Which ITGC domains should auditors assess?
The ITGC domains most often considered in financial statement audit are access management, program changes, computer operations and aspects of system development or implementation. The precise scope depends on the systems and controls relevant to the audit.
Common areas include:
- user provisioning, removal and periodic access review;
- privileged access and segregation of duties;
- approval, testing and migration of system changes;
- job monitoring, incident management and backup procedures;
- implementation or significant modification of relevant applications;
- third-party or service-organisation dependencies.
The list should not become a default testing programme applied to every client. The auditor first needs to identify which applications, automated controls and system-generated information matter to the financial reporting process or planned audit response. The relevant ITGCs follow from those dependencies.
Firms also need a clear way to distinguish a missing control from a control that is simply not relevant to the audit. A configured methodology and evidence-linked rationale make that distinction easier to review and defend.
References: PCAOB general-control examples · Platformed control assurance