Oracle IT Audit Software Consulting
Oracle IT audit software is the tooling used to test the IT general controls (ITGCs) that sit underneath every application-level SOX control in an Oracle Fusion Cloud ERP or E-Business Suite (EBS) environment — access provisioning and deprovisioning, change management over financially relevant configuration, and system operations controls like backup and job scheduling. Unlike application controls (three-way match, approval routing), ITGCs are infrastructure-level: if they fail, an auditor cannot rely on any application control that depends on them, regardless of how well that application control is designed. For Oracle specifically, ITGC testing splits along the same Fusion/EBS line as everything else — Fusion Cloud ERP shifts a meaningful share of infrastructure ITGCs to Oracle as the SaaS provider, while EBS leaves nearly all of them with the customer.
Why ITGCs matter more than they seem to for a compliance-focused reader
The PCAOB's audit approach is layered: application controls (segregation of duties, approval workflows, three-way match) are only as reliable as the ITGCs that protect the systems running them. If access provisioning is uncontrolled, a user can be granted — and quietly have removed after testing — the exact combination of duties that would otherwise be flagged by Advanced Access Controls. If change management is uncontrolled, a configuration change can silently disable an approval threshold between one testing cycle and the next. An auditor who finds an ITGC deficiency typically has to expand testing on every application control downstream of it, which is why ITGC failures are disproportionately expensive relative to their apparent scope.
IT audit software exists to make ITGC testing systematic rather than ad hoc: pulling access logs, provisioning/deprovisioning records, change tickets, and system configuration snapshots into a structured testing workflow with defined attributes, sample sizes, and sign-off — the same workpaper discipline application controls get, applied to the infrastructure layer.
What differs between Fusion Cloud ERP and E-Business Suite for ITGC scope
Fusion Cloud ERP is Oracle-managed SaaS, which means physical security, database administration, patching cadence, and infrastructure change management for the underlying platform are Oracle's responsibility, typically evidenced through Oracle's own SOC 1 Type II report rather than customer-performed testing. The customer's ITGC scope narrows to what the customer actually controls: user access provisioning and deprovisioning within Fusion's security console, configuration changes to customer-owned setup (approval hierarchies, flexfields, tax rules, security roles), and monitoring of the Application Audit Trail for those objects. IT audit software for a Fusion-only environment is largely testing customer-side access and configuration-change controls, with Oracle's SOC 1 report substituting for infrastructure-level ITGC testing the customer would otherwise have to perform itself.
E-Business Suite, run on customer-managed or customer-controlled infrastructure (on-premises or IaaS-hosted), keeps essentially the full ITGC scope with the customer: database access, patch management, backup and recovery, job scheduling, and change promotion between environments, in addition to the same application-level access and configuration controls Fusion also requires. IT audit software for an EBS environment has to cover this wider infrastructure surface, typically pulling from database access logs, DBA activity logs, and the patch/migration tracking system rather than relying on a vendor SOC report to cover any of it.
Access provisioning and deprovisioning as the highest-frequency ITGC finding
Across both Fusion and EBS, the single most common ITGC deficiency in practice is deprovisioning — access removed late or not at all when an employee changes roles or leaves. Oracle's role-based access model (job role/duty role/data role in Fusion, responsibility-based in EBS) makes provisioning relatively easy to test because it is a discrete, logged event tied to a request. Deprovisioning is harder because it depends on an HR trigger reaching IT reliably, and Oracle's own tools do not enforce that a termination in HR actually results in account deactivation in the ERP unless that integration has been explicitly built and tested.
IT audit software that tests this control well pulls a population of terminations or role changes from HR data, matches it against the Fusion or EBS access-removal timestamp, and flags any gap beyond the organization's defined SLA — typically a small number of business days. Testing that instead samples only active users and checks whether their current access looks reasonable misses this failure mode entirely, because it never examines whether access was removed on time for people who no longer need it.
What actually differentiates the options
- ·The platform can test access provisioning and deprovisioning against an independent population source (HR terminations, role-change records), not just a point-in-time review of current access.
- ·For Fusion Cloud ERP, the platform's scope correctly narrows customer-tested ITGCs to customer-controlled areas and incorporates Oracle's SOC 1 Type II report for infrastructure-level controls rather than duplicating testing Oracle already covers.
