What is an ITGC internal audit checklist?
An ITGC internal audit checklist tests controls over the IT environment that financial and operational controls depend on: user access, privileged access, segregation of duties, change management, backup/recovery, interfaces, batch jobs and audit logs.
Why does ITGC matter for process audits like P2P or R2R?
If access, change management or interface controls are weak, the auditor may not be able to rely on ERP reports, automated approvals, workflow logs or application controls used in P2P, O2C, R2R and payroll testing.
Is ITGC the same as cybersecurity audit?
No. ITGC focuses on controls relevant to reliable processing and reporting, especially access, changes, operations and data integrity. Cybersecurity audit is broader and includes vulnerability management, incident response, awareness and third-party security.
Can ITGC testing be monitored continuously?
Some ITGC areas can be monitored periodically: active users for exited employees, privileged user activity, failed jobs, interface exceptions, backup failures and master-data changes. The exception still needs auditor review before reporting.