What IT general controls actually are

IT general controls are the controls over the technology environment that financial reporting depends on: who can access systems and data, how changes reach production, how operations are monitored, and how data is protected. They matter because every automated control in an application relies on them. If access and change management are weak, nothing built on top can be relied upon.

Why this is rising up the agenda

Both UAE ICFR regimes name IT controls explicitly. The Abu Dhabi Accountability Authority (ADAA) standards for Abu Dhabi Subject Entities specify access management, change management, application controls and data integrity as in scope. As the Capital Market Authority regime moves to mandatory public reporting in 2027, listed entities face the same examination. External auditors are testing ITGCs earlier and finding the same three things: excessive privileged access, undocumented changes and shared administrator accounts.

How CLA Emirates approaches it

We scope to the systems that matter to the financial statements rather than the whole estate, which keeps the work proportionate and the findings relevant. Testing covers design and operating effectiveness across access, change, operations and data. Findings are reported with the financial statement consequence attached, so an audit committee can see why a change management gap is not merely an IT matter.

What an ITGC review actually tests

  • Access management and privileged accounts
  • Change and release management
  • IT operations and job scheduling
  • Segregation of duties in the ERP
  • Application and interface controls
  • Backup, recovery and data integrity