Instiq
Chapter 4 · IT governance & internal control·v1.0.0·Updated 7/11/2026·~16 min

What's changed: Initial version

4.4IT controls (IT general controls and IT application controls)

Key points

Covers the difference between IT general controls (ITGC) (access management, program change management, development/deployment, operations management), which control the IT foundation, and IT application controls (input/processing/output controls), which safeguard the accuracy, completeness, and validity of individual business processing, plus the dependency that ★if ITGC is not effective, IT application controls cannot be relied on either, building the judgment to diagnose how a control deficiency propagates.

IT-system controls are evaluated in two broad layers. One is IT general controls (ITGC), which protect the foundation itself on which systems run—who can change or access systems, whether changes are properly managed, whether operations are stable. The other is IT application controls, which protect the correctness of individual business processing running on that foundation—whether input data is accurate, whether processing is complete, whether output is valid. What is decisively important for an auditor is that these two layers have a dependency: if ITGC is not effective, IT application controls cannot be relied on as they stand either. Grounded in the difference in roles and this dependency, this section builds the viewpoint from which an auditor diagnoses how a control deficiency propagates.

4.4.1IT general controls (ITGC)

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.