---
title: A Sarbanes-Oxley Audit Found Applications ServiceNow Never Flagged
description: An internal compliance audit found business applications that should have been in scope for Sarbanes-Oxley compliance weren't documented as such in the CMDB.
image: https://www.apexconfiguration.com/hubfs/AI-Generated%20Media/Images/Corporate%20Auditor%20Reviewing%20Report%20In%20Dusk%20Office.png
---

[![APEX CONFIGURATION GROUP](https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png?width=135&height=93&name=ACG-logo.png "APEX CONFIGURATION GROUP")](https://www.apexconfiguration.com/)

[![APEX CONFIGURATION GROUP](https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png?width=135&height=93&name=ACG-logo.png "APEX CONFIGURATION GROUP")](https://www.apexconfiguration.com/)

- [Home](https://www.apexconfiguration.com)
- ServiceNow
    - [ServiceNow CMDB](https://www.apexconfiguration.com/servicenow-cmdb)
    - [CMDB Health Check](https://www.apexconfiguration.com/cmdb-health-check)
    - [CMDB Design & Implementation](https://www.apexconfiguration.com/cmdb-design-implementation)
    - [Managed Service](https://www.apexconfiguration.com/managed-cmdb-services)
    - [Automation & Optimisation](https://www.apexconfiguration.com/cmdb-automation-tools)
- Maximising ServiceNow
    - [CMDB Health Dashboard](https://www.apexconfiguration.com/cmdb-health-dashboard-servicenow)
    - [CMDB Dependency Mapping](https://www.apexconfiguration.com/cmdb-relationship-table)
    - [CMDB Configuration Items](https://www.apexconfiguration.com/cmdb-configuration-items)
    - [CMDB Workspace](https://www.apexconfiguration.com/cmdb-workspace-servicenow)
    - [CMDB Best Practice](https://www.apexconfiguration.com/cmdb-best-practices)
    - [ServiceNow Discovery](https://www.apexconfiguration.com/servicenow-discovery-setup)
    - [Service Mapping](https://www.apexconfiguration.com/servicenow-service-mapping)
- About
    - [How We Help](https://www.apexconfiguration.com/about-apex)
    - [What is a CMDB?](https://www.apexconfiguration.com/what-is-cmdb)
    - [Benefits](https://www.apexconfiguration.com/benefits-of-cmdb)
- Resources
    - [Blog](https://www.apexconfiguration.com/blog)
    - [Contact Us](https://www.apexconfiguration.com/contact-us)

[Contact Us](https://www.apexconfiguration.com/contact-us)

[Contact Us](https://www.apexconfiguration.com/contact-us)

- [Home](https://www.apexconfiguration.com)
- ServiceNow

    - [ServiceNow CMDB](https://www.apexconfiguration.com/servicenow-cmdb)
    - [CMDB Health Check](https://www.apexconfiguration.com/cmdb-health-check)
    - [CMDB Design & Implementation](https://www.apexconfiguration.com/cmdb-design-implementation)
    - [Managed Service](https://www.apexconfiguration.com/managed-cmdb-services)
    - [Automation & Optimisation](https://www.apexconfiguration.com/cmdb-automation-tools)
- Maximising ServiceNow

    - [CMDB Health Dashboard](https://www.apexconfiguration.com/cmdb-health-dashboard-servicenow)
    - [CMDB Dependency Mapping](https://www.apexconfiguration.com/cmdb-relationship-table)
    - [CMDB Configuration Items](https://www.apexconfiguration.com/cmdb-configuration-items)
    - [CMDB Workspace](https://www.apexconfiguration.com/cmdb-workspace-servicenow)
    - [CMDB Best Practice](https://www.apexconfiguration.com/cmdb-best-practices)
    - [ServiceNow Discovery](https://www.apexconfiguration.com/servicenow-discovery-setup)
    - [Service Mapping](https://www.apexconfiguration.com/servicenow-service-mapping)
- About

