CORAA
CORAA University / ITGC audit workbook

ITGC audit workbook

Generate an Excel/PDF workbook for user access, privileged access, SoD, change management, backups, interfaces, jobs, audit logs, report reliability and monitoring exceptions.

Engagement profile
Select audit areas
10 RCM rows selected
AreaRiskControlTestEvidenceCadence
User access lifecycleUsers are created, modified or retained without approved business need, role mapping or timely leaver removal.Access request approval, role-based provisioning, joiner-mover-leaver workflow and periodic access review.Match active user list to HR active/leaver list, sample new users, test role mapping and inspect review sign-off.User list, HR employee/leaver list, access tickets, role matrix, access review file and exception tracker.Monthly / Quarterly
Privileged accessAdmin or superuser rights allow unauthorised master changes, transaction overrides or audit-log suppression.Privileged access approval, separate admin IDs, activity logging and periodic admin review.List privileged users, inspect approval, review admin activity logs and test emergency access closure.Admin user list, privileged access approval, activity log, emergency access register and reviewer conclusion.Monthly
Segregation of dutiesOne user can initiate and conceal transactions, such as vendor creation plus payment release.SoD rule matrix, role-combination review, conflict approval and compensating control validation.Run role-conflict report, identify create/approve/post/release conflicts and review unresolved exceptions.SoD matrix, role export, conflict report, compensating control evidence and owner sign-off.Quarterly
Change managementApplication, configuration, workflow or report changes move to production without approval, testing or rollback evidence.Change request approval, UAT sign-off, production migration approval, emergency-change review and developer access restriction.Sample production changes, trace approval/UAT/deployment, review emergency changes and check production developer access.Change tickets, UAT evidence, deployment log, release note, emergency-change register and production access list.Monthly / Release based
Backup recovery and DRCritical finance data cannot be restored because backups fail, are overwritten or have never been restoration-tested.Scheduled backups, backup-failure alerts, offsite/off-network retention, restoration testing and RTO/RPO mapping.Inspect backup logs, verify restoration test, review failure tickets and compare RTO/RPO to business requirement.Backup logs, restoration report, DR drill evidence, RTO/RPO matrix, incident tickets and storage policy.Monthly / Quarterly
Interfaces and batch jobsData moving between ERP, payroll, bank, GST, inventory, WMS or reporting systems is incomplete, duplicated or stale.Interface control totals, failed-job alerts, exception queue review and manual reprocessing approval.Review failed jobs, compare source/target counts and values, age exception queues and test reprocessing approvals.Interface logs, batch totals, exception queue, reconciliation file, job scheduler report and reprocessing approval.Weekly / Monthly
Audit logs and master changesCritical configuration, vendor, customer, bank, payroll or inventory changes cannot be traced to user, timestamp and approval.Audit trail enabled, log retention, master-data change approval and high-risk change review.Verify logs for critical tables, sample master changes, compare old/new values and inspect approval evidence.Audit-log settings, master change report, old/new value extract, approval ticket, retention policy and review sign-off.Monthly
Report reliability and IPEAuditors rely on ERP reports or exported spreadsheets that are incomplete, modified or generated with wrong parameters.Report owner approval, parameter retention, source reconciliation and protected export storage.Reperform report extraction for samples, compare report totals to GL/subledger and inspect parameter evidence.Report catalogue, report parameters, export file, GL/subledger tie-out, owner sign-off and version history.Per audit / Monthly
Third-party and cloud systemsHosted ERP, payroll, POS, bank, SaaS or outsourced systems lack access, change, backup or incident evidence.Vendor responsibility matrix, SOC/assurance report review, SLA monitoring, incident reporting and exit plan.Review vendor controls, SOC exceptions, SLA breaches, incident logs and user access responsibilities.Vendor contract, responsibility matrix, SOC report, SLA dashboard, incident register and exit/BCP plan.Annual / Quarterly
ITGC monitoring and follow-upAccess, SoD, failed-job, backup or master-change exceptions repeat without ownership, due dates or closure evidence.Exception rules, owner assignment, management response, due-date tracking and closure evidence review.Review open exceptions, test ageing, inspect closure evidence and identify repeat exceptions by control owner.Exception report, ATR tracker, management response, closure evidence, ageing report and repeat-finding analysis.Monthly

Use this with the ITGC internal audit checklist, the audit trail Rule 11(g) guide and the monitoring rules repository.

How it works

ITGC audit should focus on the systems and reports that finance and operational controls rely on. The workbook connects access, SoD, changes, operations, logs, report reliability and third-party/cloud controls to the process controls affected by those systems.

The Excel export gives auditors separate sheets for engagement scope, RCM rows, user access, privileged access/SoD, changes, backup/DR, interfaces/jobs, logs/master changes, report reliability and monitoring exceptions.

Worked example

A CA firm is reviewing ERP reliance for a company using SAP, payroll software, bank portals and a reporting dashboard for P2P, payroll, inventory and R2R internal audit.

Inputs
ScopeAccess, SoD, change, backup, interfaces, logs and report reliability
OutputExcel workbook plus PDF summary
Output
WorkbookRCM, access review, privileged access, SoD conflicts, production changes, backup evidence, interface jobs, master changes, report reliability and monitoring exceptions

Common mistakes

Testing ITGC without process linkage
An ITGC exception matters most when it affects a report, workflow, approval or automated control used in P2P, O2C, R2R, payroll or another process.
Relying on screenshots only
Screenshots help, but auditors should retain exports, parameters, timestamps, source reconciliations and reviewer conclusions.
Treating cloud vendors as out of scope
Hosted ERP, payroll, POS and reporting systems still need responsibility mapping, access review, SLA/incident evidence and assurance-report review where available.

Frequently asked questions

What is included in an ITGC audit workbook?+
It includes engagement scope, ITGC RCM rows, user access review, privileged access and SoD testing, change management, backup/DR, interfaces and batch jobs, audit logs, report reliability and monitoring exceptions.
Can I export the ITGC workbook to Excel?+
Yes. The workbook exports a multi-sheet Excel file and a PDF summary so auditors can document samples, evidence, exceptions, reviewer notes and monitoring rules.
Which systems should be included first?+
Start with systems that generate accounting records, approvals, master data, reports or interfaces used by internal audit: ERP, payroll, bank portals, inventory/WMS, POS, GST/return tools and reporting dashboards.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditUse SIA planning, evidence, documentation, review, communication and reporting principles.
ICAI DAAB - Information Systems Audit Standards exposure draftUse as current ICAI direction on IS audit vocabulary; confirm final standard status before citing as mandatory.
ICAI DAAB resourcesUse for ICAI information systems audit resources, ISA course materials and DAAB updates.
ICAI - Standards on Auditing and CIS environment archiveHistorical CIS audit guidance; use current SAs/SIAs for active engagement criteria.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
ITGC internal audit checklistAudit trail Rule 11(g) guideInternal audit resource hub
Share this tool
Last reviewed: 2026-08-29 · For informational purposes only — not professional advice.