Skip to content

Cost and Management Audit · Information Systems Security Audit

General IT Controls and Application Controls in IS Audit

Updated 11 October 2026 · Fact-checked

General IT controls (GITCs) are controls over the IT environment: access, operations, change management and development. They support every application. Application controls work inside one application and cover input, processing and output. To answer questions, name the level, the control type and the risk it addresses, then classify it as preventive, detective or corrective.

Understand General IT Controls and Application Controls

Start with a simple idea. A company runs its accounts, stores and payroll on software. Two things can go wrong. The computer environment can be unsafe, or a single program can handle data wrongly. Controls exist for both.

General IT controls protect the environment in which all applications run. They cover four areas:
- Access controls: who can log in and what they can do. Unique user IDs, strong passwords, role-based rights, periodic review of users and removal of leavers.
- Operations controls: day-to-day running of systems. Job scheduling, backups, monitoring of failed jobs, incident handling and recovery.
- Change management: how changes to programs, data and systems are requested, tested, approved and moved to live use. Developers should not move their own changes to production.
- Development (acquisition) controls: how new systems are built or bought. User requirements, design review, testing, user acceptance, data migration checks and documentation.

Application controls sit inside a specific application such as a stores or payroll module. They make sure transactions are valid, complete and accurate.
- Input controls: validate data entering the system. Examples: mandatory fields, range and format checks, duplicate checks, authorisation of source documents, batch totals and hash totals.
- Processing controls: ensure data is handled correctly. Examples: run-to-run totals, reasonableness checks, control account reconciliation, system calculations and sequence checks.
- Output controls: ensure results are complete and reach only the right people. Examples: reconciliation of output to input, review of exception reports, controlled distribution, report access rights.

The link between the two matters. If general controls are weak, you cannot rely on application controls, because anyone could change the program or the data. So an auditor tests general controls first. If they work, the auditor then tests application controls and can reduce substantive testing.

Controls can also be classified by purpose. Preventive controls stop errors before they occur (password, input validation). Detective controls find errors after they occur (exception report, reconciliation). Corrective controls fix errors and restore normal operation (backup restoration, re-entry of rejected items).

Key rules to remember

Two levels of IS controls
IS controls = General IT controls (environment) + Application controls (each application)
General controls apply to all applications. Application controls apply to one application or process.
General IT control areas
Access + Operations + Change management + Development/acquisition
Use these four headings to structure any answer on general controls.
Application control areas
Input + Processing + Output
Add master data and interface controls if the question asks for more.
Classification by purpose
Preventive (before) | Detective (during or after) | Corrective (fix and recover)
Classify by what the control does, not by where it sits.
Reliance sequence
Test general controls → if effective, test application controls → reduce substantive work
Weak general controls undermine reliance on application controls.

How to solve General IT Controls and Application Controls questions

Use this method for any question that asks you to explain, classify, distinguish or evaluate IT controls.

  1. 1Read the question and decide the level: general control, application control, or both.
  2. 2Name the category: access, operations, change management or development for general; input, processing or output for application.
  3. 3State the risk the control addresses, such as unauthorised access, unapproved change, duplicate entry or incomplete output.
  4. 4Describe the control in practical terms with one or two specific examples from the case.
  5. 5Classify it as preventive, detective or corrective, with a one-line reason.
  6. 6If asked to evaluate, say what happens to reliance: weak general controls mean application controls cannot be trusted.
  7. 7Close with the audit action: inspect user lists, test change approvals, re-perform validation, or reconcile output.
  8. 8Give a clear recommendation if the case shows a gap.

Quickest way: Level, category, risk, type

When to use it: Use this for 2-mark MCQs and short case-based questions where you have under two minutes.

  1. Ask: does the control protect the whole environment or one transaction flow? Whole environment is general; one flow is application.
  2. Match the keyword: user ID, password, backup, change approval, testing means general. Validation, batch total, reconciliation, report means application.
  3. Ask when it acts: before the error means preventive; after it means detective; fixes or restores means corrective.
  4. Eliminate options that mix up levels, such as calling a password policy an input control.

Common mistakes in General IT Controls and Application Controls

  • Calling access controls an application control in every case.

    Applications also have user rights, so students assume the control is application-level.

    Fix: Treat logical access to systems, databases and networks as general. Menu-level rights inside one module can be application-specific, so read the context.

  • Confusing change management with development controls.

