IT General Controls and the SaaS Era: Why Coverage Has Become the New Control Failure
CovaCtrl
4 min read
The traditional IT general controls framework — access management, change management, and system operations — was designed for centralised, on-premise environments where all significant systems were known, governed, and administered by IT. Most organisations no longer operate that way. The average enterprise now runs over a hundred SaaS applications, a significant proportion of which were never formally sanctioned by the IT function responsible for controlling them. The controls designed to protect the financial reporting environment were not built to cover a landscape that nobody has fully mapped.
What Are IT General Controls?
IT general controls, commonly abbreviated as ITGCs, are the technology-layer controls that underpin internal controls over financial reporting. They operate across four main areas: access management, governing who can reach which systems; change management, ensuring updates are authorised, tested, and tracked; computer operations, covering monitoring, backups, and incident response; and the governance environment that ties the three together.
ITGCs are not standalone compliance obligations. They are the foundation on which automated application controls — the controls embedded in ERP and financial systems — rest. If the underlying IT environment is not reliably governed, the application controls sitting on top of it cannot be depended upon.
Why Did ITGCs Work in Centralised Environments?
In an on-premise, centralised environment, the ITGC population was bounded and stable. IT owned the infrastructure, knew which systems processed financial data, and controlled what changes were made to them. User access could be reviewed across a defined set of systems. Change management applied to a single, trackable software estate.
Periodic testing was adequate because the environment changed slowly enough for point-in-time reviews to remain meaningful. Evidence existed in the right place, in a format auditors could reach without significant reconstruction.
What Changed When SaaS Became the Dominant Model?
The shift to SaaS disrupted all three assumptions. Individual departments can now procure and deploy applications without IT involvement. According to Zylo's 2026 SaaS Management Index, shadow IT — applications operating outside IT's awareness — accounts for 34 per cent of the average organisation's SaaS portfolio.
When a system is unknown to the control function, no access controls have been designed for it, no change management is applied to it, and no audit trail exists within it. It falls outside the control perimeter entirely, sometimes while processing data that carries direct financial reporting significance.
What Are the Three Classic Failure Points in SaaS-Heavy ITGC Programmes?
Recent ITGC benchmarking analysis identifies a consistent pattern: failures are no longer driven by poor control design, but by gaps in coverage, ownership, and enforcement in cloud and SaaS environments. Three failure modes appear repeatedly across audit cycles:
- Shadow IT — applications outside IT's awareness for which no controls have been designed, tested, or evidenced
- Access drift — user permissions accumulating beyond what roles require, with former employees retaining access across unmanaged applications weeks or months after departure
- Missing audit trails — incomplete logs and decentralised administration that make constructing a reliable evidence record difficult without significant manual effort
Deprovisioning failures are among the most frequently cited access control findings in ITGC audits. Many organisations automate offboarding through single-sign-on platforms or HR integrations — but those integrations only reach the systems IT knows about. Applications outside that perimeter are never touched by the offboarding process.
Why Does Scope Matter for Financial Reporting Assurance?
ITGCs exist to ensure that automated controls embedded in financial systems are operating in a trustworthy environment. An ITGC programme that comprehensively covers the known systems but misses a material portion of the environment does not provide assurance over the full financial reporting chain. It provides assurance over a selected subset of it.
How Is CovaCtrl Different?
CovaCtrl supports teams in maintaining a structured evidence base for control performance, making it straightforward to identify where controls are operating as designed, where evidence is incomplete, and where the scope of monitoring no longer matches the actual technology environment. For control teams managing ITGC-adjacent processes, continuous structured documentation reduces the gap between the control population an organisation believes it governs and the one auditors test against.
Why This Matters Now
Nearly 39 per cent of ITGC audits still surface control or evidence deficiencies, even in organisations with well-designed frameworks. The underlying cause is rarely a flawed control principle. It is a control principle designed for an environment that most organisations left behind some years ago.
Auditors following the amended PCAOB standards effective December 2026 will take a top-down, risk-based path through the same technology landscape that has produced those deficiencies. The organisations best prepared are those that have already matched their documented control scope to the systems that actually carry financial reporting risk.
The IT general control was not broken. It was aimed at the wrong address.

