IT General Controls (ITGC) Audit
Audit the IT controls your financial reporting and assurance programs depend on. Access management, change management, IT operations, and SDLC controls, tested with evidence and findings your team can act on.
Overview
IT general controls (ITGCs) are the foundational information technology controls over your systems that underpin everything above them. Access management, change management controls, IT operations, backup and recovery, and the software development lifecycle are the ITGC domains. Weak ITGCs make application controls and financial reporting assurance unreliable, regardless of how well those upper layers are designed. Stakeholders, auditors, and boards place significant weight on whether information technology general controls are operating effectively.
We audit your ITGCs against recognised criteria, testing both control design and operating effectiveness over the relevant period. The audit process follows a structured scope and control matrix. Findings are reported with practical remediation guidance, not just a list of exceptions. ITGC compliance is what allows external auditors to rely on the controls environment rather than expanding their substantive testing. Governance over IT processes is a prerequisite for enterprise-level assurance.
This audit directly supports external financial audits, SOC 2 Type II examinations, and SOX-aligned control environments. Business continuity, unauthorized access, and data loss risks are addressed through ITGC controls. Implementing strong IT general controls, including multi-factor authentication and change management controls, reduces risk across all audit programs that depend on the ITGC foundation. A clean ITGC posture removes a significant source of auditor concern before the examination begins.
What’s included
- Logical access and identity management controls, including multi-factor authentication
- Change management and release controls
- IT operations, backup and recovery, and job-scheduling controls
- Software development lifecycle (SDLC) controls
- Control design and operating-effectiveness testing
- Findings, exceptions, and remediation guidance
- Governance and compliance assessment across ITGC domains
- Policies and procedures review
How we work
-
01
Scope
We agree the in-scope systems, the ITGC domains to test, and the period under review before any fieldwork begins. Control objectives for each domain are confirmed at scoping so the audit produces findings that are directly usable in your compliance program.
-
02
Test design
We assess whether the information technology general controls in each domain are appropriately designed to achieve their objectives. Design gaps are reported immediately because they affect operating effectiveness testing.
-
03
Test operation
We test operating effectiveness across the period using sampling and evidence, documenting every exception with its source. Implement ITGC best practices are the benchmark. Data center, user access, and change management controls receive particular scrutiny.
-
04
Report
We deliver findings, exceptions, and remediation guidance written for the people who own and fix the controls. Stakeholder-ready summaries are produced alongside the detailed findings so governance conversations have the evidence they need.
What you get
- ITGC scope and control matrix
- Design and operating-effectiveness test results
- Exceptions and rated findings
- Remediation guidance
Frequently asked questions
How does an ITGC audit relate to SOC 2 and financial audits?
ITGCs underpin both. External financial auditors and SOC 2 examiners rely on strong access management, change management controls, and IT operations controls before they can place trust in application data and financial information. A well-controlled ITGC environment, including strong backup and recovery controls and IT governance practices, smooths both types of examination and reduces the number of questions your team has to answer.
Which control framework do you use for the ITGC audit?
We align to recognised criteria including COBIT and the relevant Trust Services Criteria, and to ISO 27001 where it applies to your control environment. The ITGC framework is confirmed with you at scoping so the results are directly usable in your audit or assurance program. Our internal audit team has experience mapping ITGC findings across multiple compliance frameworks.
How long does an ITGC audit take?
Scope and the number of in-scope systems determine the timeline. We agree an estimate on the scoping call. Most engagements complete fieldwork within a defined observation window, with the report delivered shortly after. Performing an ITGC audit is a defined, structured process; the complexity comes from the number of in-scope systems and the maturity of the control documentation.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.