Advanced

ITGC scoping and testing checklist (access/change/ops)

Generates an ITGC scoping approach and detailed testing checklist for access management, change management, and IT operations. Helpful for integrated audits and SOX compliance.

Create an ITGC scoping and testing checklist for {system_name}.

Inputs:
- System purpose and key reports feeding FS: {system_purpose_reports}
- Hosting model (cloud/on-prem): {hosting_model}
- Key interfaces: {interfaces}
- User roles and privileged access: {user_roles}
- Change management process: {change_process}
- Operations (backups, jobs, incident mgmt): {ops_process}

Output:
1) ITGC scope rationale (in-scope apps, key reports, key interfaces).
2) Testing checklist by domain: Access, Change, Operations—control objectives, evidence, sampling.
3) Common gaps and compensating controls.
4) Workpaper indexing suggestions.

Use SOX-friendly wording.

Related Prompts