IT General Controls (ITGCs) (+4)
IT General Controls (ITGCs)
Controls over the IT environment that support the reliable functioning of application controls and automated processes.
Access Controls:
- User access provisioning (new access requests require approval)
- User access de-provisioning (terminated users removed timely)
- Privileged access management (admin/superuser access restricted and monitored)
- Periodic access reviews (user access recertified on a defined schedule)
- Password policies (complexity, rotation, lockout)
- Segregation of duties enforcement (conflicting access prevented)
Change Management:
- Change requests documented and approved before implementation
- Changes tested in a non-production environment before promotion
- Separation of development and production environments
- Emergency change procedures (documented, approved post-implementation)
- Change review and post-implementation validation
IT Operations:
- Batch job monitoring and exception handling
- Backup and recovery procedures (regular backups, tested restores)
- System availability and performance monitoring
- Incident management and escalation procedures
- Disaster recovery planning and testing
Manual Controls
Controls performed by people using judgment, typically involving review and approval.
Examples:
- Management review of financial statements and key metrics
- Supervisory approval of journal entries above a threshold
- Three-way match verification (PO, receipt, invoice)
- Account reconciliation preparation and review
- Physical inventory observation and count
- Vendor master data change approval
- Customer credit approval
Key attributes to test:
- Was the control performed by the right person (proper authority)?
- Was it performed timely (within the required timeframe)?
- Is there evidence of the review (signature, initials, email, system log)?
- Did the reviewer have sufficient information to perform an effective review?
- Were exceptions identified and appropriately addressed?
Automated Controls
Controls enforced by IT systems without human intervention.
Examples:
- System-enforced approval workflows (cannot proceed without required approvals)
- Three-way match automation (system blocks payment if PO/receipt/invoice don't match)
- Duplicate payment detection (system flags or blocks duplicate invoices)
- Credit limit enforcement (system prevents orders exceeding credit limit)
- Automated calculations (depreciation, amortization, interest, tax)
- System-enforced segregation of duties (conflicting roles prevented)
- Input validation controls (required fields, format checks, range checks)
- Automated reconciliation matching
Testing approach:
- Test design: Confirm the system configuration enforces the control as intended
- Test operating effectiveness: For automated controls, if the system configuration has not changed, one test of the control is typically sufficient for the period (supplemented by ITGC testing of change management)
- Verify change management ITGCs are effective (if system changed, re-test the control)
IT-Dependent Manual Controls
Manual controls that rely on the completeness and accuracy of system-generated information.
Examples:
- Management review of a system-generated exception report
- Supervisor review of a system-generated aging report to assess reserves
- Reconciliation using system-generated trial balance data
- Approval of transactions identified by a system-generated workflow
Testing approach:
- Test the manual control (review, approval, follow-up on exceptions)
- AND test the completeness and accuracy of the underlying report/data (IPE — Information Produced by the Entity)
- IPE testing confirms the data the reviewer relied on was complete and accurate
Entity-Level Controls
Broad controls that operate at the organizational level and affect multiple processes.
Examples:
- Tone at the top / code of conduct
- Risk assessment process
- Audit committee oversight of financial reporting
- Internal audit function and activities
- Fraud risk assessment and anti-fraud programs
- Whistleblower/ethics hotline
- Management monitoring of control effectiveness
- Financial reporting competence (staffing, training, qualifications)
- Period-end financial reporting process (close procedures, GAAP compliance reviews)
Significance:
- Entity-level controls can mitigate but typically cannot replace process-level controls
- Ineffective entity-level controls (especially audit committee oversight and tone at the top) are strong indicators of a material weakness
- Effective entity-level controls may reduce the extent of testing needed for process-level controls
1---2name: audit-support-it-general-controls-itgcs3description: Sub-skill of audit-support: IT General Controls (ITGCs) (+4).4---56# IT General Controls (ITGCs) (+4)78## IT General Controls (ITGCs)91011Controls over the IT environment that support the reliable functioning of application controls and automated processes.1213**Access Controls:**14- User access provisioning (new access requests require approval)15- User access de-provisioning (terminated users removed timely)16- Privileged access management (admin/superuser access restricted and monitored)17- Periodic access reviews (user access recertified on a defined schedule)18- Password policies (complexity, rotation, lockout)19- Segregation of duties enforcement (conflicting access prevented)2021**Change Management:**22- Change requests documented and approved before implementation23- Changes tested in a non-production environment before promotion24- Separation of development and production environments25- Emergency change procedures (documented, approved post-implementation)26- Change review and post-implementation validation2728**IT Operations:**29- Batch job monitoring and exception handling30- Backup and recovery procedures (regular backups, tested restores)31- System availability and performance monitoring32- Incident management and escalation procedures33- Disaster recovery planning and testing343536## Manual Controls373839Controls performed by people using judgment, typically involving review and approval.4041**Examples:**42- Management review of financial statements and key metrics43- Supervisory approval of journal entries above a threshold44- Three-way match verification (PO, receipt, invoice)45- Account reconciliation preparation and review46- Physical inventory observation and count47- Vendor master data change approval48- Customer credit approval4950**Key attributes to test:**51- Was the control performed by the right person (proper authority)?52- Was it performed timely (within the required timeframe)?53- Is there evidence of the review (signature, initials, email, system log)?54- Did the reviewer have sufficient information to perform an effective review?55- Were exceptions identified and appropriately addressed?565758## Automated Controls596061Controls enforced by IT systems without human intervention.6263**Examples:**64- System-enforced approval workflows (cannot proceed without required approvals)65- Three-way match automation (system blocks payment if PO/receipt/invoice don't match)66- Duplicate payment detection (system flags or blocks duplicate invoices)67- Credit limit enforcement (system prevents orders exceeding credit limit)68- Automated calculations (depreciation, amortization, interest, tax)69- System-enforced segregation of duties (conflicting roles prevented)70- Input validation controls (required fields, format checks, range checks)71- Automated reconciliation matching7273**Testing approach:**74- Test design: Confirm the system configuration enforces the control as intended75- Test operating effectiveness: For automated controls, if the system configuration has not changed, one test of the control is typically sufficient for the period (supplemented by ITGC testing of change management)76- Verify change management ITGCs are effective (if system changed, re-test the control)777879## IT-Dependent Manual Controls808182Manual controls that rely on the completeness and accuracy of system-generated information.8384**Examples:**85- Management review of a system-generated exception report86- Supervisor review of a system-generated aging report to assess reserves87- Reconciliation using system-generated trial balance data88- Approval of transactions identified by a system-generated workflow8990**Testing approach:**91- Test the manual control (review, approval, follow-up on exceptions)92- AND test the completeness and accuracy of the underlying report/data (IPE — Information Produced by the Entity)93- IPE testing confirms the data the reviewer relied on was complete and accurate949596## Entity-Level Controls979899Broad controls that operate at the organizational level and affect multiple processes.100101**Examples:**102- Tone at the top / code of conduct103- Risk assessment process104- Audit committee oversight of financial reporting105- Internal audit function and activities106- Fraud risk assessment and anti-fraud programs107- Whistleblower/ethics hotline108- Management monitoring of control effectiveness109- Financial reporting competence (staffing, training, qualifications)110- Period-end financial reporting process (close procedures, GAAP compliance reviews)111112**Significance:**113- Entity-level controls can mitigate but typically cannot replace process-level controls114- Ineffective entity-level controls (especially audit committee oversight and tone at the top) are strong indicators of a material weakness115- Effective entity-level controls may reduce the extent of testing needed for process-level controls