
If your parent company is publicly traded in the U.S., your Mexican subsidiary is also subject to SOX. The 5 IT controls (ITGCs) that an auditor will ask about and the most common findings.
If your parent company is listed on a U.S. stock exchange, the Sarbanes-Oxley Act (SOX) does not stop at the border. Section 404 requires management to certify the effectiveness of internal controls over financial reporting—and if the results of your Mexican plant or subsidiary are consolidated into the group’s financial statements, its internal controls, including IT controls, fall directly within the scope of that certification.
In practice, this means that an external auditor (usually one of the major accounting firms) will request concrete evidence that the systems supporting your plant’s financial operations in Mexico are controlled with the same rigor as those at the parent company—regardless of whether the local IT team consists of three people and the parent company’s IT team consists of three hundred.
ITGC (IT General Controls) are at the heart of SOX's technology requirements. They are grouped into five areas:
Common reference frameworks: COSO or COBIT—not because the auditor requires you to formally adopt them, but because they are the common language the auditor will use to evaluate your controls.
In our IT audits of subsidiaries of international groups in Mexico, the same five issues come up time and time again:
None of these findings are unusual—they are, almost word for word, what we documented in an actual audit of a group with seven Mexican subsidiaries (you can read the anonymized details here). The difference in a SOX context is that these findings are no longer just recommendations for improvement: they are control deficiencies that the external auditor must report.
Beyond the theory, the list of evidence that a Big Four auditor typically requests from a Mexican subsidiary includes: a control matrix with each ITGC mapped to its supporting evidence; change tickets for each relevant modification during the period; evidence of quarterly access reviews; the password policy as configured in the system (not just the document); and exportable logs covering the entire fiscal year, not just the current quarter.
A Mexican plant or subsidiary of a U.S. public company does not need to replicate the parent company’s compliance team—it needs an IT partner that understands the language of SOX and knows how to translate it into concrete, documented, and sustainable controls with a small local team. This is exactly the area where we work with nearshoring clients at U.S. plants and subsidiaries in Mexico.
Learn about our IT audit, designed to get your subsidiary ready before the external auditor arrives, or review the 15 most common findings we encounter in audits of subsidiaries in Mexico.
30 minutes with one of our directors. No sales pitch—straight to the point.