Workday and SOX §404: What IT Auditors Check and How to Pass
Workday processes payroll, manages headcount, and controls compensation data — all material to financial reporting. SOX §404 requires management to assess the effectiveness of the controls around that data. Here are the 12 ITGCs auditors test in every Workday review, the evidence each one requires, and exactly where to find it.

1. Why Workday is in SOX scope
Workday processes payroll (directly material to financial reporting), manages headcount and org structure (material to workforce cost reporting), and controls access to compensation and benefits data (material to benefits expense reporting). The tenant is in the §404 perimeter, full stop.
2. The four ITGC domains auditors test
- Logical Access Controls — who can access what; provisioning/deprovisioning; service-account scoping.
- Change Management — Preview testing before production promotion; documented change control; approval records.
- Computer Operations — integration monitoring; alert subscribers; integration failure response process.
- Program Development — peer review of new integration/configuration before go-live.
3. The 12 specific controls
- C1 — User access provisioning evidence.
- C2 — User access deprovisioning (#1 finding when termination date doesn't match Workday account deactivation date).
- C3 — Privileged access review.
- C4 — ISU access scope review.
- C5 — ISU UI session restriction ('Do Not Allow UI Sessions' must be checked).
- C6 — Integration monitoring (alert subscriber list and schedule run history).
- C7 — Configuration change management (Preview promotion records and change tickets).
- C8 — Segregation of duties (no single user in both Compensation Partner view and Payroll Partner modify).
- C9 — Password policy and ISU credential rotation records.
- C10 — Business process security (approval chain definitions for material transactions).
- C11 — Calculated field validation (no production fields in error state).
- C12 — SOC 2 review (Workday's SOC 1 Type II and complementary user entity controls).
4. Producing an auditor-ready evidence package
Use Workday's built-in reports for each control: 'View Security Groups,' 'Compare Security Permissions,' 'View Integration System User,' 'Integration Audit,' 'Business Process View,' 'All Calculated Fields.' Export each as evidence and tag with the control ID.

5. How Yoetz.ai covers C1–C11 in a single 2-hour scan
Every finding is automatically mapped to its SOX control ID, GDPR article, ISO 27001 Annex A control, and PCI-DSS requirement. The export is a formatted evidence package ready for SOX submission.
How SOX scoping decisions get made for Workday and why HRIT should be in the room
The decision about exactly which Workday functional areas and controls fall inside the SOX §404 perimeter is made by the internal audit or controllership function, typically in consultation with the external auditor, and is documented in a formal scoping memo at the start of each fiscal year's audit cycle. This scoping exercise determines materiality based on the dollar value flowing through a given process — payroll is almost universally in scope because of its direct financial statement impact, but the scoping of adjacent areas like benefits administration, equity compensation, or time tracking can vary based on materiality thresholds specific to your organisation's size and structure.
HRIT teams that are not involved in this annual scoping conversation frequently discover mid-audit that a functional area they did not expect to be tested is in scope, with no time to prepare evidence. Insist on a seat in the annual SOX scoping discussion specifically for Workday-related processes, and use that seat to flag any new functionality (a newly implemented compensation module, a new integration to a payroll processor) that may shift the scoping boundary before the audit cycle begins rather than after.
The management review control layer auditors increasingly test
Beyond the twelve technical ITGCs, SOX auditors increasingly test a category of control called management review controls (MRCs) — evidence that a human reviewer with appropriate authority actually reviewed and approved a given output, not just that the system produced a technically correct result. For Workday, this manifests as evidence that someone with appropriate seniority reviewed the quarterly access recertification results and signed off, that someone reviewed the population of terminated workers against the deactivation log and confirmed no discrepancies, and that someone reviewed the integration failure log on a defined cadence and confirmed no unresolved failures with financial impact remain open.
The distinction that trips organisations up is that an automated scan or system report satisfies the underlying data-gathering requirement but does not, by itself, satisfy the MRC requirement — the auditor wants evidence of a documented human review and sign-off on top of that data. Build a lightweight sign-off workflow around every recurring scan or report: the scan produces the evidence, a named reviewer with appropriate authority reviews it and documents their sign-off (even a simple dated email or a signed-off PDF export suffices), and that sign-off record is what gets filed as the actual control evidence alongside the underlying data.
