CORAA

IT General Controls (ITGC) Checklist

A risk-and-control checklist covering access management, change management, segregation of duties, backup/recovery and authentication — the IT-environment controls SIA 520 and the ICFR framework both rely on.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Standard
SIA 520 — IT environment
Domains
Access, change, SoD, backup, authentication
Matters for
Reliance on any automated/IT-dependent control
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

IT GENERAL CONTROLS (ITGC) CHECKLIST

Entity: ___ · Period: ___ · System(s) in scope: ___

Scope: the IT-environment controls under SIA 520 — access management, change management, segregation of duties, backup/recovery and authentication. These controls also underpin any automated/IT-dependent control relied on elsewhere in the audit universe; a deficiency here can invalidate reliance on those downstream controls.

Risk & Control Matrix

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What is the difference between ITGCs and application controls?
ITGCs are controls over the IT environment as a whole — who can access systems, how changes are made, whether backups work — that everything else depends on. Application controls are the specific automated checks inside one process (e.g. a 3-way-match block in the purchasing module). If ITGCs are weak, reliance cannot be placed on ANY application control in that environment, however well-designed it looks in isolation.
Why does segregation of duties get its own line instead of being folded into access management?
Access management asks "does this person have the access they were granted?" — SoD asks a different question: "even if every individual grant is properly approved, does the COMBINATION of access this person holds let them both execute and conceal a fraud (e.g. create a vendor and also approve payments to it)?" That is a distinct test, usually run via a conflict matrix, not just an access list.
How often should backup restoration actually be tested?
A backup schedule alone does not prove recoverability — only an actual restoration test does, since backups can fail silently for months without anyone noticing. Quarterly restoration testing of critical systems is common practice; the checklist tests whether this is DOCUMENTED evidence, not just an assumption that backups are "probably fine."
Related templates

You might also need.

ICFR Testing Working Paper — Sec 143(3)(i) Format
Free ICFR testing working paper for Sec 143(3)(i) — risk-control matrix (RCM), ITGC tests, deficiency vs signi
Journal Entry Testing Working Paper — SA 240
Free SA 240 journal entry testing working paper — Benford leading-digit table, characteristics battery (round,
Internal Audit Risk Assessment Matrix — Impact × Likelihood
Free internal audit risk assessment matrix template. Impact × Likelihood scoring computed automatically across