2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Chapter 1: Systems & Data GovernanceLesson 1.3

1.3 COSO Principle 11 and IT General Controls (ITGC) Taxonomy

Master the integration of technology controls within the COSO Internal Control - Integrated Framework, focusing on Principle 11 and the four core ITGC domains: Access to Programs and Data, Change Management, Program Development, and Computer Operations.

🎯 Essential Technical Takeaways

  • COSO Principle 11 explicitly mandates that organizations select and develop general control activities over technology to support objectives.
  • ITGCs provide the foundational baseline that ensures automated business application controls can be relied upon.
  • The four ITGC domains are: (1) Access to Programs and Data; (2) Program Changes; (3) Program Development; and (4) Computer Operations.
  • If ITGCs fail (e.g., developers have unmonitored write access to production), automated application controls cannot be relied upon by auditors.

The 2013 COSO Internal Control - Integrated Framework establishes 17 principles across 5 components. Within the Control Activities component, Principle 11 states: 'The organization selects and develops general control activities over technology to support the achievement of objectives.' This principle serves as the authoritative basis for IT General Controls (ITGCs) in financial statement audits and SOC examinations.

ITGCs apply to all system components—infrastructure, operating systems, database management systems, networks, and applications. They form an overarching umbrella of security and governance across four primary domains: (1) Access to Programs and Data: ensuring only authorized users have access based on least privilege; (2) Program Changes: ensuring all code changes are authorized, tested, and approved prior to release; (3) Program Development: ensuring new systems are acquired or developed under structured SDLC controls; and (4) Computer Operations: ensuring batch jobs, backups, and environmental controls operate reliably.

In financial auditing, ITGCs are pervasive. If an auditor tests an automated three-way matching control in accounts payable, that automated control is only as reliable as the underlying ITGCs. If developers can bypass change control to modify application code, or if DBAs can alter general ledger tables via native SQL, the automated application control cannot be relied upon, forcing auditors to expand substantive testing significantly.

⚠️ CPA Evolution Exam Traps & Control Pitfalls

  • Confusing IT General Controls (entity/system-level) with Business Process Application Controls (transaction-level).
  • Assuming substantive testing of application controls is valid when underlying ITGCs are severely deficient.
  • Attributing technology general controls to COSO Principle 5 or 8 instead of Principle 11.

Interactive Knowledge Checkpoint

Knowledge Checkpoint • Section 1.3

An organization is evaluating the operating effectiveness of its internal control environment using the 2013 COSO Internal Control - Integrated Framework. The engagement team reviews how the company selects and develops general control activities over technology to support the achievement of financial reporting objectives. Which of the 17 COSO principles directly addresses this technology control requirement?