Handling deficiencies found during your own testing before the auditor finds them
One of the most consequential decisions an HRIT and internal audit team makes is what happens when your own internal testing — whether manual or via an automated scan — surfaces a control deficiency before the external auditor's testing does. The instinct to quietly remediate before the auditor looks is understandable but risky if not handled correctly: SOX requires that identified deficiencies be evaluated for severity (deficiency, significant deficiency, or material weakness) and disclosed appropriately regardless of whether they were self-identified or auditor-identified. Self-identifying and remediating a deficiency before the audit, with clear documentation of the finding, the remediation, and the retest confirming the fix, is viewed favourably by auditors and by the audit committee — it demonstrates the control environment is working as intended, catching and fixing its own gaps.
What is not acceptable, and what creates real risk, is remediating a finding silently without documenting that it was ever found, because if the auditor's own testing later surfaces evidence that the same issue existed previously (an audit log showing the prior misconfigured state, for example), the appearance of concealment is far more damaging to the audit relationship than the original finding would have been. Document every self-identified deficiency and its remediation trail regardless of how quickly it gets fixed.
Coordinating Workday SOX evidence with the broader IT general controls environment
Workday does not exist in isolation from the rest of the enterprise IT control environment, and auditors will look for consistency across systems — if your organisation's broader ITGC framework requires quarterly access recertification with specific documentation standards for other financial systems, Workday's evidence package needs to meet the same bar, not a lighter one just because HRIT manages it separately from the core ERP or financial systems team. Coordinate with whichever team owns the overall SOX ITGC framework (often the internal audit function or a dedicated SOX compliance team) to confirm the Workday-specific evidence format, retention period, and review cadence align with what is expected enterprise-wide, rather than building a bespoke process in isolation that then needs to be reconciled or defended as an exception during the audit.
Preparing for the increasing scrutiny on AI-driven Workday features under SOX
As Workday's Illuminate AI capabilities move from announcement to production use — agents that can initiate business processes, recommend compensation changes, or process case management workflows autonomously — SOX auditors are beginning to ask new questions about the controls governing those agents specifically, distinct from the underlying configuration controls already discussed. Expect future audit cycles to test whether AI agent actions are logged with the same audit trail rigour as human-initiated transactions, whether there is a human-in-the-loop approval gate for agent-recommended actions that have material financial impact, and whether the training data or configuration inputs the agent relies on (job profiles, compensation bands, security models) are themselves subject to the same ITGC discipline described throughout this guide.
Organisations activating Illuminate agents ahead of building this evidentiary discipline around agent actions specifically are likely to face a gap when this scrutiny arrives, in much the same way that early cloud adopters faced a gap when auditors first began testing cloud-specific ITGCs a decade ago. Building the audit trail and human-approval-gate discipline into the initial agent rollout design, rather than retrofitting it after an auditor asks the question, is the lower-cost path.
Frequently asked questions
Does Yoetz.ai produce control-by-control evidence?
Yes — every finding maps to a specific SOX ITGC and exports as auditor-ready evidence.
Will the auditor accept automated evidence?
Yes, when paired with the source Workday report exports the scan references. Big 4 firms increasingly accept automated coverage as a basis for testing.
Can we use this for SOX 404(b) external auditor attestation?
Yes for evidence — the external auditor will still perform their own control testing on a sample.
How does this handle SoD across Workday Financials?
The scan extends to Financial Management security groups using the same connector.
How often should we run it?
Quarterly, plus once per Workday R1 and R2.
What does the auditor see?
A formatted PDF/CSV evidence package with one row per control, the test procedure, the Workday source, and the result.
Is HRIT typically included in the annual SOX scoping conversation, or is this an internal audit decision made in isolation?
It should be a joint conversation; HRIT input on new functionality and integration changes materially affects what should be in scope, and organisations that exclude HRIT from scoping frequently miss newly relevant controls.
What is a management review control and how is it different from the underlying report or scan?
An MRC is documented evidence that a qualified human reviewed and signed off on a control's output, distinct from the system-generated report or scan data itself, which satisfies data-gathering but not the human-oversight requirement auditors test for.
Should we disclose a control deficiency we found and fixed ourselves before the audit?
Yes, always document it with the finding, remediation, and retest evidence — self-identified and remediated deficiencies are viewed favourably, while undocumented silent fixes create risk if later discovered independently.
Will SOX audits start testing Workday Illuminate agent actions directly?
This is an emerging area of scrutiny as agentic features move to production; expect audit procedures to extend to agent audit trails and human-approval gates as adoption grows.
Continue reading
Find out what's broken in your tenant
Free first scan. Read-only access. Results in under 2 hours.
Start Your Free Scan