked evidence, COSO/IIA/AICPA alignment, and SOC 2 Type II controls; auditors reproduced results on request.

Why it matters

SOX compliance can be a by-product of good corporate governance, not an exercise performed for an external auditor. Torvia provides the opportunity to continuously test full-populations throughout the year; meaning you already know your compliance posture before an audit happens.

See it live

See it on your own controls.

Start a 45-day pilot at torvia.ai.