Platformed

Why do ITGCs matter in a financial statement audit?

ITGCs and technology risk · last updated 2026-09-02

ITGCs matter because financial information, automated controls and system-generated reports depend on technology continuing to operate as intended. Weak access, change or operations controls can undermine that reliance.

For example, an automated three-way match may be well designed, but its reliability is harder to support if unauthorised users can change the configuration. A management review may depend on a system report, but the audit team needs to understand whether the information in that report is complete and accurate. Relevant ITGCs help support those conclusions.

This does not mean every financial audit requires an extensive IT audit. The work should respond to the client's systems, the relevant risks and the planned audit approach. A simple, unmodified accounting environment may need a streamlined assessment. A complex environment with multiple applications, interfaces and automated controls is likely to require more depth.

The challenge for firms is applying that judgement consistently across thousands of different clients. A structured ITGC workflow helps teams reach an evidenced complexity and scoping conclusion, perform the right level of work and involve specialists where the risk genuinely requires it.

References: ISA 315 technology focus · PCAOB AS 2110

← All 60 questions