Information technology general controls (ITGCs) are the controls over the IT environment that keep applications and data reliable: access, change management, computer operations and program development. If they fail, the auditor cannot rely on automated controls or system reports, and has to widen substantive testing.
Facts checked: 10 October 2026. SA 315 (Revised 2019) wording on identifying IT risks and general IT controls was checked against the IFAC explanatory material on ISA 315 (Revised), which has no separate requirement to evaluate ITGCs as such and asks the auditor to identify the risks from IT and the general IT controls relevant to the audit (IFAC flowchart). That is the international text; I could not open the ICAI SA 315 file. Rule 3(1) proviso and Rule 11(g) were read in ICAI and practitioner material on audit trail (EIRC-ICAI background note and Taxmann FAQs) and not in the gazette. The four-domain split is a common practice framework, not a section of the Companies Act. Verify against icai.org and mca.gov.in before quoting.
The four ITGC domains
| Domain | What it protects | Example test | Typical evidence |
|---|---|---|---|
| Access to programs and data | Only authorised users do authorised things | Compare the active user list to HR leavers; test privileged access and segregation of duties | User listing with dates, HR leaver list, role matrix |
| Program change | Only approved, tested changes reach production | Sample changes; trace each to request, test, approval and migration | Change tickets, UAT sign-off, deployment log |
| Computer operations | Jobs run completely; data is backed up and recoverable | Review job failures and how they were resolved; inspect a restore test | Scheduler log, incident tickets, backup reports |
| Program development | New systems are built and migrated properly | For a new ERP or module, review testing and data migration reconciliation | Project plan, migration reconciliations, go-live approval |
Many Indian mid-size entities run Tally, SAP Business One or a cloud ERP with limited IT staff. The domains still apply, but evidence is lighter. Document that, and do not skip the domain.
How ITGC testing supports reliance
SA 315 asks the auditor to understand the entity's information system and the IT it relies on, and to identify risks arising from IT. SA 330 then governs the response. If you plan to test an automated control (say, a three-way match) once and rely on it all year, you need assurance that the control could not have changed, which is what effective ITGCs give you. See SA 315 and the worked test of controls under SA 330.
If ITGCs are ineffective, either test the application control more extensively or, usually more practically, rely on substantive procedures and test the completeness and accuracy of any report you use.
A testing approach
- List the applications and databases relevant to financial reporting.
- Identify, per application, the ITGCs that address the risks. Tailor, do not copy.
- Test design and implementation, then operating effectiveness by sampling.
- Evaluate deficiencies and their effect on reliance.
- Conclude per application, and link to the audit plan.
Use the ITGC internal audit checklist for question lists.
Common deficiencies
- Shared or generic administrator IDs, and leavers still active.
- Developers with production access, or no evidence of testing before a change.
- Backups taken but never restored.
- Direct database edits outside the application.
- Accounting software where the edit log can be switched off.
- Unreviewed logs; reviews that happen but are not evidenced.
ITGC and Rule 11(g)
Under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, the statutory auditor reports on whether the company used accounting software with an audit trail feature that operated throughout the year and was not tampered with, for financial years from 1 April 2023. This is an ITGC question in substance: who can disable the log, and are database-level changes captured? The Rule 11(g) guide sets out the tests.
ITGC in IFC audits
Section 143(3)(i) requires the auditor's report to state whether the company has adequate internal financial controls with reference to financial statements and their operating effectiveness. For many companies, ITGCs on the reporting systems are part of that conclusion, so a weakness in access or change management can feed a reportable IFC deficiency.
When to use an IT specialist
SA 620 applies if the auditor uses an auditor's expert. Consider one when the entity runs complex or customised ERP, interfaces, cloud or outsourced hosting, or when you cannot assess the technical evidence yourself. The auditor remains responsible for the opinion, and must evaluate the expert's competence, capabilities and objectivity. See SA 620.
Worked example (invented)
Baxter Metals Ltd. posts invoices in a cloud ERP. Test: 40 user IDs in the active list. Result: 3 belonged to employees who left between April and August 2026, one of whom approved purchase invoices of ₹9.6 lakh in September. The access ITGC is ineffective, so the team does not rely on the automated approval limit, extends substantive testing of purchases, and reports the deficiency to those charged with governance.
Frequently asked questions
What are ITGCs?
Controls over the IT environment that support the continued operation of applications: access, change management, operations and development.
Is an IT audit the same as a cyber security audit?
No. An IT audit (system audit) is broader. A cyber security audit focuses on threats and defences. ITGC testing for a financial statement audit is narrower still.
Do ITGCs need testing in every audit?
Only where you plan to rely on automated controls or system information. Otherwise, document why not.
Is ITGC testing covered by Rule 11(g)?
Partly. The audit trail is one ITGC-type control. Rule 11(g) reporting is specific to accounting software.
Can we rely on a vendor's SOC report?
For hosted software, a service auditor's report can help, subject to SA 402. Check the scope covers the relevant controls and period.
For the testing mechanics, see the ITGC checklist and the SA 315 page.
Statutory facts on this page are checked against their sources, and the page says where it relied on secondary reporting. How we verify · Report an error