07011011237  |  info@aceictconsult.comOffices in Abuja and Lagos, Nigeria
ACE ICT Consult logoACE ICT ConsultBook a Consultation

What an IT General Controls (ITGC) Review Actually Tests

A practical, evidence-backed breakdown of how internal and statutory auditors evaluate access, change, operations, and data integrity across the enterprise.

IT Audit & AssurancePublished: January 12, 20269 Min ReadBy ACE Assurance Practice

Whenever external financial auditors, regulatory examiners from the Central Bank of Nigeria (CBN), or internal Audit & Risk Committees inspect an organization's technology environment, the foundational starting point is the IT General Controls (ITGC) review. Yet many Chief Information Officers (CIOs) and IT managers still struggle with what auditors are actually looking for.

ITGCs do not evaluate whether a particular financial ledger entry was keyed in accurately on a Tuesday morning. Instead, they assess whether the technological foundation supporting business applications, databases, and financial systems is reliable, secure, and governed. If ITGCs fail, all automated application controls, transaction reports, and digital audit trails lose credibility in the eyes of statutory auditors.

Domain 1: Logical Access Controls (Who Can Touch What?)

Logical access testing evaluates how identity and privileges are managed across operating systems, core databases (Oracle, SQL Server, PostgreSQL), and business applications (SAP, Oracle EBS, Finacle, Microsoft Dynamics):

1. User Provisioning & Role-Based Access Control (RBAC)

Auditors request a list of all user accounts created during the audit period. From this population, they select a random statistical sample (typically 25 to 45 samples) and demand:

  • The signed access request form or automated Service Desk ticket demonstrating approval by the employee’s direct line manager and the business application owner before the account was activated.
  • Verification that granted permissions match the authorized Role-Based Access matrix, adhering to the principle of least privilege.

2. Timely Deprovisioning of Separated Staff

This is where over 40% of Nigerian enterprises incur significant audit findings. Auditors obtain an HR listing of all employees who resigned, were terminated, or retired during the review period, cross-referencing departure dates against Active Directory and ERP deactivation timestamps. Accounts that remain active 48 hours past the employee's exit date represent an immediate control deficiency.

3. Periodic User Access Recertifications (UAR)

Generating a quarterly user listing is not enough. Auditors require documented evidence that business department heads and branch managers actively reviewed the user list, confirmed ongoing business need, flagged obsolete privileges for revocation, and provided formal sign-off.

4. Privileged Access Management (PAM) & Segregation of Duties

  • Domain & Root Credentials: Privileged administrator accounts must enforce Multi-Factor Authentication (MFA), individual attribution (no shared passwords), and session logging.
  • Segregation of Duties (SoD): Software developers and testers must never possess administrative, database (DBA), or write access to production environments.

Domain 2: Program Change Management (How Does Code Move?)

Change management controls ensure that every modification to application source code, database structures, or system configurations is authorized, thoroughly tested, and safely deployed without introducing fraud or operational failure:

Domain 3: Computer Operations & Data Resiliency

Auditors evaluate whether daily operations prevent unexpected downtime and guarantee disaster recovery:

  • Batch Job Monitoring: Automated tracking of scheduled end-of-day jobs, payroll batches, and core banking interface files. Auditors inspect incident tickets for failed jobs to verify root cause analysis and timely reprocessing.
  • Backup Restoration Testing: A common auditor mantra is "Backup is not recovery." Auditors will ask to see verified evidence of a successful restore test conducted within the last 6 to 12 months, demonstrating that encrypted database snapshots were restored to a secondary server without data loss.
  • Physical & Environmental Security: Biometric data center logs, visitor visitor registers, temperature monitoring, UPS/generator maintenance logs, and FM-200 fire suppression inspection certificates.
Auditor's Advice: When preparing for an ITGC audit, create an Evidence Repository before the auditors arrive. Archive ticket screenshots, CAB minutes, quarterly access review sign-offs, and restore logs in structured folders. Well-organized evidence drastically shortens the audit duration and reduces friction.

How ITGCs Intersect with Business Application Controls (ITAC)

Once ITGCs are certified effective, auditors can place reliance on automated Business Application Controls, such as:

  • Automated 3-Way Matching: Purchase Orders matching Goods Received Notes and Supplier Invoices within approved monetary tolerances.
  • Input Validation: Automated boundary checks, mandatory field enforcement, and duplicate invoice number detection.
  • Automated Workflow Approvals: Threshold-based routing requiring dual executive authorization for payments exceeding specific limits.

Need an independent IT Audit or control evaluation?

Speak to our senior assurance team about your requirements.

Book a Consultation