General Controls and Sampling 1644

  • I’ve got the following scenario, please provide feedback on the question below:
    I am testing Change Management. There is only a population of 5 changes from in-scope Sox apps/platforms.
    Do I?:
    a) sample 25 more changes from non-Sox apps/platforms (our guidance calls for a sample of 30) or
    b) just use the 5 from Sox apps/platforms?
    Any thoughts would be appreciated.

  • I would argue for option B

  • Absolutely agree. Youwould have 100% coverage and you can’t ask for more than that.

  • You just need to cover the changes for SOx critical appls. If your universe is just 5 samples, take them all. I would not test non-sox appls.

Log in to reply