IT General Controls vs Application Controls
ITGCs sit around the systems, application controls sit inside them, and the second depends on the first.
IT general controls (ITGCs) are the controls around the systems: who can get in, how changes reach production, how jobs run and how data is backed up. Application controls are the controls inside a system: the edit check that rejects a GSTIN in the wrong format, the three-way match before an invoice can be paid.
The distinction matters because one depends on the other. An automated control in SAP is only as reliable as the change management and access controls that stop someone altering its configuration. Weak ITGCs undermine reliance on every application control they support.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
ITGCs vs Application Controls at a Glance
Where they sit
IT general controls
Across the IT environment: infrastructure, operating systems, databases, networks, IT processes
Application controls
Within a specific application, at business-process level
What they protect
IT general controls
The continued proper operation of systems, and the integrity of programs and data
Application controls
That individual transactions are authorised, complete, accurate and valid
Examples (SA 315)
IT general controls
Program change controls; access to programs and data; implementing new releases of packaged software; restricting system utilities that could change data without an audit trail
Application controls
Edit checks on input; numerical sequence checks with follow-up of exceptions; arithmetical accuracy checks; review of accounts and trial balances
Scope of a failure
IT general controls
Pervasive: can affect every application on the platform
Application controls
Usually confined to the process or transaction type
Who typically owns them
IT general controls
IT function
Application controls
Business process owner, often configured by IT
| IT general controls | Application controls | |
|---|---|---|
| Where they sit | Across the IT environment: infrastructure, operating systems, databases, networks, IT processes | Within a specific application, at business-process level |
| What they protect | The continued proper operation of systems, and the integrity of programs and data | That individual transactions are authorised, complete, accurate and valid |
| Examples (SA 315) | Program change controls; access to programs and data; implementing new releases of packaged software; restricting system utilities that could change data without an audit trail | Edit checks on input; numerical sequence checks with follow-up of exceptions; arithmetical accuracy checks; review of accounts and trial balances |
| Scope of a failure | Pervasive: can affect every application on the platform | Usually confined to the process or transaction type |
| Who typically owns them | IT function | Business process owner, often configured by IT |
The Main ITGC Areas
SA 315's list, which ICAI's Module 1 material expands with OS, database and environmental controls.
- Data centre and network operations
- Job scheduling, batch monitoring, backup and recovery, incident handling.
- System software acquisition, change and maintenance
- Operating systems, databases and utilities: patching, hardening, restricting privileged tools.
- Program change
- Requests approved, tested, and moved to production by someone other than the developer.
- Access security
- User provisioning and removal, privileged accounts, password policy, periodic access review.
- Application system acquisition, development and maintenance
- How new systems are bought or built and implemented, including data migration.
Why the Order of Testing Matters
ICAI's material states the dependency directly: application controls can be effective only if the ITGCs supporting them are effective. So the auditor normally evaluates ITGCs first. If change management over a bank's core banking system is sound and the interest-calculation parameter has not changed, a small test of the automated calculation, plus evidence that the configuration was stable, can support reliance across the year.
If ITGCs fail (developers with direct production access, no record of who changed a parameter) you cannot assume the automated control ran the same way all year. Reliance falls away and testing shifts to substantive procedures over the transactions themselves.
Quick practice on audit concepts. No signup.
A Second Way to Classify Controls
By function rather than location: preventive (stop the problem, for example a firewall or an input validation), detective (report that it happened, for example audit trails or exception reports) and corrective (reduce the impact and fix the cause, for example backups). Every control has both a location (general or application) and a function, and questions mix the two schemes deliberately.
How the DISA Assessment Test Tests This
- check_circle"Each of the following is a general control concern EXCEPT": the odd one out is something application-specific, such as balancing daily control totals. Organisation of the IT department, documentation procedures and physical access are all general.
- check_circleDependency questions: "an auditor finds weak change management; what is the impact on reliance on automated controls?" Reliance is reduced and substantive testing increases.
- check_circleClassification traps: a budget-check message that blocks a purchase order is preventive, not detective, even though it "detects" a lack of funds.
- check_circleSegregation of duties appears on both sides: as an organisational ITGC and as role restrictions configured inside an application. Read the scenario for where the control lives.
FAQs
What is the difference between general controls and application controls?expand_more
General controls apply across the IT environment and support the proper running of all systems (access, change management, operations). Application controls operate within one application to ensure its transactions are authorised, complete and accurate.
Why are ITGCs tested before application controls?expand_more
Because application controls depend on them. If access or change controls are weak, an automated control may have been altered or bypassed, so it cannot be relied on without further work.
Is segregation of duties a general control or an application control?expand_more
It can be either. Separating development from production is a general control; restricting one SAP user from both creating a vendor and approving its payment is configured in the application.
Are manual controls application controls?expand_more
They can be. ICAI's material describes application controls as automated or manual, where a manual control needs human action, such as following up an exception report the system produces.
Next steps
- Application Controlsarrow_forward
- Change Managementarrow_forward
- Logical Accessarrow_forward
- IS Audit Processarrow_forward
Assessment Test format, timed and scored.
