Skip to main content
Category: Controls Management

General IT Controls (ITGC)

Also known as: ITGC, IT General Controls, Information Technology General Controls
Simply put

General IT controls are the policies and procedures that govern how an organization's technology systems are acquired, built, run, secured, and maintained. Rather than addressing a single application, they apply broadly across systems and data to help ensure technology operates reliably. They provide the foundation on which application-specific controls typically depend.

Formal definition

IT general controls (ITGC) are pervasive controls that apply across an organization's information systems, components, processes, and data, as distinct from application controls, which operate within a specific application. In many frameworks they encompass control domains such as access and identity management, change management, systems development and acquisition, and IT operations. ITGC commonly support the effective operation of application controls; where ITGC are deficient, reliance on automated application controls may not be warranted. This entry addresses the concept at a definitional level and does not cover specific control designs, testing procedures, tooling, or jurisdiction- or standard-specific control requirements, which vary by framework, industry, and audit scope.

Why it matters

General IT controls matter because they form the foundation on which many other controls depend. Application controls, those embedded within a specific system to validate transactions or enforce business rules, typically rely on the underlying technology environment being reliable and well-governed. Where ITGC are deficient, an organization may not be able to place reliance on the automated application controls that sit on top of them, because the integrity, availability, and security of the environment cannot be assumed. This dependency makes ITGC a central concern in both compliance and assurance work.

Who it's relevant to

Internal auditors
Internal auditors assess whether ITGC are designed and operating effectively, often as a precondition for relying on automated application controls. The IIA offers a certificate program intended for internal auditors seeking to demonstrate mastery of IT general controls, reflecting the specialized knowledge this area requires. Auditors performing this work test the processes supporting the IT function as an independent assurance activity, distinct from the management activities that operate the controls themselves.
IT and information security teams
The IT function typically owns and operates ITGC as part of first-line management responsibilities, governing how systems are acquired, architected, deployed, used, and maintained. Domains such as access and identity management and change management fall largely within their remit.
Compliance officers
Because ITGC support the reliability of systems and data that underpin regulatory and financial reporting obligations, compliance professionals rely on their effectiveness. Deficient ITGC may undermine confidence in the automated controls that support compliance objectives, though specific requirements vary by framework, industry, and jurisdiction.

Inside ITGC

Access Controls
Controls over logical and physical access to systems, applications, and data, typically covering user provisioning and de-provisioning, authentication, authorization, privileged access management, and periodic access reviews. These aim to enforce that access is granted on a least-privilege and need-to-know basis.
Change Management Controls
Controls governing how changes to applications, systems, and infrastructure are requested, approved, tested, and migrated to production. They commonly include segregation between development and production environments and authorization of changes to reduce the risk of unauthorized or erroneous modifications.
IT Operations Controls
Controls over the ongoing operation of the IT environment, such as batch job scheduling and monitoring, incident and problem management, and backup and recovery processes. These support the reliable and complete processing of data over time.
Program Development / System Acquisition Controls
Controls over the development or acquisition and implementation of new systems, including project governance, testing, and approvals before deployment. They address risks arising when new applications or major system components are introduced.
Scope and Relationship to Application Controls
ITGCs are pervasive, entity- or system-level controls that support the effective operation of automated application controls. They are commonly distinguished from application controls, which operate within specific business processes, and from the business process controls they help underpin.

Common questions

Answers to the questions practitioners most commonly ask about ITGC.

