Business and Technology · Internal controls
General Controls vs Application Controls in IT Systems
Updated 11 October 2026 · Fact-checked
IT controls protect computer systems and the data in them. General controls cover the whole IT environment, such as access, backups and security. Application controls work inside one program, such as validating input and checking output. To answer questions, identify the risk, then match a control to it.
Understand Information Systems and IT Controls
Most businesses now run accounting, payroll and sales on computer systems. That brings risks: unauthorised access, data loss, errors and fraud. IT controls are the policies and procedures that reduce those risks.
Exam questions split IT controls into two groups.
General controls apply to the whole IT environment and support every application. Examples: access controls, backups and disaster recovery, physical security of servers, firewalls and anti-virus software, and controls over system development and changes.
Application controls apply to a specific program or transaction type, such as the payroll system. They cover input, processing and output. Examples: validation checks on data entered, batch totals, and review of exception reports.
A simple test: if the control protects the whole system, it is general. If it checks the data in one process, it is an application control.
Access controls stop unauthorised people using the system. They include unique user IDs, strong passwords that are changed regularly, biometrics, and user rights set by job role. Passwords alone are weak, so multi-factor authentication adds a second proof, such as a code sent to a phone.
Input controls catch errors early. Common validation checks are: range check (value within limits), format check (right pattern, such as a date), presence check (field not blank), check digit (a number calculated from the others), and limit check. Backups protect against data loss: copy data regularly and store a copy off-site or in the cloud, and test restoring it.
Key formulas to remember
- General controls
- General controls = controls over the whole IT environment
- Includes access, backup and recovery, physical security, network security, and change and development controls.
- Application controls
- Application controls = controls inside one program (input, processing, output)
- Includes validation checks, batch totals, run-to-run totals and exception reports.
- Common validation checks
- Range, format, presence, check digit, limit, reasonableness
- Each tests data at entry. They show the data is reasonable, not that it is correct.
- Control types
- Preventive, detective, corrective
- Passwords prevent, exception reports detect, restoring from backup corrects.
How to solve Information Systems and IT Controls questions
Use this method for any IT controls question, whether multiple choice, multiple response or a short multi-task item.
- 1Read the scenario and find the risk: unauthorised access, data loss, input error, fraud or system failure.
- 2Decide the level: whole system (general) or one program (application).
- 3Spot the key words in the question, such as 'access', 'backup', 'input' or 'output'.
- 4Match one control to the risk. Make sure it directly addresses that risk.
- 5Check the control type if asked: preventive, detective or corrective.
- 6For multiple response, select exactly the number stated and reject options that do not fit the risk.
- 7For number entry or statement questions, re-read the wording before you commit.
Quickest way: Risk-to-control matching
When to use it: Use for multiple choice and multiple response items when time is short.
- Underline the risk in the question.
- Ask: does this control protect everything or one program?
- Remove options that treat a different risk, such as a backup offered for an input error.
- Pick the most direct control and move on.
Common mistakes in Information Systems and IT Controls
Calling a validation check a general control.
Both groups are 'IT controls' and the labels sound alike.
Fix: Validation works on data in one program, so it is an application control.
Saying passwords alone make a system secure.
Passwords are the best-known control.
Fix: Passwords can be shared or guessed. Add regular changes, user rights by role and multi-factor authentication.
Thinking a validation check proves data is correct.
Students confuse 'valid' with 'accurate'.
Fix: A range check accepts any value in range, even a wrong one. It only filters unreasonable data.
Keeping backups on the same site or the same machine.
It is convenient and seems enough.
Fix: Store copies off-site or in the cloud, and test restores. Fire or theft could destroy both copies.
Matching the wrong control to the risk, such as a firewall for a data entry error.
Students recall a control list and pick the first option they know.
Fix: Name the risk first, then choose the control that addresses it.
Worked examples
Example 1
A payroll clerk enters an employee's hours worked as 480 instead of 48. Which control would most directly prevent this error being accepted? Options: A. Daily off-site backup. B. A range check on hours worked. C. A firewall. D. A unique user ID for each clerk.
Show the solution
- Risk: an input error with an unreasonable value.
- This is a data entry problem inside one program, so look for an application control.
- Backup deals with data loss, so A does not fit.
- A firewall protects against external network attacks, so C does not fit.
- User IDs identify who enters data but do not stop wrong values, so D does not fit.
- A range check rejects hours outside a set limit, such as above 100.
Answer: B. A range check on hours worked.
Example 2
Explain two general controls a company could use to reduce the risk that unauthorised staff alter its sales ledger data.
Show the solution
- Risk: unauthorised access leading to changes in data.
- Control 1: access controls. Give each user a unique ID and a strong password that must be changed regularly. Set user rights by job role so only authorised staff can amend the sales ledger.
- Control 2: a log of activity, reviewed by management. This detects unusual changes and links them to a user.
- Both apply across the IT environment, so they are general controls.
- Add that multi-factor authentication could strengthen the first control.
Answer: Use access controls (unique IDs, passwords, role-based rights) to prevent unauthorised changes, and review activity logs to detect any that occur.
Exam tips
- Always name the risk before the control. Marks go to a control that fits the risk.
- Know the general versus application split cold. It is a frequent objective test item.
- In multiple response items, select exactly the stated number of options.
- Learn the validation checks by name and what each tests, such as range, format and presence.
- In scenario questions, say what the control does, not just its name.
Practice questions from Internal controls
- An accounts clerk can create new supplier records in the purchase ledger system, enter supplier invoices and also authorise payment runs. Wh…
- During a review, an internal auditor finds that bank reconciliations at Tarn Ltd are prepared by the same employee who records cash receipts…
- In a small retailer, the same employee orders inventory from suppliers, receives the goods into the warehouse and records the receipt in the…
- Which of the following is a key difference between internal audit and external audit?
- Which of the following is the main purpose of segregation of duties within an internal control system?
Information Systems and IT Controls in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Information Systems and IT Controls: frequently asked questions
What is the difference between general and application controls?
General controls cover the whole IT environment, such as access, backups and security. Application controls work inside a specific program, such as validation of input data. Ask whether the control protects everything or one process.
Are passwords enough to secure a system?
No. Passwords can be guessed, shared or stolen. Combine them with regular changes, role-based access rights and multi-factor authentication.
What are examples of input validation checks?
Range checks, format checks, presence checks, check digits and limit checks. They test data at entry and reject items that look unreasonable or incomplete.
Why do businesses keep backups off-site?
A fire, flood or theft could destroy both the system and on-site copies. An off-site or cloud backup lets the business restore its data and keep operating.