Review of the IT general controls — access, change management and IT operations — that underpin the integrity of your financial reporting.
ITGCs are the controls financial auditors depend on when they rely on your systems. Weak ITGCs undermine the reliability of every application control above them.
We assess your controls over logical access, change management and IT operations across in-scope systems, identifying deficiencies before your financial-statement or SOX auditors do.
Provisioning, reviews, privileged access and SoD.
Authorisation, testing and migration of changes.
Job scheduling, backup and incident management.
Controls over new and changed systems.
Conflicting access across key processes.
Where this engagement tends to add the most value.
IT general controls underpin the systems that financial statements and regulatory reporting depend on and are tested as part of statutory and SOX audits; weak ITGCs undermine reliance on every automated control above them.
An orderly lifecycle designed for a credible, defensible result.
Identifying the applications and infrastructure supporting reporting.
Walking through access, change and operations control domains.
Testing the design and operating effectiveness of ITGCs.
Reviewing segregation of duties and privileged access.
Evaluating and classifying control deficiencies.
Reporting findings to the audit and management teams.
This work maps to the standards and regulatory requirements relevant to you.
What to have in place before we begin.
Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Explore this offering in detail.
Learn more →Back to the full pillar.
View pillar →Let us know your objectives, and we’ll design the engagement around them.