Back to all articles
ITGC

What Are ITGC Controls? A Plain-English Guide for Finance Directors

ITGCs underpin financial reporting. Here is what finance leaders need to know — without the technical jargon.

If you have been through an audit in recent years, you have probably heard the term ITGC. You may have received a management letter point about it. You may have nodded along while your IT team and the auditors discussed it in terms you found impenetrable.

This article explains what ITGCs are, why they matter to the Finance Director specifically, and what you should be able to evidence before auditors ask.

What ITGC Stands For

ITGC stands for Information Technology General Controls. These are the controls that govern how your IT systems operate — not what they calculate, but whether those calculations can be trusted.

The distinction matters. Financial systems produce numbers. The question auditors are asking is: are those numbers the result of a process that is properly controlled, or could they have been altered, corrupted or manipulated without detection?

ITGCs are the controls that answer that question.

Why Auditors Care About ITGCs

Modern financial reporting relies almost entirely on IT systems. Your ERP produces the trial balance. Your payroll system calculates staff costs. Your billing system generates revenue. Your consolidation tool produces the group accounts.

If an auditor is going to place reliance on any of these outputs — and they usually need to — they first need to establish that the systems producing them are properly controlled. If the controls over the systems are weak, the numbers they produce cannot be relied upon without extensive manual testing. That testing takes time and increases audit cost.

Auditors also care about ITGCs because system-level failures can lead to material misstatement at scale. A poorly configured ERP that allows a single user to both create and approve a payment is a fraud risk. A system with no change control process could be producing outputs based on code that was modified without authorisation.

The Four Core ITGC Domains

ITGC frameworks typically organise controls across four main areas.

Access to programs and data

This is the most commonly tested ITGC area. It covers who can access your financial systems, what they can do within them, and how access is managed over time.

Key questions: Is access granted based on job role and approved by an appropriate authority? Are access rights reviewed periodically and removed promptly when someone leaves? Does any user have access that allows them to initiate and approve a transaction without a second person involved?

That last point — segregation of duties — is a particularly common source of audit findings in SMEs, where team sizes mean that ideal segregation is not always achievable. Where segregation conflicts exist, compensating controls are needed. These need to be documented, not just asserted.

Program change management

This covers how changes are made to your financial systems and how those changes are controlled.

Key questions: Is there a formal process for requesting, testing and approving changes to systems? Is there a log of all changes made in the period? Are changes tested in a non-production environment before being deployed? Is there someone independent of the developer who approves each change before it goes live?

An absence of change management controls means auditors cannot be confident that the system producing your financial data is operating as intended.

Computer operations

This covers the day-to-day running of systems — job scheduling, batch processing, monitoring and exception handling.

Key questions: Are automated processes (such as overnight batch runs or scheduled reports) monitored for completion and failures? Are exceptions flagged and investigated? Are system logs retained?

Program development

This covers the process by which new systems or significant new functionality are developed and implemented.

Key questions: Was the development properly scoped, tested and signed off before going live? Were users involved in acceptance testing? Is there a documented record of the go-live approval?

For most SMEs, program development controls become relevant when a new system is implemented or a major upgrade takes place — which is also the point at which audit risk is highest.

Common ITGC Findings in PE-Backed SMEs

Generic or shared user accounts. Where multiple users log in under the same account, auditors cannot establish individual accountability for transactions. This is particularly common in businesses that have grown quickly.

Leavers with active access. One of the most frequently cited ITGC findings across all business sizes. A departed employee with active access to financial systems is both a fraud risk and an audit observation — even if nothing has gone wrong.

No formal access review process. Access may have been set up correctly initially but never reviewed. Over time, users accumulate access they no longer need. Without a regular review — typically quarterly or at minimum annually — there is no evidence that access is appropriate.

Unlimited or super-user access granted routinely. Administrator accounts that bypass normal controls are appropriate for specific maintenance tasks. They should not be used for day-to-day processing.

No segregation between IT and finance. Where the person who administers the financial system is also responsible for financial processing, there is no independent check that system-level access has not been used to manipulate records.

Undocumented or informal change management. Changes made directly to production systems, without a log, without testing and without approval, are a significant ITGC concern. In cloud-based SaaS environments, this is often not a risk — but for on-premise or heavily customised systems, it is.

What Finance Directors Need to Own

ITGC is often treated as an IT department responsibility. That is partly correct — IT owns the technical implementation of many of these controls. But Finance Directors own the outcomes.

If an ITGC finding results in a management letter point, it appears in a document addressed to the board and investors. The explanation of what went wrong and what is being done about it falls to Finance, not IT.

More practically, Finance Directors need to:

  • Understand the ITGC risk profile of the systems their team relies on
  • Own the process for reviewing access rights to financial systems
  • Ensure that IT changes with a financial impact go through appropriate approval
  • Maintain a record of ITGC controls that can be produced to auditors

You do not need to be a systems specialist to do this. You do need to have enough of a working knowledge to ask the right questions of your IT function and to be able to answer auditor queries without routing everything through the technical team.

The Practical Checklist

Before fieldwork begins, be able to answer the following:

  • Who has access to the financial system, at what level, and when was access last reviewed?
  • Are there any users with access that allows them to initiate and approve transactions without a second reviewer?
  • How many people have administrator-level access? Is this appropriate?
  • How are system changes requested, tested and approved?
  • Is there a log of all system changes made in the audit period?
  • What happens when an employee leaves — how quickly is their system access removed, and who is responsible for that?
  • Have there been any significant system changes or implementations in the audit period?

If the answers to any of these require significant effort to establish, that is where to start.