CPA AUDITING & ATTESTATION (AUD) • ASSESSING RISK AND DEVELOPING A PLANNED RESPONSE

IT General Controls — Evaluate IT General Controls

Understanding how auditors assess the technology infrastructure that safeguards financial reporting integrity.

Historical Context & Motivation

The concept of IT General Controls (ITGCs) arose as organizations increasingly migrated their accounting processes from manual ledgers to computerized systems. In the early days of business computing during the 1960s and 1970s, auditors recognized that the reliability of financial reports depended not merely on whether individual transactions were correctly entered, but on whether the entire technology environment supporting those transactions was properly governed. As IT systems grew more complex—spanning enterprise resource planning platforms, databases, and networked infrastructure—the auditing profession developed frameworks to evaluate the controls that underpin every automated financial process. Today, evaluating ITGCs is a fundamental component of the audit risk model, directly informing the auditor's assessment of control risk and the nature, timing, and extent of substantive procedures.

1977
Foreign Corrupt Practices Act (FCPA)
The FCPA required publicly traded companies to maintain adequate internal accounting controls, catalyzing attention to IT environments as core components of internal control systems.
1992
COSO Internal Control Framework
The Committee of Sponsoring Organizations published its landmark framework, explicitly recognizing information systems as a critical element of the control environment and laying the groundwork for formal ITGC evaluation.
1996
COBIT Framework Released
ISACA released Control Objectives for Information and Related Technologies (COBIT), providing a detailed governance model that auditors could map to ITGC categories such as access controls, change management, and operations.
2002
Sarbanes-Oxley Act (SOX)
Following corporate scandals at Enron and WorldCom, SOX Section 404 mandated management assessment and auditor attestation of internal controls over financial reporting, elevating ITGCs to a central audit concern.
2010–Present
Cloud, Automation & Continuous Auditing
The migration to cloud computing, robotic process automation, and AI-driven analytics has expanded the scope of ITGCs to include vendor management, data encryption, and real-time monitoring of system integrity.

The central question driving ITGC evaluation is straightforward yet consequential: Can the auditor rely on the IT environment to produce complete, accurate, and authorized financial data? If ITGCs are deficient, every application-level control that depends on the IT infrastructure becomes suspect, potentially requiring the auditor to expand substantive testing significantly—a costly and time-consuming outcome for both the audit firm and the client.

Core Principles & Definitions

IT General Controls are the policies and procedures that apply broadly across an organization's IT environment, ensuring that application controls embedded in specific software programs—such as automated three-way matching in accounts payable or input validation rules—continue to function effectively over time. Unlike application controls, which target individual transaction classes, ITGCs operate at the infrastructure level and affect every financial application that runs on the organization's systems. The PCAOB's AS 2201 and AICPA professional standards both emphasize that an auditor must obtain an understanding of ITGCs when the entity relies on IT-dependent controls for financial reporting. Failure at the ITGC level can cascade through every downstream application, making ITGC evaluation a prerequisite for any audit strategy that relies on controls testing.

1

Logical Access Controls

Policies governing who can access systems, databases, and applications. Includes user provisioning, authentication mechanisms (passwords, multi-factor), role-based access, and periodic access reviews to prevent unauthorized transactions.
2

Program Change Management

Controls ensuring that modifications to application code, configurations, or data structures are authorized, tested, and approved before migration to production. Prevents unapproved changes that could compromise data integrity.
3

Program Development (SDLC)

Controls over the system development life cycle, ensuring that new applications or significant enhancements are designed with appropriate security, data validation, and audit trail capabilities before deployment.
4

Computer Operations

Controls over day-to-day IT operations including job scheduling, batch processing, backup and recovery, incident management, and monitoring of system performance to ensure continuous, reliable processing of financial data.
KEY TAKEAWAY
Think of ITGCs as the foundation of a building. Application controls are the rooms where people work—each with its own locks, fire alarms, and ventilation. But if the foundation cracks, every room above it shifts. A weak ITGC environment undermines the reliability of every application control sitting on top of it. No matter how sophisticated the automated three-way match in accounts payable, if an unauthorized user can modify the matching parameters through a gap in access controls, that application control can no longer be trusted.

