Compliance · IT General Controls (ITGC) 4 domains · COBIT 2019 · SSAE 18 / SOC 1 · SOX 404 / AS 2201

IT General Controls (ITGC) Assessment & Assurance

IT general controls are the foundation every other control sits on — the access, change, development and operations controls that decide whether your systems, and the financial data they carry, can be trusted. We assess them against the frameworks auditors actually use, test whether they truly operate, and validate them the way an attacker would, so the assurance you take to your audit committee and your auditors is earned.

CERT-In Empaneled. Anchored to COBIT, SSAE 18 / SOC 1 and SOX / PCAOB AS 2201. We test the controls we assess.

SOX 404 support SOC 1 readiness Internal IT-controls review General ITGC assessment CERT-In Empaneled
Category
IT General Controls — a control category, not a certifiable standard
Domains
4 — access, program changes, development, operations
Anchored to
COBIT 2019 · SSAE 18 / SOC 1 · SOX 404 / PCAOB AS 2201
Role
Assessment + technical validation — the CPA signs SOC 1, the external auditor opines on SOX
02

The controls every other control depends on

IT General Controls — ITGC — are the controls that apply across your whole IT environment rather than to any one transaction: who can get into your systems and data, how changes reach production, how new systems are built and migrated, and how your production environment is run day to day. They are not a law and not a certifiable standard; they are a control category, recognized across the major governance and audit frameworks, and they sit underneath everything else. Application controls — the automated checks inside your accounting, billing or ERP systems — can only be relied upon if the general controls around them hold. If privileged access is uncontrolled or changes reach production untested, every automated control above can be quietly overridden.

That is why ITGC is central to financial-reporting assurance. For a company that reports under the Sarbanes-Oxley Act, IT general controls are a core part of internal control over financial reporting (ICFR) — and in recent years, IT-control deficiencies have become one of the most frequently cited issues in adverse auditor opinions. For a service organization that issues a SOC 1 report, ITGC are exactly the controls a user's auditor relies on. And for any organization building toward ISO 27001, a SOC 2 report or an RBI IS audit, a clean ITGC baseline is the same foundation under a different name. The framework changes; the controls are the same four families.

"Application controls tell you the system did the right thing. IT general controls tell you whether the system could be trusted to in the first place — so we assess the foundation, then prove it holds."
03

ITGC, framed to your programme

"ITGC" means something specific depending on what it has to support. We scope the assessment to the framework that actually governs you — and the four control domains stay the same underneath.

Criterion What we assess and how
SOX 404 / financial-statement audit support Your IT general controls are part of internal control over financial reporting. We assess and test them against the control objectives your external auditor evaluates under PCAOB AS 2201, so the IT layer of your SOX programme stands up to an integrated audit.
SOC 1 readiness If you are a service organization whose systems affect your clients' financial reporting, we get your ITGC and process controls ready for a SOC 1 examination — and coordinate the independent attestation through our licensed CPA partner, who signs the report.
Internal IT-controls review (feeding ISO 27001 / RBI / SOC 2) A clean ITGC baseline is the same foundation under access control, change management and operations across ISO 27001, an RBI IS audit and SOC 2. We assess once and map the evidence into whichever programme you're driving.
General ITGC assessment A health-check of your IT general controls against COBIT and the four ITGC domains — useful before a transaction, a new system go-live, a board request, or simply to know where you stand.

Tell us which of these you're solving for and we'll calibrate the assessment — the same four domains, anchored to the framework that governs you.

04

The four domains of IT general controls

Across every framework — COBIT, the SOC 1 control objectives, and SOX/PCAOB guidance alike — IT general controls resolve to four domains. Each answers a different question about whether your IT environment can be trusted, and each maps to controls auditors test directly.

The strip beneath them shows the dependency that makes ITGC matter: general controls support the application controls that, in turn, support reliable financial reporting.

05

The standards behind the assessment

ITGC isn't a single standard, so we anchor every assessment to the authoritative frameworks that define and test these controls — and tell you exactly which one your engagement maps to.

ISACA COBIT 2019

Control Objectives for Information and Related Technologies

The leading IT governance and control framework — 40 governance and management objectives across five domains (EDM, APO, BAI, DSS, MEA). The four ITGC families map cleanly onto its objectives: access to DSS05 (managed security), changes to BAI06 (managed IT changes), development to BAI03 (managed solutions delivery) and operations to DSS01 (managed IT operations). COBIT gives us the control objectives we assess against.

AICPA SSAE No. 18 / SOC 1

System and Organization Controls 1, under AT-C Section 320

The AICPA attestation standard for a service organization's controls relevant to user entities' internal control over financial reporting. A SOC 1 report — Type I (design as of a date) or Type II (operating effectiveness over a period) — is issued by an independent licensed CPA firm. Where your engagement targets SOC 1, we get the ITGC and process controls ready and coordinate the attestation through our CPA partner.

