Back to Explore
🔐

Internal Controls

IT General Controls Status

Effectiveness of ITGCs across access, change, operations and security control domains.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why IT general controls status matters

IT general controls underpin the reliability of every automated control and financial system the institution relies on, and the AGSA routinely raises ITGC weaknesses, particularly around access and change, as drivers of audit findings and POPIA exposure. Tracking ITGC effectiveness across access, change, operations and security domains reveals whether the technology foundation supporting financial reporting is sound. AuditPro Core monitors ITGC status by domain so management can remediate the IT control weaknesses that quietly undermine application-level controls and data integrity.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

ITGCs tested

126

Effective

84%

▲ 6 pts YoY

Deficient

20

16%

Pervasive impact

3

affect app controls

Effectiveness by ITGC domain (%)

Deficiencies by domain

DomainTestedDeficientTop severity
Access management347High
Change management284Medium
IT operations243Low
Security management265High
Backup & recovery141Low

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

IT general controls

ITGCs are the controls over the IT environment that ensure applications and data operate reliably, spanning access, change management, operations and security. Application controls cannot be relied upon if the ITGCs beneath them are weak.

Access management

Access controls ensure that only authorised users can perform sensitive functions, supporting both segregation of duties and POPIA's data-protection requirements. Weak access management is among the most common and consequential ITGC failures.

Change management

Change controls ensure that modifications to systems are authorised, tested and documented before deployment. Uncontrolled changes can silently break controls or corrupt data without detection.

Operations and security

Operations controls cover backups, job scheduling and incident handling, while security controls defend against unauthorised access and breaches. Both protect the availability and integrity of financial data.

How AuditPro Core Bridges the Gap

  • Domain scoring: ITGC effectiveness is rated across access, change, operations and security for a structured view.
  • Weakness exceptions: domains scoring below threshold are flagged, with access and change typically prioritised.
  • Traceability to tests: each domain score links to the underlying ITGC tests and evidence.
  • Audit-ready ITGC report: the domain view exports to support reliance on automated controls for AGSA and POPIA assurance.

Key Takeaways

  • Application controls cannot be relied upon over weak ITGCs.
  • Access weaknesses are the most common and consequential ITGC failures.
  • Uncontrolled changes can silently break controls or corrupt data.
  • Operations and security controls protect financial data availability and integrity.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.