How do ITGC and IT application control relationships affect the audit response?
IT application controls, or ITACs, perform specific processing functions within an application. ITGCs support the environment in which those controls operate. The audit response needs to consider the relationship between them.
An automated application control may consistently perform a calculation or validation, but its continued reliability can depend on access and change controls. If unauthorised people can change the program or configuration, the auditor may not be able to rely on the automated control in the intended way.
The relationship is rarely one-to-one. One set of ITGCs may support several application controls across an ERP, while a control may also depend on interfaces, source data and reports from other applications. Mapping these dependencies helps the team see where an ITGC finding affects more than one part of the audit.
AI can maintain this relationship map across systems, risks, controls and evidence. That makes the impact of a finding easier to assess and gives reviewers a clearer line from the technology environment to the planned audit response. The auditor still determines whether a deficiency changes reliance or requires alternative procedures.
Platformed capability: Platformed maps ITGCs and application controls to their systems, risks and evidence. When a control issue arises, reviewers can see the affected dependencies; the audit team decides the consequence for reliance and further procedures.
References: PCAOB AS 2201 · Platformed ITGC assessments