General IT Controls
General IT controls are the policies and procedures an organization puts in place to manage and protect the technology systems that support its business activities. They cover how IT systems are acquired, built, deployed, used, and maintained, and they apply broadly across an organization's systems, data, and processes rather than to a single application. Their purpose is to help ensure that IT systems operate reliably and securely so the information they produce can be trusted.
General IT Controls (ITGC) are pervasive controls that apply across an organization's information systems, components, processes, and data, as distinct from application controls that are embedded within specific applications or transactions. Typically maintained over the IT environment as a whole, often the functions of the IT or MIS support unit, ITGC commonly address domains such as access and identity management, change management, system acquisition and development, and IT operations. In an audit context, ITGC are frequently tested to establish the reliability of the underlying IT environment on which application-level controls and financially significant reporting depend; weaknesses in ITGC can undermine reliance on otherwise effective application controls. The precise scope, control objectives, and testing approach vary by organization, sector, applicable frameworks, and regulatory context, and specific requirements should be confirmed against the relevant standards and primary sources.
Why it matters
General IT controls matter because most modern organizations depend on information systems to record transactions, safeguard data, and produce the reports that management, auditors, and regulators rely on. When the underlying IT environment is well governed, the information those systems generate can generally be trusted. When ITGC are weak, that trust erodes: even an application control that appears to work may not be reliable if unauthorized users can change data, if untested code can be moved into production, or if system operations are not properly monitored. For this reason, ITGC are often treated as foundational to the reliability of the broader control environment.
In an audit context, ITGC frequently determine how much reliance can be placed on application-level controls and on financially significant reporting. Because ITGC apply pervasively across systems, components, processes, and data rather than to a single application, a deficiency in a shared control domain, such as access management or change management, can affect many downstream processes at once. Auditors commonly test ITGC precisely to establish whether the IT environment as a whole provides a dependable basis for the controls that sit on top of it.
It is important to note that the specific scope, control objectives, and testing approaches for ITGC vary by organization, sector, applicable frameworks, and regulatory context. What constitutes an adequate control set in one environment may be insufficient or excessive in another, and specific requirements should be confirmed against the relevant standards and primary sources rather than assumed.
Who it's relevant to
Inside ITGC
Common questions
Answers to the questions practitioners most commonly ask about ITGC.

