What does general IT control mean on the CPA exam?
General IT control. A control over the entity's IT processes that supports the continued effective functioning of information-processing controls and the integrity of information. Grouped by IT process: managing access, managing program changes, and managing IT operations. It supports other controls rather than addressing an assertion.
Defined against AU-C 315.12 and Appendix F.
Which CPA exam sections use general IT control?
General IT control appears in the ISC section of the CPA exam.
Other terms defined against AU-C 315
- application controls: Controls built into one business process or system, such as a validity check on an input field or a three-way match.
- assessed risk: The auditor's judgment about the risk of material misstatement at the assertion level, combining inherent and control risk.
- control environment: The governance and management functions and the attitudes, awareness, and actions of those charged with governance and management concerning the entity's system of internal control.
- general controls: Controls over the IT environment as a whole -- access, change management, operations -- that everything else depends on.
- information and communication: One of the five components of internal control: how an entity obtains the information it needs and gets it to the people who have to act on it.
- information-processing control: A control over processing in an IT application or a manual information process that directly addresses a risk to the integrity of information.
- rights and obligations: The assertion that the entity genuinely owns the assets it reports and genuinely owes the liabilities.
- risk assessment procedures: The audit procedures designed and performed to identify and assess the risks of material misstatement at the financial statement and assertion levels.
Related terms
- access control: Deciding who may reach what, and enforcing it.
- COSO Internal Control - Integrated Framework: The reference model for internal control: five components and seventeen principles, all of which must be present and functioning for control to be effective.
- program changes: The IT general control area covering modifications to systems already in production: requested, tested, approved and migrated by someone other than the developer.
- program development: The IT general control area covering how new systems are built, tested and approved before going live.
- service organization: A third party whose processing affects a user entity's financial reporting, such as a payroll bureau or a claims processor.
- SOC 2 report: A report on a service organization's controls against the trust services criteria, covering security plus any of availability, processing integrity, confidentiality, and privacy that are selected.