What an ITGC audit is
An ITGC audit evaluates the IT general controls that govern your IT environment — access management, change management, system operations and data security. It assesses whether those controls are well designed and operating effectively across the applications, databases and infrastructure that support your critical and financial-reporting systems.
Mapped to recognised control frameworks, a structured ITGC audit reduces operational risk, improves IT governance and gives internal and external auditors the assurance that your systems are reliable, secure and compliant.
Who needs an ITGC audit
An ITGC audit matters most where control weaknesses carry a direct financial-reporting, regulatory or customer-assurance cost:
- Banks, NBFCs and fintech companies under RBI IT-governance expectations.
- Organisations subject to SOX or preparing for a SOC 1 / SOC 2 report.
- SaaS and cloud providers whose customers require evidence of effective controls.
- Healthcare, insurance and capital-market firms protecting sensitive systems and data.
- Any organisation preparing for a regulatory or financial audit that relies on IT controls.
CyberSigma’s role
We are the independent auditor. We scope the IT environment, review access and change management, test operations and control effectiveness against the framework, rate the findings, and issue the audit report — along with the risk-rated remediation you need to close the gaps.
Independence and empanelment
CyberSigma is a CERT-In empanelled auditor, and the audit is conducted independently of the teams that build and run your systems. That independence is what gives the audit report its standing with your internal audit function, external auditors and regulators.
How we deliver
Scoping and planning
We define the IT environment in scope — the applications, databases, operating systems and infrastructure that support your critical and financial-reporting systems — agree the control framework we assess against, and confirm the evidence and access we will need.
Access and change review
We examine logical access management, user provisioning and de-provisioning, privileged access and segregation of duties, then review the change-management process to confirm system changes are approved, tested and documented before they go live.
Operations and control testing
We test IT operations, job scheduling, monitoring, and backup and recovery, and assess the design and operating effectiveness of each control against the framework — sampling real evidence rather than relying on stated policy.
Reporting and remediation review
We document the findings, rate each control gap by risk, set out the practical remediation, then re-verify closure so the audit report reflects the true state of your IT general controls.
What you receive
- ITGC audit report on the design and operating effectiveness of your controls
- Gap analysis mapping your controls to recognised frameworks
- Risk and control evaluation backed by sampled audit evidence
- Access and change-management review across the IT environment
- Risk-rated, practical remediation recommendations
- Compliance documentation that evidences the audit outcome for internal and external auditors
Indicative timeline
A typical ITGC audit runs from about two to six weeks, depending on the size of the organisation, the number of applications and systems in scope, and the maturity of your current controls.
Timelines vary with scope and readiness; we confirm a schedule after scoping.
Control weaknesses the audit surfaces
Across IT general controls and their supporting systems, an ITGC audit commonly identifies weaknesses such as:
Weak access management
Excessive privileges, weak authentication and poor user-access controls that expose your systems.
Ineffective change management
Unauthorised system changes and missing approvals that undermine the integrity of your controls.
Inadequate system monitoring
Gaps in logging and monitoring that leave IT activity without oversight.
Poor segregation of duties
Conflicting user roles that let a single user control critical end-to-end processes.
Weak backup and recovery
Untested backup and recovery procedures that put critical IT systems at risk.
Incomplete documentation
Missing policies and audit trails that break alignment with recognised frameworks.
Representative engagement
A SaaS provider preparing for its first SOC 2 report needed an independent view of its IT general controls. We scoped its production applications, databases and cloud infrastructure, reviewed access provisioning and change management, tested operations, backup and monitoring, rated and re-verified the findings, and issued the audit report its auditors relied on. Named client references are available under NDA on request.
Who leads your engagement
Your engagement is led by a senior auditor with hands-on experience of SOX, SOC 1/SOC 2 and RBI IT-governance requirements — supported by application, database and infrastructure specialists. Every finding passes independent quality review before the report reaches you. We introduce your named lead on the first call.
Not sure where you stand on ITGC audit?
Get a free ITGC audit scope and readiness review — share your work email and a senior consultant maps your gaps and next steps. No obligation.
Frequently asked questions
What is an ITGC audit?
An ITGC (IT general controls) audit is a structured assessment of the foundational IT controls that govern how technology systems are managed, secured and changed within an organisation. It evaluates controls across logical access management, change management, computer operations and IT risk management. ITGC audits are a prerequisite for SOX ITGC work, SOC 2 reporting and many regulatory frameworks, because weak IT general controls can undermine the reliability of every application-level control built on top of them.
Who needs an ITGC audit in India?
Organisations in India that need an ITGC audit include listed companies and their subsidiaries subject to SEBI internal controls over financial reporting, businesses seeking SOC 2 Type I or Type II reports, companies under SOX ITGC mandates (typically subsidiaries of US-listed parent companies), banks and NBFCs under RBI IT governance guidelines and organisations pursuing ISO 27001 certification or PCI DSS assessment and validation. Any business that relies on IT systems to process financial transactions or sensitive data benefits from a formal ITGC audit.
