IT general controls audit services sit at an unusual intersection: the audience is often the financial audit team rather than the security team. If your ITGCs fail, your external auditor cannot rely on any system-generated figure, and the substantive testing that replaces that reliance is slow, expensive and unwelcome.
ITGCs are the foundational controls over the IT environment supporting financial reporting: who can access the systems and the data, how changes reach production, how the operations that keep them running are managed, and how the data is protected. Application controls sit on top and only work if these hold.
We test them the way an auditor does (sampling evidence, walking through transactions, checking that the control operated on the date it was supposed to) and report deficiencies with their impact on control reliance. The same testing supports SOC 2 and ISO 27001:2022 evidence, so it is rarely worth running these separately.