Audit teams should verify that each control is tested at the layer it actually governs. That means infrastructure reviews for ITGC, application transaction testing for ITAC, and explicit evidence that segregation of duties, access restriction and recovery processes are functioning. If the same evidence is used to prove both layers, the assurance case is usually too weak.
How to Test ITGC and ITAC Without Blurring the Control Boundary
When both control types are in scope, the first audit task is to separate what each layer is actually supposed to prove. ITGCs support the reliability of the environment around the application, while ITACs show that the application itself processes transactions correctly. Audit work should therefore follow the control objective, not the convenience of the evidence set.
A strong audit design asks whether the test would still make sense if the other layer were removed. If not, the evidence is probably doing double duty and the assurance conclusion may be overstated.
What Evidence Belongs to Each Layer
ITGC testing should focus on infrastructure and platform controls such as access provisioning, change management, backup and recovery, job scheduling, logging, and operating effectiveness of key IT processes. ITAC testing should focus on application logic, configuration, transaction processing, input validation, approvals, calculations, and exception handling. The same control objective may relate to both layers, but the test method should remain distinct.
That distinction matters because one layer can look strong while the other fails. For example, a well-run infrastructure review does not prove that the application enforces transaction-level authorization, and transaction testing does not prove that privileged admin access is tightly governed.
Audit teams should also check whether segregation of duties is enforced in the right place. In ITGCs, that often means privileged access and change authority. In ITACs, it often means whether the application itself prevents incompatible functions, unauthorized overrides, or manual workarounds.
Where Assurance Breaks Down in Mixed-Scope Audits
Mixed-scope audits often fail when teams reuse the same sample to support both general controls and application controls. That usually weakens the conclusion because the evidence is answering only one question, not two. The problem is not just efficiency, it is scope drift: a control may operate properly at the infrastructure level while leaving transaction-level risk untouched.
Recovery and access restrictions deserve particular attention because they are often assumed rather than demonstrated. Audit teams should want evidence that backup, restore, restricted access, and emergency change paths work as designed, not just that policies exist. Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful for the broader governance pattern, while Privileged Access Management Guide and Authorisation Models Guide help frame how access and permission evidence should be separated from process evidence.
Risk and Threat Considerations
When ITGC and ITAC are both in scope, the main risk is false assurance: a control environment can appear complete even though the evidence only covers one layer well. That creates blind spots in segregation of duties, unauthorized access, transaction manipulation, and recovery readiness.
Failure mechanism: Teams accept one test artefact as proof for both the general-control and application-control layers, so gaps in access enforcement, transaction logic, or recovery execution remain untested.
Impact: The audit opinion may overstate control reliability, and undetected weaknesses can persist across financial reporting, operational processing, and incident recovery.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while SOC 2 (AICPA) defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | ITGC and ITAC both depend on limiting administrative and application access appropriately. |
| AU-6 — Audit Review, Analysis, and Reporting | Mixed-scope assurance depends on traceable evidence and reviewable logs for each control layer. | |
| CP-9 — System Backup | Recovery processes are explicitly part of the assurance boundary when testing ITGCs. | |
| Recommendation — Review access paths separately at infrastructure and application layers, and remove excess privilege. Verify that audit evidence and logs support each layer's operating effectiveness test. Test backup and restore evidence separately from application transaction testing. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | Access restriction is central to proving general controls around the environment and supporting systems. |
| CC7.2 — Detecting and Responding to Security Events | Monitoring and response evidence helps demonstrate that supporting controls are functioning as intended. | |
| Recommendation — Map access testing to the environment layer and retain evidence of enforced restrictions. Confirm that monitoring and response evidence supports the specific layer being tested. | ||
Practitioner Guidance
What to verify: Ask for separate test objectives, separate evidence trails, and separate conclusions for ITGC and ITAC. If the same screenshot, export, or walkthrough is being reused, require a clear explanation of which control objective it proves and which one it does not.
Decision rule: If the evidence only shows a control exists, treat it as design evidence, not operating evidence. If it only shows one environment or one transaction path, do not extend it to the wider control population without additional testing.
Practitioner takeaway: Good mixed-scope auditing is less about collecting more evidence and more about proving the right evidence against the right control layer.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org