25 Jul
25Jul

As financial reporting becomes increasingly dependent on ERP systems, cloud platforms, automated calculations, system-generated reports, and digital interfaces, IT General Controls, or ITGCs, are no longer matters that can be delegated entirely to the IT department. The CFO and Audit Committee do not need to understand every technical configuration, but they must understand ITGCs sufficiently to assess whether financial information can be trusted, whether identified weaknesses could affect the financial statements, and whether management’s remediation plan is credible.


ITGCs are controls that support the reliable operation of information systems and the automated controls within them. They commonly cover user access, privileged access, program changes, system development, computer operations, interfaces, backups, incident management, and the monitoring of outsourced or cloud service providers. Their importance arises because many financial controls depend on systems operating consistently. The PCAOB notes that automated controls are generally expected to present lower risk when the relevant ITGCs are effective, while controls over program changes, access to programs, and computer operations may support continued reliance on automated controls.


The CFO should understand ITGCs at a level that connects technology with financial reporting. This means knowing which systems process significant transactions, which systems feed the general ledger, which reports are used in key management reviews, which calculations are automated, and where manual spreadsheets or interfaces bridge gaps between systems. The CFO does not need to know how to configure a server or write program code, but should be able to explain how a sales transaction, payment, journal entry, inventory movement, or consolidation adjustment flows from initiation to the financial statements.


The CFO should also understand the four main areas of ITGC risk. The first is access management: who can enter, approve, change, or delete financial information, and whether incompatible duties are appropriately separated. Particular attention should be given to system administrators, emergency access, terminated employees, shared accounts, and users who can both create and approve transactions.


The second area is change management. The CFO should know whether changes to ERP configurations, interfaces, reports, tax calculations, consolidation rules, and automated controls are authorised, tested, approved, and moved into production by appropriate personnel. A small configuration change can have a large financial effect when it is applied automatically to thousands of transactions.


The third area is computer operations. This includes whether scheduled processing jobs run completely, interfaces are monitored, failures are investigated, backups are performed, data can be restored, and incidents affecting financial systems are resolved promptly. The objective is not merely to keep systems online, but to ensure that transactions are processed completely, accurately, and in the correct accounting period.

The fourth area is governance over third-party and cloud systems. Moving an accounting system to the cloud does not transfer all control responsibility to the service provider. Management must understand which controls are performed by the provider, which remain the company’s responsibility, and whether reports from service auditors cover the relevant systems, periods, and control objectives. The company must also perform any complementary controls that the provider assumes its customers will operate.


The Audit Committee should generally operate at a higher governance level than the CFO. It does not need to review detailed access listings or individual test scripts. However, it should understand which financial processes depend heavily on technology, whether the company has identified its critical systems, whether ITGC weaknesses are isolated or systemic, and whether those weaknesses affect the external auditor’s ability to rely on automated controls and system-generated reports.


ISA 315 (Revised 2019) strengthened the auditor’s risk assessment requirements and supports a more robust understanding of the entity’s systems, internal controls, and risks of material misstatement. IT risks are therefore not evaluated as a separate technical exercise; they form part of understanding how transactions are initiated, authorised, processed, recorded, and reported.


The Audit Committee should expect management and the auditor to translate technical findings into business and financial reporting consequences. A report stating that “user access reviews were not completed” provides limited insight. A more useful explanation would identify which systems were affected, how many users had inappropriate access, whether privileged users could change transactions or system configurations, how long the weakness existed, whether compensating controls operated, and which financial statement accounts were exposed.

The CFO and Audit Committee should also understand that an ITGC deficiency does not automatically mean the financial statements are misstated. However, it may reduce confidence in automated controls, system-generated reports, or the integrity of data used by management. The external auditor may then need to perform additional substantive procedures, expand testing, use IT specialists, or reconsider whether audit evidence generated from the system is reliable. Under PCAOB standards, IT involvement is treated as an integral part of understanding transaction flows, identifying potential sources of misstatement, and selecting the controls to test.


