ITGC Testing: A Practical Guide for Auditors in 2026

IT General Controls (ITGCs) are foundational IT controls that support the reliability, security, and integrity of information systems used in compliance frameworks such as SOX and SOC 2. ITGC testing is now integral to the readiness and assurance of controls for an audit, given the increased use of cloud infrastructure, SaaS, and automated processes. To what extent do your IT general controls operate effectively and not just serve to be compliance exercises?
Modern audits are increasingly evidence-driven due to decentralized systems and expanding compliance requirements. Many audit teams face challenges arising out of collecting evidence manually, having disintegrated systems, and dealing with inconsistent approvals and missing audit trails. The most recent PCAOB inspection reports have identified deficiencies related to audit evidence and control testing procedures.
In this article, I will explain the ITGC testing, review the most common core control areas that an auditor will assess, describe the challenges of testing to ITGCs, and demonstrate the ways organizations are transforming their audit processes through continuous monitoring and evidence collection from a single location.
What exactly are IT General Controls (ITGCs)?
IT general controls (ITGCs) are the foundational policies and procedures implemented by an organization to control and secure its entire IT environment. ITGCs help ensure systems operate securely and reliably. They help to ensure that the data is secure and that any changes are made with proper authorization.
Unlike other controls that may relate to a specific business transaction, ITGCs establish a secure environment within which business applications operate. A common point of confusion is the relationship between ITGCs and IT Application Controls (ITACs). ITGCs control the environment, whereas ITACs control the business applications. For example, an ITGC would control who is allowed to access the accounting system, while an ITAC would put a validation rule in the system to prevent entry of a negative value for an invoice. Weak ITGCs can reduce auditor reliance on ITACs
Which core areas do ITGCs cover?
ITGCs most often include the following core areas:
Access Controls (controlling who can access or change data)
Change Controls (ensuring approved changes to systems are implemented)
IT Operations (controlling and monitoring system jobs, backups and response to incidents)
System Development Life Cycle (SDLC) Controls (ensuring that systems are developed securely)
Why do ITGCs matter for SOX and SOC 2 compliance?
ITGCs are the first line of defense in establishing compliance with key regulations, including the Sarbanes-Oxley Act (SOX) and SOC 2 audits. For SOX compliance, ITGCs help protect financial reporting systems from unauthorized access or changes that could affect data integrity. For SOC 2, ITGCs provide users with assurance that sensitive data is secured.
Why is ITGC testing critical for modern audits?
With an increase in the intricacy of cloud infrastructures and Software as a Service (SaaS) and with an increase in auditing intensity, expectations of continuous compliance have developed, eliminating the traditional mindset of audits occurring once a year.
What are the risks of weak ITGCs?
Weak ITGCs can result in much more than a failed audit. Weak ITGCs can result in a loss of control over critical data, fraud, system outages, and data integrity issues. Failure to maintain data integrity can lead to the loss of confidence from stakeholders and regulatory actions.
Why do auditors test ITGCs before relying on automated controls?
Auditors test ITGCs first to determine the extent to which automated controls can be relied upon. Based on the effectiveness of the ITGCs within the financial system, auditors can rely on the system’s automated controls and reduce the extent of substantive testing. In a case where the ITGC audit risks are high because of ITGC shortcomings, auditors will perform the testing of the related transactions, which can increase audit effort and extend audit timelines.
What are the four core ITGC domains?

To execute a practical ITGC audit, teams focus on four distinct domains.
1. How do access management controls secure user provisioning?
Access management controls govern user access to systems in alignment with their roles. This includes the testing of user provisioning and the enforcement of privileged access controls, as well as the verification of multi-factor authentication (MFA). Review of terminated users and Separation of Duties (SoD) are also the focus of auditors. Common examples of auditor testing include a sample of access requests, the validation of control and approval workflows, and access recertification.
2. What role do change management controls play in system updates?
Change management controls allow system updates while maintaining application controls and system integrity. This includes the testing of evidence for change approval and justification for emergency changes, as well as the restriction of production access. Auditors will review change control tickets, verify User Acceptance Testing (UAT), and review evidence supporting approved changes.
3. How do IT operations controls ensure disaster readiness?
IT operations controls encompass the management of the IT environment. This includes the management of backups, incident management, job management, and system monitoring. Auditors will check backup logs, verify monitoring of system alerts, and demand incident management controls.
4. What are SDLC controls for secure deployment?
SDLC controls govern how software is developed, tested, approved, and deployed within the IT environment. Critical focus areas include the management of secure development and the control of environment segregation, SDLC controls, and the governance and approval for changes. Evidence for the approval of deployments, the documentation of releases, and the signoff of UAT is the focus of auditors.
What are the most common ITGC testing challenges?
Audit teams have different challenges when assessing IT general controls. Potentially, the biggest challenge is isolating a single symptom of a problem and addressing that, causing similar issues to recur across audit cycles.
How does manual evidence collection slow down audits?