    - [How We Help](https://www.apexconfiguration.com/about-apex)
    - [What is a CMDB?](https://www.apexconfiguration.com/what-is-cmdb)
    - [Benefits](https://www.apexconfiguration.com/benefits-of-cmdb)
- Resources

    - [Blog](https://www.apexconfiguration.com/blog)
    - [Contact Us](https://www.apexconfiguration.com/contact-us)

[Contact Us](https://www.apexconfiguration.com/contact-us)

[tel:+442080588135](tel:+442080588135)[mailto:contact@apexconfiguration.com](mailto:contact@apexconfiguration.com)<https://www.linkedin.com/company/apex-configuration-group>

[Case Studies](https://www.apexconfiguration.com/blog/tag/case-studies)[CMDB Data Quality](https://www.apexconfiguration.com/blog/tag/cmdb-data-quality)

[ServiceNow](https://www.apexconfiguration.com/blog/tag/servicenow)[IT Governance](https://www.apexconfiguration.com/blog/tag/it-governance)[Compliance & Audit](https://www.apexconfiguration.com/blog/tag/compliance-audit)

# A Sarbanes-Oxley Audit Found Applications ServiceNow Never Flagged

[![Iain Moone](https://www.apexconfiguration.com/hs-fs/hubfs/iain-moone.webp?width=40&height=40&name=iain-moone.webp)](https://www.apexconfiguration.com/blog/author/iain-moone)

by [Iain Moone](https://www.apexconfiguration.com/blog/author/iain-moone)

 7 min read

Oct 5, 2026, 9:00:00 AM

Last updated on 6 Oct 2026, 14:53:26

An internal compliance team ran its scheduled audit of the CMDB and found that most business applications needing to be in scope for Sarbanes-Oxley compliance weren't documented as in scope at all. Their underpinning infrastructure had no link back to the applications it supported. On paper, the compliance-critical part of the estate looked smaller than it actually was.

## Key Takeaways

- Sarbanes-Oxley scope isn't set once and left correct. It depends on what an application does now, and that changes as applications are built, extended and repurposed.
- An internal audit found that most applications needing to be in scope weren't flagged, and their underpinning infrastructure had no documented link to them.
- The gap stayed invisible because every application had a record and nothing in day-to-day operations needed the in-scope flag.
- The audit found it by checking what each application actually does against what its record said, instead of trusting the existing flags.
- Correcting the documentation cost the client $80,000 in Apex's fees, a fraction of what the same gap could cost if an external auditor or regulator found it first.
- The fix traced each application down to its real infrastructure, re-assessed scope against current function and linked the infrastructure explicitly. It also removed some applications from scope.

This wasn't a case of the configuration management database being empty or obviously wrong. For context on what a CMDB is supposed to hold and why that matters for audits like this one, see our guide to [what a CMDB is and how it works](https://www.apexconfiguration.com/what-is-cmdb). In this estate, the applications existed as records. What was missing was the classification and the linkage that would have told an auditor, or anyone else, that they mattered for compliance at all.

## How compliance scope goes missing without anyone noticing

Sarbanes-Oxley scope isn't a property that gets set once and stays correct. It depends on what a business application actually does, which changes as applications are built, extended and repurposed. If nothing in the CMDB process re-checks scope against current reality, the classification set at onboarding just persists, whether or not it's still accurate.

In this estate, that's what had happened. Applications that had grown into compliance-relevant territory, handling financial reporting data or processes that fed it, hadn't been reclassified. Their underpinning infrastructure, the servers and services actually running the compliance-relevant workload, had never been linked to them in the CMDB in the first place.

The result was a compliance picture that looked complete because every application had a record, the same failure pattern that shows up whenever a CMDB is graded on coverage rather than on accuracy.

It's worth being specific about what "underpinning infrastructure with no link" actually means in practice. The applications themselves were documented well enough: an application record existed, with an owner and a description. What was missing was the chain running from that application down through its technical services to the servers, databases and integrations actually processing the compliance-relevant data. Without that chain, flagging the application as in scope wouldn't have been enough on its own. An auditor still needs to know which infrastructure to include in a control review.