Not every cybersecurity issue is an ITGC issue for financial reporting, and not every ITGC issue is a cybersecurity incident. Nevertheless, the two areas may overlap. For example, weak privileged-access controls may create both a cybersecurity risk and a risk that accounting records or system configurations can be altered without detection. The CFO and Audit Committee should therefore understand how financial reporting controls, cybersecurity, data privacy, business continuity, and technology governance connect, while avoiding the assumption that one review covers all objectives.


The Audit Committee should focus particularly on significant or recurring weaknesses, unresolved prior-year findings, excessive reliance on manual compensating controls, major system implementations, ERP migrations, acquisitions involving new systems, and situations in which management cannot produce reliable evidence that controls operated. A material weakness in internal control over financial reporting may exist even when no material misstatement has yet been identified, because the question is whether there is a reasonable possibility that a material misstatement would not be prevented or detected on a timely basis. PCAOB standards also require material weaknesses and significant deficiencies identified in an integrated audit to be communicated in writing to management and the Audit Committee.


Management’s remediation plan should go beyond resetting passwords or reminding employees to follow policy. A credible plan should identify the root cause, affected systems, accountable owner, interim controls, required resources, completion date, testing approach, and evidence needed to demonstrate that the revised control has operated effectively for a sufficient period. Where a weakness arises from system architecture, insufficient segregation of duties, or an outdated ERP environment, remediation may require investment and cannot always be completed through a procedural change alone.

The CFO should receive more detailed and frequent reporting than the Audit Committee. A useful CFO dashboard may include critical systems, control owners, testing status, exceptions, ageing of unresolved findings, privileged-access issues, overdue user reviews, failed system changes, interface incidents, remediation progress, and the potential effect on financial reporting. The Audit Committee should receive a more focused view covering major risks, trend information, management accountability, residual exposure, auditor concerns, and matters requiring additional resources or Board support.


COBIT distinguishes governance from management and provides a structured framework connecting technology objectives with enterprise goals, risk management, and resource optimisation. This distinction is useful in defining responsibilities: management designs and operates IT controls, while the Board and Audit Committee evaluate whether the governance arrangements, risk responses, and accountability mechanisms are appropriate.


In summary, the CFO should understand ITGCs deeply enough to own the financial reporting risk, challenge system and process owners, evaluate control deficiencies, and fund remediation. The Audit Committee should understand them deeply enough to oversee whether critical technology risks are identified, whether significant weaknesses are properly assessed, whether management is responding with sufficient urgency, and whether the external auditor can rely on the company’s systems. Neither group needs to become an IT engineer, but both must be able to ask informed questions and recognise when a technical weakness has become a financial reporting and governance issue.

CFO และ Audit Committee ควรเข้าใจ ITGC ในระดับใด?


เมื่อการจัดทำงบการเงินพึ่งพาระบบ ERP ระบบคลาวด์ การคำนวณอัตโนมัติ รายงานที่สร้างจากระบบ และการเชื่อมต่อข้อมูลระหว่างระบบมากขึ้น การควบคุมทั่วไปด้านเทคโนโลยีสารสนเทศ หรือ ITGC จึงไม่ใช่เรื่องที่สามารถมอบให้ฝ่ายเทคโนโลยีสารสนเทศรับผิดชอบเพียงฝ่ายเดียว CFO และคณะกรรมการตรวจสอบไม่จำเป็นต้องเข้าใจการตั้งค่าทางเทคนิคทุกขั้นตอน แต่ต้องเข้าใจ ITGC มากพอที่จะประเมินได้ว่าข้อมูลทางการเงินน่าเชื่อถือหรือไม่ ข้อบกพร่องที่พบอาจกระทบงบการเงินอย่างไร และแผนแก้ไขของฝ่ายบริหารมีความเหมาะสมเพียงใด


