ISA 315 and IT Controls in External Audits

The Growing Need for ITGC Review and Why It Matters
IT is now at the heart of financial reporting. So naturally, it is also at the heart of the audit.
Most organisations rely on Enterprise Resource Planning (ERP) systems, cloud applications, automated processes, and system-generated reports to prepare their financial statements. If the underlying IT controls are weak, the information produced by these systems may not be reliable.

This is where ISA 315 becomes important.
The revised ISA 315 places greater emphasis on understanding an organisation's information systems, technology environment and internal controls when assessing the risk of material misstatement.
In a typical modern ERP, Information Technology General Controls (ITGCs) and IT Application Controls (ITACs) are the bedrock of financial reporting integrity and operational stability.

For auditors, this means IT can no longer be treated as a separate technical issue. For an external or internal audit, ITGCs and ITACs testing would be treated as one exercise. Understanding the IT environment and ITGCs would be first, identifying the applications and risks that matter to the audit would follow, and then assessing whether the relevant application controls can be relied upon.

What auditors look out for
  1. IT General Controls (ITGCs) - They are the foundation.
    They cover the broader IT environment—access, change management, IT operations, and resilience.
  2. IT Application Controls (ITACs) – They protect individual business processes
    They operate within specific applications such as ERP systems. They help ensure transactions are complete, accurate, valid and properly authorised.
Some of the key areas include:
  • User access – Who can access critical systems?
  • Change management – Who can change systems and configurations?
  • Privileged access – Who has administrator-level access?
  • Segregation of duties – Can one person perform conflicting activities?
  • System interfaces – Does data move completely and accurately between systems?
  • Data integrity – Can we rely on the data used in the audit?
  • Backups and Recovery – Can critical systems and data be recovered?
  • Automated controls and reports – Can we rely on system-generated information?

Why does this matter?
A weakness in IT controls can affect financial reporting, audit evidence, and the auditor's ability to rely on system-generated information.
The rule of thumb is; IT General Controls (ITGCs) provide the foundation for IT Application Controls (ITACs). If ITGCs are weak, auditors may not be able to place reliance on ITACs.
For example, if access to an ERP system is not properly controlled, users may be able to make unauthorised changes to transactions or financial data.
If system changes are not properly controlled, an automated financial process could produce incorrect results without management immediately knowing.

What does this mean for organisations?
An IT controls review should not be an exercise you only carry out for or during an audit.
A proactive review can help:
  • Identify control gaps early
  • Improve the reliability of financial systems
  • Strengthen audit evidence
  • Reduce audit findings
  • Avoid unnecessary audit delays
  • Improve overall governance

The bottom line
Strong IT controls support strong financial reporting.
As businesses become more digital and automated, understanding and managing IT risks is becoming an increasingly important part of the financial statement audit.
IT Control failures are not just an IT risk. They are financial reporting and business risk.

Ready to strengthen your IT controls?
As technology becomes more central to financial reporting, IT controls should be assessed before they become an audit issue.
A proactive ITGC and ITAC review can help identify weaknesses early, improve system reliability and support a smoother external audit.
Talk to BDO Ghana about assessing your IT controls and strengthening your audit readiness.