Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
IT audit

ITGC explained for finance teams who have just been asked for evidence

IT general controls are the controls over access, change, development and operations. External auditors rely on them to decide how much they can trust the systems producing your financial information.

The request usually arrives by email with no explanation: please provide your ITGC evidence. This is what it means.

DomainWhat is testedTypical failure
AccessProvisioning, privileged access, periodic review, MFAReviews done but not documented
Program changesChange request, testing, approval, segregationEmergency changes never retrospectively approved
Program developmentProject approval, requirements, testing, migrationMigration testing with no evidence trail
OperationsScheduling, monitoring, incidents, backup and restoreBackups taken but restore never tested

Why the auditor cares

If anyone can change production data without a record, the auditor cannot rely on the system, and has to test manually instead. That is more expensive for you and slower for everyone.

What this means for you

In most ITGC reviews that fall short, the control was performed but not documented. Access reviews take place without a retained record, and emergency changes are approved verbally without retrospective written approval.

Where to start

Start with the access review. It is the single most requested item, and it is also the most commonly missing.

Sources
ISO/IEC 27001:2022, Annex A — information security controls
HKCAS accreditation criteria referencing ISO/IEC 17021-1 — itc.gov.hk