IT General Controls (ITGC) Assessment & Assurance
IT general controls are the foundation every other control sits on — the access, change, development and operations controls that decide whether your systems, and the financial data they carry, can be trusted. We assess them against the frameworks auditors actually use, test whether they truly operate, and validate them the way an attacker would, so the assurance you take to your audit committee and your auditors is earned.
CERT-In Empaneled. Anchored to COBIT, SSAE 18 / SOC 1 and SOX / PCAOB AS 2201. We test the controls we assess.
The controls every other control depends on
IT General Controls — ITGC — are the controls that apply across your whole IT environment rather than to any one transaction: who can get into your systems and data, how changes reach production, how new systems are built and migrated, and how your production environment is run day to day. They are not a law and not a certifiable standard; they are a control category, recognized across the major governance and audit frameworks, and they sit underneath everything else. Application controls — the automated checks inside your accounting, billing or ERP systems — can only be relied upon if the general controls around them hold. If privileged access is uncontrolled or changes reach production untested, every automated control above can be quietly overridden.
That is why ITGC is central to financial-reporting assurance. For a company that reports under the Sarbanes-Oxley Act, IT general controls are a core part of internal control over financial reporting (ICFR) — and in recent years, IT-control deficiencies have become one of the most frequently cited issues in adverse auditor opinions. For a service organization that issues a SOC 1 report, ITGC are exactly the controls a user's auditor relies on. And for any organization building toward ISO 27001, a SOC 2 report or an RBI IS audit, a clean ITGC baseline is the same foundation under a different name. The framework changes; the controls are the same four families.
"Application controls tell you the system did the right thing. IT general controls tell you whether the system could be trusted to in the first place — so we assess the foundation, then prove it holds."
ITGC, framed to your programme
"ITGC" means something specific depending on what it has to support. We scope the assessment to the framework that actually governs you — and the four control domains stay the same underneath.
| Criterion | What we assess and how |
|---|---|
| SOX 404 / financial-statement audit support | Your IT general controls are part of internal control over financial reporting. We assess and test them against the control objectives your external auditor evaluates under PCAOB AS 2201, so the IT layer of your SOX programme stands up to an integrated audit. |
| SOC 1 readiness | If you are a service organization whose systems affect your clients' financial reporting, we get your ITGC and process controls ready for a SOC 1 examination — and coordinate the independent attestation through our licensed CPA partner, who signs the report. |
| Internal IT-controls review (feeding ISO 27001 / RBI / SOC 2) | A clean ITGC baseline is the same foundation under access control, change management and operations across ISO 27001, an RBI IS audit and SOC 2. We assess once and map the evidence into whichever programme you're driving. |
| General ITGC assessment | A health-check of your IT general controls against COBIT and the four ITGC domains — useful before a transaction, a new system go-live, a board request, or simply to know where you stand. |
Tell us which of these you're solving for and we'll calibrate the assessment — the same four domains, anchored to the framework that governs you.
The four domains of IT general controls
Across every framework — COBIT, the SOC 1 control objectives, and SOX/PCAOB guidance alike — IT general controls resolve to four domains. Each answers a different question about whether your IT environment can be trusted, and each maps to controls auditors test directly.
The strip beneath them shows the dependency that makes ITGC matter: general controls support the application controls that, in turn, support reliable financial reporting.
Access to Programs & Data — Who can reach your systems and data, and what they can do. Logical access and authentication, user provisioning and de-provisioning, privileged and administrative access, segregation of duties, and periodic access recertification — so access is authorized, least-privilege and reviewed, and no super-user can quietly bypass the controls above.
Program Changes — How modifications reach production. Change requests, approvals, testing and sign-off, and the separation of development from production access — so changes are authorized and tested, and a developer can't push unreviewed code straight into the system of record.
Program Development — How new systems are built and brought live. SDLC governance, project approval, requirements and design, testing and acceptance, and controlled data migration — so new and replaced systems meet their financial-reporting and control objectives before go-live.
Computer Operations — How the production environment is run day to day. Job scheduling and monitoring, batch and interface integrity, incident and problem management, and — critically — backup and recovery, so processing completes as approved, failures are caught and corrected, and data can be restored.
General controls are the foundation: when they're weak, the automated application controls above them — and the financial data they produce — can no longer be relied upon.
The standards behind the assessment
ITGC isn't a single standard, so we anchor every assessment to the authoritative frameworks that define and test these controls — and tell you exactly which one your engagement maps to.
