CORAA
Resources · Internal Audit ITGC

ITGC internal audit checklist.

IT general controls decide whether an auditor can rely on ERP approvals, workflow logs, system reports and automated application controls. Use this checklist to scope access, SoD, change management, backup/recovery, interfaces and audit-log testing before relying on process-control evidence.

Build ITGC audit workbookDownload Word checklist
Testing map

Six ITGC domains to cover domains

User access management

Risk: Users have access that is not approved, not role-appropriate or not removed when they leave.

Controls
  • Access request approval
  • Role-based provisioning
  • Periodic access review
  • Leaver access removal
Tests
  • Match active user list to HR active employee list
  • Sample new users for approved request and role mapping
  • Review admin/privileged access separately
  • Check leaver IDs disabled within policy timeline
Evidence

User listing, role matrix, access request tickets, HR active/leaver list, access review sign-off and exception tracker.

Segregation of duties

Risk: One user can initiate and conceal a transaction, such as vendor creation plus payment approval.

Controls
  • SoD conflict matrix
  • Role-combination review
  • Emergency access log review
  • Compensating control approval
Tests
  • Run user-role conflict report
  • Identify create/approve/post/release combinations
  • Review compensating controls for unresolved conflicts
  • Test emergency access grants and closure
Evidence

SoD matrix, user-role export, conflict report, compensating-control approval, emergency access log and reviewer conclusion.

Change management

Risk: Application, configuration or report changes move to production without approval, testing or rollback evidence.

Controls
  • Change request approval
  • UAT sign-off
  • Production migration approval
  • Emergency change review
Tests
  • Sample production changes and trace each to request, approval and UAT
  • Review emergency changes for after-the-fact approval
  • Check developer access to production
  • Verify rollback/backout plan where relevant
Evidence

Change tickets, UAT sign-off, deployment logs, production access list, emergency-change register and release notes.

Backup and recovery

Risk: The entity assumes data is recoverable, but backups are missing, corrupted or not restoration-tested.

Controls
  • Scheduled backup jobs
  • Offsite/off-network storage
  • Restoration test
  • Backup failure alert review
Tests
  • Inspect backup job success/failure logs
  • Verify restoration test evidence for critical systems
  • Review RTO/RPO mapping for finance systems
  • Check failure alerts and remediation trail
Evidence

Backup logs, restoration test report, RTO/RPO matrix, incident tickets, storage policy and DR drill report.

Interfaces and batch jobs

Risk: Data between ERP, payroll, bank, GST, inventory or reporting systems is incomplete or duplicated.

Controls
  • Interface reconciliation
  • Failed job alert review
  • Batch total check
  • Exception queue clearance
Tests
  • Review failed and delayed jobs
  • Compare source and target record counts/value totals
  • Test exception queue ageing
  • Trace manual reprocessing approval
Evidence

Interface logs, batch control totals, exception queue, reconciliation file, failed-job ticket and reprocessing approval.

Audit logs and master data

Risk: Critical master-data or configuration changes cannot be traced to a user, approval and timestamp.

Controls
  • Audit trail enabled
  • Master-data change approval
  • Log retention
  • Periodic high-risk change review
Tests
  • Verify audit logs are enabled for critical tables
  • Review vendor/customer/bank master changes
  • Check log retention and exportability
  • Sample changes for approval evidence
Evidence

Audit-log setting, master change report, old/new value extract, approval ticket, retention policy and reviewer sign-off.

Workpapers

Templates and linked tools downloads

ITGC Audit Workbook

Excel/PDF workbook for access, SoD, change, backup, interfaces, audit logs, report reliability and monitoring exceptions.

Open ->
ITGC Checklist Template

Editable Word checklist for access, change, SoD, backup and authentication controls.

Open ->
Internal Audit RCM Builder

Export ITGC rows into an engagement-specific Excel/PDF RCM.

Open ->
Monitoring Rules Repository

Convert leaver access, privileged activity and failed jobs into recurring exception rules.

Open ->
Control Repository

Place ITGC beside P2P, O2C, R2R, payroll, treasury and compliance controls.

Open ->
ICFR Working Paper

Use when ITGC reliance also supports Section 143(3)(i) internal financial controls testing.

Open ->
Audit Trail Rule 11(g)

Audit-trail enablement and retention context for accounting software used for books.

Open ->
Reliance decision

How ITGC affects process-control reliance evidence

ITGC exceptions do not automatically invalidate every process-control test. The auditor should identify which ERP modules, reports and workflows are affected, whether the exception relates to the period tested, and whether compensating manual controls exist. The conclusion should be documented at the same level as the reliance placed on system evidence.

Map process controlsMonitor ITGC exceptions
FAQ

ITGC checklist FAQs questions

What is an ITGC internal audit checklist?

An ITGC internal audit checklist tests controls over the IT environment that financial and operational controls depend on: user access, privileged access, segregation of duties, change management, backup/recovery, interfaces, batch jobs and audit logs.

Why does ITGC matter for process audits like P2P or R2R?

If access, change management or interface controls are weak, the auditor may not be able to rely on ERP reports, automated approvals, workflow logs or application controls used in P2P, O2C, R2R and payroll testing.

Is ITGC the same as cybersecurity audit?

No. ITGC focuses on controls relevant to reliable processing and reporting, especially access, changes, operations and data integrity. Cybersecurity audit is broader and includes vulnerability management, incident response, awareness and third-party security.

Can ITGC testing be monitored continuously?

Some ITGC areas can be monitored periodically: active users for exited employees, privileged user activity, failed jobs, interface exceptions, backup failures and master-data changes. The exception still needs auditor review before reporting.