Visual Explanation — The ITGC Ecosystem

This diagram illustrates the layered relationship between ITGCs, application controls, and financial statements. The bottom layer represents the four ITGC domains—logical access, change management, program development, and operations. Application controls (middle layer) depend on the integrity of these ITGCs. Financial statement reliability (top layer) ultimately rests upon both layers functioning effectively.

As depicted in the diagram, the four ITGC domains form the technological foundation upon which all automated and IT-dependent manual controls rely. When an auditor identifies a deficiency in logical access controls—for example, the absence of periodic user access reviews—the implication extends beyond the access control itself. Every application control that depends on proper user restrictions, such as segregation of duties enforced by the ERP system, becomes potentially unreliable. The auditor must then consider whether compensating controls exist or whether the audit strategy should shift toward increased substantive testing. Understanding this cascading dependency is essential for CPA candidates, because audit risk assessment under AU-C Section 315 requires the auditor to obtain a sufficient understanding of information systems relevant to financial reporting, including the ITGCs that maintain system integrity.

How the Auditor Evaluates ITGCs

The evaluation of ITGCs follows a structured methodology that mirrors the broader audit risk model. The auditor first identifies the IT systems that are relevant to financial reporting, then maps the ITGCs associated with those systems, designs and performs tests of those controls, and finally evaluates any deficiencies discovered. While ITGC evaluation does not typically involve mathematical formulas in the traditional sense, the relationship between ITGCs, control risk, and audit risk can be expressed through the audit risk model, which provides a conceptual framework for understanding why ITGC deficiencies matter quantitatively.

AUDIT RISK MODEL
AR = IR × CR × DR
Where AR = Audit Risk (the risk the auditor expresses an inappropriate opinion), IR = Inherent Risk, CR = Control Risk (inversely related to ITGC and application control effectiveness), DR = Detection Risk. ITGC deficiencies increase CR, forcing DR to decrease—meaning the auditor must perform more extensive substantive procedures.

The Four-Phase ITGC Evaluation Process

1

Phase 1 — Scoping

Identify financially significant applications (e.g., ERP, payroll, treasury systems) and the IT infrastructure supporting them. Map data flows from transaction initiation through financial statement line items to determine which systems are in scope.
2

Phase 2 — Design Assessment

Evaluate whether ITGCs are properly designed to achieve their objectives. Perform walkthroughs by tracing a control from policy documentation through execution. Determine whether the control, if operating effectively, would prevent or detect misstatement.
3

Phase 3 — Operating Effectiveness

Test whether ITGCs operated consistently throughout the audit period. Techniques include inquiry of IT personnel, inspection of system logs, re-performance of access reviews, and observation of change management approval workflows.
4

Phase 4 — Deficiency Evaluation

Classify identified deficiencies as control deficiencies, significant deficiencies, or material weaknesses. Assess the pervasive impact of ITGC failures on related application controls and adjust the audit strategy accordingly.
CONTROL RISK RELATIONSHIP
If ITGC Deficiency → CR ↑ → Required DR ↓ → Substantive Testing ↑
This directional relationship demonstrates the practical consequence: when ITGCs are weak, the auditor cannot rely on controls to reduce control risk, so detection risk must decrease. The only way to decrease detection risk is to increase the nature, timing, and extent of substantive audit procedures.

Detailed Breakdown of ITGC Categories & Testing Approaches

Each ITGC category targets a distinct risk vector within the IT environment. Understanding the specific controls within each category—and the audit procedures used to test them—is essential for CPA candidates who must be prepared to evaluate client IT environments or assess an IT specialist's findings. The following diagram and table provide a detailed taxonomy of ITGC categories, their sub-controls, and the typical audit procedures applied to each.

