•  
  •  
 

Abstract

Digital transformation has increased organizational reliance on the Digital Accounting Information System (DAIS) to support financial reporting, making the effectiveness of Information Technology General Controls (ITGC) a critical factor in maintaining system reliability and supporting Internal Control over Financial Reporting (ICoFR). This study aims to evaluate the implementation of ITGC and explain its implications for the reliability of DAIS, Information Technology Application Controls (ITAC), Information Technology-Dependent Manual Controls (ITDM), and ICoFR. The study uses a qualitative conceptual-evaluative approach through literature studies and analysis of ITGC evaluation documents at a bank. The evaluation was conducted on four ITGC domains: Access to Program and Data, Program Development, Program Changes, and Computer Operations, using a checklist method with binary scoring based on PCAOB, ISA 315, COSO, COBIT, and GAO FISCAM standards. The results show that three ITGC domains are categorized as effective, while the Computer Operations domain is categorized as partially effective. Diagnostic analysis yielded a score of 39 out of 53 indicators (74%), with the main weakness being in post-incident evaluation documentation, particularly documentation of lessons learned, root cause analysis, and follow-up improvements. Overall, the implementation of ITGC has established an adequate information technology control environment, thus providing a foundation for supporting the reliability of DAIS. This study also develops an evaluative framework that maps the analytical relationships between ITGC, DAIS, ITAC, ITDM, and ICoFR. This framework is expected to serve as a reference for management, control owners, and auditors in interpreting the results of ITGC evaluations and establishing priorities for strengthening information technology controls to support the effectiveness of financial reporting.

Bahasa Abstract

Transformasi digital telah meningkatkan ketergantungan organisasi terhadap Digital Accounting Information System (DAIS) dalam mendukung pelaporan keuangan, sehingga efektivitas Information Technology General Controls (ITGC) menjadi faktor penting dalam menjaga keandalan sistem dan mendukung Internal Control over Financial Reporting (ICoFR). Penelitian ini bertujuan mengevaluasi implementasi ITGC serta menjelaskan implikasinya terhadap keandalan DAIS, Information Technology Application Controls (ITAC), Information Technology-Dependent Manual Controls (ITDM), dan ICoFR. Penelitian menggunakan pendekatan kualitatif konseptual-evaluatif melalui studi literatur dan analisis dokumen evaluasi ITGC pada sebuah bank. Evaluasi dilakukan terhadap empat domain ITGC, yaitu Access to Program and Data, Program Development, Program Changes, dan Computer Operations, menggunakan metode checklist dengan binary scoring berdasarkan standar PCAOB, ISA 315, COSO, COBIT, dan GAO FISCAM. Hasil penelitian menunjukkan bahwa tiga domain ITGC memperoleh kategori effective, sedangkan domain Computer Operations memperoleh kategori partially effective. Analisis diagnostik menghasilkan skor 39 dari 53 indikator (74%), dengan kelemahan utama terdapat pada dokumentasi evaluasi pascainsiden, khususnya dokumentasi lessons learned, root cause analysis, dan tindak lanjut perbaikan. Secara keseluruhan, implementasi ITGC telah membentuk lingkungan pengendalian teknologi informasi yang memadai sehingga memberikan dasar yang mendukung keandalan DAIS. Penelitian ini juga mengembangkan kerangka evaluatif yang memetakan hubungan analitis antara ITGC, DAIS, ITAC, ITDM, dan ICoFR. Kerangka tersebut diharapkan dapat menjadi acuan bagi manajemen, control owner, dan auditor dalam menginterpretasikan hasil evaluasi ITGC serta menetapkan prioritas penguatan pengendalian teknologi informasi untuk mendukung efektivitas pelaporan keuangan.

References

REFERENCES

 

Ashraf, M. (2025). Does automation improve financial reporting? Evidence from internal controls. Review of Accounting Studies, 30(1), 436–479. https://doi.org/10.1007/s11142-024-09822-y

Ashraf, M., Michas, P. N., & Russomanno, D. (2020). The Impact of Audit Committee Information Technology Expertise on the Reliability and Timeliness of Financial Reporting. The Accounting Review, 95(5), 23–56. https://doi.org/10.2308/accr-52622

Bhimani, A., Cinquini, L., & Malmi, T. (2026). What happens at the interface of digitalisation and accounting? The British Accounting Review, 58(2), 101742. https://doi.org/https://doi.org/10.1016/j.bar.2025.101742

Boulhaga, M., Bouri, A., & Elbardan, H. (2022). The effect of internal control quality on real and accrual-based earnings management: evidence from France. Journal of Management Control, 33(4), 545–567. https://doi.org/10.1007/s00187-022-00348-5

COSO. (2013). Internal Control---Integrated Framework. Committee of Sponsoring Organizations of the Treadway Commission.

