Platformed

What are IT general controls?

ITGCs and technology risk · last updated 2026-09-02

IT general controls, usually shortened to ITGCs, are controls over the technology environment that support the reliable operation of systems and automated controls. They commonly cover access, system changes, computer operations and the development or implementation of applications.

Typical examples include approving new user access, removing access when someone leaves, restricting privileged accounts, testing and approving system changes, monitoring scheduled jobs, backing up data and responding to incidents.

ITGCs are “general” because their effect can extend across multiple applications and processes. If access and change controls are weak, the auditor may have less confidence that an automated control continued to operate as configured or that system-generated information is reliable.

The audit scope should still be risk-based. Not every control in an IT framework is relevant to every financial statement audit. The team needs to understand the systems and automated controls on which the financial reporting process or audit approach depends, then identify the ITGCs that support them.

Platformed capability: Platformed collects client evidence, assesses the relevant ITGCs and prepares linked conclusions for auditor review. The aim is a proportionate and defensible assessment, not a longer checklist.

References: PCAOB description of general and application controls · Platformed ITGC assessments

← All 60 questions