This mind-map diagram breaks down the four primary ITGC categories—Logical Access (violet), Change Management (pink), Program Development (cyan), and Computer Operations (emerald)—into their constituent sub-controls. The italic text at the bottom of each branch indicates the primary audit testing approach for that category.
Summary of ITGC Categories, Risks, Procedures, and Deficiency Impacts
ITGC CategoryKey Risk AddressedCommon Audit ProceduresImpact if Deficient
Logical AccessUnauthorized users access or modify financial dataInspect user access lists; re-perform periodic access reviews; test password parameters; verify terminated employee removalAll application controls relying on user restrictions are undermined; SOD violations may go undetected
Change ManagementUnauthorized or untested changes corrupt processing logicInspect change tickets for authorization and testing evidence; verify Dev/Test/Prod environment segregation; sample emergency changesApplication calculations may be altered without detection; data integrity compromised across financial modules
Program DevelopmentNew systems lack adequate controls or audit trailsReview SDLC documentation; verify UAT sign-offs; inspect requirements traceability; evaluate post-implementation reviewsNewly deployed applications may process transactions incorrectly from inception
Computer OperationsSystem outages, data loss, or processing failuresInspect backup logs and recovery test results; review incident management records; verify job scheduling completeness; observe physical data center securityTransactions may be lost or processed incompletely; financial data unavailable for audit testing

Worked Example — Evaluating ITGCs at a Mid-Size Manufacturer

Consider a scenario in which you are auditing Apex Manufacturing, Inc., a mid-size company that uses an ERP system (SAP) for its revenue cycle, purchasing cycle, and general ledger. The company has 800 employees, an IT department of 12 people, and recently migrated to a cloud-hosted version of its ERP. Your engagement team has identified that the client relies on automated controls for revenue recognition (percentage-of-completion calculations) and accounts payable (automated three-way matching). You must evaluate the ITGCs to determine whether you can rely on those application controls.

ITGC Evaluation for Apex Manufacturing, Inc.
1
Step 1 — Scope the IT EnvironmentIdentify the financially significant applications: SAP ERP (revenue, purchasing, GL), the cloud hosting provider's infrastructure, and the company's Active Directory (AD) for authentication. Determine that the relevant ITGCs span all four categories—logical access to SAP and AD, change management for SAP configuration updates, program development for a recent custom revenue recognition module, and computer operations for the cloud-hosted environment's backup and availability.
Scope: SAP ERP, Active Directory, Cloud infrastructure — all four ITGC domains in scope.
2
Step 2 — Assess Design of Logical Access ControlsPerform a walkthrough of user provisioning: new employees are granted SAP roles via a helpdesk ticket that requires manager approval. Password policy mandates 10-character minimum with complexity. However, you discover that quarterly access recertification was designed but only covers SAP roles—it does not review Active Directory group memberships that grant elevated privileges to shared folders containing sensitive financial data. You note this design gap.
Design gap identified: AD access recertification not included in quarterly review.
3
Step 3 — Test Operating Effectiveness of Change ManagementSelect a sample of 25 SAP transport requests (changes) from the audit period. For each, inspect the change ticket for: (a) documented business justification, (b) approval by an authorized individual, (c) evidence of testing in the QA environment, and (d) a separate migration approval before promotion to production. You find that 23 out of 25 changes have complete documentation. Two emergency changes lack pre-migration testing documentation, though they have post-implementation review sign-offs. Evaluate whether the emergency change procedure was followed appropriately.
Change management: 92% full compliance; 2 emergency changes followed alternate procedure with compensating post-implementation review.
4
Step 4 — Evaluate the Custom Revenue Module (Program Development)Because Apex deployed a custom percentage-of-completion module during the audit year, you must evaluate its development controls. Review the project charter, requirements specification, design documentation, QA test scripts and results, UAT sign-off by the finance team, and the post-implementation review report. You confirm that the module was tested with parallel runs against manual calculations for two months before go-live, and the finance team formally accepted the results. No significant variances were identified during parallel testing.
Program development controls: Adequately designed and effectively operated for the custom revenue module.
5
Step 5 — Aggregate Assessment & Impact on Audit StrategyAggregate your findings: change management and program development ITGCs are operating effectively. Logical access has a design deficiency (AD recertification gap). You assess this as a significant deficiency because it could allow unauthorized access to sensitive financial data, though it does not rise to a material weakness since SAP application-level access controls remain intact. You decide to: (1) communicate the deficiency to those charged with governance, (2) continue relying on SAP application controls for the revenue and purchasing cycles, and (3) perform additional substantive procedures related to journal entries initiated from shared folders to compensate for the AD access gap.
Final assessment: Significant deficiency in logical access; rely on application controls with targeted supplemental substantive testing for journal entries.

