Back to all articles
Systems Governance & ITGC

ITGC Isn't Just for Listed Companies. Here's What Mid-Market Businesses Get Wrong.

ITGC failures are more common and more damaging at mid-market level. The blind spots auditors find first — and how to fix them proportionately.

IT General Controls have a reputation problem. Finance Directors at mid-market businesses hear "ITGC" and picture SOX compliance programmes at FTSE 100 companies — expensive, bureaucratic, and entirely irrelevant to a £30m business running on a cloud ERP and a spreadsheet or two.

That perception is both understandable and costly.

The reality is that ITGC failures are more common, and more damaging, at mid-market level than at large corporates. Larger organisations have dedicated IT audit functions, GRC platforms and well-resourced remediation cycles. Smaller businesses have a Finance Director who is also the de facto system owner, a part-time IT resource, and an ERP that was implemented by a consultant who left two years ago.

That's a control environment with significant exposure — and most Finance Directors don't know it until their external auditors find it first.

What ITGC Actually Covers

IT General Controls are the controls that govern how your technology environment operates. They underpin every automated process your business relies on — from how your ERP processes journal entries to how user access is managed when someone leaves.

At a practical level, ITGC covers four domains:

Access management. Who can access what systems, at what permission level, and how that access is granted, reviewed and revoked. In mid-market businesses, this is frequently the weakest area. Starters and leavers processes are inconsistent. Privileged access is broader than necessary. No one has done a formal access review in 18 months.

Change management. How changes to systems and configurations are authorised, tested and deployed. The classic failure here is a developer or IT contractor who can push changes directly to production without a formal approval process. It sounds unlikely until you check your ERP's change log.

Computer operations. How daily IT operations are monitored — including backup, recovery, job scheduling and incident management. For finance systems specifically, this includes ensuring that period-end processes run completely and accurately, and that failures are escalated appropriately.

System development. How new systems or significant enhancements are acquired, configured and implemented. Given the pace of SaaS adoption at mid-market level, this is increasingly relevant: every new tool integrated into your finance stack is a potential ITGC exposure if it isn't governed properly.

Why Auditors Care — Even If You're Not Listed

External auditors rely on IT controls to determine how much substantive testing they need to do. Strong ITGCs mean auditors can place reliance on automated controls and system-generated data. Weak ITGCs mean they can't trust the output of your systems — and they compensate by doing more manual testing, requesting more samples and applying more professional scepticism to everything your finance team produces.

The practical effect is that ITGC weaknesses extend your audit, increase your fees and introduce findings that go into your management letter and, in some cases, your audit report. For a PE-backed business, a management letter citing material ITGC weaknesses is an uncomfortable document to share with your board.

More importantly: if your auditors have discovered ITGC weaknesses, they've been sitting in your business for a while. The risks they represent — unauthorised access, undetected system changes, unreliable data — were present throughout the period. The audit finding is the symptom. The underlying exposure is the real issue.

The Mid-Market Blind Spots

Having worked across dozens of mid-market businesses, the ITGC failures I see most consistently are not exotic. They are mundane and fixable.

Leavers with active accounts. This is the single most common finding. An employee leaves, IT closes their email, but their ERP access remains active for weeks or months. In some cases, indefinitely. In businesses with high staff turnover or multiple acquisitions, this becomes endemic.

Superuser access in production. Someone needs to run a correcting journal, fix a configuration error or process a one-off transaction. Rather than using a properly scoped access request, the IT team grants temporary superuser access — and then forgets to revoke it. The system now has an account with full access to every transaction, every module, every configuration setting.

No formal change approval process. Changes to ERP configurations, chart of accounts, pricing masters or approval thresholds are made informally — via email, verbal instruction or directly in the system. There's no log of what changed, when, who authorised it, or why. Auditors cannot rely on controls they cannot verify.

Backups that have never been tested. A backup that has never been restored is a belief, not a control. Mid-market businesses often have backup processes in place but no documented evidence of recovery testing. This is a straightforward ITGC gap that's easy to remediate — but only once someone flags it.

Building a Proportionate ITGC Framework

The answer is not to implement a FTSE 100 compliance programme. It is to build a proportionate, documented control framework that addresses the real risks in your specific IT environment.

For most mid-market businesses, that starts with an honest assessment: which systems are financially significant? What controls currently exist, and are they operating as documented? Where are the gaps, and which gaps represent genuine audit risk?

From there, remediation is typically straightforward. Formalising a quarterly access review process, implementing a lightweight change management log, documenting backup recovery tests — these are not large projects. They are disciplined processes that, once embedded, require modest ongoing effort.

The benefit is not just a cleaner audit. It's a business that knows its systems are operating as intended, that can demonstrate the integrity of its financial data, and that doesn't spend management time reacting to audit findings that were entirely foreseeable.