Audit and Assurance · Systems of internal control
Information Systems and IT Controls: General vs Application Controls
Updated 11 October 2026 · Fact-checked
IT controls are split into general controls, which cover the whole IT environment (access, change management, backup, operations), and application controls, which work inside one program to keep transactions complete and accurate (input, processing, output). To answer a question, identify the risk, then name a matching control.
Understand Information Systems and IT Controls
Most entities now run their accounting on computer systems. This brings benefits: fast processing, consistent application of rules and fewer random errors. It also brings risks that you must be able to describe in the exam.
General IT controls relate to the whole IT environment. They support the continued, proper operation of every application. They cover areas such as access security, program development and changes, computer operations and backup, and data and disaster recovery. If general controls are weak, the auditor cannot rely on application controls, because the programs could be changed or bypassed.
Application controls operate within a specific application, such as payroll or sales invoicing. They aim to ensure that transactions are authorised, complete, accurate and valid. They are usually grouped into input controls, processing controls and output controls, plus controls over master files and standing data.
Typical risks in computerised systems include unauthorised access to data and programs, unauthorised or untested program changes, loss of data through failure or lack of backup, errors in the program that are repeated on every transaction, reduced segregation of duties because one person can do many tasks, and reduced paper evidence of authorisation. Hacking, viruses and ransomware are also common risks.
The auditor links this to the audit. The auditor assesses the IT environment as part of understanding internal control. If controls look reliable, the auditor can test them and reduce substantive work. If they are weak, more substantive work is needed, often using computer-assisted audit techniques.
Key rules to remember
- General controls (categories)
- Access + Change management + Operations/backup + Recovery
- Apply across all applications. Use these as headings in a written answer.
- Application controls (categories)
- Input + Processing + Output (+ master files)
- Specific to one application. Link each control to an assertion such as completeness or accuracy.
- Answer pattern
- Risk → Control → Purpose
- State what could go wrong, the control that prevents or detects it, and why it works.
- Reliance rule
- Effective general controls → application controls can be relied on
- If general controls are ineffective, application controls may not operate consistently.
How to solve Information Systems and IT Controls questions
Use this method for any question asking for risks, controls or audit implications of an IT system.
- 1Read the scenario and note the system: payroll, sales, inventory, online ordering or the whole network.
- 2Decide whether the requirement asks for general controls, application controls, risks or audit procedures.
- 3For general controls, work through access, changes, operations and backup, and recovery.
- 4For application controls, work through input, processing and output, using the scenario's transactions.
- 5Tie each point to scenario facts, such as remote staff, a new system or a single IT person.
- 6Write each point as risk, control and purpose, using one short paragraph or bullet per point.
- 7If asked for audit impact, state whether the auditor can rely on controls and how substantive testing would change.
Quickest way: Heading-and-pair method
When to use it: Use for Section B or C requirements asking you to list controls, or for objective questions that ask you to classify a control.
- Classify the control: does it affect the whole IT environment or one program? Whole environment means general; one program means application.
- For written answers, jot headings: access, changes, backup, input, processing, output.
- Write one risk-and-control pair under each heading, using scenario details.
- Check you have matched the number of points to the marks available, usually one point per mark.
Common mistakes in Information Systems and IT Controls
Confusing general and application controls, for example calling passwords an application control.
Both types can involve software, so the line seems blurry.
Fix: Ask whether the control protects the whole system or checks one transaction type. Network passwords are general; a check that an employee number exists in payroll is application.
Listing controls without explaining the risk or purpose.
Students memorise lists of controls and write them as bare nouns.
Fix: Write a full pair: for example, a backup stored offsite prevents permanent data loss after a fire or ransomware attack.
Giving generic answers that ignore the scenario.
Students recall textbook lists and do not read for the facts.
Fix: Use named details in the scenario, such as a new online ordering system or staff working remotely, in each point.
Saying computers remove the risk of error.
Computers process consistently, so students assume they are always right.
Fix: State that an error in the program is repeated consistently on every transaction, so program controls and change controls matter.
Mixing up controls and audit procedures in a requirement.
Both use words like test or check.
Fix: If the question asks for controls, describe what management should do. If it asks for audit procedures, describe what the auditor does, such as reperforming or inspecting access logs.
Worked examples
Example 1
A retailer introduces a new online sales system linked to its inventory and accounting records. Describe four application controls the retailer could implement over this system. (4 marks)
Show the solution
- Identify the area: application controls, so use input, processing and output.
- Input: drop-down lists and format checks on customer address and quantity fields, which reduce keying errors and invalid data.
- Input: the system rejects orders where payment authorisation fails, so only valid, paid sales are recorded.
- Processing: automatic matching of each order to inventory, with a flag when stock is insufficient, which prevents sales of goods not available.
- Output: a daily exception report of orders that failed checks, reviewed and cleared by a supervisor, so errors are followed up and corrected.
Answer: Four application controls: (1) format and range checks on input fields; (2) rejection of orders without payment authorisation; (3) automatic matching of orders to inventory with flags for shortages; (4) review of a daily exception report by a supervisor.
Example 2
An audit client has a small IT team. Programmers can also update live data and there is no formal process for approving program changes. Explain the risks this creates and recommend two general controls. (6 marks)
Show the solution
- Risk 1: programmers who can change live data could make unauthorised or fraudulent changes, which may be undetected.
- Risk 2: untested or unapproved program changes may contain errors, and the errors would be repeated on every transaction processed.
- Risk 3: the lack of segregation of duties between development and operations weakens reliance on any application control.
- Control 1: separate development and live environments, with programmers having no access to live data or programs.
- Control 2: a formal change process requiring written request, testing in a separate environment and approval by management before a change goes live.
- Audit implication: general controls are weak, so the auditor is unlikely to rely on application controls and will do more substantive work.
Answer: The risks are unauthorised changes to data, repeated errors from untested program changes, and weak segregation of duties. Recommended controls: separate development from live systems with restricted access, and a formal approved and tested change-management process. Weak general controls reduce reliance on application controls and increase substantive testing.
Exam tips
- Always label points as general or application when the requirement asks you to distinguish them.
- Use the scenario facts in every point. Generic lists score fewer marks.
- In objective questions, look for key words: whole system, access, backup mean general; input, processing, output mean application.
- Do not write about CAATs unless asked for audit procedures. Answer the requirement exactly.
Information Systems and IT Controls in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Information Systems and IT Controls: frequently asked questions
What is the difference between general controls and application controls?
General controls apply to the whole IT environment and cover access, program changes, operations and backup. Application controls work within one program and check that transactions are complete, accurate and valid. Effective general controls support reliance on application controls.
How do I answer an IT controls question in ACCA AA?
Identify whether the question wants risks, controls or audit procedures. Use headings such as access, changes, input, processing and output. Write each point as risk, control and purpose, linked to the scenario.
Why do weak general controls matter to the auditor?
They mean application controls might not operate consistently, because programs or data could be changed without authority. The auditor is then less able to rely on controls and must do more substantive testing.
Can I give examples of application controls?
Yes. Examples include format and range checks on input, matching orders to inventory, sequence checks on documents, and review of exception reports. Always say what error each control prevents or detects.