Strengths & Limitations of ITGC-Reliant Audit Strategies

An audit strategy that places substantial reliance on ITGCs and the application controls they support offers significant efficiency advantages—but it also carries inherent limitations. Understanding both sides is crucial for CPA candidates, particularly because exam scenarios often present situations where the auditor must decide whether a controls-reliance approach is appropriate or whether a primarily substantive approach would be more effective given the circumstances.

Strengths and Limitations of ITGC-Reliant Audit Strategies
StrengthsLimitations
Automated controls operate consistently without human fatigue or variability—once validated, they provide high assurance over large transaction volumes.ITGCs are pervasive—a single weakness can undermine multiple application controls simultaneously, creating a cascading failure effect across financial assertions.
Reliance on ITGCs allows the auditor to reduce the extent of substantive testing, lowering overall audit cost and improving efficiency.Evaluating ITGCs often requires specialized IT audit skills; the engagement team may need to involve IT specialists, increasing coordination complexity.
ITGCs provide continuous control throughout the period, unlike manual controls that may be performed only at specific intervals.Management override of IT controls (e.g., a DBA with unrestricted access) may not be detectable through standard ITGC testing procedures.
Effective ITGCs provide a strong basis for data integrity, supporting the auditor's reliance on system-generated reports used in substantive testing.In rapidly changing IT environments (frequent system migrations, cloud transitions), prior-period ITGC conclusions may not carry forward, requiring fresh evaluation each year.
ITGC evaluation aligns with the integrated audit approach required under SOX (Section 404), creating synergies between the financial statement audit and the audit of internal controls.Third-party IT environments (cloud providers, outsourced processing) require evaluation through SOC reports, which may not align perfectly with the audit period or scope.
KEY TAKEAWAY
Think of ITGC reliance like flying an aircraft on autopilot. When the autopilot system is properly calibrated and monitored (effective ITGCs), it handles thousands of micro-adjustments per second far more reliably than a human pilot could—analogous to how automated controls process millions of transactions consistently. However, if the autopilot's underlying software has an undetected flaw or if someone gains unauthorized access to reprogram it, the consequences are systemic and potentially catastrophic—just as a pervasive ITGC failure can compromise every automated control in the financial reporting environment.

Connection to Advanced IT Audit Concepts

As organizations adopt increasingly sophisticated technology architectures, the traditional ITGC framework must be extended to address emerging risks. CPA candidates should understand how foundational ITGC evaluation connects to advanced audit considerations, including the use of SOC reports for third-party service organizations, continuous auditing techniques that leverage data analytics to monitor ITGCs in real time, and the evolving standards around cybersecurity risk assessment. The table below contrasts the traditional ITGC evaluation approach with advanced and emerging practices.