    Both involve programs and testing.

    Fix: Development is building or buying a new system. Change management is modifying a system already in use.

  • Treating a batch total as a processing control.

    Totals are checked during processing, so it seems to fit.

    Fix: A batch total set at data entry to check completeness of input is an input control. Run-to-run totals between processing stages are processing controls.

  • Classifying every control as preventive.

    Students link controls with stopping errors.

    Fix: Ask when the control acts. Reconciliations and exception reports are detective. Backup restoration is corrective.

  • Ignoring the dependence of application controls on general controls.

    The two are learned as separate lists.

    Fix: State that effective application controls cannot be relied on unless general controls over access and change are effective.

  • Giving a list of controls without linking them to a risk or the case facts.

    Students memorise lists instead of applying them.

    Fix: For each control, write the risk it addresses and tie it to the company in the question.

Worked examples

Example 1

Sundaram Auto Components Ltd runs its payroll on in-house software. A programmer recently changed the overtime calculation and moved it to live use without any approval or testing. Identify the control area that failed, state the risk, and suggest controls.

Show the solution
  1. Level: the failure is in the IT environment, not in one transaction, so it is a general IT control.
  2. Category: modification of a system already in use, so it is change management.
  3. Risk: unauthorised or untested changes may cause wrong overtime payments or fraud. The programmer also had the ability to move code to production.
  4. Controls: require a written change request, approval by the payroll head, testing in a separate test environment, user sign-off, and movement to live use by someone other than the developer.
  5. Classification: change approval and segregation of duties are preventive. A post-implementation review and a comparison of overtime before and after the change are detective.
  6. Audit effect: weak change management reduces reliance on payroll application controls, so the auditor should increase substantive testing of overtime.

Answer: The failed area is general IT control over change management. The risk is unauthorised, untested changes to payroll logic. Introduce approval, testing, user sign-off and segregation between developer and production movement. Until fixed, the auditor should not rely on payroll application controls and should extend substantive testing.

Example 2

In a stores application of Bharat Steels Ltd, the system rejects a goods receipt if the quantity field is blank or negative, flags a purchase order number already used, and prints a daily list of receipts above ₹10,00,000 for the stores manager. Classify each control by type (input, processing or output) and as preventive or detective.

Show the solution
  1. Blank or negative quantity rejection: it checks data as it enters, so it is an input control (field and range check). It acts before the record is accepted, so it is preventive.
  2. Duplicate purchase order number flag: it checks data at entry, so it is an input control (duplicate check). It stops duplicate posting, so it is preventive.
  3. Daily list of receipts above ₹10,00,000: it is a report produced after processing, so it is an output control (exception report). It lets the manager find unusual items after posting, so it is detective.
  4. Link to general controls: all three depend on the program staying unchanged, so the auditor should confirm change management and access to the validation settings are effective.

Answer: Blank or negative quantity check: input, preventive. Duplicate PO check: input, preventive. Daily exception report of large receipts: output, detective. Reliance on these requires effective general controls over change and access.

Exam tips

  • For case-based MCQs, decide the level first. Most wrong options mix general and application controls.
  • In descriptive answers, use headings access, operations, change management, development, then input, processing, output. This makes marking easy.
  • Always add the preventive, detective or corrective label when the question mentions classification, and give a one-line reason.
  • Mention that application controls depend on general controls. This one sentence often separates a good answer from an average one.
  • Tie each example to the business in the case, such as payroll, stores or billing, instead of writing generic lists.

Practice questions from Information Systems Security Audit

General IT Controls and Application Controls in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

General IT Controls and Application Controls: frequently asked questions

What is the difference between general controls and application controls?

General controls cover the IT environment for all applications: access, operations, change management and development. Application controls work within a single application and cover input, processing and output. General controls support the reliability of application controls.

Are IT general controls tested before application controls?

Usually yes. The auditor first assesses whether general controls such as access and change management are effective. If they are, the auditor can rely on application controls and reduce substantive testing. If not, reliance is limited.

How do I classify a control as preventive, detective or corrective?

Ask when the control acts. If it stops an error before it happens, it is preventive. If it identifies an error after it happens, it is detective. If it fixes the error or restores operations, it is corrective.

Is a password policy a general control or an application control?

A password policy for network, system or database access is a general control under access controls. It is preventive. Rights set inside one application can be treated as application-level, so read the context in the question.