What IT domains does an ITGC audit cover?
An ITGC audit covers four core domains: (1) logical access controls — who has access to systems, how access is provisioned and de-provisioned, privileged access management and segregation of duties; (2) change management controls — how software and infrastructure changes are authorised, tested and deployed to prevent unauthorised modifications; (3) computer operations controls — job scheduling, backup and recovery, and incident and problem management; and (4) IT risk management — oversight of IT governance, vendor management and business continuity planning. Our ITGC audit covers all four domains with evidence-based testing.
How is an ITGC audit different from a VAPT or ISO 27001 audit?
A VAPT (vulnerability assessment and penetration test) identifies technical security vulnerabilities in systems and networks through active testing. An ISO 27001 audit evaluates whether your information security management system meets the standard. An ITGC audit examines the design and operating effectiveness of the IT process controls that support financial reporting and regulatory compliance — it is process-oriented and evidence-driven rather than technical or standard-based. ITGC audits are typically scoped to the systems in scope for SOX, SOC 1/SOC 2 or similar financial and regulatory audits, and are run by auditors familiar with control frameworks such as COBIT and COSO.
How long does an ITGC audit take?
A typical ITGC audit for a mid-sized Indian organisation takes 3 to 6 weeks from kickoff to final report. The timeline depends on the number of in-scope applications and infrastructure components, the maturity of existing documentation, the complexity of your IT environment and whether the engagement is a readiness assessment or a formal audit. We follow a phased approach: scoping and planning (Week 1), evidence collection and walkthroughs (Weeks 2–3), control testing and gap identification (Week 4), and reporting with remediation guidance (Weeks 5–6).
What evidence is required for an ITGC audit?
Common evidence collected during an ITGC audit includes user access listings and role matrices, access provisioning and termination records, privileged account inventories, change request logs and approvals, release notes and test evidence for production changes, job scheduler and batch processing records, backup logs and restoration test results, incident and problem management tickets, IT policies and procedures, and vendor management contracts. We provide a detailed evidence request list at project start so your team can prepare efficiently.
What are common ITGC gaps found in Indian organisations?
The deficiencies we see most often include excessive privileged access and shared administrator credentials, inadequate segregation of duties in ERP systems such as SAP and Oracle, no formal change management with developers holding direct production access, infrequent or untested backup recovery, missing periodic user access reviews, undocumented IT policies and weak third-party vendor oversight. Our audit identifies these gaps and provides risk-rated remediation recommendations suited to your team's capacity.
Does CyberSigma conduct ITGC audits for SOX compliance?
Yes. We conduct ITGC audits scoped for SOX ITGC, including walkthroughs, control design assessments and operating effectiveness testing aligned to PCAOB AS 2201 and the COSO framework. We have experience working with Indian subsidiaries of US-listed companies where the parent company's external auditors require ITGC testing evidence. We deliver audit-ready documentation and can coordinate directly with your external auditors so our work products meet their reliance requirements.
Can an ITGC audit help with SOC 2 readiness?
Yes. ITGC controls map directly to the SOC 2 Common Criteria, particularly CC6 (logical and physical access), CC7 (system operations) and CC8 (change management). An ITGC readiness assessment before your SOC 2 audit identifies control gaps early, avoids findings that could lead to a qualified opinion and shortens your path to a clean SOC 2 Type II report. We offer combined ITGC and SOC 2 readiness engagements to reduce duplicated effort.
What does CyberSigma deliver at the end of an ITGC audit?
At the end of an ITGC audit you receive an executive summary of your overall ITGC risk posture, a control testing workbook documenting each control tested, the evidence reviewed and the result, a gap report listing every deficiency rated by severity (critical, high, medium, low), a remediation roadmap with prioritised action items and suggested owners, and a management representation of findings for use with external auditors or regulators. All deliverables are provided in editable formats to support your follow-up.
How much does an ITGC audit cost in India?
ITGC audit costs in India depend on the size and complexity of the IT environment, the number of in-scope systems and business processes, whether the engagement includes remediation support and the reporting requirements (readiness assessment or formal audit documentation for external auditors). Engagements for small to mid-sized organisations typically start from INR 2.5 lakhs, while larger environments with multiple ERP systems and regulatory requirements are priced accordingly. We provide a fixed-fee proposal after a brief scoping call so you have full cost visibility before committing.
Why choose CyberSigma for ITGC audit services?
CyberSigma is a CERT-In empanelled cybersecurity firm working with over 1,000 organisations across India and the UAE. Our ITGC audits are run by senior auditors with hands-on experience in SOX ITGC, SOC 1/SOC 2, PCI DSS and RBI IT governance. We pair a working understanding of IT systems with audit methodology, so findings are accurate and actionable. With offices in India and the UAE, we support organisations with cross-border compliance needs and deliver audit-ready documentation that satisfies internal and external auditors.