Damayanti, K., & Fardinal. (2019). The Effect of Information Technology Utilization, Management Support, Internal Control, and User Competence on Accounting Information System Quality (Study on Finance Company in Jakarta). Scholars Bulletin. https://api.semanticscholar.org/CorpusID:216649439

Diavastis, I., Chrysafis, K., & Papadopoulou, G. (2024). Determinants of Accounting Information Systems Success: The Case of the Greek Hotel Industry. International Journal of Financial Studies, 12, 42. https://doi.org/10.3390/ijfs12020042

GAO. (2021). Federal Information System Controls Audit Manual (FISCAM) (Issue GAO-21-368G). https://www.gao.gov/products/gao-21-368g

Garrett, C., & Swarts, J. (2024). IT Controls and ICFR: The Increasing Importance of Information Technology Controls in Internal Control Over Financial Reporting. KPMG LLP. https://kpmg.com/us/en/articles/2024/it-controls-and-icfr.html

Indrasti, D., & Sulistyawati, A. (2021). PENERAPAN SISTEM INFORMASI AKUNTANSI PENGGAJIAN DALAM MENUNJANG EFEKTIFITAS PENGENDALIAN INTERNAL. Solusi, 19, 203–217. https://doi.org/10.26623/slsi.v19i2.3163

ISA 315 (Revised 2019). (2019). ISA 315 (Revised 2019): Identifying and Assessing the Risks of Material Misstatement (Issue ISA 315 (Revised 2019)). https://www.iaasb.org/publications/isa-315-revised-2019-identifying-and-assessing-risks-material-misstatement

Kocsis, D. (2019). A conceptual foundation of design and implementation research in accounting information systems. International Journal of Accounting Information Systems, 34, 100420. https://doi.org/https://doi.org/10.1016/j.accinf.2019.06.003

KPMG (2024). (2024). IT Controls and ICFR: The Increasing Importance of Information Technology Controls in Internal Control Over Financial Reporting. KPMG LLP. https://kpmg.com/us/en/articles/2024/it-controls-and-icfr.html

Lutfi, A., Alkelani, S. N., Alqudah, H., Alshira’h, A. F., Alshirah, M. H., Almaiah, M. A., Alsyouf, A., Alrawad, M., Montash, A., & Abdelmaksoud, O. (2022). The Role of E-Accounting Adoption on Business Performance: The Moderating Role of COVID-19. Journal of Risk and Financial Management, 15(12), 617. https://doi.org/10.3390/jrfm15120617

Martín-Zamora, M.-P., & Borralho, J. M. C. (2024). Digitalization of Financial Reporting. Advances in Finance, Accounting, and Economics Book Series, 123–164. https://doi.org/10.4018/979-8-3693-5923-5.ch005

Mascha, M. F., Lamboy-Ruiz, M. A., & Janvrin, D. J. (2018). PCAOB inspections: An analysis of entity-level and application-level control audit deficiencies. International Journal of Accounting Information Systems, 30, 19–39. https://doi.org/https://doi.org/10.1016/j.accinf.2018.06.002

Mojtahedi, A., & Zhou, L. (2024). Information technology internal control material weaknesses in financial reporting: Categories, trends, associations, and industry effects. International Journal of Accounting Information Systems, 53(C), None. https://doi.org/10.1016/j.accinf.2024.100679

PCAOB. (2010). AS 2110: Identifying and Assessing Risks of Material Misstatement. https://pcaobus.org/oversight/standards/auditing-standards/details/AS2110

PCAOB. (2025). AS 1105: Audit Evidence. Public Company Accounting Oversight Board. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105

PCAOB. (2026). AS 2110: Identifying and Assessing Risks of Material Misstatement. Public Company Accounting Oversight Board. https://pcaobus.org/oversight/standards/auditing-standards/details/as-2110--identifying-and-assessing-risks-of-material-misstatement-%28effective-on-12-15-2026%29

PCAOB AS 1105. (2024). AS 1105: Audit Evidence. Public Company Accounting Oversight Board. https://pcaobus.org/oversight/standards/auditing-standards/details/AS1105

PCAOB AS 2110. (2026). AS 2110: Identifying and Assessing Risks of Material Misstatement. Public Company Accounting Oversight Board. https://pcaobus.org/oversight/standards/auditing-standards/details/as-2110--identifying-and-assessing-risks-of-material-misstatement-%28effective-on-12-15-2026%29

PCAOB AS 2201. (2026). AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements. Public Company Accounting Oversight Board. https://pcaobus.org/oversight/standards/auditing-standards/details/AS2201

Sampaio, C., & Silva, R. (2025). Digital Transformation in Accounting: An Assessment of Automation and AI Integration. International Journal of Financial Studies, 13(4), 206. https://doi.org/10.3390/ijfs13040206

Schiavi, G. S., Behr, A., & Marcolin, C. B. (2024). Institutional theory in accounting information systems research: Shedding light on digital transformation and institutional change. International Journal of Accounting Information Systems, 52, 100662. https://doi.org/https://doi.org/10.1016/j.accinf.2023.100662

Wu, T.-H., Huang, S. Y., Chiu, A.-A., & Yen, D. C. (2024). IT governance and IT controls: Analysis from an internal auditing perspective. International Journal of Accounting Information Systems, 52, 100663. https://doi.org/https://doi.org/10.1016/j.accinf.2023.100663

Yu, L., & Ma, D. (2019). Internal Control Weakness: A Literature Review. Accounting and Finance Research, 8, 15294. https://doi.org/10.5430/afr.v8n2p121

Included in

Accounting Commons

Share

COinS