IDEAS home Printed from https://ideas.repec.org/a/eee/ijoais/v56y2025ics1467089525000284.html

Measuring the pervasiveness of IT general controls: A model and empirical validation

Author

Listed:
  • Benaroch, Michel

Abstract

Auditing IT general controls (ITGC) for Sarbanes-Oxley (SOX) compliance is challenging because all ITGCs are presumed to be pervasive and in need of detailed testing. However, some ITGCs are more pervasive than others and have a greater impact on financial reporting. We developed a network model of ITGCs embedded in a system of enterprise information systems (IS) processes and used network centrality metrics to score the pervasiveness of an ITGC based on its connectivity and its implied disruptive influence on the information flow needed for the IS process system to function as intended. We tested our pervasiveness scores by examining the equity market reactions to revelations of specific ITGC deficiencies that led to cyber incidents (e.g., data breaches, cyberattacks). We found a direct relationship between ITGC pervasiveness and equity market reactions, suggesting that equity market participants attach greater value-relevance to more pervasive ITGCs. Our pervasiveness scores also explained equity market reactions better than the “priority” scores senior IT auditors assign to testing (auditing) specific ITGCs based on their importance to SOX compliance. Our findings are robust and hold for 17-day event windows and for the pre- and post-SOX periods.

Suggested Citation

  • Benaroch, Michel, 2025. "Measuring the pervasiveness of IT general controls: A model and empirical validation," International Journal of Accounting Information Systems, Elsevier, vol. 56(C).
  • Handle: RePEc:eee:ijoais:v:56:y:2025:i:c:s1467089525000284
    DOI: 10.1016/j.accinf.2025.100752
    as

    Download full text from publisher

    File URL: http://www.sciencedirect.com/science/article/pii/S1467089525000284
    Download Restriction: Full text for ScienceDirect subscribers only

    File URL: https://libkey.io/10.1016/j.accinf.2025.100752?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to

    for a different version of it.

