IT & Cyber Audit
IT General Controls Effectiveness
If general IT controls are weak, every automated control and every financial figure that depends on the system is in doubt.
Why ITGC Effectiveness Matters
IT general controls are the foundation on which application controls and the integrity of financial data rest, which is why the AGSA, COSO and ISSAI 5300 give them prominence in any computerised environment. Weak access, change, operations or security controls mean an auditor cannot rely on system-generated information, often forcing extended substantive testing or a qualification. AuditPro Core assesses each ITGC domain across key systems so the entity knows where the control foundation is sound and where it is cracked.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Domains effective
68%
▲ 6 pts
Deficient controls
41
Systems not reliable
5
Systems in scope
17
Control rating by domain
Systems flagged not reliable
| System | Weakest domain | Deficiencies | Rating |
|---|---|---|---|
| Financial ledger | Access mgmt | 7 | Ineffective |
| Payroll system | Security mgmt | 6 | Ineffective |
| Billing system | Change mgmt | 5 | Partial |
| HR system | Access mgmt | 5 | Ineffective |
| Asset register | IT operations | 4 | Partial |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
The four ITGC domains
ITGCs span access security, change management, IT operations and information security. A failure in any one domain can undermine reliance on the whole system, so each must be assessed rather than averaged away.
Foundation for application controls
Automated application controls are only trustworthy if the general controls around them are effective. A perfectly designed system control means nothing if a developer can change it without authorisation.
Design versus operating effectiveness
A control can be well designed yet fail to operate consistently. ITGC assessment must test that controls actually work over the period, not just that policies exist.
How AuditPro Core Bridges the Gap
- Domain scoring: access, change, operations and security are assessed and scored per key system rather than as a single blended rating.
- Control-test traceability: each rating links to the evidence of the test performed.
- Exception workflow: ineffective controls route to owners with remediation milestones.
- Audit-ready export: the ITGC matrix exports to support the auditor's reliance decision and the COSO control assessment.
Key Takeaways
- Weak ITGCs undermine reliance on every system-generated number.
- Assess all four domains; a single failure can break reliance on the whole system.
- Test operating effectiveness over the period, not just control design.
- Strong ITGCs reduce the substantive testing burden and qualification risk.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
