How should auditors scope ITGC work?
Auditors should scope ITGC work from the financial reporting risks and technology dependencies, not from a generic list of systems or controls.
Start by understanding the significant processes and how transactions move through the information system. Identify the applications, interfaces, reports and automated controls relevant to those processes. Then determine which ITGCs support the continued operation or reliability of those items.
The scope should reflect complexity. Relevant factors include the number of applications, level of integration, use of customisation, manual interfaces, outsourced services, privileged access model, system changes and the extent to which the planned audit approach relies on automated controls or system-generated information.
This is an area where errors are costly. Missing a feeder system can leave an important data flow outside the assessment. Overscoping can burden the team and client with work that does not change the audit response.
AI can support a more consistent first-pass scope by connecting process evidence, application information and the firm's methodology. The auditor should still stand back, confirm completeness and approve the final scope.
Platformed capability: Platformed starts from the financial reporting flows and technology dependencies, then prepares a first-pass application and ITGC scope with its rationale. The team can add, remove or escalate items before approving the work.
References: ISA 315 technology resources · Platformed ITGC workflow