← Back to Guides
SOX Compliance
August 15, 2026

SOX and IT Controls: What Your Subsidiary in Mexico Must Demonstrate to the U.S.

If your parent company is publicly traded in the U.S., your Mexican subsidiary is also subject to SOX. The 5 IT controls (ITGCs) that an auditor will ask about and the most common findings.

Why Your Plant in Mexico Is Also Subject to SOX

If your parent company is listed on a U.S. stock exchange, the Sarbanes-Oxley Act (SOX) does not stop at the border. Section 404 requires management to certify the effectiveness of internal controls over financial reporting—and if the results of your Mexican plant or subsidiary are consolidated into the group’s financial statements, its internal controls, including IT controls, fall directly within the scope of that certification.

In practice, this means that an external auditor (usually one of the major accounting firms) will request concrete evidence that the systems supporting your plant’s financial operations in Mexico are controlled with the same rigor as those at the parent company—regardless of whether the local IT team consists of three people and the parent company’s IT team consists of three hundred.

The 5 General IT Controls (ITGCs) an auditor will ask for

ITGC (IT General Controls) are at the heart of SOX's technology requirements. They are grouped into five areas:

  • Administrator Account Management. Who has elevated privileges, who authorized them, and how they are reviewed on a regular basis.
  • Software lifecycle management. Ensure that every change—from a ERP update to a configuration adjustment—is planned, authorized, tested, and documented before it is implemented.
  • Patch management. Identification, acquisition, and verifiable deployment of security updates for servers, operating systems, and applications.
  • Access controls. Password policies and identity authentication to restrict unauthorized access to every application that handles financial information.
  • Audit trail. Ensure that all transactions and changes to the systems are recorded and available for future review.

Common reference frameworks: COSO or COBIT—not because the auditor requires you to formally adopt them, but because they are the common language the auditor will use to evaluate your controls.

The most common findings in Mexican subsidiaries

In our IT audits of subsidiaries of international groups in Mexico, the same five issues come up time and time again:

  • Shared or generic administrator accounts ("admin," "support") with no way to track who used them.
  • There is no formal change management process —adjustments to the ERP or the accounting system are made “because they were needed,” without a ticket or documented authorization.
  • ERP s that are never reviewed after initial setup—employees who have changed positions or left the company retain permissions that no longer apply to them.
  • Lack of auditable logs beyond a few weeks, when the auditor will request evidence covering the entire fiscal year.
  • Password policies documented in the matrix but not technically implemented on local systems.

None of these findings are unusual—they are, almost word for word, what we documented in an actual audit of a group with seven Mexican subsidiaries (you can read the anonymized details here). The difference in a SOX context is that these findings are no longer just recommendations for improvement: they are control deficiencies that the external auditor must report.

What the auditors will literally ask you for

Beyond the theory, the list of evidence that a Big Four auditor typically requests from a Mexican subsidiary includes: a control matrix with each ITGC mapped to its supporting evidence; change tickets for each relevant modification during the period; evidence of quarterly access reviews; the password policy as configured in the system (not just the document); and exportable logs covering the entire fiscal year, not just the current quarter.

Checklist Before the Next Audit

  • Are there any shared administrator accounts on your financial systems? Remove them before the auditor finds them.
  • Is there a record (even a simple one) of every change made to ERP in the last 12 months?
  • When was the last time you reviewed the access rights of users who are no longer with the company?
  • Do your system logs cover the entire fiscal year, or are they overwritten every few weeks?
  • Does the corporate document's password policy match what the system actually allows?

Prepare Before the Auditor Arrives

A Mexican plant or subsidiary of a U.S. public company does not need to replicate the parent company’s compliance team—it needs an IT partner that understands the language of SOX and knows how to translate it into concrete, documented, and sustainable controls with a small local team. This is exactly the area where we work with nearshoring clients at U.S. plants and subsidiaries in Mexico.

Learn about our IT audit, designed to get your subsidiary ready before the external auditor arrives, or review the 15 most common findings we encounter in audits of subsidiaries in Mexico.

Do you need specific help with this topic?

30 minutes with one of our directors. No sales pitch—straight to the point.

Free Diagnosis · 30 minQuote within 24 hours