What does SAS 145 require for IT general controls and design and implementation?
SAS 145 strengthened the auditor's work over relevant controls, including controls that address risks arising from the entity's use of IT. For identified controls in the control-activities component, the auditor evaluates whether the control is designed effectively to address the risk and determines whether it has been implemented.
That does not mean every US audit needs a full, identical ITGC testing programme. The work remains risk-based. Auditors first understand the information system, identify the applications and technology dependencies relevant to financial reporting, and determine which general IT controls are relevant to the identified controls and risks. Operating-effectiveness testing is a separate step where the audit plans to rely on the control.
The practical difficulty is making this proportionate and consistent. Teams need to distinguish a relevant general IT control from a broad technology checklist, obtain evidence beyond enquiry, and document the connection between the IT environment, control and risk.
Platformed capability: Platformed assesses IT complexity, guides teams to the relevant ITGC work, evaluates design and implementation against linked evidence and prepares the conclusion for auditor review. It can support a streamlined assessment for a non-complex client and deeper application-level work where the environment requires it.
References: AICPA SAS 145 risk-assessment guidance · Platformed ITGC assessments