    References listed on IDEAS

    as
    1. Benaroch, Michel & Chernobai, Anna & Goldstein, James, 2012. "An internal control perspective on the market value consequences of IT operational risk events," International Journal of Accounting Information Systems, Elsevier, vol. 13(4), pages 357-381.
    2. Hollis Ashbaugh‐Skaife & Daniel W. Collins & William R. Kinney Jr & Ryan Lafond, 2009. "The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity," Journal of Accounting Research, John Wiley & Sons, Ltd., vol. 47(1), pages 1-43, March.
    3. Navarro, Patricia & Robb, Sean W.G. & Sutton, Steve G. & Weisner, Martin M., 2020. "The cost stickiness of information technology material weaknesses: An intertemporal comparison between it-related and other material weaknesses," International Journal of Accounting Information Systems, Elsevier, vol. 37(C).
    4. Mascha, Maureen Francis & Lamboy-Ruiz, Melvin A. & Janvrin, Diane J., 2018. "PCAOB inspections: An analysis of entity-level and application-level control audit deficiencies," International Journal of Accounting Information Systems, Elsevier, vol. 30(C), pages 19-39.
    5. Shapiro, Brian & Matson, Diane, 2008. "Strategies of resistance to internal control regulation," Accounting, Organizations and Society, Elsevier, vol. 33(2-3), pages 199-228.
    6. Austen, Lizabeth A. & Eilifsen, Aasmund & Messier Jr., William F., 2004. "Auditor Detected Misstatements and the Effect of Information Technology," Discussion Papers 2004/1, Norwegian School of Economics, Department of Business and Management Science.
    7. Kam Chan & Gary Kleinman & Picheng Lee, 2009. "The impact of Sarbanes‐Oxley on internal control remediation," International Journal of Accounting & Information Management, Emerald Group Publishing Limited, vol. 17(1), pages 53-65, June.
    8. Pierangelo Rosati & Fabian Gogolin & Theo Lynn, 2022. "Cyber-Security Incidents and Audit Quality," European Accounting Review, Taylor & Francis Journals, vol. 31(3), pages 701-728, May.
    9. Kamiya, Shinichi & Kang, Jun-Koo & Kim, Jungmin & Milidonis, Andreas & Stulz, René M., 2021. "Risk management, firm reputation, and the impact of successful cyberattacks on target firms," Journal of Financial Economics, Elsevier, vol. 139(3), pages 719-749.
    10. Eli Amir & Shai Levi & Tsafrir Livne, 2018. "Do firms underreport information on cyber-attacks? Evidence from capital markets," Review of Accounting Studies, Springer, vol. 23(3), pages 1177-1206, September.
    11. Stefano Azzali & Tatiana Mazza, 2013. "Internal Control Over Financial Reporting Quality and Information Technology Control Frameworks," Lecture Notes in Information Systems and Organization, in: Daniela Mancini & Eddy H. J. Vaassen & Renata Paola Dameri (ed.), Accounting Information Systems for Decision Making, edition 127, pages 47-62, Springer.
    12. repec:eme:maj000:02686900810899536 is not listed on IDEAS
    13. Kim, Yongtae & Park, Myung Seok, 2009. "Market uncertainty and disclosure of internal control deficiencies under the Sarbanes-Oxley Act," Journal of Accounting and Public Policy, Elsevier, vol. 28(5), pages 419-445, September.
    14. Fengyi Lin & Liming Guan & Wenchang Fang, 2010. "Critical Factors Affecting the Evaluation of Information Control Systems with the COBIT Framework," Emerging Markets Finance and Trade, Taylor & Francis Journals, vol. 46(1), pages 42-55, January.
    15. Stoel, M. Dale & Muhanna, Waleed A., 2011. "IT internal control weaknesses and firm performance: An organizational liability lens," International Journal of Accounting Information Systems, Elsevier, vol. 12(4), pages 280-304.
    16. Kam Chan & Gary Kleinman & Picheng Lee, 2009. "The impact of Sarbanes‐Oxley on internal control remediation," International Journal of Accounting & Information Management, Emerald Group Publishing Limited, vol. 17(1), pages 53-65, June.
    17. Gerry H. Grant & Karen C. Miller & Fatima Alali, 2008. "The effect of IT controls on financial reporting," Managerial Auditing Journal, Emerald Group Publishing, vol. 23(8), pages 803-823, September.
    18. Jacqueline S. Hammersley & Linda A. Myers & Catherine Shakespeare, 2008. "Market reactions to the disclosure of internal control weaknesses and to the characteristics of those weaknesses under section 302 of the Sarbanes Oxley Act of 2002," Review of Accounting Studies, Springer, vol. 13(1), pages 141-165, March.
    19. Ramayya Krishnan & James Peters & Rema Padman & David Kaplan, 2005. "On Data Reliability Assessment in Accounting Information Systems," Information Systems Research, INFORMS, vol. 16(3), pages 307-326, September.
    20. Gerry H. Grant & Karen C. Miller & Fatima Alali, 2008. "The effect of IT controls on financial reporting," Managerial Auditing Journal, Emerald Group Publishing Limited, vol. 23(8), pages 803-823, September.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Benaroch, Michel & Chernobai, Anna & Goldstein, James, 2012. "An internal control perspective on the market value consequences of IT operational risk events," International Journal of Accounting Information Systems, Elsevier, vol. 13(4), pages 357-381.
    2. Oliver Henk, 2020. "Internal control through the lens of institutional work: a systematic literature review," Journal of Management Control: Zeitschrift für Planung und Unternehmenssteuerung, Springer, vol. 31(3), pages 239-273, September.
    3. Saeed Rabea Baatwah & Mohammed Asiri & Mohammed Saleh Bajaher & Ayoob Alyafai & Salem Baajajah, 2026. "Thriving post-cyberattacks: the power of control, disclosure, and IT maturity," Electronic Commerce Research, Springer, vol. 26(2), pages 1705-1743, April.
    4. Chelsea Liu & Muhammad Ali Babar, 2026. "Corporate cybersecurity risk and data breaches: A systematic review of empirical research," Australian Journal of Management, Australian School of Business, vol. 51(1), pages 62-92, February.
    5. Mounia Boulhaga & Abdelfettah Bouri & Ahmed A. Elamer & Bassam A. Ibrahim, 2023. "Environmental, social and governance ratings and firm performance: The moderating role of internal control quality," Corporate Social Responsibility and Environmental Management, John Wiley & Sons, vol. 30(1), pages 134-145, January.
    6. Masoud, Najeb & Al-Utaibi, Ghassan, 2022. "The determinants of cybersecurity risk disclosure in firms’ financial reporting: Empirical evidence," Research in Economics, Elsevier, vol. 76(2), pages 131-140.
    7. Wang, Duo & Hu, Yunge & Li, Yanxi, 2026. "Cybersecurity risk and corporate maturity mismatch," International Review of Financial Analysis, Elsevier, vol. 109(C).
    8. Lisa Yao Liu, 2025. "Financial Statement Audits and Data Breaches," Management Science, INFORMS, vol. 71(8), pages 6340-6366, August.
    9. Trinh, Vu Quang & Elnahass, Marwa & Pasiouras, Fotios, 2025. "Personal traits of CEOs and cybersecurity-related disclosure," Journal of International Accounting, Auditing and Taxation, Elsevier, vol. 58(C).
    10. Wunhong Su & Liuzhen Zhang & Chao Ge & Shuai Chen, 2022. "Association between Internal Control and Sustainability: A Literature Review Based on the SOX Act Framework," Sustainability, MDPI, vol. 14(15), pages 1-30, August.
    11. Elsayed, Mohamed & Elshandidy, Tamer, 2021. "Internal control effectiveness, textual risk disclosure, and their usefulness: U.S. evidence," Advances in accounting, Elsevier, vol. 53(C).
    12. Jin, Justin & Li, Na & Liu, Suyi & Khalid Nainar, S.M., 2023. "Cyber attacks, discretionary loan loss provisions, and banks’ earnings management," Finance Research Letters, Elsevier, vol. 54(C).
    13. Lin, Weizheng & Wang, Chih-Wei & Li, Ying-Jie & Chen, Jian-Yun, 2025. "From green to digital: Exploring the role of ecological footprints on cybersecurity risk," Energy Economics, Elsevier, vol. 146(C).
    14. Joost Impink & Martien Lubberink & Bart Praag & David Veenman, 2012. "Did accelerated filing requirements and SOX Section 404 affect the timeliness of 10-K filings?," Review of Accounting Studies, Springer, vol. 17(2), pages 227-253, June.
    15. Fang-Nan Liao & Xiao-Li Ji & Zhi-Ping Wang, 2019. "Firms’ Sustainability: Does Economic Policy Uncertainty Affect Internal Control?," Sustainability, MDPI, vol. 11(3), pages 1-26, February.
    16. Martins, António Miguel & Moutinho, Nuno, 2025. "Stock-Term market impact of major cyber-attacks: Evidence for the ten most exposed insurance firms to cyber risk," Finance Research Letters, Elsevier, vol. 71(C).
    17. Feng, Yuan & Mao, Yihuan & Cai, Jing & Xu, Nan, 2024. "Can board IT expertise improve corporate internal control?," Finance Research Letters, Elsevier, vol. 62(PA).
    18. Rezaee, Zabihollah & Zhou, Gaoguang & Bu, Luofan (Luther), 2024. "Corporate social irresponsibility and the occurrence of data breaches: A stakeholder management perspective," International Journal of Accounting Information Systems, Elsevier, vol. 53(C).
    19. Lee, Chien-Chiang & Wang, Chih-Wei & Lin, Weizheng & Chen, En-Jia, 2025. "Cyber risk and corporate share repurchases," International Review of Financial Analysis, Elsevier, vol. 103(C).
    20. Vafeas, Nikos & Vlittis, Adamos, 2015. "Board influence on the selection of external accounting executives," The British Accounting Review, Elsevier, vol. 47(1), pages 46-65.

    More about this item

    Keywords

    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:eee:ijoais:v:56:y:2025:i:c:s1467089525000284. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Catherine Liu (email available below). General contact details of provider: https://www.journals.elsevier.com/international-journal-of-accounting-information-systems/ .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.