Skip to content

IT General Controls (ITGCs)

Definition

Controls over the IT environment that support the reliable operation of application controls. Key categories include access management, change management, computer operations, and data integrity controls. Weaknesses in ITGCs can undermine the entire control framework built on top of automated systems.

Full term
IT general controls
Key categories
Access, change management, operations, data integrity
Supports
Reliability of application-level controls
Weakness impact
Undermines controls built on top

Common questions

How do ITGCs differ from application controls?+

Application controls are built into a specific system, such as a validation rule in an accounting package, while ITGCs govern the environment that application runs in, such as who can change the code or access the database. A strong application control is only as reliable as the ITGCs protecting the environment around it.

Why do auditors test ITGCs before relying on automated evidence?+

If access management or change management is weak, an auditor cannot be confident that the automated controls they are relying on have operated consistently throughout the period, since unauthorised changes or access could have altered how the system behaved without leaving an obvious trace.

Related terms

COBIT
Control Objectives for Information and Related Technologies, published by ISACA. A governance and management framework for enterprise IT that defines IT-specific control...
Control Environment
The first and foundational component of the COSO framework. It encompasses the board's oversight, management's philosophy and operating style, organisational structure, commitment...
COSO Integrated Framework
A framework for internal control published by the Committee of Sponsoring Organizations of the Treadway Commission, defining five interrelated components: control environment,...
Detective Control
A control designed to identify an error or irregularity after it has occurred. Examples include bank reconciliations, exception reports, variance analysis, and...
Preventive Control
A control designed to stop an error or fraudulent act before it occurs. Examples include segregation of duties, mandatory authorisation limits, access...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.