Are general IT controls the same as application controls?
No. General IT controls (ITGC) are pervasive controls over the IT environment that support the reliable operation of systems and applications, typically covering areas such as access management, change management, and IT operations. Application controls, by contrast, are embedded within individual applications and address the completeness, accuracy, and validity of specific transactions or data processing. The two are complementary: application controls often depend on effective ITGC to operate reliably, but they are distinct in scope and should not be treated as interchangeable.
Do effective ITGC guarantee that financial or operational data is accurate?
No. ITGC provide a foundation that supports the reliable functioning of automated processes and application controls, but they do not by themselves ensure data accuracy. ITGC operate at the environment level, addressing matters such as who can access systems and how changes are managed, rather than validating individual transactions. Data accuracy typically depends on application controls and other business process controls operating in conjunction with ITGC. Even where ITGC are well designed, they reduce rather than eliminate the risk of error or misstatement.
Which domains are commonly included within the scope of ITGC?
ITGC scope commonly includes logical and physical access management, change management, systems development or acquisition, and IT operations such as batch processing, backup, and incident management. The precise domains and their boundaries may vary depending on the framework used, the organization's environment, and the objectives of the assessment. Organizations typically define scope with reference to the systems and processes that support in-scope reporting or regulatory objectives, so the applicable set of domains should be confirmed against the relevant framework and engagement context.
How is the scope of ITGC typically determined for an assessment?
Scope is commonly driven by the objectives being supported, such as financial reporting, regulatory compliance, or operational reliability, and by identifying the systems, applications, databases, and infrastructure relevant to those objectives. A common approach is to trace significant processes and application controls to the underlying IT layers on which they rely, then include the ITGC governing those layers. Scoping decisions depend on the organization's environment and the purpose of the assessment, and this entry does not address specific scoping methodologies or tooling.
How do the first, second, and third lines interact in relation to ITGC?
Under the three lines model articulated by the Institute of Internal Auditors, first line functions, typically IT management and operations, own and operate ITGC as part of managing the environment. Second line functions, such as IT risk or compliance, may set policies, provide oversight, and monitor control performance. Third line internal audit provides independent assurance over the design and operating effectiveness of ITGC. Maintaining the independence and objectivity of assurance activities from the management activities being assessed is important; those who operate or oversee controls should not also provide independent assurance over them.
How is the operating effectiveness of ITGC commonly evaluated?
Operating effectiveness is commonly evaluated by testing whether controls functioned as intended over a defined period, using techniques that may include inquiry, observation, inspection of evidence, and reperformance. Assessors typically consider both design and operating effectiveness, and a deficiency in a pervasive ITGC, such as change or access management, may affect reliance on the application controls that depend on it. The nature, timing, and extent of testing vary with the objectives, the assessed risk, and the applicable framework, and this entry does not cover specific testing procedures or provide audit or legal advice.

Common misconceptions

ITGCs are the same as application controls.
ITGCs are pervasive controls over the IT environment, such as access, change management, and operations, whereas application controls operate within a specific application or business process. ITGCs support the reliable operation of application controls but are conceptually and operationally distinct.
Effective ITGCs guarantee data accuracy or the prevention of all IT-related failures.
ITGCs reduce the likelihood and impact of certain risks, but no control set guarantees outcomes. Residual risk typically remains, and ITGCs provide reasonable, not absolute, assurance over the integrity of the systems supporting financial and operational processing.
Assessing ITGCs is solely an IT department responsibility.
Designing and operating ITGCs is commonly a management (first line) activity, while independent evaluation may be performed by internal audit or external assurance providers. Confusing the operation of controls with their independent assessment blurs the separation between management and assurance functions.

Best practices

Maintain a clear inventory of in-scope systems and map ITGCs to the applications and automated controls they support, so control coverage aligns with the risks that matter to relevant objectives.
Distinguish and document access, change management, and IT operations controls separately, defining a control objective for each so that the purpose of a control is not conflated with the control activity itself.
Perform periodic access reviews and enforce least-privilege and appropriate segregation of duties, giving particular attention to privileged accounts and to timely de-provisioning of departed users.
Enforce segregation between development, testing, and production environments and require documented authorization and testing before changes are migrated to production.
Keep the operation of ITGCs (a management responsibility) separate from their independent evaluation, and preserve the independence and objectivity of any internal audit or assurance function assessing them.
Align ITGC scope and rigor with applicable jurisdictional, sectoral, and regulatory context rather than assuming a single universal standard applies across all environments.
Application Security Isn’t Optional Anymore.