ISACA COBIT 2019
Control Objectives for Information and Related Technologies
The leading IT governance and control framework — 40 governance and management objectives across five domains (EDM, APO, BAI, DSS, MEA). The four ITGC families map cleanly onto its objectives: access to DSS05 (managed security), changes to BAI06 (managed IT changes), development to BAI03 (managed solutions delivery) and operations to DSS01 (managed IT operations). COBIT gives us the control objectives we assess against.
AICPA SSAE No. 18 / SOC 1
System and Organization Controls 1, under AT-C Section 320
The AICPA attestation standard for a service organization's controls relevant to user entities' internal control over financial reporting. A SOC 1 report — Type I (design as of a date) or Type II (operating effectiveness over a period) — is issued by an independent licensed CPA firm. Where your engagement targets SOC 1, we get the ITGC and process controls ready and coordinate the attestation through our CPA partner.
SOX Section 404 + PCAOB AS 2201
An Audit of Internal Control Over Financial Reporting Integrated with an Audit of Financial Statements
For public companies, Section 404 of the Sarbanes-Oxley Act requires management and the external auditor to report on ICFR. PCAOB AS 2201 governs how the auditor runs that integrated, top-down, risk-based audit — and ITGC are assessed because effective general controls are what let the auditor rely on a company's automated application controls.
ISO/IEC 27001 — optional mapping
Information security management
Where you also run an ISMS, we map ITGC findings to ISO/IEC 27001:2022 Annex A — access control, secure development, change and operations — so a single assessment feeds your security certification as well as your financial-controls programme. COBIT defines the objectives; ISO 27001 enumerates the controls; the two reconcile.
How an ITGC assessment runs
A disciplined, evidence-led path from a scoped control matrix to a re-tested clean result — built so your finance, IT and audit teams always know where the controls stand and what to fix next.
FIG. 02 — ITGC assessment lifecycle · 01–03 design & testing · 04 technical validation (the offensive edge) · 05–07 gap, remediation & re-test
Design says the control should work. Operating-effectiveness testing says it did work over the period. Technical validation says it can't be bypassed. We do all three — and the last one is where most assessments stop short.
What an engagement includes
We scope to your framing and your systems, and cover the four ITGC domains end to end — plus the cross-cutting work that ties them to your financial reporting.
Logical access and authentication review
(including MFA where applicable)
User provisioning and de-provisioning, and joiner-mover-leaver controls
Privileged and administrative access, and segregation of duties
Periodic access recertification and review evidence
Change-management workflow
request, approval, testing and sign-off
Segregation of development and production access
Emergency-change handling and post-implementation review
Patch and configuration-change controls
SDLC governance, project approval and acceptance testing
Data-migration and conversion controls for new and replaced systems
Job scheduling, batch/interface monitoring and processing integrity
Incident and problem management
backup, restore-testing and recovery
Technical control validation
penetration testing and configuration review that proves access, change and segregation controls actually hold
Evidence collection and an audit-ready ITGC artifact pack
Remediation retest after fixes
Mapping of findings to COBIT objectives, SOC 1 control objectives, SOX/AS 2201 or ISO/IEC 27001:2022 Annex A
Complementary user-entity-control guidance
(for SOC 1 service organizations)
Coordination of the independent CPA attestation through our partner
(for SOC 1)
We don't just inspect the evidence. We test the control.
A conventional ITGC review samples a few access reviews and change tickets and ticks the box. We test whether the control would survive contact with someone trying to defeat it.
The evidence-only assessment
Most ITGC work inspects evidence — it pulls a sample of access-recertification sign-offs, reads a handful of change-approval tickets, and confirms a backup job ran. That satisfies an operating-effectiveness test on paper. But a completed access review doesn't prove that privileged access can't be abused, and an approval workflow doesn't prove that development and production are genuinely segregated. The gaps that never appear in a sampled ticket are exactly the gaps that surface in a breach — or in a restatement.
The technically validated assessment
Intect is CERT-In Empaneled with an offensive-security heritage, so where it matters we validate ITGC by testing them. Can a standard user escalate to privileged access the access-control evidence says they shouldn't have? Can a developer push a change to production the segregation control says they can't? We find out — safely, the way an adversary would — and bring you proof the control operates, not just a sampled artifact. You walk into your SOC 1 or SOX audit with general controls that have already withstood a real probe.