## How the audit found it

The client's internal compliance team audited the CMDB as part of routine Sarbanes-Oxley preparation. Rather than accepting the existing in-scope flags, the audit checked what applications actually did against what the CMDB said about them.

That comparison is where the gap surfaced. Most in-scope applications weren't flagged as in scope, and their underpinning infrastructure had no documented link to them at all. An auditor working from the CMDB's own classification would have missed most of the applications that needed to be reviewed.

The audit team's method matters on its own terms. Rather than sampling a handful of applications and extrapolating, they went through the estate's business applications systematically and asked, for each one, whether its function touched financial reporting. That's slower than trusting the existing flags, and it's the only way this kind of gap gets found before an external party finds it.

## What it would have cost to leave unfixed

Correcting the documentation cost the client $80,000 in Apex's fees. That's the cost of a proactive fix, found and corrected before an external audit or a regulator found it first. The client's own assessment was that a compliance violation, discovered externally rather than internally, could have cost many times that figure per violation.

That asymmetry is the reason this kind of audit is worth running before you're required to, in the same way a [CMDB health assessment](https://www.apexconfiguration.com/blog/cmdb-health-assessment-what-it-involves-and-what-it-risks) is cheaper before an incident than after one. An internal audit that finds a documentation gap is a fixable finding. The same gap, found by an external auditor or a regulator, is a different conversation entirely.

## What this looks like from the outside, before it's fixed

From day to day, none of this was visible. The applications ran normally. Financial reporting processes completed on schedule. Nothing about how the estate operated signalled that its compliance documentation was wrong, because the gap was in the paperwork trail, not in the applications themselves.

That's precisely what makes this kind of gap dangerous rather than merely untidy. A broken integration or a failed change announces itself. A missing compliance flag doesn't, right up until someone goes looking for it, whether that's an internal audit team doing its job properly or an external one doing the same thing on a schedule you don't control.

Nothing actually triggered a review in this case, even though it's usually assumed something would. No incident referenced the missing classification. No change was rejected because an application's compliance status was unclear. The applications simply operated, correctly, without anyone needing to consult their in-scope flag for day-to-day purposes. The flag only mattered the moment someone needed it for its actual purpose, which is exactly the profile of a gap that a purely operational monitoring approach, watching for incidents and failed changes, will never catch.

## How Apex documented the applications correctly

The fix used the same top-down, pattern-based [service mapping](https://www.apexconfiguration.com/servicenow-service-mapping) approach Apex applies wherever tagging or manual classification has let scope drift from reality, the same underlying discipline covered in [what to check in a CMDB audit when data can't be trusted](https://www.apexconfiguration.com/blog/cmdb-audit-servicenow-data-integrity-checks):

- **Trace from the business application down to its actual infrastructure.** Rather than trusting existing classification, Apex mapped what each compliance-relevant application actually depends on, using pattern-based discovery rather than self-reported tags.
- **Re-assess in-scope status against what the application does now, not what it was built to do.** Applications change scope as they're extended. The reclassification checked current function, not the original onboarding record.
- **Link underpinning infrastructure explicitly, so scope travels with the dependency.** Once an application is correctly flagged as in scope, its infrastructure needs the same status, or an auditor tracing from the application still won't find everything that matters.

The output wasn't just a corrected classification field. It was a documented, traceable link between each in-scope application and the infrastructure underneath it, in a form an auditor could actually follow.

That last point is where a lot of remediation work falls short. It's possible to correct a classification field without changing what an auditor can actually see when they trace an application down. The work here treated the traceability itself as the deliverable, not the flag, because a flag with nothing underpinning it fails the same audit again the next time someone checks.

The reclassification work also produced a shorter list than the client expected going in. A handful of applications that had been flagged as in scope for years no longer met the criteria, because what they did had changed since onboarding in the other direction too. Compliance scope drift isn't only a one-way problem where applications quietly become relevant without anyone noticing. An accurate, current picture removes applications from scope as readily as it adds them, which matters for audit workload as much as for risk.

## What this means before your next compliance audit

If your CMDB's compliance scope was set once, at onboarding, and hasn't been re-checked against what applications actually do today, that's worth treating as a live risk rather than a historical decision. The gap doesn't show up in day-to-day operations. It shows up in an audit, and the cost of finding it yourself is a fraction of the cost of someone else finding it first.

## How Apex helps

We run a CMDB health baseline over two weeks that produces a scored report on which configuration items and application classifications are trustworthy, suitable for taking straight to your change advisory board or your compliance team ahead of an audit.

Book a [CMDB diagnostic call](https://www.apexconfiguration.com/cmdb-diagnostic-call) to talk through your current compliance scope, or go straight to [booking a meeting](https://www.apexconfiguration.com/book-a-meeting).

## Frequently asked questions

### How often should Sarbanes-Oxley scope be reassessed in the CMDB?

At minimum whenever an in-scope application changes function meaningfully, and as a matter of course during any scheduled compliance audit. Treating scope as a one-off classification set at onboarding is the pattern that produced this gap.

### Why wasn't the underpinning infrastructure linked to the applications already?

The applications had been documented as records, but the dependency mapping connecting them to their actual infrastructure hadn't kept pace, the same gap that shows up in change impact analysis when service maps are built by tagging rather than by tracing dependencies.

### Is this specific to Sarbanes-Oxley, or does it apply to other compliance frameworks?

The specific regulation varies, but the pattern doesn't. Any framework that depends on the CMDB correctly identifying in-scope applications and their infrastructure is exposed to the same kind of drift if scope isn't actively re-checked.

### Can this kind of audit be run without disrupting live systems?

Yes. The work is discovery and documentation against existing infrastructure and application records. It doesn't require changes to production systems, though the corrected classifications and links do need to be reviewed and approved before they're relied on for an actual audit.

*Written by Iain Moone, Apex Configuration Group.*

Book a free call to discuss how Apex can help you on your journey to a better CMDB

 

[![\<p\>CMDB Diagnostic Call\</p\>](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/147949153/interactive-378363509978.png)](https://www.apexconfiguration.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKDM3p2aCtimexEnp%2B4Bqoo00Vx4hjIN4707PQPwtJePezj7uy6h2ziBsu8p1aaaHtjYCi%2Bb7sMKJMNh2HtxPP806VpLhwHa9In8tH5YIekJoxnkfxblU2xRY%2BoSFxN%2Fh796hMG7yljJZ2lDRPwjVUp1K%2F7imRI1B4CtH7cfG1DMMnB%2Bmgk7XVQ6tZ4GTM9N9%2BpShvdOIyX8ocTcx8%2FxNretvZtWnaIFmYDQKvP93A%3D&webInteractiveContentId=378363509978&portalId=147949153)

- Recent
- Topics
- Archive

Recent

### Recent

Topics

### Topics

- [ServiceNow (33)](https://www.apexconfiguration.com/blog/tag/servicenow)
- [CMDB (25)](https://www.apexconfiguration.com/blog/tag/cmdb)
- [CMDB Data Quality (11)](https://www.apexconfiguration.com/blog/tag/cmdb-data-quality)
- [Case Studies (5)](https://www.apexconfiguration.com/blog/tag/case-studies)
- [Duplicate CIs (5)](https://www.apexconfiguration.com/blog/tag/duplicate-cis)
- [CI Ownership (4)](https://www.apexconfiguration.com/blog/tag/ci-ownership)
- [Change Management (4)](https://www.apexconfiguration.com/blog/tag/change-management)
- [Compliance & Audit (4)](https://www.apexconfiguration.com/blog/tag/compliance-audit)
- [Service Mapping (4)](https://www.apexconfiguration.com/blog/tag/service-mapping)
- [Vulnerability Management (4)](https://www.apexconfiguration.com/blog/tag/vulnerability-management)
- [Agentic AI (3)](https://www.apexconfiguration.com/blog/tag/agentic-ai)
- [Data Model Design (3)](https://www.apexconfiguration.com/blog/tag/data-model-design)
- [Enterprise Risk Management (3)](https://www.apexconfiguration.com/blog/tag/enterprise-risk-management)
- [IRE (3)](https://www.apexconfiguration.com/blog/tag/ire)
- [IT Governance (3)](https://www.apexconfiguration.com/blog/tag/it-governance)
- [Incident Management (3)](https://www.apexconfiguration.com/blog/tag/incident-management)
- [Service Graph Connectors (3)](https://www.apexconfiguration.com/blog/tag/service-graph-connectors)
- [ServiceNow Discovery (3)](https://www.apexconfiguration.com/blog/tag/servicenow-discovery)
- [Cyber Security (2)](https://www.apexconfiguration.com/blog/tag/cyber-security)
- [Dependency Views (2)](https://www.apexconfiguration.com/blog/tag/dependency-views)
- [IT Cost Optimisation (2)](https://www.apexconfiguration.com/blog/tag/it-cost-optimisation)
- [Problem Management (2)](https://www.apexconfiguration.com/blog/tag/problem-management)
- [CI Reconciliation (1)](https://www.apexconfiguration.com/blog/tag/ci-reconciliation)
- [CMDB Remediation (1)](https://www.apexconfiguration.com/blog/tag/cmdb-remediation)
- [CSDM (1)](https://www.apexconfiguration.com/blog/tag/csdm)
- [Configuration Management (1)](https://www.apexconfiguration.com/blog/tag/configuration-management)
- [IT Asset Management (1)](https://www.apexconfiguration.com/blog/tag/it-asset-management)
- [ITOM (1)](https://www.apexconfiguration.com/blog/tag/itom)
- [Manufacturing (1)](https://www.apexconfiguration.com/blog/tag/manufacturing)
- [Operational Efficiency (1)](https://www.apexconfiguration.com/blog/tag/operational-efficiency)
- [ServiceNow Advisory (1)](https://www.apexconfiguration.com/blog/tag/servicenow-advisory)

See all

Archive

### Archive

- [October 2026 (6)](https://www.apexconfiguration.com/blog/archive/2026/10)
- [September 2026 (16)](https://www.apexconfiguration.com/blog/archive/2026/09)
- [August 2026 (2)](https://www.apexconfiguration.com/blog/archive/2026/08)
- [July 2026 (4)](https://www.apexconfiguration.com/blog/archive/2026/07)
- [June 2026 (3)](https://www.apexconfiguration.com/blog/archive/2026/06)
- [May 2026 (2)](https://www.apexconfiguration.com/blog/archive/2026/05)

See all

### Subscribe by email

Share this

[Share on X](https://x.com/intent/post?url=https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications&text=A+Sarbanes-Oxley+Audit+Found+Applications+ServiceNow+Never+Flagged) [Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications&t=A+Sarbanes-Oxley+Audit+Found+Applications+ServiceNow+Never+Flagged) [Share on LinkedIn](https://www.linkedin.com/shareArticle?mini=true&url=https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications&t=A+Sarbanes-Oxley+Audit+Found+Applications+ServiceNow+Never+Flagged)

Previous story

[← Run Discovery Before Your CMDB Is Ready And You Get Duplicates](https://www.apexconfiguration.com/blog/discovery-rollout-duplicate-cis)

<https://www.apexconfiguration.com/blog>

Next story

[The Patch Task Assigned To An Owner Who Had Left →](https://www.apexconfiguration.com/blog/patch-task-owner-who-had-left)

![Iain Moone](https://www.apexconfiguration.com/hs-fs/hubfs/iain-moone.webp?width=64&height=64&name=iain-moone.webp)

By [Iain Moone](https://www.apexconfiguration.com/blog/author/iain-moone)

Before founding Apex Configuration Group, I held senior global roles including Director, Global Head of SACM, and CMDB Architect within complex, regulated, multi-national environments. I help large…

[Full profile & credentials →](https://www.apexconfiguration.com/blog/author/iain-moone)

## You May Also Like

These Related Stories

[The 3 Cs of a CMDB: Completeness, Correctness and Compliance](https://www.apexconfiguration.com/blog/the-3-cs-of-a-cmdb-completeness-correctness-and-compliance-in-practice)

![IT consultant reviewing configuration data in a server room, illustrating the 3 Cs of CMDB data quality](https://www.apexconfiguration.com/hs-fs/hubfs/AI-Generated%20Media/Images/Datacenter%20Interior%20with%20Tech%20Workers-1.png?width=480&name=Datacenter%20Interior%20with%20Tech%20Workers-1.png)

[CMDB](https://www.apexconfiguration.com/blog/tag/cmdb)

### The 3 Cs of a CMDB: Completeness, Correctness and Compliance

Jun 24, 2026, 12:13:23 PM 8 min read

[Bad CMDB Data Leads To False Patch Compliance](https://www.apexconfiguration.com/blog/false-patch-compliance-cmdb-data)

![Patch compliance dashboard showing a mismatch between patched servers and the CMDB record count, illustrating false patch compliance from bad CMDB data](https://www.apexconfiguration.com/hs-fs/hubfs/AI-Generated%20Media/Images/Office%20Worker%20in%20Blonde%20Short%20Skirt%20Suit.png?width=480&name=Office%20Worker%20in%20Blonde%20Short%20Skirt%20Suit.png)

[CMDB](https://www.apexconfiguration.com/blog/tag/cmdb)

### Bad CMDB Data Leads To False Patch Compliance

Sep 16, 2026, 8:41:30 AM 8 min read

[CMDB Audit In ServiceNow: What To Check When Data Can’t Be Trusted](https://www.apexconfiguration.com/blog/cmdb-audit-servicenow-data-integrity-checks)

![A laptop with a connected data network and security icons overlay, showing CMDB governance.](https://www.apexconfiguration.com/hs-fs/hubfs/CMDB-audit-in-Service-Now-what-to-check-when-your-data-cannot-be-trusted.jpg?width=480&name=CMDB-audit-in-Service-Now-what-to-check-when-your-data-cannot-be-trusted.jpg)

[CMDB](https://www.apexconfiguration.com/blog/tag/cmdb)

### CMDB Audit In ServiceNow: What To Check When Data Can’t Be Trusted

Aug 20, 2026, 10:00:01 AM 4 min read

### Get Email Notifications

[![APEX CONFIGURATION GROUP](https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png?width=135&height=93&name=ACG-logo.png)](https://www.apexconfiguration.com/)

ServiceNow CMDB specialists delivering enterprise-grade implementation, remediation, and managed services.

Address: 20 Wenlock Road, London,  
England, N1 7GU

VAT Number: 505 0347 31

Company Number: 15871442

Email: [contact@apexconfiguration.com](mailto:contact@apexconfiguration.com)

<iframe title="Cyber Essentials certificate" style="margin: 0px; display: inline-block; border-image: initial; border: medium none currentcolor;" xml="lang" src="https://registry.blockmarktech.com/certificates/fb6a3f80-c037-4589-a043-1b781ef328f9/widget/?tooltip_position=top_left&amp;theme=transparent&amp;hover=t" width="114" height="140"></iframe>

[Follow Apex Configuration Group on LinkedIn](https://www.linkedin.com/company/apex-configuration-group)

Services

- [CMDB Health Check](https://www.apexconfiguration.com/cmdb-health-check)
- [Design & Implementation](https://www.apexconfiguration.com/cmdb-design-implementation)
- [Managed Service](https://www.apexconfiguration.com/managed-cmdb-services)
- [Automation & Optimisation](https://www.apexconfiguration.com/cmdb-automation-tools)
- [Health Dashboard & Reporting](https://www.apexconfiguration.com/cmdb-health-dashboard-servicenow)

