During a statutory audit of Liffey Tech Solutions Ltd — a Dublin-based software services company with €62m revenue, publicly listed on Euronext Dublin — the audit team discovers that administrative access to the client's cloud ERP is controlled by a single service account, shared across three managed service providers, whose password was last rotated 22 months ago. Forty-one staff members across two of those providers have unrestricted access to payroll, revenue and accounts payable data simultaneously. No IT audit had been performed in the prior year. IAASA's inspection team has previously cited inadequate general IT controls evaluation as the most common quality deficiency in Irish statutory audit files. The finding now threatens the team's ability to place any reliance on application controls over a €12.4m payroll charge.
General IT Controls (GITCs)
The policies, procedures and practices governing IT infrastructure that underpin the reliability of automated application controls. GITCs cover access management, change management, computer operations and business continuity/disaster recovery. Under ISA (Ireland) 315 (revised 2022) — adopted by IAASA from IAASB ISA 315 — auditors must evaluate GITCs when placing reliance on application controls embedded in client systems. A weak GITC environment means no automated control can be relied upon without compensating manual procedures, regardless of how robust the application-level design appears.
NCSC Ireland Cyber Baseline
The National Cyber Security Centre (NCSC) Ireland — part of the Department of the Environment, Climate and Communications — publishes cybersecurity guidance aligned with ENISA frameworks and the EU NIS2 Directive (transposed into Irish law by SI 322 of 2024). For auditors, the NCSC baseline covers five control categories: network security, secure configuration, user access control, malware protection and patch management. It provides a documented standard against which Irish entity control gaps can be benchmarked without commissioning a full penetration test.
Effective IT audit planning begins with an IT landscape map: which systems produce financially significant data, which interfaces transfer data between them, and where manual processes bridge the gaps. For Liffey Tech Solutions Ltd, the cloud ERP (Microsoft Dynamics 365 Business Central, hosted on Azure Ireland), the payroll system (Sage Micropay) and the revenue recognition module form an interdependent triangle — a change management or access failure in any one leg invalidates reliance on all application controls downstream.
| GITC domain | Key control to test | Finding at Liffey Tech |
|---|---|---|
| Access management | Role-based provisioning; no shared accounts; quarterly access re-certification | Single shared service account across 3 MSPs; 41 users with unrestricted ERP access; no re-certification in 22 months |
| Change management | All changes approved, tested in staging and documented before live migration | 4 emergency production changes in Q3 with no test evidence; 2 without approval sign-off |
| Computer operations | Automated job scheduling with exception alerting; batch job failure notification | Month-end close batch runs manually triggered; no failure alerting — 2 failed runs undetected for 72 hours |
| Business continuity / DR | Tested recovery time objective (RTO) < 4 hours for critical systems; off-site backup | DR plan exists but last tested in 2022; backups stored in same Azure region as primary |
The audit team issues a control-deficiency report to the audit committee identifying four high-severity GITC weaknesses. The remediation plan — approved within 15 days — includes: migrating all MSP access to Azure Active Directory with role-based access controls and Conditional Access policies; implementing a quarterly privileged-access review dashboard surfaced to the CFO; and scheduling an annual DR test with documented RTO evidence submitted to the audit committee. The audit opinion for the current year requires expanded substantive testing over payroll (full population vs. sample), but the clean opinion is expected to be restored in the following year after re-testing controls post-remediation.
⚠️Treating IT audit as disconnected from financial statement assertions
→ Map every GITC weakness to a specific financial assertion (existence, completeness, accuracy, cut-off). A shared admin account over Sage Micropay is not only an IT risk — it is a completeness and accuracy risk over every payroll journal processed through that system. IAASA inspection findings consistently flag this disconnect as the primary GITC evaluation deficiency in Irish audit files.
⚠️Relying on management self-assessment of control effectiveness
→ Walk-through and re-performance testing are required for every GITC upon which the team intends to place reliance. A policy stating that access reviews occur quarterly must be corroborated by sign-off records, access logs or re-certification screenshots — not management representation alone.
⚠️Overlooking SaaS and cloud environments used by Irish SMEs
→ Many Irish mid-market entities run core financials on cloud platforms (Surf Accounts, Sage Business Cloud, Xero). Obtain and review the vendor's SOC 2 Type II report or ISAE 3402 assurance report — do not assume cloud hosting equates to a sound control environment. Where no report is available, perform compensating procedures.