Answers to the questions practitioners most commonly ask about ITGC.
Are general IT controls the same as application controls?
No. General IT controls (ITGC) are pervasive controls over the IT environment that support the reliable operation of systems and applications, typically covering areas such as access management, change management, and IT operations. Application controls, by contrast, are embedded within individual applications and address the completeness, accuracy, and validity of specific transactions or data processing. The two are complementary: application controls often depend on effective ITGC to operate reliably, but they are distinct in scope and should not be treated as interchangeable.
Do effective ITGC guarantee that financial or operational data is accurate?
No. ITGC provide a foundation that supports the reliable functioning of automated processes and application controls, but they do not by themselves ensure data accuracy. ITGC operate at the environment level, addressing matters such as who can access systems and how changes are managed, rather than validating individual transactions. Data accuracy typically depends on application controls and other business process controls operating in conjunction with ITGC. Even where ITGC are well designed, they reduce rather than eliminate the risk of error or misstatement.
Which domains are commonly included within the scope of ITGC?
ITGC scope commonly includes logical and physical access management, change management, systems development or acquisition, and IT operations such as batch processing, backup, and incident management. The precise domains and their boundaries may vary depending on the framework used, the organization's environment, and the objectives of the assessment. Organizations typically define scope with reference to the systems and processes that support in-scope reporting or regulatory objectives, so the applicable set of domains should be confirmed against the relevant framework and engagement context.
How is the scope of ITGC typically determined for an assessment?
Scope is commonly driven by the objectives being supported, such as financial reporting, regulatory compliance, or operational reliability, and by identifying the systems, applications, databases, and infrastructure relevant to those objectives. A common approach is to trace significant processes and application controls to the underlying IT layers on which they rely, then include the ITGC governing those layers. Scoping decisions depend on the organization's environment and the purpose of the assessment, and this entry does not address specific scoping methodologies or tooling.
How do the first, second, and third lines interact in relation to ITGC?
Under the three lines model articulated by the Institute of Internal Auditors, first line functions, typically IT management and operations, own and operate ITGC as part of managing the environment. Second line functions, such as IT risk or compliance, may set policies, provide oversight, and monitor control performance. Third line internal audit provides independent assurance over the design and operating effectiveness of ITGC. Maintaining the independence and objectivity of assurance activities from the management activities being assessed is important; those who operate or oversee controls should not also provide independent assurance over them.
How is the operating effectiveness of ITGC commonly evaluated?
Operating effectiveness is commonly evaluated by testing whether controls functioned as intended over a defined period, using techniques that may include inquiry, observation, inspection of evidence, and reperformance. Assessors typically consider both design and operating effectiveness, and a deficiency in a pervasive ITGC, such as change or access management, may affect reliance on the application controls that depend on it. The nature, timing, and extent of testing vary with the objectives, the assessed risk, and the applicable framework, and this entry does not cover specific testing procedures or provide audit or legal advice.