CONTROLS

IT General Controls and the SaaS Era: Why Coverage Has Become the New Control Failure

C

CovaCtrl

4 min read

The traditional IT general controls framework — access management, change management, and system operations — was designed for centralised, on-premise environments where all significant systems were known, governed, and administered by IT. Most organisations no longer operate that way. The average enterprise now runs over a hundred SaaS applications, a significant proportion of which were never formally sanctioned by the IT function responsible for controlling them. The controls designed to protect the financial reporting environment were not built to cover a landscape that nobody has fully mapped.

What Are IT General Controls?

IT general controls, commonly abbreviated as ITGCs, are the technology-layer controls that underpin internal controls over financial reporting. They operate across four main areas: access management, governing who can reach which systems; change management, ensuring updates are authorised, tested, and tracked; computer operations, covering monitoring, backups, and incident response; and the governance environment that ties the three together.

ITGCs are not standalone compliance obligations. They are the foundation on which automated application controls — the controls embedded in ERP and financial systems — rest. If the underlying IT environment is not reliably governed, the application controls sitting on top of it cannot be depended upon.

Why Did ITGCs Work in Centralised Environments?

In an on-premise, centralised environment, the ITGC population was bounded and stable. IT owned the infrastructure, knew which systems processed financial data, and controlled what changes were made to them. User access could be reviewed across a defined set of systems. Change management applied to a single, trackable software estate.

Periodic testing was adequate because the environment changed slowly enough for point-in-time reviews to remain meaningful. Evidence existed in the right place, in a format auditors could reach without significant reconstruction.

What Changed When SaaS Became the Dominant Model?

The shift to SaaS disrupted all three assumptions. Individual departments can now procure and deploy applications without IT involvement. According to Zylo's 2026 SaaS Management Index, shadow IT — applications operating outside IT's awareness — accounts for 34 per cent of the average organisation's SaaS portfolio.

When a system is unknown to the control function, no access controls have been designed for it, no change management is applied to it, and no audit trail exists within it. It falls outside the control perimeter entirely, sometimes while processing data that carries direct financial reporting significance.

What Are the Three Classic Failure Points in SaaS-Heavy ITGC Programmes?

Recent ITGC benchmarking analysis identifies a consistent pattern: failures are no longer driven by poor control design, but by gaps in coverage, ownership, and enforcement in cloud and SaaS environments. Three failure modes appear repeatedly across audit cycles:

  • Shadow IT — applications outside IT's awareness for which no controls have been designed, tested, or evidenced
  • Access drift — user permissions accumulating beyond what roles require, with former employees retaining access across unmanaged applications weeks or months after departure
  • Missing audit trails — incomplete logs and decentralised administration that make constructing a reliable evidence record difficult without significant manual effort

Deprovisioning failures are among the most frequently cited access control findings in ITGC audits. Many organisations automate offboarding through single-sign-on platforms or HR integrations — but those integrations only reach the systems IT knows about. Applications outside that perimeter are never touched by the offboarding process.

Why Does Scope Matter for Financial Reporting Assurance?

Control area What breaks when SaaS applications fall outside scope
Access management Terminated users retain access; over-privileged accounts go undetected
Change management Vendor-initiated and configuration changes occur outside the formal process
Computer operations Monitoring and incident response cannot cover systems that are invisible
Audit trail Evidence cannot be produced for controls that were never applied

ITGCs exist to ensure that automated controls embedded in financial systems are operating in a trustworthy environment. An ITGC programme that comprehensively covers the known systems but misses a material portion of the environment does not provide assurance over the full financial reporting chain. It provides assurance over a selected subset of it.

How Is CovaCtrl Different?

CovaCtrl supports teams in maintaining a structured evidence base for control performance, making it straightforward to identify where controls are operating as designed, where evidence is incomplete, and where the scope of monitoring no longer matches the actual technology environment. For control teams managing ITGC-adjacent processes, continuous structured documentation reduces the gap between the control population an organisation believes it governs and the one auditors test against.

Why This Matters Now

Nearly 39 per cent of ITGC audits still surface control or evidence deficiencies, even in organisations with well-designed frameworks. The underlying cause is rarely a flawed control principle. It is a control principle designed for an environment that most organisations left behind some years ago.

Auditors following the amended PCAOB standards effective December 2026 will take a top-down, risk-based path through the same technology landscape that has produced those deficiencies. The organisations best prepared are those that have already matched their documented control scope to the systems that actually carry financial reporting risk.

The IT general control was not broken. It was aimed at the wrong address.

Related Articles

CONTROLS4 min read

The Remediation Gap: Why the Same Audit Findings Keep Coming Back

JUNE 26, 2026

CONTROLS4 min read

Outsourcing a Process Does Not Outsource the Control

JUNE 19, 2026

CONTROLS4 min read

Control Rationalization: Why Fewer Controls Often Means Better Assurance

JUNE 05, 2026

COMPLIANCE4 min read

ESG Reporting Has a Controls Problem: Why Sustainability Data Needs the Same Rigour as Financial Data

MAY 29, 2026

COMPLIANCE4 min read

SOX Under Two Watchdogs: What the SEC's New Enforcement Group and Revised PCAOB Standards Mean for Internal Controls

MAY 22, 2026

CONTROLS4 min read

When the Tool Becomes the Risk: Governing AI in Your Control Framework

MAY 18, 2026

RISK5 min read

Why Your GRC Platform Is Just a Documentation System in Disguise

APRIL 13, 2026

RISK4 min read

The Role of Dependencies in Operational Risk: Why One Weak Link Can Break the Chain

APRIL 9, 2026

RISK4 min read

Why Most Incidents Start Small and Go Unnoticed

APRIL 7, 2026

CONTROLS3 min read

What Makes an Internal Control Effective? Key Principles Explained

MARCH 24, 2026

RISK3 min read

The Danger of Periodic Monitoring: Why Risks Are Often Detected Too Late

MARCH 5, 2026

COMPLIANCE3 min read

Internal Control in the UK Corporate Governance Code: What Boards Need to Know

FEBRUARY 24, 2026

COMPLIANCE3 min read

Internal Control Maturity: How to Strengthen and Scale Your Control Framework

FEBRUARY 19, 2026

RISK4 min read

Why Traditional GRC Systems Are Outdated, And What Modern Risk Management Requires

FEBRUARY 13, 2026

RISK3 min read

Risk Management Without Spreadsheets: What Changes?

FEBRUARY 9, 2026

COMPLIANCE3 min read

5 Internal Controls Every Scaling Company Needs (and Why)

FEBRUARY 2, 2026

RISK3 min read

Operational Risks in Supply Chains: What They Are and How to Manage Them

JANUARY 29, 2026

COMPLIANCE4 min read

SOX Compliance Explained: What It Is, Why It Matters and Why It's Still Hard

JANUARY 20, 2026

RISK3 min read

Risk Appetite vs. Risk Tolerance: What's the Difference and Why It Matters

JANUARY 12, 2026

RISK2 min read

The Future of Risk Management: From Static Control to Living System

JANUARY 8, 2026

RISK3 min read

Making the Three Lines of Defence Work in Practice

DECEMBER 9, 2025

QUALITY4 min read

Quality Control in Modern Operations

NOVEMBER 20, 2025