Traditional vs. Advanced ITGC Evaluation Approaches
DimensionTraditional ITGC EvaluationAdvanced / Emerging Practices
ScopeOn-premise systems; single ERP platformsMulti-cloud, SaaS, hybrid environments; third-party APIs; microservices architectures
Third-Party AssuranceDirect testing of client-managed systemsSOC 1 / SOC 2 reports; bridge letters; complementary user entity controls (CUECs) evaluation
Testing FrequencyPoint-in-time or periodic sample-based testingContinuous monitoring using automated scripts and data analytics; real-time exception reporting
Cybersecurity IntegrationITGCs viewed primarily through a financial reporting lensIntegration with cybersecurity risk assessments; NIST/ISO 27001 framework alignment; penetration testing results reviewed
Data GovernanceFocus on transaction processing controlsExtended to data lakes, ETL processes, master data management; data lineage tracing from source to financial statement

Looking forward, the integration of artificial intelligence and machine learning into audit workflows will further transform ITGC evaluation. Auditors may increasingly use automated tools to continuously monitor access logs, flag anomalous changes, and assess the operating effectiveness of ITGCs in near-real-time—a significant departure from the traditional sample-based, periodic testing paradigm. CPA candidates should be prepared for these shifts while maintaining a firm grounding in the foundational ITGC evaluation principles that remain the backbone of any audit engagement involving technology-dependent controls.

💡 CPA EXAM TIP
On the AUD exam, questions about ITGCs frequently test whether the candidate understands the pervasive nature of ITGC deficiencies. A common trap is selecting an answer that treats an ITGC failure as affecting only one application. Remember: ITGC deficiencies typically affect all applications and controls that depend on the compromised IT infrastructure.

Practice Problems

1
Which of the following best describes the primary purpose of evaluating IT general controls (ITGCs) during an audit?
2
An auditor identifies four categories of IT general controls relevant to the audit: access to programs and data, program changes, program development, and computer operations. During evaluation, the auditor determines that controls over access to programs and data and controls over program changes are ineffective. Which of the following best describes the effect on the auditor's risk assessment?
3
During the audit of a manufacturing company, the auditor learns that the IT department implemented a major upgrade to the enterprise resource planning (ERP) system during the year under audit. Several modules affecting financial reporting were modified. Which of the following ITGC areas should be of greatest concern to the auditor when evaluating controls related to this system change?
4
An auditor is evaluating IT general controls at a client that uses a third-party cloud service provider to host its financial reporting application. The client has obtained a SOC 1 Type II report from the service organization's auditor. Which of the following actions should the auditor take when using this report to evaluate ITGCs at the service organization?
5
An auditor is assessing IT general controls at a mid-sized company. The auditor finds that the company's IT environment has the following characteristics: (1) the same individual who develops programs also has the ability to migrate changes to the production environment, (2) access reviews for the financial reporting system are performed annually but the last review was completed 18 months ago, and (3) automated application controls within the ERP system have not been modified during the period. Based on these findings, which of the following conclusions is most appropriate?

Lesson Summary

Evaluating IT General Controls is a foundational step in any audit of an organization that relies on technology for financial reporting. ITGCs encompass four pervasive domains: logical access controls (governing who can access and modify systems), program change management (ensuring modifications are authorized and tested), program development (controlling the system development life cycle), and computer operations (maintaining continuous, reliable processing through backup, recovery, and monitoring). The auditor's evaluation follows a four-phase methodology: scoping the relevant IT environment, assessing design adequacy, testing operating effectiveness, and evaluating and classifying any deficiencies as control deficiencies, significant deficiencies, or material weaknesses.

The critical concept for CPA candidates is the pervasive nature of ITGCs: a weakness in any one domain can cascade through every application control that depends on the compromised infrastructure. When ITGCs are deficient, control risk increases within the audit risk model (AR = IR × CR × DR), requiring the auditor to reduce detection risk by expanding substantive procedures. In modern environments, auditors must also evaluate third-party controls through SOC reports, address coverage gaps with bridge letters, and assess complementary user entity controls—skills that are increasingly tested on the AUD section of the CPA exam.

Varsity Tutors • CPA Auditing & Attestation (AUD) • IT General Controls — Evaluate IT General Controls