ITGC audit services

We test the four IT general control domains behind your financial reporting: access, change management, program development, and computer operations. Findings are documented with evidence for your SOX 404(a) assessment.
Talk to an auditor
Definition

What is an ITGC audit?

IT general controls are the controls your financial reporting rests on. When access, change management, or computer operations controls fail, every application control and system-generated report above them becomes suspect. An ITGC audit tests those controls across the systems that feed financial reporting, from the ERP down to the databases and operating systems underneath, and documents findings for management's assessment under SOX Section 404(a). BD Emerson is not your external financial statement auditor and does not issue an opinion on internal control over financial reporting. We test the controls and report findings with evidence. Your team remediates, and we verify the corrective action closed the finding.

Four situations bring companies to an ITGC audit: public companies supporting their Section 404(a) assessment, pre-IPO companies building their first SOX year, subsidiaries of public parents responding to group audit requests, and companies whose external auditor found ITGC deficiencies last year and who want them independently retested before the next cycle.

The engagement produces a risk and control matrix for your ITGCs, test plans with sampling, workpapers with evidence references, findings with root cause and financial reporting exposure, and retest verification after management remediates. Fieldwork aligns to your fiscal year so testing covers the period your external auditor examines, and most companies pair interim testing during the year with an update through year-end. Companies that co-source internal audit with BD Emerson fold ITGC testing into that annual plan.

Service organizations that run financially relevant processes for their customers get asked for SOC 1 reports. BD Emerson performs SOC examinations through its CPA attest arm.

Services

What does an ITGC audit cover?

Access to programs and data
Program changes
Program development
Computer operations
Scoping from the financials
IPE and report testing

Access to programs and data

We test provisioning against documented approvals and deprovisioning against HR termination data, which is where the gaps usually sit. We also test privileged access restriction and monitoring, user access reviews for evidence they actually completed, authentication configuration, and segregation of duties in the ERP.

Program changes

We trace a sample of changes from ticket to production, checking that each carried approval and testing evidence and that the person who developed the change did not also migrate it. We test emergency changes for retroactive approval and confirm configuration changes are tracked.

Program development

For implementations and major upgrades, we test the SDLC controls: project and design approvals, data conversion and migration testing, and go-live sign-off. A new ERP that cut over without tested conversion is a finding waiting for year-end.

Computer operations

We test job scheduling and monitoring, follow-up on failed jobs, backup completion, and restoration testing for financially relevant systems. Incident and problem management gets tested for the same population, because an unresolved processing incident can mean unrecorded transactions.

Scoping from the financials

Scoping starts at the financial statement line items and maps each to the applications and reports behind it: the ERP, HRIS and payroll, billing, revenue recognition, and consolidation, plus the databases and operating systems underneath. We test the ITGCs at each layer, because a control that holds in the application and fails in the database still fails.

IPE and report testing

System-generated reports used in controls get tested for completeness and accuracy, the work auditors call IPE, or information produced by the entity. A reconciliation built on an incomplete report is a failed control no matter how carefully the reconciler works.

Our approach

How we test

01

Scope from the financial statements

Every in-scope system earns its place by feeding a line item or a key report. We map the applications, databases, and operating system layers to the financials before testing starts, so effort lands where misstatement risk actually lives.

02

Evidence over inquiry

A control that cannot show it operated gets treated as a control that did not operate. We test against the records your environment already retains: tickets, approvals, system configurations, access logs, and HR data.

03

Findings built for 404(a)

Each finding states the control, the condition we found, the root cause, its pervasiveness, and the financial reporting exposure. Classifying a deficiency as significant or material stays with management and its external auditor; we supply the evidence that call depends on.

04

Retest after remediation

We do not remediate findings, because testing your own fixes is not independence. When your team closes a finding, we retest the control and document whether the corrective action worked.

contact us

Schedule an ITGC audit

Talk to an auditor about the systems in scope, your fiscal calendar, and where interim and year-end testing should land.

Our Advantage

Why BD Emerson for ITGC audits

Independent by design

BD Emerson's audit practice operates separately from its consulting and technology businesses. The team that tests your controls has no build work to defend and no remediation project to sell.

ITGC testing is one engagement within our audit practice, which sells audit work and nothing else.

Testing at every layer

Our auditors test where controls actually enforce: in the application, in the database beneath it, and in the operating system beneath that. A clean application layer over an open database is still a finding.

Workpapers that stand up

Test plans, samples, and evidence references are documented so your external audit firm can evaluate the work under its own standards. The reliance decision is theirs; complete workpapers make it a faster one.

How We Work

How an ITGC audit runs

The engagement moves from scoping to verified remediation in ten steps, each producing evidence the next one builds on:
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What are IT general controls, and how do they differ from application controls?

Which systems are in scope for an ITGC audit?

Can our external auditor rely on your ITGC testing?

What happens when a control fails testing?

How long does an ITGC audit take, and what does it cost?

When should a pre-IPO company start ITGC testing?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners