IT general controls (ITGC): what they are and why auditors focus on them

IT-audit8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

IT general controls, or ITGC, are the overarching controls around the IT environment that ensure applications and data continue to function reliably. They form the foundation on which auditors lean in almost every assurance engagement, from SOC 2 to ISAE 3402. Yet organizations often underestimate them, precisely because they are not about a specific business process but about the IT underneath. This article explains what ITGC are, which domains they span, how they relate to application controls, and why their quality determines whether an auditor can rely on your automated controls.

What are IT general controls?

ITGC are the controls that safeguard the integrity of programs and data within an IT environment. They operate not at the level of a single transaction but at the level of the infrastructure, the systems and the processes that carry all applications. Think of how access is granted and revoked, how changes to systems are tested and approved, and how backups and disruptions are managed. When these controls are sound, you can trust that systems do what they are supposed to and that the data within them is reliable.

The difference with application controls

The distinction between ITGC and application controls is essential to understanding the role of ITGC. Application controls sit within a specific application and ensure the accuracy, completeness and authorization of individual transactions. An input check that prevents you from posting a negative amount, an automated approval limit, or a three-way match between order, receipt and invoice are application controls.

IT general controls work a layer deeper. They determine whether you may rely on those application controls at all. Suppose an application enforces an approval limit of ten thousand euros. That control is only reliable if no one can quietly alter the configuration and if changes to the application are properly tested and approved. The latter is ITGC. In other words: the application control is only as strong as the general controls beneath it.

The four domains of ITGC

In audit practice ITGC are usually divided into four domains. The first is access to programs and data, or logical access security. This covers the management of user accounts, granting rights based on role, timely revocation of access on departure, management of administrator accounts and periodic access reviews. In practice this is the domain where auditors record the most findings.

The second domain is program change management. The point is that changes to systems are requested, tested, approved and controlled into production, with a segregation of duties between who develops and who deploys to production. The third domain is system development: the structured development and implementation of new systems, including acceptance testing and data migration. The fourth domain is computer operations, which covers backup and recovery, batch and job processing, monitoring and incident handling. Together these four domains cover the lifecycle of systems and their day-to-day control.

Why ITGC form the basis for application controls

The heart of why auditors focus so heavily on ITGC lies in a dependency. An auditor wants to rely as much as possible on automated controls, because they work consistently and are efficient to test. But that reliance is only justified if the underlying IT environment is reliable. If the ITGC fail, for example because developers can push changes into production uncontrolled or because everyone has administrator rights, the auditor can no longer assume that an automated control worked correctly throughout the year.

The consequence is concrete and costly. If the ITGC are not effective, the auditor cannot rely on the application controls and must fall back on substantive testing: manually reviewing large numbers of transactions. That is more expensive, slower and more disruptive for the organization. Weak ITGC therefore undermine the entire chain of assurance, which is exactly why this foundation receives so much attention.

ITGC in SOC 2 and ISAE 3402

In assurance reports such as SOC 2 and ISAE 3402, ITGC form a fixed and weighty component. Both reports make a statement about the design and, in a type 2 report, the operating effectiveness of controls over a period. A large share of those controls are general controls: access management, change management and operations. A user organization that relies on such a report is in practice mainly relying on the quality of the ITGC at its provider. That is why an auditor tests the general controls thoroughly before drawing conclusions about the more specific process controls.

Common mistakes

The most common mistake is that controls exist in practice but are not demonstrable. A change process that is followed properly but not documented cannot be tested by an auditor. Without evidence of execution, a control does not count. A second classic is overdue access revocation: employees who have left but still have active accounts, or rights that accumulate with every role change without ever being cleaned up. A third mistake is missing segregation of duties, where the same person develops, approves and deploys a change. And finally we often see administrator accounts and service accounts falling outside regular access management, while that is precisely where the greatest risks lie.

How you make ITGC demonstrable

An effective control you cannot demonstrate is worthless for an audit. Demonstrability starts with systematically recording execution: tickets of changes with the associated approvals and test results, logs of granted and revoked rights, and the outcomes of periodic access reviews. We advise organizations to make the evidence part of the process itself, rather than gathering it after the fact just before the audit. A change that has not gone through the process should not be in production, and a process that is consistently followed automatically produces the evidence an auditor needs.

How Secure Audit helps

Secure Audit assesses and strengthens IT general controls as part of internal IT audits and in preparation for SOC 2 and ISAE 3402 engagements. We map where the ITGC are effective and where demonstrability falls short, and help anchor the evidence structurally in the processes. Get in touch for an introduction.

Frequently asked questions

What is the difference between IT general controls and application controls?+

IT general controls operate at the level of the IT environment as a whole: access management, change management, development and operations. Application controls sit within a specific application and ensure the accuracy and completeness of a transaction, such as an input check or an automated approval limit. ITGC form the basis on which application controls operate reliably.

Which domains fall under ITGC?+

Four domains are classically distinguished: access to programs and data (logical access security), program change management, system development, and computer operations such as backups, batch processing and incident handling.

Why do ITGC matter for a SOC 2 or ISAE 3402 report?+

Both reports rely on the reliability of the IT environment. If the ITGC are not effective, for example because anyone can push changes into production uncontrolled, the auditor cannot rely on the automated controls above them. Weak ITGC undermine the entire chain of assurance.

What is a common mistake with ITGC?+

The most common mistake is that controls exist but are not demonstrable. A change process that is followed in practice but not documented cannot be tested by an auditor. Without evidence of execution, a control does not count.

Need help with it-audit?

Independent assurance reports for service organizations. We work with you to determine which type of report fits your situation and what your clients or regulators expect.

Explore IT-Audit Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us