modern auditing

Glossary

ITGC

Also known as: IT general controls

The controls over the IT environment that financial and operational controls depend on — access, change management, and operations — and the most commonly failed area in SOX programmes.

ITGCs are the foundation layer. If you cannot rely on who has access to a system, on the fact that changes to it were tested and approved, or on the jobs and backups that keep it running, then no automated control inside that system can be relied on either. A single ITGC failure can invalidate a large population of application controls, which is why ITGC deficiencies escalate so quickly.

Three domains carry most of the weight:

  • Access to programs and data — provisioning, de-provisioning, privileged access, periodic recertification, segregation of duties.
  • Program change — that changes were requested, tested, approved and migrated by someone who could not also develop them.
  • Program development and operations — implementation of new systems, plus job scheduling, backup and recovery.

ITGCs are also where population testing pays off first and most visibly. Access recertification and privileged-change matching are exactly the tasks that are miserable by sample and straightforward against the full population — and they are the two that most reliably surface exceptions nobody expected.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.