IT General Controls Reviews
ITGC findings appear in almost every public sector audit report, and usually in the same four places. We test the controls against evidence rather than reading the policy that describes them, because the distance between the two is exactly where the finding comes from. Our team runs these reviews at municipal level, where the results are read by the Auditor General.
1
Scope
Systems that carry financial risk
2
Walkthrough
How the control actually runs
3
Test
Sample against evidence
4
Evaluate
Design and operating effectiveness
5
Report
Root cause and action plan
How We Test
01
Scoping and Risk Assessment
We identify which systems actually carry financial reporting risk, rather than testing everything with a login screen. That means tracing each significant account back to the applications, databases and infrastructure it depends on, and agreeing the scope with you and with your external auditors before fieldwork starts.
- Mapping of financial processes to supporting systems
- In scope application, database and operating system layers
- Reliance on service organisations and hosted platforms
- Scope agreed with management and external audit
02
Access Management Testing
Who can get into the system, what they can do once inside, and whether anyone checks. This is where the largest share of findings sits, usually because leavers keep their accounts and privileged access is never reviewed.
- User provisioning and approval evidence
- Privileged and generic account usage
- Periodic user access reviews
- Timeliness of terminations and role changes
03
Change Management Testing
Whether changes reach production through a controlled path. We follow a sample of changes end to end and check that the person who wrote the change is not also the person who approved and deployed it.
- Change request, approval and testing evidence
- Segregation between development and production
- Emergency change handling
- Version control and rollback capability
04
IT Operations Testing
The routine that keeps the environment running and recoverable. Backups tend to be configured and never restored, which is only discovered at the worst possible moment.
- Backup configuration and successful restore evidence
- Batch job scheduling, monitoring and failure handling
- Incident and problem management records
- Physical and environmental controls
05
Reporting and Remediation
Every finding is written with the control weakness underneath it rather than the symptom, because a symptom gets patched and returns the following year. We agree the action plan with the owner and retest once you say it is fixed.
- Findings with root cause, not just the observation
- Risk rating and management response
- Action plan with owners and due dates
- Retesting of remediated controls
What You Receive
- ITGC testing matrix showing what was tested and how
- Findings register with root cause and risk rating
- Management action plan with owners and due dates
- Retest report once remediation is complete
- Summary suitable for the audit committee
Indicative Timeline
Most reviews run three to five weeks depending on the number of in scope systems and how quickly evidence is produced. Evidence gathering is the usual bottleneck, so we send the request list at the point of scoping rather than at the start of fieldwork.
- Scoping and evidence request: three to five days
- Walkthroughs and testing: two to three weeks
- Evaluation and draft report: one week
- Management comment and final report: one week
Frameworks We Test Against
We map testing to the framework your auditors and regulator actually apply, rather than to a single house methodology.
COBIT 2019
The control framework most ITGC testing maps back to, and the one external auditors generally reference.
King IV
Principle 12 places technology and information governance with the governing body, which is where most root causes end up.
ISO/IEC 27001
Information security management, used where a certifiable baseline is required rather than an audit opinion.
ITIL
Service management practice for change, incident and problem handling, useful as a benchmark for operations controls.
POPIA
Where personal information is processed, access rights and retention fall inside the control scope.
MFMA and PFMA
Public sector financial management requirements that the ICT control environment has to support.
Frequently Asked Questions
What exactly is an IT general control?
It is a control over the technology environment rather than over a single transaction. Access, change, operations and backup are the four domains. They matter because almost every automated financial control depends on them, so a weakness in ITGC undermines the controls sitting on top of it.
How is this different from a cyber security assessment?
An ITGC review asks whether the controls management says exist are actually operating, and reports in audit language. A cyber security assessment asks what an attacker could do. They overlap on access control but answer different questions for different audiences.
Do you test, or do you rely on what IT tells you?
We test. Walkthroughs establish how a control is meant to run, then we sample against evidence such as tickets, approvals, logs and system extracts. A control described but not evidenced is reported as a deficiency.
Will this improve our audit outcome?
It should reduce repeat findings, which is where most of the damage is done. Finding and fixing a weakness before the external auditors arrive is considerably cheaper than explaining it afterwards, but we cannot promise an outcome that depends on the whole audit.
Which systems will be in scope?
Whichever ones carry financial reporting risk. That usually means the financial system, payroll, billing or revenue, and the infrastructure underneath them. We agree scope in writing before fieldwork so there are no surprises about coverage.
Can you retest after we remediate?
Yes, and we recommend it. A finding is only closed once the control has been observed operating, not once an action plan has been signed.
Related Services
This sits inside our ICT Audit practice. Related work: Cyber Security Assessments for the attacker view of the same environment, and Internal Audit where controls testing needs to run continuously rather than annually.
