IT General Controls
IT general controls are the policies and practices that govern how an organization's technology is acquired, built, deployed, used, and maintained. They generally apply broadly across an organization's systems, components, processes, and data rather than to a single application or transaction. In practice, they often involve people performing activities within or to systems to keep the technology environment reliable and secure.
ITGC are controls that typically apply pervasively across all of an organization's systems, components, processes, and data for a given information environment, in contrast to IT application controls (ITAC), which operate at the level of a specific application or transaction. They are generally process- or policy-based controls governing the acquisition, architecture, deployment, use, and maintenance of technology. ITGC are commonly evaluated within IT audit and IT governance activities and, alongside ITAC, are used as a model for assessing the maturity of the processes an auditor tests; the specific scope, framework alignment, and testing approach vary by organization, engagement, and applicable requirements, and should be determined through professional judgment. This entry is educational and not legal, audit, or compliance advice.
Why it matters
IT general controls matter because they form the foundation on which many other controls depend. Because ITGC generally apply pervasively across an organization's systems, components, processes, and data, weaknesses in these controls can undermine confidence in the systems that process transactions and produce financial and operational information. When the broad environment governing how technology is acquired, built, deployed, used, and maintained is unreliable, the application-level controls that sit on top of it become harder to rely on.
For assurance and compliance purposes, ITGC are commonly evaluated within IT audit and IT governance activities. Alongside IT application controls, they are often used as a model for assessing the maturity of the processes an auditor has to test, which gives audit and assurance functions a structured way to understand and evaluate the technology environment. The scope, framework alignment, and testing approach are not uniform, however; they vary by organization, engagement, and applicable requirements, and should be determined through professional judgment rather than assumed to be standardized across contexts.
Because ITGC are typically process- or policy-based and frequently involve people performing activities within or to systems, they also require sustained attention from those responsible for maintaining the technology environment. This entry is educational and not legal, audit, or compliance advice, and the specific controls an organization needs will depend on its facts and circumstances.
Who it's relevant to
Inside ITGC
Common questions
Answers to the questions practitioners most commonly ask about ITGC.