Company

- [What is a CMDB?](https://www.apexconfiguration.com/what-is-cmdb)
- [Benefits](https://www.apexconfiguration.com/benefits-of-cmdb)
- [About](https://www.apexconfiguration.com/about-apex)
- [Blog](https://www.apexconfiguration.com/blog)

Resources

- [Contact Us](https://www.apexconfiguration.com/contact-us)
- [CMDB Diagnostic Call](https://www.apexconfiguration.com/cmdb-diagnostic-call)
- [Book A Meeting](https://www.apexconfiguration.com/book-a-meeting)

 © 2026 Apex Configuration Group. All rights reserved.

ServiceNow is a trademark of ServiceNow, Inc. We are not affiliated with or endorsed by ServiceNow.

- [Terms](https://www.apexconfiguration.com/terms)
- [Cookies](https://www.apexconfiguration.com/cookie-policy)
- [Privacy](https://www.apexconfiguration.com/privacy-policy)

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.apexconfiguration.com/#organization",
  "@type" : [ "Organization", "ProfessionalService" ],
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "GB",
    "addressLocality" : "London",
    "addressRegion" : "England",
    "postalCode" : "N1 7GU",
    "streetAddress" : "20 Wenlock Road"
  },
  "alternateName" : "Apex Configuration Group",
  "areaServed" : "GB",
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "GB",
    "availableLanguage" : "en",
    "contactType" : "customer service",
    "telephone" : "+44 20 8058 8135"
  },
  "identifier" : {
    "@type" : "PropertyValue",
    "propertyID" : "UK Companies House company number",
    "value" : "15871442"
  },
  "image" : "https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/Configuration-data.webp",
  "legalName" : "Apex Configuration Group Ltd",
  "logo" : "https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png",
  "name" : "Apex Configuration Group Ltd",
  "sameAs" : [ "https://www.linkedin.com/company/apex-configuration-group", "https://find-and-update.company-information.service.gov.uk/company/15871442", "https://www.crunchbase.com/organization/apex-configuration-group-ltd" ],
  "telephone" : "+44 20 8058 8135",
  "url" : "https://www.apexconfiguration.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.apexconfiguration.com/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-GB",
  "name" : "Apex Configuration Group",
  "publisher" : {
    "@id" : "https://www.apexconfiguration.com/#organization"
  },
  "url" : "https://www.apexconfiguration.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "WebPage",
  "description" : "An internal compliance audit found business applications that should have been in scope for Sarbanes-Oxley compliance weren't documented as such in the CMDB.",
  "inLanguage" : "en-GB",
  "name" : "A Sarbanes-Oxley Audit Found Applications ServiceNow Never Flagged",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png"
    },
    "name" : "Apex Configuration Group Ltd",
    "url" : "https://www.apexconfiguration.com/"
  },
  "url" : "https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://www.apexconfiguration.com/",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications",
    "name" : "A Sarbanes-Oxley Audit Found Applications ServiceNow Never Flagged",
    "position" : 2
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Iain Moone",
    "sameAs" : [ "https://www.linkedin.com/in/iainmoone/" ],
    "url" : "https://www.apexconfiguration.com/blog/author/iain-moone"
  },
  "dateModified" : "2026-10-06T13:53:26+0000",
  "datePublished" : "2026-10-05T08:00:00+0000",
  "headline" : "A Sarbanes-Oxley Audit Found Applications ServiceNow Never Flagged",
  "image" : [ "https://147949153.fs1.hubspotusercontent-eu1.net/hubfs/147949153/AI-Generated%20Media/Images/Corporate%20Auditor%20Reviewing%20Report%20In%20Dusk%20Office.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.apexconfiguration.com/blog/sox-audit-found-unflagged-in-scope-applications",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.apexconfiguration.com/hs-fs/hubfs/Act3%20child/images/ACG-logo.png"
    },
    "name" : "Apex Configuration Group Ltd",
    "url" : "https://www.apexconfiguration.com/"
  }
}
```