HomeComplianceCanadian SOX

Canadian SOX and NI 52-109 IT controls

North Star helps Canadian organizations document, test, and improve the technology controls that support reliable financial reporting. The work is designed around accountable owners and usable evidence—not a claim that an IT provider can certify an issuer.

Clarify the term

“Canadian SOX” commonly points to NI 52-109

Canadian searchers often use “Canadian SOX” as shorthand when looking for controls related to financial reporting. The applicable Canadian instrument is National Instrument 52-109, Certification of Disclosure in Issuers' Annual and Interim Filings. The instrument and its companion policy address issuer certification, disclosure controls and procedures, and internal control over financial reporting. Applicability and management's obligations should be confirmed with securities counsel and the organization's auditors.

System and data scope

Identify applications, integrations, spreadsheets, databases, infrastructure, service providers, and manual processes that can affect financial reporting. Record owners and dependencies before testing controls.

Logical access

Review user provisioning, role design, privileged access, segregation concerns, MFA, shared accounts, periodic access reviews, emergency access, and timely removal when duties change.

Change management

Document requests, approvals, development, testing, migration, emergency changes, and evidence. The process should cover configuration, code, integrations, reports, and infrastructure that can affect relevant data.

Computer operations

Assess scheduled jobs, interfaces, monitoring, incident handling, backups, restoration, vulnerability remediation, and capacity. Exceptions need owners, impact assessment, and evidence of resolution.

Third-party services

Map vendors to control objectives, contracts, service reports, complementary user controls, subservice organizations, data access, incident notification, and exit procedures.

Evidence and remediation

Define what demonstrates operation, where evidence is retained, who reviews it, how exceptions are evaluated, and how remediation is tracked through retesting and closure.

Practical engagement

From inherited systems to a testable control set

North Star begins by agreeing on scope with management, finance, IT, legal counsel, and auditors as appropriate. We document the current environment and map technology activities to the control objectives supplied by the organization. We can then help close technical gaps, produce operating procedures, assign evidence owners, and establish a review calendar.

Deliverables may include an IT system inventory, risk and control matrix, access and change-management procedures, evidence index, vendor responsibility register, backup and recovery test results, exception log, remediation plan, and status reporting. Work can be completed remotely across Canada. Physical work is quoted separately and scheduled honestly from Prince George or Grande Prairie.

Boundaries matter

North Star does not provide legal opinions, financial-statement audit services, issuer certification, or independent assurance. Management, legal counsel, and the organization's auditors determine applicability, materiality, testing reliance, and reporting conclusions. Our role is technical assessment, implementation, documentation, evidence support, and ongoing operation within an agreed scope.

Related services

Keep overlapping compliance intents separated

SOC 2 readiness

Use the SOC 2 page for service-organization trust criteria and readiness work; it is not the owner for Canadian SOX searches.

Managed compliance support

Use the managed compliance page for recurring evidence collection, review calendars, ownership, and remediation follow-through.

Cybersecurity services

Use the cybersecurity hub for security risk assessment and controls that are broader than financial-reporting scope.

Primary source

Official Canadian securities guidance

Make the IT control environment testable

Bring the reporting scope, systems, service providers, existing controls, known exceptions, and deadlines. North Star will define a practical technical work plan.

Request an assessment