The main problem with manual evidence collection is the increased time it takes to conduct an audit. Gathering screenshots and approval evidence via email while figuring out tracking evidence manually through spreadsheets is time-consuming and leads to a greater chance of evidence being incomplete or inconsistent. There are some problems that can arise for the IT audit in relation to these manual processes:
Issues with versions
Missing approvals
Evidence submitted late
Audit evidence traceability is reduced
Why do cloud and SaaS environments complicate evidence quality?
The cloud and SaaS make it difficult to track user access. Identities in AWS, Azure, and GCP are decentralized, making it hard to access and review. This does inconsistent documentation and evidence quality, including incomplete evidence, evidence that has been created, and screenshots that do not have verifiable metadata.
What counts as strong ITGC audit evidence?
A control can only be substantiated by evidence of its proper operation.
Which documents qualify as ITGC audit evidence?
There are many examples of ITGC audit evidence such as system access reports, authentication logs, activity logs, change management tickets, approval workflows, backup reports, recovery reports, and evidence of system logs. Evidence of ITGC control is best obtained from raw or system logs or deployment evidence. Auditors prefer evidence from the authority system rather than evidence that users create or edit.
What characteristics define verifiable audit evidence?
ITGC evidence must be verifiable, complete, accurate, system-generated, and directly traceable to the control being tested. Evidence must be generated by a system, and evidence of a verbal approval and a spreadsheet generated by a system that has been modified multiple times will be considered evidence of a nonconformity.
How are audit teams modernizing ITGC workflows?
Modern audit teams have created workflows that focus on compliance and the evidence collection associated with it.
How does continuous evidence collection improve compliance?
With continuous evidence collection, systems are integrated using APIs and centralized logging, and evidence is collected in an automated fashion. Evidence is collected in near real time, which reduces the effort needed to collect evidence and the pressure on the audit team to prepare for the audit on short notice.
Your team can expedite responses to requests by being able to maintain more up-to-date evidence repositories and thereby improve audit readiness. With the ability to continuously monitor, you are able to detect critical business impact issues, such as:
Configuration drift
Missing evidence
Unauthorized access changes
Control execution gaps
What role does AI play in control reviews?
Using AI for audit workflows, organizations can process large volumes of compliance documentation faster. AI can assist with automating evidence collection, initial gap detection, and report preparation workflows' operational value. AI provides the ability for the auditor to focus on the complex risk issues rather than on the data entry tasks.
However, human oversight remains critical. An auditor must still validate AI-driven conclusions to ensure the final report is defensible.
What are the best practices for ITGC testing?
To execute a successful ITGC audit, follow these standard practices:
Standardize Control Narratives: Clearly define who owns the control, how often it runs, and what evidence it produces.
Automate Access Reviews: Replace manual spreadsheets with automated workflows to ensure timely provisioning and de-provisioning.
Centralize Evidence Storage: Keep all audit documentation in a single, secure repository.
Separate Development and Production Access: Ensure developers cannot push their own code into production without independent review.
Perform Continuous Monitoring: Set up real-time alerts for unauthorized changes or failed backups.
Retain Immutable Audit Trails: Ensure system logs cannot be edited or deleted after the fact.
Review Privileged Access Regularly: Audit administrative accounts frequently, as they pose the highest risk.
How does Roz help streamline ITGC testing workflows?
Roz is an AI-native audit platform that helps CPA firms and advisory teams streamline ITGC testing workflows through structured documentation and AI-assisted audit workflows.
Unlike standard storage drives, Roz acts as an intelligent enterprise data room. The platform helps teams:
Centralize evidence and documentation in secure, client-specific workspaces
Maintain evidence traceability with source-linked audit trails
Support structured control mapping across multiple frameworks
Identify potential documentation gaps during first-pass analysis
Generate AI-assisted draft workpapers from uploaded evidence
Support evidence sufficiency reviews and documentation analysis
Use risk and control matrix views to structure engagements
Search evidence and streamline reporting workflows more efficiently
Roz supports audit readiness and engagement workflows without replacing auditors, assurance conclusions, or certification processes.
Conclusion
ITGC testing ensures the integrity and transparency of any financial and security system and offers a means of defense. Structuring access management, change controls, and IT operations can help organizations protect their data and make external audits easier.
It is common for organizations to have more consistent and defensible programs for their Information Security Management System (ISMS) when internal audits are integrated into the risk and compliance management framework. Standardized control narratives and centralized evidence workflows can help organizations build more sustainable compliance programs.
Frequently Asked Questions about ITGC testing
How often should ITGC controls be tested?
For monitoring the operation of control mechanisms and finding the gaps, internal ITGC testing should be done continuously or at least quarterly. ITGC controls should be assessed by external compliance audits (namely, SOX or SOC 2), which are usually done on an annual basis.
What is the difference between ITGCs and application controls?
ITGCs regulate change management, network security, and general system-wide user access controls. Conversely, application controls ensure transaction accuracy and completeness by not allowing users to leave a field empty or by preventing the entry of a duplicate invoice.
What evidence is required for ITGC testing?
Verification of a control functioning as intended should be done through system documents on access logs, approval tickets of system modifications, completion documents of the backup, and periodic and documented reviews of access.























