SOX Section 404 + PCAOB AS 2201

An Audit of Internal Control Over Financial Reporting Integrated with an Audit of Financial Statements

For public companies, Section 404 of the Sarbanes-Oxley Act requires management and the external auditor to report on ICFR. PCAOB AS 2201 governs how the auditor runs that integrated, top-down, risk-based audit — and ITGC are assessed because effective general controls are what let the auditor rely on a company's automated application controls.

ISO/IEC 27001 — optional mapping

Information security management

Where you also run an ISMS, we map ITGC findings to ISO/IEC 27001:2022 Annex A — access control, secure development, change and operations — so a single assessment feeds your security certification as well as your financial-controls programme. COBIT defines the objectives; ISO 27001 enumerates the controls; the two reconcile.

06

How an ITGC assessment runs

A disciplined, evidence-led path from a scoped control matrix to a re-tested clean result — built so your finance, IT and audit teams always know where the controls stand and what to fix next.

01
Scoping & Control Matrix
We define the framing (SOX, SOC 1, or internal), identify the in-scope systems and the financially significant applications behind them, and build the ITGC control matrix — the controls, objectives and risks we'll assess across all four domains.
02
Design Review
We assess whether each control is designed to meet its objective — examining policies, configurations, workflows and roles to confirm the control, as built, would actually mitigate the risk it's meant to.
03
Operating-Effectiveness Testing
We test whether each control operates — sampling access reviews, change tickets, approvals, job logs and backup restores over the period — because a control that exists on paper but isn't performed is a finding, not a control.
04
Technical Validation
Where it matters, our researchers go beyond inspecting evidence and test the control technically — can privileged access actually be abused? are development and production really segregated? — so you get proof the control holds, not just a sampled artifact.
05
Gap Analysis
We measure each finding against the applicable framework's control objective, rate design and operating deficiencies by severity and risk, and separate true control gaps from documentation issues.
06
Reporting & Remediation
We deliver a clear, prioritized report for both the engineers who will fix issues and the audit committee that must understand the risk — with concrete, sequenced remediation guidance.
07
Re-test
We re-verify remediated controls so closure is evidenced, not asserted — and, where the engagement supports a SOC 1 or SOX cycle, leave you ready for the attestation or integrated audit that follows.

FIG. 02 — ITGC assessment lifecycle · 01–03 design & testing · 04 technical validation (the offensive edge) · 05–07 gap, remediation & re-test

Design says the control should work. Operating-effectiveness testing says it did work over the period. Technical validation says it can't be bypassed. We do all three — and the last one is where most assessments stop short.

07

What an engagement includes

We scope to your framing and your systems, and cover the four ITGC domains end to end — plus the cross-cutting work that ties them to your financial reporting.

Access to Programs & Data
01

Logical access and authentication review

(including MFA where applicable)

02

User provisioning and de-provisioning, and joiner-mover-leaver controls

03

Privileged and administrative access, and segregation of duties

04

Periodic access recertification and review evidence

Program Changes
05

Change-management workflow

request, approval, testing and sign-off

06

Segregation of development and production access

07

Emergency-change handling and post-implementation review

08

Patch and configuration-change controls

Program Development & Computer Operations
09

SDLC governance, project approval and acceptance testing

10

Data-migration and conversion controls for new and replaced systems

11

Job scheduling, batch/interface monitoring and processing integrity

12

Incident and problem management

backup, restore-testing and recovery

Validate (the offensive edge)
13

Technical control validation

penetration testing and configuration review that proves access, change and segregation controls actually hold

14

Evidence collection and an audit-ready ITGC artifact pack

15

Remediation retest after fixes

Tie to your programme
16

Mapping of findings to COBIT objectives, SOC 1 control objectives, SOX/AS 2201 or ISO/IEC 27001:2022 Annex A

17

Complementary user-entity-control guidance

(for SOC 1 service organizations)

18

Coordination of the independent CPA attestation through our partner

(for SOC 1)

08

We don't just inspect the evidence. We test the control.

A conventional ITGC review samples a few access reviews and change tickets and ticks the box. We test whether the control would survive contact with someone trying to defeat it.

Confirms the artifact

The evidence-only assessment

Most ITGC work inspects evidence — it pulls a sample of access-recertification sign-offs, reads a handful of change-approval tickets, and confirms a backup job ran. That satisfies an operating-effectiveness test on paper. But a completed access review doesn't prove that privileged access can't be abused, and an approval workflow doesn't prove that development and production are genuinely segregated. The gaps that never appear in a sampled ticket are exactly the gaps that surface in a breach — or in a restatement.

Proves the control

The technically validated assessment

Intect is CERT-In Empaneled with an offensive-security heritage, so where it matters we validate ITGC by testing them. Can a standard user escalate to privileged access the access-control evidence says they shouldn't have? Can a developer push a change to production the segregation control says they can't? We find out — safely, the way an adversary would — and bring you proof the control operates, not just a sampled artifact. You walk into your SOC 1 or SOX audit with general controls that have already withstood a real probe.