- ·For E-Business Suite, the platform covers the full infrastructure ITGC surface — database access, patch management, change promotion — not just application-level access and configuration.
- ·Change-management testing can trace a sample of production changes back to an approved change ticket with an approver distinct from the requester, across both Fusion configuration changes and EBS patches/customizations.
- ·The platform integrates with or ingests Oracle's Application Audit Trail and Setup and Maintenance change history rather than relying on manually compiled change logs.
Requirement, control, evidence
| Requirement | Control | Evidence |
|---|---|---|
| ITGC — access provisioning must be authorized and logged | New user access in Fusion or EBS requires a documented request and approval before provisioning, executed through Oracle's role-assignment workflow. | Sample of new-hire or role-change access requests matched to the corresponding Oracle provisioning timestamp and approver. |
| ITGC — access deprovisioning must occur within a defined SLA | Terminated or transferred employees have Fusion/EBS access removed or reduced within a defined number of business days of the HR trigger. | Population of terminations/transfers from HR data cross-referenced to Oracle access-removal timestamps, with exceptions beyond SLA documented and remediated. |
| ITGC — infrastructure controls for SaaS-hosted Fusion Cloud ERP | Reliance on Oracle's SOC 1 Type II report for infrastructure-level controls (physical security, DB administration, platform patching) that Oracle, not the customer, operates. | Current Oracle SOC 1 Type II report reviewed for scope, exceptions, and complementary user-entity controls (CUECs) the customer must independently perform. |
| ITGC — change management for EBS-hosted infrastructure and customizations | Database patches, PL/SQL customizations, and Forms personalizations promoted through a documented environment-migration process with an approver distinct from the requester. | Sample of production changes traced to a change ticket, approval record, and promotion log, retained for the audit period. |
What this actually costs
| Cost driver | Low | High | What moves it |
|---|---|---|---|
| ITGC scoping assessment (Fusion Cloud ERP or EBS infrastructure) | $40,000 | $120,000 | Fusion-only environments trend toward the low end since infrastructure ITGCs shift to Oracle's SOC 1 report; EBS or hybrid environments trend toward the high end. |
| Deprovisioning control remediation (HR-to-Oracle integration and SLA enforcement) | $60,000 | $200,000 | Driven by whether an automated HR feed exists already or needs to be built, and number of business units with independent access-request processes. |
| IT audit software licensing and ongoing ITGC testing | $45,000/yr | $160,000/yr | Includes platform cost, quarterly access-population testing, and change-management sampling; higher end reflects EBS or hybrid Fusion/EBS scope. |
- · Ranges assume a single primary Oracle environment; parallel Fusion/EBS environments during migration trend toward or beyond the high end for all three drivers.
- · Figures are illustrative estimates based on typical mid-market to large-enterprise Oracle engagements, not a quote for a specific organization.
- · Costs exclude Oracle license fees for Risk Management Cloud modules and reflect advisory, integration, and testing labor only.
A representative scenario
A hypothetical healthcare services company running Oracle Fusion Cloud ERP passes its first two years of SOX testing on application controls but has never independently tested deprovisioning as an ITGC — the assumption internally was that Fusion's SaaS model meant Oracle handled it. During a first 404(b) year, IT audit testing that pulls a population of terminations from HR and matches it against Fusion access-removal timestamps typically finds a meaningful minority of terminated employees — commonly in the range of 5-15% of the sample — retained active Fusion access beyond the organization's stated SLA, usually because deprovisioning depended on a manual ticket from HR to IT rather than an automated feed. Remediation typically involves building a direct HR-to-Fusion deprovisioning integration or at minimum a daily reconciliation report, plus retesting the corrected population before the auditor's sample is drawn. The recurring lesson in this pattern is that SaaS ERP shifts infrastructure ITGCs to the vendor but does not touch access lifecycle controls, which remain entirely the customer's responsibility. This scenario is illustrative of a common finding pattern, not a specific client engagement.
Common questions
An ITGC is an infrastructure-level control — access provisioning, change management, system operations — that the application controls depend on to function reliably. An application control (three-way match, approval routing, segregation of duties) operates inside Oracle Fusion or EBS itself. If an ITGC fails, auditors generally cannot rely on the application controls layered on top of it, regardless of how well those application controls are designed.
Book an assessment
Get a scoping call on oracle it audit software for your organisation's platform and entity structure.
Book an Assessment →