CORAA
Internal audit programme - ITGC audit programme

ITGC Internal Audit Programme programme.

An ITGC internal audit programme tests user access, privileged access, segregation of duties, change management, backup and recovery, interfaces, batch jobs, audit logs, report logic and IT operations controls.

Download Excel/PDF workbookOpen detailed checklist
Why this cycle matters

Business-cycle testing often relies on ERP reports. ITGC gives the auditor confidence that access, changes, interfaces and reports did not undermine the evidence population.

Leaver or excessive access
Privileged users changing master data
SoD conflicts
Unapproved production changes
Backup/DR gaps
Unvalidated report logic or interface failures
Fieldwork programme

Audit procedures, evidence and sample basis procedures

User access lifecycle

Objective: Access is approved, appropriate and removed promptly.

Procedure steps
  • Match user listing to active employee/consultant list.
  • Test additions, modifications and removals.
  • Review periodic access recertification.
Evidence

User list, HR list, access tickets, recertification, leaver report.

Sample basis

All privileged users, all leavers, risk-based access changes.

Privileged access and SoD

Objective: Powerful roles and conflicting rights are controlled.

Procedure steps
  • Identify admin and sensitive business roles.
  • Test privileged activity logs.
  • Review SoD conflicts and compensating controls.
Evidence

Role matrix, admin list, activity logs, SoD report, review sign-off.

Sample basis

All admins and high-risk SoD conflicts.

Change management

Objective: System changes are requested, tested, approved and deployed safely.

Procedure steps
  • Select production changes and trace to ticket, UAT and approval.
  • Review emergency changes and post-implementation review.
  • Check developer access to production.
Evidence

Change tickets, UAT, approvals, deployment logs, rollback evidence.

Sample basis

Changes in audit period, all emergency changes.

Operations, interfaces and report reliance

Objective: Reports and data flows used by audit are reliable.

Procedure steps
  • Review backup/DR evidence and failed jobs.
  • Test interface reconciliation and batch job monitoring.
  • Document report logic and filters for key audit reports.
Evidence

Backup logs, DR test, interface logs, job monitor, report specification.

Sample basis

Key audit reports/interfaces and failed jobs.

Data requests

  • Application/AD user listing with role/status/last login
  • Privileged user and SoD reports
  • Change ticket register with UAT/approval/deployment evidence
  • Backup, DR, interface, batch job, report logic and audit-log records

Analytics to run

  • Leavers with active access
  • Admin changes to master data
  • SoD conflicts without review
  • Emergency changes without closure
  • Failed interfaces not reprocessed

Red flags

  • Shared admin IDs
  • Developers with production access
  • Report extracted manually with no filter evidence
  • Inactive users with last login after exit
  • Backup jobs failing without escalation
Execution workflow

Build a defensible file RCM to evidence.

Use this cycle programme after the SOW, data request list and RCM are aligned. The Excel workbook should carry sample rationale, extraction filters, preparer sign-off, reviewer sign-off and observation references.

Authority

Use current standards and entity facts sources

ICAI IASB lists the Compendium of Standards on Internal Audit as on February 2026 as applicable from 1 April 2026. Use this page as a practical workpaper starter, then verify the latest standard, law, regulation, ERP report and client fact pattern before concluding.

FAQ

ITGC audit programme questions answers

What should an ITGC audit programme cover?

It should cover user access, privileged access, SoD, change management, backup and recovery, interfaces, batch jobs, report reliance, audit logs and IT operations.

Is this ITGC programme a substitute for professional judgement?

No. It is a fieldwork starter. The internal auditor must tailor it to the approved scope, ERP, delegation matrix, locations, volumes, materiality, prior findings and current legal position.

Can I download a ITGC audit programme in Excel?

Yes. Use the linked CORAA workbook for the cycle. It contains editable RCM, testing, evidence and monitoring sheets that can be used as a fieldwork base.

Build PBC listBuild RCMSee Internal Audit module