Finance Index

What are IT general controls (ITGC) vs business process controls in AP?

Reference guide to itgc vs Business process controls AP, including control design, audit evidence, risk points, finance procedures, and compliance review.

Business process controls are the AP-specific controls over transactions - invoice approval, matching, reconciliation. IT general controls (ITGCs) are the controls over the systems those rely on: who can access the AP system, how changes to it are managed, and how it's operated and backed up. ITGCs matter because an automated AP control is only as trustworthy as the system running it - if anyone can change the matching rules or grant themselves approval rights, the business process control can't be relied on.

At a Glance

Aspect Short Answer Why It Matters
IT general controls (ITGC) vs Business process controls are the AP-specific controls over transactions - invoice approval, matching, reconciliation. Keeps evidence clear and reduces control risk.
Control point Dependency. Keeps evidence clear and reduces control risk.
ITGCs matter for an AP Four domains. Helps finance decide what to do next.
Workflow It's the control ensuring workflow and routing changes are authorized, reviewed, and recorded rather than made ad hoc. Keeps evidence clear and reduces control risk.
Our cloud AP vendor's Both. Keeps evidence clear and reduces control risk.

Why do ITGC failures contaminate automated AP controls?

Dependency. When auditors rely on an automated control - say, system-enforced authority limits - they're implicitly trusting that no one altered the configuration and no unauthorized user gained the rights to bypass it. That trust comes from ITGCs: logical access controls and change management. If change management is broken (anyone can edit the approval rules without review) or access is loose (developers or admins have unchecked production access), the auditor can no longer assume the automated control operated as designed all period - so the ITGC failure "contaminates" reliance on every automated control that depends on it, often forcing a fallback to heavier manual testing.

Which ITGCs matter for an AP automation system?

Four domains. Logical access - who can log in and what they can do, including admin and configuration rights. Change management - how changes to workflows, rules, and integrations are requested, approved, tested, and recorded. Operations - job scheduling, interface monitoring, and error handling for the ERP sync. And backup/recovery for the data. For a cloud AP platform, much of this is covered by the vendor's SOC 1, but the customer-side pieces - your access provisioning, your configuration change approvals, your monitoring of the sync - remain yours to control and evidence.

What is change management control for approval workflow rules - who can change routing and how is it tested?

It's the control ensuring workflow and routing changes are authorized, reviewed, and recorded rather than made ad hoc. Auditors test it by sampling configuration changes and checking each had approval and a record. The remediation when admins can change rules without a ticket is to introduce a request-and-approval step and log every change.

Does our cloud AP vendor's SOC 1 cover the ITGCs, or do we still have controls to perform ourselves (CUECs)?

Both. The SOC 1 covers the ITGCs the vendor operates (their access, change, and operations controls), but it lists complementary user entity controls - things you must do, like provisioning users appropriately, reviewing access, and approving your own configuration changes. Reliance on the vendor's controls is only valid if your CUECs operate.

What are complementary user entity controls (CUECs) and how do I map ours for the AP system?

CUECs are the controls the SOC report assumes you perform so the vendor's controls work as intended. Map them by reading the CUEC section of the vendor's SOC 1 and assigning each to an owner on your side - typically user provisioning and deprovisioning, periodic access reviews, configuration-change approval, and reconciliation of the data flowing between systems.

Auditors flagged that workflow admins can change approval rules without a ticket - how do we remediate?

Introduce change governance: require a documented request and independent approval before workflow or routing changes, restrict edit rights to named admins, and ensure every change is logged with who and when. Then evidence a period of operation. The underlying capability you need is an immutable record of configuration changes so the control is testable.

How do I test interface/integration controls between the AP tool and the ERP?

Test completeness and accuracy of the sync: confirm every approved invoice that should post does, in the right amount and coding, with no silent failures. Reconcile counts and totals between systems, review the export-error queue and its resolution, and confirm exceptions surface to a human rather than dropping.

What is a system-generated report reliability test (ipe) and which AP reports need it?

IPE testing verifies that a report your systems produce - and that controls or auditors rely on - is complete and accurate. AP reports needing it include the aging, approval listings used as control evidence, user access reports, and any population extract auditors run analytics on. Testers verify the report's parameters, logic, and completeness before trusting its contents.

Stampli perspective

Stampli supports the customer-side ITGCs SOX programs test: role-based access control with no self-service escalation to administrator or sensitive roles, SSO and MFA through the organization's identity provider, and immutable activity history so configuration and user changes leave a record. Bi-directional, real-time ERP sync with pre-validation before posting addresses the interface-completeness concern, surfacing export errors rather than letting them post silently. For the controls Stampli operates on customers' behalf, its compliance posture supports SOX, SOC 2, and internal-control programs - and customers should map their complementary user entity controls (access reviews, configuration change approval) on top.