Skip to content

Strategic Business Leader · IT systems security and control

IT General and Application Controls for ACCA SBL

Updated 11 October 2026 · Fact-checked

IT general controls (ITGCs) cover the whole IT environment: access, change management, operations, backup and security. Application controls work inside one system and cover input, processing and output. Both can be preventive, detective or corrective. In SBL, name the control type, link it to a scenario risk and say what it achieves.

Understand IT General and Application Controls

An organisation relies on IT to record transactions, run operations and report results. If the IT environment is weak, every system on it is unreliable. Controls exist to reduce that risk. In SBL you are asked to judge whether controls are adequate and to recommend improvements, not to configure systems.

IT general controls (ITGCs) apply across the IT environment. They support all applications and the data they hold. Typical areas are:

  • Logical and physical access, such as passwords, user rights and secure server rooms.
  • Change management: authorising, testing and approving changes to software before use.
  • System development and acquisition controls.
  • IT operations: job scheduling, monitoring, incident handling.
  • Backup, recovery and business continuity.
  • Segregation of duties between developers, operators and users.

Application controls sit inside a specific system, such as payroll, sales ledger or an online ordering platform. They aim to make sure transactions are complete, accurate and valid. They are grouped as:

  • Input controls: stop wrong or unauthorised data entering. Examples are validation checks, mandatory fields, authorisation before entry and duplicate checks.
  • Processing controls: make sure data is handled correctly. Examples are control totals, run-to-run checks, reasonableness checks and automated calculations.
  • Output controls: make sure results reach the right people and are right. Examples are report review, reconciliation to source, restricted distribution and exception reports.

The two layers depend on each other. If ITGCs fail, for example anyone can change code or override access, then application controls cannot be relied on, because they might have been altered or bypassed. Strong ITGCs let you trust application controls.

Controls are also classed by their purpose. Preventive controls stop an error or fraud happening, such as a password or a validation check. Detective controls find problems after they occur, such as a reconciliation or an exception report. Corrective controls fix the problem and restore normal running, such as restoring from backup or re-entering rejected items. A good system uses all three. Preventive controls are usually cheaper than fixing damage later, but no preventive control is perfect, so detection and correction are still needed.

Key rules to remember

ITGC vs application control
ITGC = environment-wide (access, change, operations, backup); Application control = within one system (input, processing, output)
Use this as your first split in any answer. Say which level each control works at.
Control purpose
Preventive = stop it; Detective = find it; Corrective = fix it
Label each control you recommend. Give a concrete example, not just the label.
Application control groups
Input → Processing → Output
Follows the flow of a transaction. Use it to structure a list of controls.
Dependency rule
Weak ITGCs reduce reliance on application controls
Application controls are only reliable if ITGCs stop them being changed or bypassed.
Common control objectives
Completeness, Accuracy, Validity (authorisation), Restricted access
Tie each control to one of these objectives to show purpose.

How to solve IT General and Application Controls questions

Use this method for any question on IT controls in a scenario. It keeps your answer structured and tied to the facts.

  1. 1Read the requirement. Decide if it asks you to identify weaknesses, recommend controls, explain concepts or evaluate adequacy.
  2. 2Scan the scenario and mark IT facts: shared passwords, unapproved changes, manual re-keying, no backups, remote working, new systems.
  3. 3Split the facts into environment-wide issues (ITGCs) and system-specific issues (application controls).
  4. 4For each issue, state the risk it creates for this business, such as fraud, error, data loss or non-compliance.
  5. 5Recommend a control that fits the issue. Say if it is preventive, detective or corrective, and for application controls whether it is input, processing or output.
  6. 6Explain the benefit and any cost or limit, such as user resistance, expense or the need for staff training.
  7. 7Prioritise the most serious weaknesses first and finish with a short conclusion or recommendation in the format asked (report, memo, briefing).

Quickest way: Weakness – Risk – Control – Type

When to use it: Use when time is short or when the requirement asks for a list of weaknesses and recommendations. It works well for 8 to 12 mark requirements.

  1. Draw four columns on your plan: weakness, risk, control, type.
  2. Take each scenario fact and fill one row only, in a single line.
  3. Write the type as P, D or C, plus I, Pr or O if it is an application control.
  4. Turn each row into one or two sentences in your answer. Start with the weakness from the scenario.
  5. Check you have both ITGC and application examples if the question asks for both.

Common mistakes in IT General and Application Controls

  • Treating general controls and application controls as the same thing.

    Both are described as IT controls and the terms sound similar.

    Fix: Ask whether the control protects the whole environment or one system. Passwords for all users are general. A validation check on one input screen is application.

  • Listing textbook controls without linking them to the scenario.

    Students memorise lists and write them out to save thinking time.

    Fix: Open each point with a fact from the case and show the risk to this business. Generic lists earn little credit.

  • Labelling a control preventive, detective or corrective wrongly.