ITGC คือการควบคุมที่สนับสนุนให้ระบบสารสนเทศและการควบคุมอัตโนมัติภายในระบบทำงานอย่างน่าเชื่อถือ โดยทั่วไปครอบคลุมการให้และยกเลิกสิทธิผู้ใช้งาน สิทธิของผู้ดูแลระบบ การเปลี่ยนแปลงโปรแกรมและการตั้งค่าระบบ การพัฒนาระบบ การประมวลผลประจำวัน การเชื่อมต่อข้อมูล การสำรองและกู้คืนข้อมูล การจัดการเหตุขัดข้อง และการกำกับดูแลผู้ให้บริการภายนอกหรือระบบคลาวด์ ความสำคัญของ ITGC เกิดจากการที่การควบคุมทางการเงินจำนวนมากทำงานผ่านระบบ หาก ITGC มีประสิทธิผล ผู้สอบบัญชีอาจมีความเชื่อมั่นต่อการทำงานอย่างสม่ำเสมอของการควบคุมอัตโนมัติได้มากขึ้น


CFO ควรเข้าใจ ITGC ในระดับที่สามารถเชื่อมโยงเทคโนโลยีกับการรายงานทางการเงินได้ กล่าวคือ ต้องทราบว่าระบบใดประมวลผลรายการที่สำคัญ ระบบใดส่งข้อมูลเข้าสู่บัญชีแยกประเภท รายงานใดถูกใช้ในการสอบทานของผู้บริหาร การคำนวณใดทำโดยอัตโนมัติ และจุดใดต้องใช้ตารางคำนวณหรือการเชื่อมต่อข้อมูลมาทดแทนข้อจำกัดของระบบ CFO ไม่จำเป็นต้องตั้งค่าเครื่องแม่ข่ายหรือเขียนโปรแกรมได้ แต่ควรอธิบายเส้นทางของรายการขาย การจ่ายเงิน รายการบัญชี สินค้าคงเหลือ หรือรายการปรับปรุงงบการเงินรวม ตั้งแต่จุดเริ่มต้นจนถึงงบการเงินได้


CFO ควรเข้าใจความเสี่ยงของ ITGC อย่างน้อยสี่ด้าน ด้านแรกคือการบริหารสิทธิผู้ใช้งาน ต้องทราบว่าใครสามารถบันทึก อนุมัติ แก้ไข หรือลบข้อมูลทางการเงิน และมีการแบ่งแยกหน้าที่ที่ขัดแย้งกันอย่างเหมาะสมหรือไม่ ประเด็นที่ต้องให้ความสำคัญเป็นพิเศษ ได้แก่ สิทธิของผู้ดูแลระบบ สิทธิฉุกเฉิน พนักงานที่ลาออกแต่ยังมีสิทธิใช้งาน บัญชีผู้ใช้ร่วมกัน และผู้ที่สามารถทั้งสร้างและอนุมัติรายการเดียวกัน


ด้านที่สองคือการเปลี่ยนแปลงระบบ CFO ควรเข้าใจว่าการเปลี่ยนแปลงโปรแกรม การตั้งค่าระบบ ERP รายงาน การเชื่อมต่อข้อมูล การคำนวณภาษี กฎการรวมงบ และการควบคุมอัตโนมัติ ได้รับอนุมัติ ทดสอบ สอบทาน และนำขึ้นใช้งานโดยบุคคลที่เหมาะสมหรือไม่ การเปลี่ยนแปลงเพียงเล็กน้อยอาจสร้างผลกระทบทางการเงินจำนวนมาก หากระบบนำการตั้งค่านั้นไปใช้กับรายการหลายพันรายการโดยอัตโนมัติ


ด้านที่สามคือการปฏิบัติงานของระบบ เช่น งานประมวลผลตามตารางทำงานครบถ้วนหรือไม่ การเชื่อมต่อข้อมูลได้รับการติดตามหรือไม่ รายการที่ประมวลผลล้มเหลวได้รับการสอบสวนหรือไม่ มีการสำรองและกู้คืนข้อมูลได้จริงหรือไม่ และเหตุขัดข้องของระบบการเงินได้รับการแก้ไขอย่างทันท่วงทีหรือไม่ เป้าหมายไม่ใช่เพียงให้ระบบเปิดใช้งานได้ แต่ต้องทำให้มั่นใจว่ารายการถูกประมวลผลครบถ้วน ถูกต้อง และอยู่ในงวดบัญชีที่เหมาะสม


ด้านที่สี่คือการกำกับดูแลผู้ให้บริการภายนอกและระบบคลาวด์ การย้ายระบบบัญชีขึ้นคลาวด์ไม่ได้หมายความว่าความรับผิดชอบด้านการควบคุมทั้งหมดถูกโอนไปให้ผู้ให้บริการ ฝ่ายบริหารต้องเข้าใจว่าการควบคุมใดเป็นหน้าที่ของผู้ให้บริการ การควบคุมใดยังคงเป็นหน้าที่ของบริษัท และรายงานของผู้สอบบัญชีของผู้ให้บริการครอบคลุมระบบ ช่วงเวลา และวัตถุประสงค์ของการควบคุมที่บริษัทต้องใช้หรือไม่ บริษัทยังต้องปฏิบัติตามการควบคุมของผู้ใช้บริการที่ผู้ให้บริการกำหนดเป็นเงื่อนไขด้วย


คณะกรรมการตรวจสอบควรเข้าใจ ITGC ในระดับการกำกับดูแล ซึ่งสูงกว่ารายละเอียดการปฏิบัติงาน คณะกรรมการไม่จำเป็นต้องตรวจรายชื่อผู้ใช้งานหรือเอกสารทดสอบแต่ละรายการ แต่ควรทราบว่ากระบวนการทางการเงินใดพึ่งพาระบบอย่างมาก บริษัทระบุระบบที่มีความสำคัญครบถ้วนหรือไม่ ข้อบกพร่องที่พบเป็นเรื่องเฉพาะจุดหรือเป็นปัญหาทั่วทั้งองค์กร และปัญหาดังกล่าวกระทบความสามารถของผู้สอบบัญชีในการเชื่อถือการควบคุมอัตโนมัติและรายงานจากระบบหรือไม่


มาตรฐานการสอบบัญชี ISA 315 ฉบับปรับปรุงให้ความสำคัญมากขึ้นกับกระบวนการประเมินความเสี่ยง ระบบสารสนเทศ และการควบคุมภายใน ความเสี่ยงด้านเทคโนโลยีจึงไม่ควรถูกประเมินแยกออกเป็นเรื่องทางเทคนิค แต่เป็นส่วนหนึ่งของการทำความเข้าใจว่ารายการถูกเริ่มต้น อนุมัติ ประมวลผล บันทึก และนำเสนอในงบการเงินอย่างไร


คณะกรรมการตรวจสอบควรคาดหวังให้ฝ่ายบริหารและผู้สอบบัญชีแปลงข้อค้นพบทางเทคนิคให้เป็นผลกระทบทางธุรกิจและงบการเงิน การรายงานเพียงว่า “ไม่ได้สอบทานสิทธิผู้ใช้งาน” อาจยังไม่ทำให้เห็นภาพ ควรอธิบายเพิ่มเติมว่าระบบใดได้รับผลกระทบ มีผู้ใช้งานที่ไม่เหมาะสมจำนวนเท่าใด ผู้มีสิทธิระดับสูงสามารถแก้ไขรายการหรือการตั้งค่าระบบใดได้ ข้อบกพร่องเกิดมานานเพียงใด มีการควบคุมทดแทนหรือไม่ และบัญชีหรือรายการในงบการเงินใดอยู่ภายใต้ความเสี่ยง


