Audit & Assurance
IT General Controls (ITGC) Audit
ITGC is the control layer your external auditor relies on before they will place any reliance on a system-generated report. We test it independently, document it to a standard that survives review, and tell you plainly where it fails.
What an ITGC audit actually covers
IT general controls are the controls over the IT environment as a whole, rather than over any single business transaction. If they fail, every automated control and every system-generated report sitting above them becomes unreliable. That is why external auditors test ITGC first and why a weak ITGC opinion cascades into substantive testing across the whole financial statement audit.
- Access to programs and data — user provisioning and de-provisioning, periodic access recertification, privileged and emergency access, segregation of duties, authentication and password configuration, service and generic accounts.
- Program change management — change request and approval, segregation between development, test and production, testing and UAT evidence, emergency change handling, migration controls and version integrity.
- Program development and acquisition — project governance, requirements and design sign-off, data conversion and migration controls, go-live authorisation, post-implementation review.
- Computer operations — job scheduling and monitoring, incident and problem management, backup execution and restoration testing, capacity and availability monitoring, physical and environmental controls over hosting.
Why organisations commission one
- The external auditor has raised an ITGC deficiency and management needs it closed before the next cycle.
- A regulator — most commonly the State Bank of Pakistan under its technology governance framework — expects a periodic independent IT audit.
- The audit committee wants assurance that is not produced by the IT function that runs the controls.
- An ERP has gone live and nobody has yet tested whether the control design survived the implementation.
- The internal audit function has no IT specialist and needs the ITGC portion of its annual plan co-sourced.
The four ITGC domains
Scoping: which systems are in scope
We scope by financial and regulatory relevance, not by asset inventory. That normally means the core banking or ERP platform, the operating systems and databases beneath it, the directory service that authenticates into it, any middleware moving data in or out, and the change and ticketing tooling that evidences the controls. Peripheral systems are excluded explicitly and in writing, so there is no ambiguity later about what was and was not covered.
How the engagement runs
-
1
Planning and risk assessment
Understand the IT environment, agree in-scope systems, confirm the reporting period, and set the control objectives and sample basis in an approved audit programme.
-
2
Walkthroughs
Walk each control end to end with the process owner to confirm the design before we test whether it operated.
-
3
Design effectiveness
Assess whether the control as designed would prevent or detect the risk. A control that is well-operated but wrongly designed still fails.
-
4
Operating effectiveness
Sample-test across the period using population completeness evidence, not management-prepared extracts taken on trust.
-
5
Exception validation
Every exception is put back to the control owner with the evidence attached before it becomes a finding. No surprises at closing.
-
6
Reporting and closing
Draft findings, agree management responses and target dates, then issue the final report to the audit committee.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal