Skip to content

Advanced Auditing, Assurance and Professional Ethics · Digital Auditing & Assurance

Auditing in an IT Environment: Risks and Controls

Updated 5 October 2026 · Fact-checked

Auditing in an IT environment means understanding how the entity uses IT, identifying risks that arise from it, and testing the controls that address them. General IT controls (ITGCs) protect the systems; application controls protect individual transactions. Link each risk to a control, test it, then decide the audit response.

Understand Auditing in an IT Environment: Risks and Controls

Most entities now run on ERP, banking portals and automated interfaces. IT is not a separate audit. It is part of how the entity processes transactions, so it affects your risk assessment under SA 315 (Revised 2019). You must understand the IT environment, the IT applications, and the risks arising from the use of IT that could cause a material misstatement.

IT risks are things that can go wrong because of IT. Examples: unauthorised access to data, unauthorised changes to programs, wrong or incomplete data processing, loss of data, inappropriate access to master data, and failure to make needed program changes. Automation also has a benefit: a properly designed automated control works the same way every time, so it is not affected by human error or fatigue.

Controls over IT fall in two groups. General IT controls (ITGCs) are policies and procedures over the IT environment that support the effective working of the whole system. Typical areas: access security, program change management, program development/acquisition, IT operations (backup, job scheduling, incident management). Application controls are applied to individual transactions in an application. They cover input, processing and output, and ensure completeness, accuracy and validity. Examples: edit checks, mandatory fields, three-way match, automated calculation of depreciation, exception reports.

The two groups depend on each other. If ITGCs are weak, you cannot rely on application controls staying effective all year, because someone could have changed the program or the data. So the audit logic is: identify the relevant applications, identify risks from IT, identify the controls that address them (ITGCs and application controls), test design and implementation, then test operating effectiveness where you plan to rely on controls or where substantive procedures alone cannot give sufficient appropriate evidence.

Cybersecurity adds external threats such as hacking, ransomware, phishing and data theft. For the auditor, the concern is how such events could affect financial reporting: corrupted or lost records, fraud through compromised credentials, disruption of systems, and possible non-compliance with data protection requirements. You respond through understanding the entity's security controls, inquiring about incidents, and considering the impact on risk assessment, going concern and disclosures.

Key rules to remember

Core relationship
Reliable ITGCs → application controls can be relied on consistently → possible reduction in substantive testing
If ITGCs are ineffective, application controls cannot be assumed to operate consistently. Consider other evidence or more substantive work.
Categories of ITGCs
Access security + Program change management + Program development/acquisition + IT operations
Use this as a checklist when an answer asks you to list or evaluate general controls.
Categories of application controls
Input controls + Processing controls + Output controls (+ master data controls)
Each aims at completeness, accuracy and validity of transactions.
Risk assessment link
Understand IT environment → identify IT risks → identify related controls → assess RMM → design responses
This is the SA 315 flow for IT. Always tie a risk to an assertion and a response.
Testing automated controls
Test once (design and implementation) + test relevant ITGCs = evidence for the period
Applies when the control is truly automated and ITGCs over change and access are effective. Exceptions arise if the program has changed.

How to solve Auditing in an IT Environment: Risks and Controls questions

Use this method for any question on IT risks, controls or audit approach in a computerised environment. Always work from the facts in the case.

  1. 1Identify the IT elements in the scenario: applications, databases, interfaces, infrastructure, cloud or service providers.
  2. 2List the IT risks the facts show, such as unauthorised access, unapproved changes, data loss or interface failure. Link each to the assertion or account affected.
  3. 3Classify each control mentioned or missing as a general control or an application control. Name the ITGC area or the input, processing or output type.
  4. 4Assess the effect on risk of material misstatement under SA 315. State whether control deficiencies raise the risk.
  5. 5Decide the response: test design and implementation, test operating effectiveness, use data analytics or CAATs, or do more substantive procedures if controls are not reliable.
  6. 6Consider cybersecurity, service organisations and going concern or disclosure impact where the facts suggest them.
  7. 7Conclude: state the effect on the audit approach and, where relevant, communication of deficiencies to those charged with governance under SA 265.

Quickest way: Risk – Control – Test – Response

When to use it: Use this for short written answers and case MCQs when time is tight.

  1. Write the risk in one line (what can go wrong).
  2. Name the control type: ITGC (access, change, operations, development) or application (input, processing, output).
  3. State the test: inquiry, observation, inspection, re-performance, or a CAAT.
  4. State the effect: rely on control, or increase substantive work.
  5. Check the question verb. For 'differentiate', give two or three contrast points. For 'discuss', add the audit response.

Common mistakes in Auditing in an IT Environment: Risks and Controls

  • Treating general controls and application controls as the same thing.

    Both are 'IT controls' and examples overlap in students' minds.

    Fix: Ask: does the control protect the whole IT environment (general) or one transaction type inside one application (application)? Access to the server is general. A mandatory field on an invoice screen is application.

  • Relying on an automated control after testing it once, without looking at ITGCs.

    Students remember that automated controls are consistent.

    Fix: State that consistency holds only if the program is not changed and access is controlled. Test change management and access controls, or retest.

  • Writing generic cybersecurity points with no link to financial statements.

    Cyber is treated as an IT topic and not an audit topic.

    Fix: Tie each point to the audit: effect on records, fraud risk, going concern, disclosures, legal non-compliance, and impact on risk assessment.

  • Saying the auditor must test every IT control.

    Students overlook that SA 315 requires identifying only relevant controls.

    Fix: Focus on controls that address risks of material misstatement, and those where substantive procedures alone are not enough.

  • Ignoring the entity's size and complexity.

    Students write the same answer for every case.

    Fix: Scale your answer. A small entity on off-the-shelf software has fewer, simpler IT risks than a large entity with a customised ERP.

  • Stopping at identifying the deficiency without stating the audit response.

    Answers end at the problem.

    Fix: Always add what you will do: change the approach, add substantive procedures, communicate the deficiency.

Worked examples

Example 1

Case: Nova Retail Ltd uses an ERP for sales and inventory. During the year the IT head gave a developer direct access to the live production environment to correct an invoicing bug. No change request or approval was recorded. The ERP automatically blocks invoices where the price differs from the price master. You plan to rely on this automated control. How will you respond?

Show the solution
  1. Risk: unapproved change in the live program could alter or disable the price check, so invoices may be priced wrongly. This affects the accuracy and occurrence of revenue.
  2. Classification: the price check is an application control (processing). The missing approval and uncontrolled developer access are deficiencies in general controls (program change management and access security).
  3. Effect: ITGC deficiency means you cannot assume the application control worked consistently through the year. The risk of material misstatement for revenue is higher.
  4. Response: obtain details of the change and confirm what was altered. Test the price check again after the change, for example by re-performing it with test data. Check the period before and after the change separately.
  5. If you cannot get assurance over the period, do more substantive work: analytical review of selling prices, tests of invoices against the price master, and use of data analytics on the full invoice population.
  6. Communicate the change management and access deficiency to those charged with governance under SA 265.

Answer: Do not rely on the automated price check for the whole year. Retest it after the change, extend substantive procedures on revenue, and report the ITGC deficiency in writing to those charged with governance.

Example 2

Case: Kavya Pharma Ltd was hit by ransomware three weeks before year end. Servers were down for six days. Staff recorded sales and stock movements manually on paper and entered them in the system later. Management says all data was restored from backups. Discuss the audit implications.

Show the solution
  1. Risk to records: data may be incomplete, duplicated or entered late or wrongly after manual capture. Cut-off and completeness of sales and inventory are most exposed.
  2. Control impact: the incident shows weaknesses or a test of IT operations controls (backup and recovery) and security controls. Manual processing in the gap period bypasses the normal application controls.
  3. Fraud and integrity: compromised systems may allow unauthorised changes. Consider whether data was altered and whether logs are reliable.
  4. Procedures: inquire about the incident and the response. Inspect incident reports and the restoration records. Reconcile manual records to the system for the six days. Test cut-off around year end, and attend or review the stock count with attention to movements in the outage period.
  5. Other effects: consider going concern if operations or customers were hit, any ransom payment and its accounting and legal aspects, and disclosure of the event. Obtain written representations on the incident.
  6. Reporting: assess whether the control deficiencies are significant and communicate them under SA 265. Consider the effect on the auditor's report if you cannot get sufficient appropriate evidence.

Answer: Treat the incident as a significant risk to completeness, cut-off and data integrity. Reconcile the manual period, extend cut-off and stock testing, review backups and security controls, consider going concern and disclosure, and communicate deficiencies. If evidence is insufficient, consider a modified opinion.

Exam tips

  • In case questions, name the control type (ITGC or application) before you explain. This earns the easy marks.
  • Always link an IT risk to an assertion or account, and finish with an audit response. Examiners reward the full chain.
  • For 'differentiate' questions, give points in a table-like pair: scope, example, who depends on whom. Keep each point to one line.
  • Cyber questions want the audit angle, not a technical lecture. Mention records, fraud, going concern, disclosure and legal compliance.
  • Mention SA 315 for risk assessment and SA 265 for communicating deficiencies, but do not quote paragraph numbers unless you are sure.

Practice questions from Digital Auditing & Assurance

Auditing in an IT Environment: Risks and Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Auditing in an IT Environment: Risks and Controls: frequently asked questions

What is the difference between general controls and application controls?

General controls apply across the IT environment and support all applications. They cover access, program changes, development and IT operations. Application controls work within one application on individual transactions, covering input, processing and output.

Can I rely on application controls if general controls are weak?

Not safely. Weak ITGCs mean programs or data could be changed without detection, so the application control may not work consistently. You would need other evidence or more substantive procedures.

How does SA 315 deal with IT?

SA 315 requires you to understand the entity's use of IT and identify risks arising from IT. You also identify the controls that address those risks, including ITGCs, and assess their effect on the risk of material misstatement.

What should an auditor do about cybersecurity risks?

Understand how the entity manages cyber threats, inquire about incidents, and assess the effect on financial reporting. Consider records integrity, fraud, going concern, disclosures and compliance, then adjust the audit response.