The request usually arrives by email with no explanation: please provide your ITGC evidence. This is what it means.
| Domain | What is tested | Typical failure |
|---|---|---|
| Access | Provisioning, privileged access, periodic review, MFA | Reviews done but not documented |
| Program changes | Change request, testing, approval, segregation | Emergency changes never retrospectively approved |
| Program development | Project approval, requirements, testing, migration | Migration testing with no evidence trail |
| Operations | Scheduling, monitoring, incidents, backup and restore | Backups taken but restore never tested |
Why the auditor cares
If anyone can change production data without a record, the auditor cannot rely on the system, and has to test manually instead. That is more expensive for you and slower for everyone.
What this means for you
In most ITGC reviews that fall short, the control was performed but not documented. Access reviews take place without a retained record, and emergency changes are approved verbally without retrospective written approval.
Where to start
Start with the access review. It is the single most requested item, and it is also the most commonly missing.