A sampled artifact proves the control was performed once. Our testing proves it can't be bypassed.

VAPT-BACKED VALIDATION
09

What you receive

Every engagement produces the artifacts your IT, finance and audit teams need to operate and evidence the controls — and the pack your auditor or CPA expects to review.

01

ITGC control matrix & risk assessment

The in-scope controls across all four domains, mapped to control objectives, risks and the applicable framework.

02

Design & operating-effectiveness assessment report

Each control, its design conclusion, and the result of operating-effectiveness testing over the period, with severity-rated findings.

03

Technical control validation report

Pentest-backed evidence that access, change and segregation controls genuinely hold, with reproducible proof and remediation guidance.

VAPT-BACKED
04

Gap analysis & remediation roadmap

Prioritized, specific remediation guidance with clear ownership and sequencing — not generic advice.

05

Audit-ready evidence pack

Collected, organized artifacts that map cleanly to the control objectives, ready for your external auditor or CPA.

06

Framework mapping

Findings cross-referenced to COBIT 2019 objectives, SOC 1 control objectives, SOX/AS 2201, or ISO/IEC 27001:2022 Annex A, as applicable.

07

Remediation retest & closure evidence

Re-verification of remediated controls so closure is evidenced, not claimed.

COBIT 2019 SSAE 18 / SOC 1 SOX 404 PCAOB AS 2201 ISO/IEC 27001:2022 mapping CERT-In Empaneled VAPT-backed validation
10

Why teams choose Intect for ITGC

CERT-In Empaneled Researcher-led · offensive heritage

CERT-In Empaneled — An assessor accredited under India's national cybersecurity authority — credibility your auditors and audit committee recognize.

We test, not just inspect — Most ITGC reviews sample evidence and stop. We come from offensive security, so we test whether access, change and segregation controls actually hold — proof, not paperwork.

Researcher-led, framework-fluent — Senior practitioners who speak COBIT, SOC 1 and SOX as fluently as they speak attacker tradecraft — so findings are accurate, contextual and defensible.

One assessment, many programmes — A single ITGC baseline that maps into your SOX, SOC 1, ISO 27001 or SOC 2 programme — assess once, reuse the evidence; and for SOC 1, we coordinate the independent CPA attestation through our partner.

11

Frequently asked questions

Is ITGC a certification?

No. IT General Controls are a control category, not a standard you certify against — there is no "ITGC certificate." An ITGC engagement is an assessment: we evaluate the design and operating effectiveness of your IT general controls against an authoritative framework (COBIT, the SOC 1 control objectives, or SOX/PCAOB guidance) and produce an evidenced report. Where it feeds a SOC 1 or SOX programme, the attestation or opinion is a separate, formal step — see below.

Who signs the SOC 1 report?

A licensed CPA firm — not Intect. A SOC 1 examination under SSAE 18 must be performed and signed by an independent CPA. Intect designs, assesses, tests and remediates your IT general and process controls to get you ready, and coordinates the attestation through our licensed CPA partner, who issues the report. We do the engineering and assurance work; the CPA signs.

What's the difference between ITGC and application controls?

Application controls are the automated checks inside a specific system — a three-way match, a credit-limit check, a validation rule. IT general controls are the environment-wide controls around all of those — access, change, development and operations. The relationship is one of dependence: an auditor can only rely on your application controls if the general controls around them are effective. Weak ITGC undermines every application control above it.

How is ITGC different from ISO 27001 or SOC 2?

They overlap heavily. ITGC, ISO 27001 Annex A and the SOC 2 criteria all cover access control, change management and operations — the difference is framing and purpose. ITGC is framed around financial reporting (SOX, SOC 1); ISO 27001 is a certifiable security-management standard; SOC 2 is an attestation against the Trust Services Criteria. A clean ITGC baseline is the same foundation under all three, which is why we map findings across them.

What does "operating effectiveness" mean?

It's the difference between a control being designed well and a control actually being performed. Design effectiveness asks: would this control, as built, mitigate the risk? Operating effectiveness asks: was it actually carried out, consistently, over the period — every access review completed, every change approved and tested? A SOC 1 Type II report and a SOX integrated audit both test operating effectiveness over time, not just design at a point in time.

How long does an ITGC assessment take?

It depends on the framing, the number of in-scope systems and the maturity of your current controls — which the scoping step establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so nothing blocks your audit or attestation date.

Do you test the controls or just review documents?

Both — and that's the point. We assess design and test operating effectiveness the way any rigorous assessor would, and then, where it matters, we go further and technically validate the controls: we test whether privileged access can be abused and whether development and production are really segregated. You get proof the control holds, not just a sampled artifact.

12

One foundation, many programmes

A clean ITGC baseline feeds far more than one audit.

Scope an engagement

Prove the controls behind your numbers.

Tell us your framing — SOX support, SOC 1 readiness, or an internal IT-controls review — and we'll scope an ITGC assessment that fits, or connect you with an assessor.