ข้อบกพร่องของ ITGC ไม่ได้หมายความว่างบการเงินผิดพลาดโดยอัตโนมัติ แต่อาจทำให้ความเชื่อมั่นต่อการควบคุมอัตโนมัติ รายงานจากระบบ หรือความถูกต้องของข้อมูลลดลง ผู้สอบบัญชีอาจต้องเพิ่มการตรวจสอบเนื้อหาสาระ ขยายขนาดตัวอย่าง ใช้ผู้เชี่ยวชาญด้านเทคโนโลยี หรือพิจารณาใหม่ว่าหลักฐานที่สร้างจากระบบมีความน่าเชื่อถือเพียงใด มาตรฐาน PCAOB จึงถือว่าการทำความเข้าใจผลของเทคโนโลยีต่อเส้นทางรายการและการควบคุมเป็นส่วนหนึ่งของการประเมินความเสี่ยง ไม่ใช่งานที่แยกออกจากการตรวจสอบงบการเงิน


ความเสี่ยงด้านความมั่นคงปลอดภัยทางไซเบอร์และ ITGC มีส่วนที่เกี่ยวข้องกัน แต่ไม่ใช่เรื่องเดียวกันทุกประการ ตัวอย่างเช่น การควบคุมสิทธิผู้ดูแลระบบที่อ่อนแออาจสร้างทั้งความเสี่ยงจากการโจมตีทางไซเบอร์และความเสี่ยงที่ข้อมูลบัญชีหรือการตั้งค่าระบบถูกเปลี่ยนแปลงโดยไม่ถูกตรวจพบ CFO และคณะกรรมการตรวจสอบจึงควรมองความเชื่อมโยงระหว่างการรายงานทางการเงิน ความปลอดภัยทางไซเบอร์ การคุ้มครองข้อมูล ความต่อเนื่องทางธุรกิจ และการกำกับดูแลเทคโนโลยี โดยไม่สรุปว่าการประเมินเรื่องหนึ่งสามารถทดแทนอีกเรื่องหนึ่งได้ทั้งหมด


คณะกรรมการตรวจสอบควรให้ความสำคัญเป็นพิเศษกับข้อบกพร่องที่มีนัยสำคัญหรือเกิดซ้ำ ประเด็นจากปีก่อนที่ยังไม่แก้ไข การพึ่งพาการควบคุมทดแทนแบบใช้มือมากเกินไป การติดตั้ง ERP ใหม่ การย้ายระบบ การซื้อกิจการที่มีระบบแตกต่างกัน และกรณีที่ฝ่ายบริหารไม่สามารถแสดงหลักฐานว่าการควบคุมได้ปฏิบัติจริง ข้อบกพร่องที่มีสาระสำคัญอาจมีอยู่ได้แม้ยังไม่พบว่างบการเงินมีข้อผิดพลาดที่มีสาระสำคัญ เพราะประเด็นสำคัญคือมีความเป็นไปได้หรือไม่ที่ข้อผิดพลาดขนาดใหญ่จะไม่ถูกป้องกันหรือตรวจพบอย่างทันท่วงที มาตรฐาน PCAOB ยังกำหนดให้ผู้สอบบัญชีสื่อสารข้อบกพร่องที่มีสาระสำคัญและข้อบกพร่องที่มีนัยสำคัญต่อฝ่ายบริหารและคณะกรรมการตรวจสอบเป็นลายลักษณ์อักษร


แผนแก้ไขไม่ควรหยุดอยู่เพียงการเปลี่ยนรหัสผ่านหรือกำชับพนักงานให้ปฏิบัติตามนโยบาย แผนที่น่าเชื่อถือควรระบุสาเหตุราก ระบบที่ได้รับผลกระทบ ผู้รับผิดชอบ การควบคุมชั่วคราว ทรัพยากรที่ต้องใช้ วันที่คาดว่าจะแก้ไขเสร็จ วิธีทดสอบ และหลักฐานที่แสดงว่าการควบคุมใหม่ได้ทำงานอย่างมีประสิทธิผลเป็นระยะเวลาที่เพียงพอ หากข้อบกพร่องเกิดจากโครงสร้างระบบ การแบ่งแยกหน้าที่ไม่เพียงพอ หรือระบบ ERP ที่ล้าสมัย การแก้ไขอาจต้องใช้งบลงทุนและไม่สามารถแก้ด้วยการออกระเบียบเพิ่มเติมเพียงอย่างเดียว