A sampled artifact proves the control was performed once. Our testing proves it can't be bypassed.
VAPT-BACKED VALIDATIONWhat you receive
Every engagement produces the artifacts your IT, finance and audit teams need to operate and evidence the controls — and the pack your auditor or CPA expects to review.
ITGC control matrix & risk assessment
The in-scope controls across all four domains, mapped to control objectives, risks and the applicable framework.
Design & operating-effectiveness assessment report
Each control, its design conclusion, and the result of operating-effectiveness testing over the period, with severity-rated findings.
Technical control validation report
Pentest-backed evidence that access, change and segregation controls genuinely hold, with reproducible proof and remediation guidance.
Gap analysis & remediation roadmap
Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.
Audit-ready evidence pack
Collected, organized artifacts that map cleanly to the control objectives, ready for your external auditor or CPA.
Framework mapping
Findings cross-referenced to COBIT 2019 objectives, SOC 1 control objectives, SOX/AS 2201, or ISO/IEC 27001:2022 Annex A, as applicable.
Remediation retest & closure evidence
Re-verification of remediated controls so closure is evidenced, not claimed.
Why teams choose Intect for ITGC
CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility your auditors and audit committee recognize.
We test, not just inspect — Most ITGC reviews sample evidence and stop. We come from offensive security, so we test whether access, change and segregation controls actually hold — proof, not paperwork.
Researcher-led, framework-fluent — Senior practitioners who speak COBIT, SOC 1 and SOX as fluently as they speak attacker tradecraft — so findings are accurate, contextual and defensible.
One assessment, many programmes — A single ITGC baseline that maps into your SOX, SOC 1, ISO 27001 or SOC 2 programme — assess once, reuse the evidence; and for SOC 1, we coordinate the independent CPA attestation through our partner.
Frequently asked questions
Is ITGC a certification?
No. IT General Controls are a control category, not a standard you certify against — there is no "ITGC certificate." An ITGC engagement is an assessment: we evaluate the design and operating effectiveness of your IT general controls against an authoritative framework (COBIT, the SOC 1 control objectives, or SOX/PCAOB guidance) and produce an evidenced report. Where it feeds a SOC 1 or SOX programme, the attestation or opinion is a separate, formal step — see below.
Who signs the SOC 1 report?
A licensed CPA firm — not Intect. A SOC 1 examination under SSAE 18 must be performed and signed by an independent CPA. Intect designs, assesses, tests and remediates your IT general and process controls to get you ready, and coordinates the attestation through our licensed CPA partner, who issues the report. We do the engineering and assurance work; the CPA signs.
What's the difference between ITGC and application controls?
Application controls are the automated checks inside a specific system — a three-way match, a credit-limit check, a validation rule. IT general controls are the environment-wide controls around all of those — access, change, development and operations. The relationship is one of dependence: an auditor can only rely on your application controls if the general controls around them are effective. Weak ITGC undermines every application control above it.
How is ITGC different from ISO 27001 or SOC 2?
They overlap heavily. ITGC, ISO 27001 Annex A and the SOC 2 criteria all cover access control, change management and operations — the difference is framing and purpose. ITGC is framed around financial reporting (SOX, SOC 1); ISO 27001 is a certifiable security-management standard; SOC 2 is an attestation against the Trust Services Criteria. A clean ITGC baseline is the same foundation under all three, which is why we map findings across them.
What does "operating effectiveness" mean?
It's the difference between a control being designed well and a control actually being performed. Design effectiveness asks: would this control, as built, mitigate the risk? Operating effectiveness asks: was it actually carried out, consistently, over the period — every access review completed, every change approved and tested? A SOC 1 Type II report and a SOX integrated audit both test operating effectiveness over time, not just design at a point in time.
How long does an ITGC assessment take?
It depends on the framing, the number of in-scope systems and the maturity of your current controls — which the scoping step establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so nothing blocks your audit or attestation date.
Do you test the controls or just review documents?
Both — and that's the point. We assess design and test operating effectiveness the way any rigorous assessor would, and then, where it matters, we go further and technically validate the controls: we test whether privileged access can be abused and whether development and production are really segregated. You get proof the control holds, not just a sampled artifact.
One foundation, many programmes
A clean ITGC baseline feeds far more than one audit.
Prove the controls behind your numbers.
Tell us your framing — SOX support, SOC 1 readiness, or an internal IT-controls review — and we'll scope an ITGC assessment that fits, or connect you with an assessor.