What's changed: Initial version
4.4IT controls (IT general controls and IT application controls)
Covers the difference between IT general controls (ITGC) (access management, program change management, development/deployment, operations management), which control the IT foundation, and IT application controls (input/processing/output controls), which safeguard the accuracy, completeness, and validity of individual business processing, plus the dependency that ★if ITGC is not effective, IT application controls cannot be relied on either, building the judgment to diagnose how a control deficiency propagates.
IT-system controls are evaluated in two broad layers. One is IT general controls (ITGC), which protect the foundation itself on which systems run—who can change or access systems, whether changes are properly managed, whether operations are stable. The other is IT application controls, which protect the correctness of individual business processing running on that foundation—whether input data is accurate, whether processing is complete, whether output is valid. What is decisively important for an auditor is that these two layers have a dependency: if ITGC is not effective, IT application controls cannot be relied on as they stand either. Grounded in the difference in roles and this dependency, this section builds the viewpoint from which an auditor diagnoses how a control deficiency propagates.
4.4.1IT general controls (ITGC)
- IT general controls (ITGC) are the foundational controls that serve as the premise for individual application controls to function effectively. The representative areas are four: (1) access management (permission management and authentication for who can access and operate what), (2) program change management (ensuring changes to production programs go through approval, testing, and migration procedures), (3) system development and deployment (controls over requirements, testing, and migration), and (4) operations management (job execution, backup, incident response, configuration management).
- Segregation of duties is deeply involved in each ITGC area. For example, a setup where a developer can release programs directly into the production environment is an absence of the preventive control against untested or unauthorized changes slipping in, and constitutes an ITGC weakness. An auditor evaluates, from both a design and operating standpoint, "whether the authority for development and production migration is separated" and "whether there is an approval record for changes."
4.4.2IT application controls
- IT application controls are controls that, within each business application, ensure the accuracy, completeness, validity, and maintenance/continuity of the transaction data processed. They divide into input controls (check digits, validity checks on input values, mandatory-field checks, etc.), processing controls (batch controls = reconciling record counts and total amounts, preventing double processing), and output controls (limiting the output destination, reconciling output results).
- IT application controls are designed to correspond to "what errors or impersonations can occur in that operation." For order-entry, for example, they include validation that prevents entering a negative quantity (input control), reconciliation of whether the registered count matches the processed count (processing control), and control limiting invoice output to approved transactions (output control).
Most-tested: distinguishing "ITGC = the foundational controls of access management, change management, development/deployment, and operations management" from "IT application controls = controls for the accuracy, completeness, and validity of input/processing/output", plus the dependency ★"if ITGC is not effective, IT application controls cannot be relied on either". Check digits and batch controls are application controls (within the app); access-permission management and program change management are ITGC (the foundation)—do not misassign them.
Suppose a systems auditor is evaluating the IT controls of an order-entry system. Examining the application, the application controls are well designed—order entry has validity checks (an input control rejecting negative quantities), and a batch control (processing control) reconciling the daily order count against the accounting-integration count is running. The auditor is tempted here to conclude, "the application controls are effective, so this order data can be relied on." But checking the IT general controls reveals a serious problem—a developer holds the authority to rewrite production programs directly, without approval or testing, and no change-management record is kept. The judgment the auditor should make here is the heart of this section. No matter how finely the IT application controls are designed, if someone can rewrite the very program that implements that control logic without approval or testing, there is no assurance that the application controls actually operate as designed. In the extreme, even if a developer quietly disables the check that rejects negative quantities, no one can notice because there is no change-management record. In other words, if ITGC (program change management, access management) is not effective, the very reliability of the IT application controls running on top of it collapses. The auditor therefore judges that, even though the application controls appear effective on the surface, the ITGC deficiency is the root cause, reliance on the application controls should be limited, and broader substantive procedures (expanding the sample scope or directly verifying the data) are needed. The trap here is to look only at the in-app controls (input/processing/output) and end the evaluation with "it is well made, so we can rest easy"—it is an audit principle that the evaluation of IT controls must always build up from the foundation (ITGC), and if ITGC is weak, the degree of reliance on application controls is discounted.
| Category | IT general controls (ITGC) | IT application controls |
|---|---|---|
| Target | The entire foundation on which systems run | Processing within each individual business application |
| Representative examples | Access management, program change management, development/deployment, operations management | Check digits, input validity checks, batch controls |
| What it ensures | The premise for application controls to function effectively | The accuracy, completeness, and validity of transaction data |
| Dependency | ★If this is ineffective, application controls cannot be relied on either | Can be relied on only on the premise of effective ITGC |
Trap: "if IT application controls (input/processing/output) are well designed, the data can be relied on even if ITGC is weak" is wrong—★if ITGC (program change management, access management, etc.) is not effective, the application-control logic itself can be altered without authorization, so the degree of reliance on application controls must be discounted. Also wrong: "a check digit is an IT general control"—check digits and batch controls are application controls (within the app), whereas access rights and change management are ITGC (the foundation).
4.4.3Section summary
- IT general controls (ITGC) = the foundational controls of access management, program change management, development/deployment, and operations management (the premise for application controls)
- IT application controls = controls safeguarding the accuracy, completeness, and validity of input/processing/output (check digits, batch controls, etc.)
- ★If ITGC is not effective, IT application controls cannot be relied on either—an auditor builds up from the foundation and discounts reliance on application controls if ITGC is weak
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. In an IT-control evaluation of an order-entry system, IT application controls such as input validity checks and batch controls are well designed. However, it was found that a developer can rewrite production programs directly without approval or testing, and no change-management record is kept. Which judgment by the auditor is most appropriate?
Q2. Among the following controls, which is classified as an IT application control rather than an IT general control (ITGC)?
Q3. Which is the audit-correct understanding of the relationship between IT general controls (ITGC) and IT application controls?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

