Skip to main content
Loyca
Service reference 25Audit & AssuranceACTIVE PRACTICE PROTOCOL

IT General Controls Assessment

The controls your financial auditor will ask about

ITGC review across access, change, operations, and development, sized for financial statement audit support.

PROTOCOL OVERVIEW

Executive Context & Technical Scope

Your external auditor relies on IT general controls to trust the numbers your systems produce. We assess those controls the way they will: logical access provisioning and review, change management, job scheduling and monitoring, and program development. Findings are documented to a standard your auditor can rely on.

TARGET PROFILES

Who Requires This Protocol

Finance teams supporting a statutory audit
Organisations whose auditor raised ITGC deficiencies
Companies preparing for a first-time external audit

ENGAGEMENT ARTIFACTS

Verifiable Outputs & Deliverables

ITGC matrix across four control domains

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Test-of-design and test-of-effectiveness results

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Deficiency register with severity classification

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Remediation plan aligned to the audit calendar

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

PRACTITIONER FAQ

Frequently Asked Scoping Questions

When should this happen relative to our audit?
Ideally one quarter before fieldwork, so deficiencies can be remediated and the remediation itself can be tested.
Which systems are in scope?
Anything that feeds the financial statements — ERP, payroll, banking interfaces, and the infrastructure beneath them.
PRACTICE CONTINUUM

INTELLIGENCE WITHOUT LIMITS

Scope IT General Controls Assessment for your organization.

Get a fixed-scope proposal, verifiable deliverables list, and exact timeline for it general controls assessment.

Direct Hotline:+254 740 658 068
NO-OBLIGATION GUARANTEE

What to expect in your scoping call

  • Direct Senior Lead

    You talk to a seasoned cybersecurity consultant, never a sales script.

  • Strict Confidentiality

    We operate under mutual NDA before discussing sensitive architecture.

  • Actionable Next Steps

    Immediate priorities and costed options, whether you engage us or not.

Message Loyca on WhatsApp