    Some controls look like more than one type, such as a reconciliation that also triggers correction.

    Fix: Judge by the main purpose. A reconciliation finds errors after the event, so it is detective. Restoring from backup is corrective. Say why in a few words.

  • Ignoring the link between ITGCs and application controls.

    Students treat each group as a separate list.

    Fix: Add a sentence that weak access or change controls undermine reliance on automated checks. This shows analysis and earns professional skills marks.

  • Recommending expensive or impractical controls with no judgement.

    Students assume more controls are always better.

    Fix: Comment on cost versus benefit and the size and risk of the business. A small firm may rely more on management review than on complex systems.

  • Writing only about technology and forgetting people and process.

    The topic feels technical, so staff behaviour is overlooked.

    Fix: Include training, segregation of duties, authorisation and review. Many weaknesses in cases come from people overriding or sharing access.

Worked examples

Example 1

Brightway Retail runs an online store and a separate payroll system. The scenario says: all IT staff can change live software without approval; the sales system accepts orders with blank delivery addresses; and payroll reports are emailed to a shared mailbox. Identify each weakness, say whether it is a general or application control issue, and recommend a control with its type.

Show the solution
  1. Weakness 1: unapproved changes to live software. This is an ITGC issue under change management. Risk: errors or fraud introduced into systems, and application controls could be altered.
  2. Control 1: a formal change process with request, authorisation, testing and approval before release, and separate developers from those who move code to live. This is preventive. A later review of change logs adds a detective layer.
  3. Weakness 2: orders accepted with blank delivery addresses. This is an application input control issue. Risk: failed deliveries, lost sales and customer complaints.
  4. Control 2: mandatory field and format validation that rejects incomplete orders. This is a preventive input control.
  5. Weakness 3: payroll reports sent to a shared mailbox. This is an application output control issue, with an access element. Risk: unauthorised people see confidential pay data.
  6. Control 3: restrict report distribution to named authorised users, using secure delivery or password protection. This is a preventive output control. Logging who accessed reports would be detective.

Answer: Weakness 1 is a general (change management) control failure; fix with authorised, tested changes and segregation of duties (preventive). Weakness 2 is an application input failure; fix with mandatory field validation (preventive). Weakness 3 is an application output failure; fix with restricted, secure report distribution (preventive), with access logs as a detective back-up.

Example 2

A manufacturer's inventory system recently posted a batch of goods received twice, overstating inventory. The finance director asks you to explain how preventive, detective and corrective controls could be applied to this type of error, and why general controls still matter.

Show the solution
  1. Preventive: the system checks each goods received note number against those already posted and rejects duplicates. Batch totals agreed before posting stop incomplete or repeated batches. These are input and processing controls.
  2. Detective: a regular reconciliation of inventory records to physical counts, and an exception report of unusually large or repeated receipts, would reveal the overstatement after posting.
  3. Corrective: once found, the duplicate is reversed through an authorised adjustment, the cause is investigated and the process is fixed. If data was corrupted, it can be restored from backup. Staff should be retrained if the cause was manual.
  4. General controls: access controls limit who can post or amend batches. Change management ensures the duplicate check is not removed or altered without approval. Backups support recovery. Without these, the application controls cannot be relied upon.
  5. Conclude: use a mix of types. Prevention reduces the number of errors, detection catches those that get through and correction limits the harm.

Answer: Preventive controls (duplicate checks, batch totals) stop double posting. Detective controls (stock reconciliations, exception reports) find it afterwards. Corrective controls (authorised reversal, root-cause fix, restore from backup) repair it. General controls over access, change and backup keep the application controls reliable, so all layers are needed.

Exam tips

  • Always state which level a control works at: general or application. The marker looks for that split.
  • Anchor every control to a fact in the scenario. Quote the weakness first, then give the fix.
  • Label controls as preventive, detective or corrective, and add input, processing or output where relevant, but keep the labels short so you have time for explanation.
  • Show professional skills: prioritise the biggest risks, comment on cost and practicality, and write in the format requested, such as a report to the audit committee.
  • Link IT controls to wider topics such as risk, internal audit and governance when the case allows. It shows commercial awareness.

Practice questions from IT systems security and control

IT General and Application Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

IT General and Application Controls: frequently asked questions

What is the difference between general controls and application controls?

General controls apply across the whole IT environment and cover access, change management, operations and backup. Application controls work inside a single system and check input, processing and output. Strong general controls make application controls reliable.

Can one control be both preventive and detective?

Some controls have both effects, but you should classify by main purpose. A password stops access, so it is preventive. A reconciliation finds errors after they happen, so it is detective. State your reasoning briefly.

How much IT detail does SBL expect?

SBL tests business judgement, not technical configuration. You need to know the types of control, give sensible examples and link them to risk in the scenario. You do not need to explain how the technology works.

Are input, processing and output controls general or application controls?

They are application controls because they operate within a specific system. General controls sit around them and protect the environment in which the applications run.