Whenever external financial auditors, regulatory examiners from the Central Bank of Nigeria (CBN), or internal Audit & Risk Committees inspect an organization's technology environment, the foundational starting point is the IT General Controls (ITGC) review. Yet many Chief Information Officers (CIOs) and IT managers still struggle with what auditors are actually looking for.
ITGCs do not evaluate whether a particular financial ledger entry was keyed in accurately on a Tuesday morning. Instead, they assess whether the technological foundation supporting business applications, databases, and financial systems is reliable, secure, and governed. If ITGCs fail, all automated application controls, transaction reports, and digital audit trails lose credibility in the eyes of statutory auditors.
The Core Equation of IT Assurance
Strong ITGCs + Valid Application Controls = Verifiable Financial and Operational Integrity.
Without effective ITGCs, statutory auditors cannot rely on system-generated reports (Information Produced by the Entity - IPE) and must resort to expensive, disruptive manual substantive testing.
Domain 1: Logical Access Controls (Who Can Touch What?)
Logical access testing evaluates how identity and privileges are managed across operating systems, core databases (Oracle, SQL Server, PostgreSQL), and business applications (SAP, Oracle EBS, Finacle, Microsoft Dynamics):
1. User Provisioning & Role-Based Access Control (RBAC)
Auditors request a list of all user accounts created during the audit period. From this population, they select a random statistical sample (typically 25 to 45 samples) and demand:
- The signed access request form or automated Service Desk ticket demonstrating approval by the employee’s direct line manager and the business application owner before the account was activated.
- Verification that granted permissions match the authorized Role-Based Access matrix, adhering to the principle of least privilege.
2. Timely Deprovisioning of Separated Staff
This is where over 40% of Nigerian enterprises incur significant audit findings. Auditors obtain an HR listing of all employees who resigned, were terminated, or retired during the review period, cross-referencing departure dates against Active Directory and ERP deactivation timestamps. Accounts that remain active 48 hours past the employee's exit date represent an immediate control deficiency.
3. Periodic User Access Recertifications (UAR)
Generating a quarterly user listing is not enough. Auditors require documented evidence that business department heads and branch managers actively reviewed the user list, confirmed ongoing business need, flagged obsolete privileges for revocation, and provided formal sign-off.
4. Privileged Access Management (PAM) & Segregation of Duties
- Domain & Root Credentials: Privileged administrator accounts must enforce Multi-Factor Authentication (MFA), individual attribution (no shared passwords), and session logging.
- Segregation of Duties (SoD): Software developers and testers must never possess administrative, database (DBA), or write access to production environments.
Domain 2: Program Change Management (How Does Code Move?)
Change management controls ensure that every modification to application source code, database structures, or system configurations is authorized, thoroughly tested, and safely deployed without introducing fraud or operational failure:
| Change Control Phase | What the Auditor Inspects | Key Failure Vector |
|---|---|---|
| 1. Initiation & Approval | Formal change ticket with business justification, risk classification (Major, Minor, Emergency), and management sign-off. | Undocumented developer changes or informal chat requests without ticket references. |
| 2. Testing & UAT | Documented User Acceptance Testing (UAT) sign-off with test scripts, test data, and user sign-off in an isolated staging environment. | Testing conducted directly in production or UAT performed by the developer who wrote the code. |
| 3. CAB Sign-off | Change Advisory Board (CAB) meeting minutes confirming cross-functional review of deployment schedules and backout plans. | Deployments executed without formal CAB awareness or documented rollback procedures. |
| 4. Migration to Prod | Separation of duties: Deployment executed by dedicated release engineers or automated CI/CD pipelines, not developers. | Software engineers holding SSH/RDP production server credentials. |
| 5. Emergency Changes | Formal post-implementation review and retrospective CAB approval within 48 to 72 hours of incident resolution. | Emergency changes left permanently open without retrospective documentation. |
Domain 3: Computer Operations & Data Resiliency
Auditors evaluate whether daily operations prevent unexpected downtime and guarantee disaster recovery:
- Batch Job Monitoring: Automated tracking of scheduled end-of-day jobs, payroll batches, and core banking interface files. Auditors inspect incident tickets for failed jobs to verify root cause analysis and timely reprocessing.
- Backup Restoration Testing: A common auditor mantra is "Backup is not recovery." Auditors will ask to see verified evidence of a successful restore test conducted within the last 6 to 12 months, demonstrating that encrypted database snapshots were restored to a secondary server without data loss.
- Physical & Environmental Security: Biometric data center logs, visitor visitor registers, temperature monitoring, UPS/generator maintenance logs, and FM-200 fire suppression inspection certificates.
How ITGCs Intersect with Business Application Controls (ITAC)
Once ITGCs are certified effective, auditors can place reliance on automated Business Application Controls, such as:
- Automated 3-Way Matching: Purchase Orders matching Goods Received Notes and Supplier Invoices within approved monetary tolerances.
- Input Validation: Automated boundary checks, mandatory field enforcement, and duplicate invoice number detection.
- Automated Workflow Approvals: Threshold-based routing requiring dual executive authorization for payments exceeding specific limits.
About the ACE Assurance Practice
ACE ICT Consult provides independent IT audit, ITGC readiness assessments, and regulatory technology reviews for financial institutions, fintechs, and corporate organizations across Nigeria. Our certified auditors (CISA, CRISC, CISSP) help you identify and remediate control weaknesses before statutory inspectors arrive.