Platformed

Which ITGC domains should auditors assess?

ITGCs and technology risk · last updated 2026-09-02

The ITGC domains most often considered in financial statement audit are access management, program changes, computer operations and aspects of system development or implementation. The precise scope depends on the systems and controls relevant to the audit.

Common areas include:

The list should not become a default testing programme applied to every client. The auditor first needs to identify which applications, automated controls and system-generated information matter to the financial reporting process or planned audit response. The relevant ITGCs follow from those dependencies.

Firms also need a clear way to distinguish a missing control from a control that is simply not relevant to the audit. A configured methodology and evidence-linked rationale make that distinction easier to review and defend.

References: PCAOB general-control examples · Platformed control assurance

← All 60 questions