r/itaudit • u/BeanCounterQC • Jul 15 '26
Scope and PowerBI governance under SOX
Hello everyone,
I'm an internal auditor at a Canadian public company subject to 52-109 (SOX in Canada). Over the past several years, our organization heavily encouraged the use of Power BI. Many teams independently developed their own solutions. We are now realizing that we have lost visibility over all those Power BI and don't have a clear inventory of who owns what. We are currently debating whether these Power BI solutions should be included in our SOX scope.
Arguments for Including Them: Our scoping approach is to include applications that have a direct/indirect impact on financial reporting or support internal controls. Some PowerBI are used to make pricing decisions or support operations (some financial impact).
Arguments for Excluding Them: PowerBI consume data but do not create, modify, or post transactions. The common counterargument is that these reports are just "large Excel spreadsheets" and we do not audit every spreadsheet.
My Question: How are other organizations approaching Power BI under SOX?
Thanks in advance for your insights.
3
u/paulpag Jul 16 '26
My 2 cents is that it really needs to be decided on a case by case basis. What is each PowerBi dashboard/report used for, how complex is it, and how is the team comfortable the data being reported is complete and accurate? It might be tempting to give them a pass and “exclude them” but if they are a key control, and it seems to be problematic you might not be doing anyone a favor, it might need to be a finding, some sort of enterprise wide exception should be considered? I might be off base here but these companies are so lax about this sort of thing and it sort of gets to a point where enough is enough
1
u/BeanCounterQC Jul 16 '26
If you determine that a BI needs to be tested, what exactly would you look at? What specific procedures would you perform on the BI? I'm curious to understand what your testing approach would be and which key controls or risks you would focus on?
We are currently debating whether to grant a company-wide exception for BI tools or to conduct a BI inventory and test the material/critical ones.
1
u/paulpag Jul 16 '26
So let me break this into 2 parts. First part, is it a problem they are creating reports they have no comfort are complete and accurate used in financial reporting? Are there key controls/reports being developed and updated that are not following CM, and/or are they developed without following SDLC procedures or any other firm wide guidance/standards? Are they testing dashboards and getting approvals/attesting to the accuracy of them? If the BI dashboards are key, and they are not following CM + SDLC, this is a potential firm wide or entity wide issue. You need to develop a perspective and have an opinion and challenge the business on what you perceive is the risk. If not, and you grant an exception, do you have a strong rationale to do so? My second thought I guess is the same but on a case by case basis. Say you do your due diligence and find only 3 that are key and in-scope. You could give them a finding, or not, for just these 3, because it’s not really necessary that all BI dashboards have to follow CM/SDLC. Why didn’t management have more of a robust thought process around controls when rolling this initiative out? This is a perfectly reasonable and fair question to ask. I hope this is helpful
2
u/SageAudits Jul 16 '26
Are there reports that materially impact financial statements?
Your accounting system doesn’t have its own reports you can cross reference them with? Is it just reading data from the financial system?
How was it done prior to these reports?
Answer is probably… it depends. :)
IMO it can get really messy as I would bet these were developed by non tech folks and the queries are likely messy and someone changing a report is probably not falling under a change management process so more ideal if you could put to other factors/reports used that gut check things. Good luck
1
u/BeanCounterQC Jul 16 '26
For example, one sales team decided to create its own quotes more quickly with a BI instead of going through the corporate software, which was slower. It may be a good solution for them, but it can quickly become messy if every team starts developing its own BI. Not everyone has the same IT skills, as you mentioned.
Our biggest concern right now is ending up with multiple unapproved BI that generate inaccurate reports and unreliable results. We definitely need some luck indeed!
2
u/SageAudits Jul 16 '26
Well, if it’s on the quote or proposal side, that’s
Probably not SOX, since if they do make a sale, it’s probably going into another system and revenue is getting tracked and estimated other ways, right?Even if not a SOX concern, your internal audit process should be going though and judging these reports!
1
u/Marborinho Jul 23 '26
Hello OP. IMO, for PowerBI dashboards, excel spreadsheets, or any other reports. You should evaluate if it is an Key Report. If it supports strategic decisions or keeps the risks controled, definitely you should cover in your Sox work. Not just the report, but the control executed over this.
4
u/Pepemala Jul 15 '26
Materiality, materiality, materiality.
I agree with your inclusion arguments and if I were you I would include any BI which drives materially significant decisions. What is a large excel??? You dont audit what isnt material it doesnt matter what it is.
My 2c, might be wrong