CFO ควรได้รับรายงานที่ละเอียดและถี่กว่าคณะกรรมการตรวจสอบ รายงานสำหรับ CFO อาจแสดงระบบสำคัญ ผู้รับผิดชอบการควบคุม ผลการทดสอบ ข้อยกเว้น อายุของประเด็นที่ยังไม่ปิด ปัญหาสิทธิผู้ดูแลระบบ การสอบทานผู้ใช้งานที่ล่าช้า การเปลี่ยนแปลงระบบที่ผิดขั้นตอน เหตุขัดข้องของการเชื่อมต่อข้อมูล ความคืบหน้าในการแก้ไข และผลกระทบที่อาจมีต่อการรายงานทางการเงิน ส่วนคณะกรรมการตรวจสอบควรได้รับภาพรวมที่เน้นความเสี่ยงสำคัญ แนวโน้ม ความรับผิดชอบของฝ่ายบริหาร ความเสี่ยงคงเหลือ ข้อกังวลของผู้สอบบัญชี และเรื่องที่ต้องได้รับงบประมาณหรือการสนับสนุนจากคณะกรรมการ


กรอบ COBIT แยกบทบาทด้านการกำกับดูแลออกจากการบริหารจัดการ และเชื่อมโยงวัตถุประสงค์ด้านเทคโนโลยีกับเป้าหมายองค์กร การบริหารความเสี่ยง และการใช้ทรัพยากร บทบาทจึงควรถูกแบ่งให้ชัดเจนว่า ฝ่ายบริหารเป็นผู้จัดทำและปฏิบัติตามการควบคุม ขณะที่คณะกรรมการและคณะกรรมการตรวจสอบมีหน้าที่ประเมินว่าระบบกำกับดูแล การตอบสนองต่อความเสี่ยง และความรับผิดชอบมีความเหมาะสมหรือไม่


โดยสรุป CFO ควรเข้าใจ ITGC ลึกพอที่จะรับผิดชอบความเสี่ยงต่อการรายงานทางการเงิน ท้าทายเจ้าของระบบ ประเมินข้อบกพร่อง และจัดสรรทรัพยากรเพื่อแก้ไข ส่วนคณะกรรมการตรวจสอบควรเข้าใจลึกพอที่จะกำกับดูแลว่าความเสี่ยงของระบบสำคัญถูกระบุครบถ้วนหรือไม่ ข้อบกพร่องได้รับการประเมินอย่างเหมาะสมหรือไม่ ฝ่ายบริหารแก้ไขด้วยความเร่งด่วนเพียงพอหรือไม่ และผู้สอบบัญชีสามารถพึ่งพาระบบของบริษัทได้มากน้อยเพียงใด ทั้งสองฝ่ายไม่จำเป็นต้องเป็นวิศวกรระบบ แต่ต้องสามารถตั้งคำถามอย่างมีข้อมูลและมองออกว่าเมื่อใดปัญหาทางเทคนิคได้กลายเป็นความเสี่ยงต่องบการเงินและการกำกับดูแลแล้ว

External References

  • IAASB — ISA 315 (Revised 2019), Identifying and Assessing the Risks of Material Misstatement.
  • IAASB — 2025 Handbook of International Quality Management, Auditing, Review, Other Assurance, and Related Services Pronouncements.
  • PCAOB — AS 2201, An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements.
  • ISACA — COBIT 2019 Framework and Governance and Management Objectives.
Comments
* The email will not be published on the website.