Why IT controls matter more than ever in external audit

In today’s digital environment, technology underpins most financial processes. As organisations become increasingly connected to the internet and rely on third party technology providers, they face greater exposure to cyber security risks. The integrity of an organisation’s financial reporting is now inseparable from the integrity of the systems that support it, which is why management should have in place IT General Controls (ITGCs) that protect the entity’s data.

Management has legislative obligations to protect their data – including intellectual property, and business and employee confidential information. As external auditors, we also have mandatory legislative requirements to assess management’s internal control environment which includes ITGCs. Purchasing cyber insurance does not remove the need for effective cyber controls. In fact, insurers generally require appropriate security controls to be in place for the organisation to even make a claim.

However, many finance staff still question why auditors spend time assessing ITGCs and what this means for their financial statement audit. Here we explain what ITGCs are, why they are essential, what auditors look for, and how strong IT controls can reduce audit effort.

What are ITGCs?

ITGCs are foundational controls that ensure financial systems operate securely, consistently and accurately, and protect the confidentiality, integrity and availability of financial data.

They fall broadly into four categories:

User access management

Ensures only authorised individuals can access key financial systems, reducing the risk of unauthorised transactions, data manipulation, or fraud.

Change management

Controls the way system changes, upgrades, patches, and configuration updates are made. Poorly managed changes can introduce errors directly into financial data and security vulnerabilities into financial systems.

IT operations

Covers backups, batch job monitoring, incident resolution, and system availability. These controls ensure financial data is processed accurately and completely and that the financial data is always available and recoverable if required.

Third party vendor and cloud management

As organisations rely more heavily on cloud platforms, there must be adequate oversight to ensure external providers are managing systems securely and consistently, in line with expected security controls.

These domains collectively form the foundation of a reliable financial reporting environment.

Technology underpins financial reporting

Most financial information no longer flows through manual processes. It flows through applications, interfaces, and automated workflows. As a result, the quality of reported financial information depends heavily on the:

  • security of the systems
  • way changes to those systems are controlled
  • stability and consistency of day to day IT operations.

If the underlying technology is not well controlled, it introduces risk that financial data can be altered, mis stated, or lost – either intentionally or accidentally.

This is why external audits increasingly focus on ITGCs, to ensure financial information can be trusted.

Why auditors examine ITGCs

For auditors, effective ITGCs are not a technical exercise. They are a requirement to rely on system-generated reports and automated financial controls.

If ITGCs are effective, auditors can:

  • rely on system reports for analytics and substantive testing
  • place reliance on automated application controls
  • reduce the volume and time spent on manual sampling
  • streamline overall audit effort.

However, if ITGCs are weak, auditors may:

  • increase the extent of substantive testing
  • expand sampling
  • perform more manual, time-consuming procedures
  • in serious cases, consider IT-related control deficiencies significant enough to impact the audit opinion.

Ultimately, ineffective ITGCs drive cost, complexity, and risk.

Why ITGC requirements may feel “new” to many organisations

Even though these controls have been part of auditing standards for many years, several recent trends have elevated their importance:

  • The shift to cloud and SaaS systems has blurred responsibility between internal teams and external vendors
  • Cybersecurity risks have increased significantly, and regulators expect tighter oversight
  • Finance processes have become more automated, increasing dependency on system accuracy
  • Businesses now use interconnected systems and integrations that introduce new points for failure and risk.

This environment has made ITGCs more visible, scrutinised, and critical to the audit process.

Common misconceptions from finance teams

Many audit challenges stem from a misunderstanding of where responsibility lies. Frequent misconceptions include:

“Our system is cloud-based, so the vendor handles the controls.”

Cloud providers manage the infrastructure or system – but organisations remain responsible for user access, changes (in infrastructure as a service or platform as a service setup), configuration, and governance.

“We’ve never had an issue, so why is the audit asking for more evidence?”

Absence of observed issues doesn’t demonstrate effective controls or satisfy audit requirements. Each financial year, new evidence is required to demonstrate the effectiveness of controls over the current financial period being audited.

“ITGCs are an IT problem, not a finance issue.”

Finance owns the integrity of financial reporting. ITGCs directly protect the accuracy of financial statements.
Addressing these misconceptions early helps reduce delays and improve audit outcomes.

The strategic value of strong ITGCs beyond the audit

While driven by audit requirements, effective ITGCs also deliver broader benefits such as:

  • stronger cybersecurity
  • improved accuracy and trust in internal reporting
  • reduced operational disruptions
  • better alignment between IT and finance.

The bottom line for finance teams, audit committees and boards

ITGCs are no longer optional or “nice to have”. They are core financial governance controls that underpin the reliability of every number reported to management, shareholders, and regulators.

Finance leaders who proactively strengthen ITGC environments not only simplify their audit – they reduce the risk of financial reporting failures which may lead to unwanted attention from regulators, loss of reputation and financial penalties.
 

Need advice on strengthening your IT controls ahead of your next audit?

Get in touch