IT General Controls Reviews

ITGC findings appear in almost every public sector audit report, and usually in the same four places. We test the controls against evidence rather than reading the policy that describes them, because the distance between the two is exactly where the finding comes from. Our team runs these reviews at municipal level, where the results are read by the Auditor General.

1

Scope

Systems that carry financial risk

2

Walkthrough

How the control actually runs

3

Test

Sample against evidence

4

Evaluate

Design and operating effectiveness

5

Report

Root cause and action plan

How We Test

01

Scoping and Risk Assessment

We identify which systems actually carry financial reporting risk, rather than testing everything with a login screen. That means tracing each significant account back to the applications, databases and infrastructure it depends on, and agreeing the scope with you and with your external auditors before fieldwork starts.

02

Access Management Testing

Who can get into the system, what they can do once inside, and whether anyone checks. This is where the largest share of findings sits, usually because leavers keep their accounts and privileged access is never reviewed.

03

Change Management Testing

Whether changes reach production through a controlled path. We follow a sample of changes end to end and check that the person who wrote the change is not also the person who approved and deployed it.

04

IT Operations Testing

The routine that keeps the environment running and recoverable. Backups tend to be configured and never restored, which is only discovered at the worst possible moment.

05

Reporting and Remediation

Every finding is written with the control weakness underneath it rather than the symptom, because a symptom gets patched and returns the following year. We agree the action plan with the owner and retest once you say it is fixed.

What You Receive

Indicative Timeline

Most reviews run three to five weeks depending on the number of in scope systems and how quickly evidence is produced. Evidence gathering is the usual bottleneck, so we send the request list at the point of scoping rather than at the start of fieldwork.

Frameworks We Test Against

We map testing to the framework your auditors and regulator actually apply, rather than to a single house methodology.

COBIT 2019

The control framework most ITGC testing maps back to, and the one external auditors generally reference.

King IV

Principle 12 places technology and information governance with the governing body, which is where most root causes end up.

ISO/IEC 27001

Information security management, used where a certifiable baseline is required rather than an audit opinion.

ITIL

Service management practice for change, incident and problem handling, useful as a benchmark for operations controls.

POPIA

Where personal information is processed, access rights and retention fall inside the control scope.

MFMA and PFMA

Public sector financial management requirements that the ICT control environment has to support.

Frequently Asked Questions

It is a control over the technology environment rather than over a single transaction. Access, change, operations and backup are the four domains. They matter because almost every automated financial control depends on them, so a weakness in ITGC undermines the controls sitting on top of it.

An ITGC review asks whether the controls management says exist are actually operating, and reports in audit language. A cyber security assessment asks what an attacker could do. They overlap on access control but answer different questions for different audiences.

We test. Walkthroughs establish how a control is meant to run, then we sample against evidence such as tickets, approvals, logs and system extracts. A control described but not evidenced is reported as a deficiency.

It should reduce repeat findings, which is where most of the damage is done. Finding and fixing a weakness before the external auditors arrive is considerably cheaper than explaining it afterwards, but we cannot promise an outcome that depends on the whole audit.

Whichever ones carry financial reporting risk. That usually means the financial system, payroll, billing or revenue, and the infrastructure underneath them. We agree scope in writing before fieldwork so there are no surprises about coverage.

Yes, and we recommend it. A finding is only closed once the control has been observed operating, not once an action plan has been signed.

Related Services

This sits inside our ICT Audit practice. Related work: Cyber Security Assessments for the attacker view of the same environment, and Internal Audit where controls testing needs to run continuously rather than annually.

Discuss an ITGC review