Back to Explore
🛡️

IT & Cyber Audit

IT General Controls Effectiveness

If general IT controls are weak, every automated control and every financial figure that depends on the system is in doubt.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why ITGC Effectiveness Matters

IT general controls are the foundation on which application controls and the integrity of financial data rest, which is why the AGSA, COSO and ISSAI 5300 give them prominence in any computerised environment. Weak access, change, operations or security controls mean an auditor cannot rely on system-generated information, often forcing extended substantive testing or a qualification. AuditPro Core assesses each ITGC domain across key systems so the entity knows where the control foundation is sound and where it is cracked.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Domains effective

68%

▲ 6 pts

Deficient controls

41

Systems not reliable

5

Systems in scope

17

Control rating by domain

Systems flagged not reliable

SystemWeakest domainDeficienciesRating
Financial ledgerAccess mgmt7Ineffective
Payroll systemSecurity mgmt6Ineffective
Billing systemChange mgmt5Partial
HR systemAccess mgmt5Ineffective
Asset registerIT operations4Partial

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

The four ITGC domains

ITGCs span access security, change management, IT operations and information security. A failure in any one domain can undermine reliance on the whole system, so each must be assessed rather than averaged away.

Foundation for application controls

Automated application controls are only trustworthy if the general controls around them are effective. A perfectly designed system control means nothing if a developer can change it without authorisation.

Design versus operating effectiveness

A control can be well designed yet fail to operate consistently. ITGC assessment must test that controls actually work over the period, not just that policies exist.

How AuditPro Core Bridges the Gap

  • Domain scoring: access, change, operations and security are assessed and scored per key system rather than as a single blended rating.
  • Control-test traceability: each rating links to the evidence of the test performed.
  • Exception workflow: ineffective controls route to owners with remediation milestones.
  • Audit-ready export: the ITGC matrix exports to support the auditor's reliance decision and the COSO control assessment.

Key Takeaways

  • Weak ITGCs undermine reliance on every system-generated number.
  • Assess all four domains; a single failure can break reliance on the whole system.
  • Test operating effectiveness over the period, not just control design.
  • Strong ITGCs reduce the substantive testing burden and qualification risk.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.