Internal Control Deficiencies: Severity, Causes, and Remediation

Internal control deficiencies are gaps in a company’s financial reporting controls, and auditing standards sort them into three tiers of severity: an ordinary control deficiency, a significant deficiency, and a material weakness. The tier a problem lands in decides who has to be told, whether the public has to be told, and how much work it takes to close the issue out. Everything else about handling one of these problems — the root-cause analysis, the remediation plan, the re-testing, the disclosure decision — flows from that classification.

A deficiency exists whenever the design or operation of a control doesn’t let the people running it prevent or detect misstatements on a timely basis. A design deficiency means a necessary control is missing or built in a way that can’t meet its objective. An operating deficiency means the control looks right on paper but doesn’t work in practice, often because the person performing it lacks the training or authority to execute it.1Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements

The Three Severity Levels

Control Deficiency

The baseline tier. Any gap in design or operation that keeps a control from catching errors in time qualifies. Control deficiencies are communicated internally to the process owner and relevant management, and they do not trigger public disclosure.

Significant Deficiency

A deficiency, or a combination of deficiencies, that is less severe than a material weakness but important enough to warrant attention from those overseeing the company’s financial reporting — in practice, the audit committee.1Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements The judgment call is whether the problem could produce a misstatement that’s more than trivial but wouldn’t likely be material.

Auditors must communicate every significant deficiency in writing to both management and the audit committee.1Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements Public disclosure is not required, but documented remediation plans and audit committee follow-up are.

Material Weakness

The top of the ladder. A material weakness exists when there’s a reasonable possibility that a material misstatement of the financial statements won’t be prevented or detected in time. “Reasonable possibility” tracks the accounting-standard definition — either “reasonably possible” or “probable.”1Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements That bar is lower than most people assume. You don’t need to show the misstatement is likely. You need to show it’s more than remote.

One material weakness is enough. When any material weakness exists, internal control over financial reporting cannot be concluded to be effective, and management is not permitted to say otherwise.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements3eCFR. 17 CFR 229.308 – Item 308 Internal Control Over Financial Reporting The weakness must be disclosed in the company’s annual report along with a statement that internal controls are not effective.

One other rule worth knowing: auditors are prohibited from issuing a report stating that no significant deficiencies were identified during the audit. Silence from the auditor should not be read as a clean bill of health.4Public Company Accounting Oversight Board. AI 12 – Communications About Control Deficiencies in an Audit of Financial Statements

Indicators That Force a Material Weakness Conclusion

PCAOB standards flag certain circumstances as indicators of a material weakness. When an auditor sees any of these, the standard directs them to treat it as such and evaluate accordingly.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

  • Any fraud on the part of senior management, whether or not the dollar amount is material.
  • Restatement of previously issued financial statements to correct a material misstatement.
  • A material misstatement identified by the external auditor that the company’s own controls should have caught but didn’t.
  • Ineffective audit committee oversight of financial reporting and internal control.

The fraud indicator is the one people miss most often. It applies regardless of the size of the fraud, because a small-dollar fraud by a senior executive still signals that the control environment itself is broken.

Outside these bright lines, severity comes down to a judgment about whether the deficiency, alone or combined with others, would prevent a reasonable person from concluding that transactions are being recorded properly.2Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements

Where Deficiencies Come From

Fixing the symptom without addressing the underlying cause almost guarantees the deficiency will come back in a slightly different form. A few root causes account for most of what turns up.

Lack of Segregation of Duties

When one person can initiate a transaction, approve it, and record it, there’s no independent check. Classic example: the same employee sets up new vendors and approves payments to them, which opens the door to fictitious vendor fraud. Smaller organizations often can’t fully separate every function, and that’s where compensating controls like management review and surprise audits have to carry the load.

Inadequate Training or Competence

A well-designed control is worthless if the person performing it doesn’t understand what they’re supposed to be checking. This shows up most often after turnover in key accounting roles, where institutional knowledge walks out and the replacement is left to learn on the fly. The underlying failure is a lack of training programs and documented procedures that survive personnel changes.

Poor Control Design

Sometimes the control is performed perfectly and still misses the risk. The scope is too narrow, the review threshold is set too high, or the control tests the wrong attribute. A purchase order review that triggers only above $50,000 lets every unauthorized expenditure below that number sail through. Design problems are hard to spot because everyone can point to evidence that they did their job.

Management Override and Collusion

Every control system has an inherent limitation: the people who designed it can circumvent it. Management override involves a senior leader bypassing a control to manipulate results or conceal misappropriation. Collusion, where two or more employees coordinate to defeat segregation of duties, creates the same blind spot. Routine testing rarely catches either, because the people involved are usually in a position to suppress the evidence.

IT General Control Weaknesses

IT general controls sit under every automated control and every piece of financial data in the system. When they break down, the damage spreads across accounts and processes at once. The two most common problem areas are access management and change management. Weak access controls let unauthorized users view or modify financial data. Weak change management lets untested code go into production, corrupting data in ways that don’t surface until a reconciliation fails weeks later. Gaps in backup and recovery add another layer, because they mean the integrity of financial data can’t be assured after a system failure.

What You Have to Do When You Find One

Waiting for the external auditor to find your control problems is the most expensive way to discover them. Identification should be continuous and driven by internal audit teams, compliance staff, and management’s own monitoring.

Assess Severity

For every documented exception, estimate both the likelihood that a misstatement could result and how large that misstatement could be. A deficiency in a control over a $200,000 account carries different weight than the same deficiency in a control over a $200 million account.

Aggregate Related Deficiencies

This is where companies most often get tripped up. Multiple deficiencies affecting the same account or assertion have to be considered together. Three individually minor deficiencies in revenue recognition might combine to create a reasonable possibility of a material revenue misstatement. Compensating controls can be factored in, but only if those compensating controls have been tested and shown to work.

Communicate to the Right Level

Simple control deficiencies go to the process owner and management. Significant deficiencies and material weaknesses go in writing to both management and the audit committee.1Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements For public companies, a material weakness triggers mandatory public disclosure in the annual 10-K, along with an assessment of ICFR effectiveness and identification of the framework used for the evaluation.3eCFR. 17 CFR 229.308 – Item 308 Internal Control Over Financial Reporting The standard framework for that evaluation, and the one virtually every U.S. public company uses, is COSO’s Internal Control–Integrated Framework.5U.S. Securities and Exchange Commission. Commission Guidance Regarding Management’s Report on Internal Control Over Financial Reporting

Consequences of a Material Weakness

Disclosure and Market Reaction

SOX Section 404(a) requires every annual report to include a management report on ICFR. For accelerated and large accelerated filers, Section 404(b) adds an auditor attestation on top.6GovInfo. Sarbanes-Oxley Act of 2002 – Section 404 An adverse opinion is a public event that investors, analysts, and regulators all watch. Disclosing a material weakness typically raises the cost of capital, increases external audit fees because the auditor has to expand testing, and dents investor confidence. Those costs generally normalize once the weakness is remediated, which is one reason companies push hard to close the issue quickly.

CEO and CFO Certification Liability

SOX Section 302 requires the CEO and CFO to personally certify each periodic report, including a statement that they have disclosed all significant deficiencies and any fraud involving management to the auditors and audit committee. Section 906 adds criminal exposure. A knowing false certification carries fines up to $1,000,000 and up to 10 years in prison. A willful false certification raises the maximum to $5,000,000 in fines and 20 years in prison.7Office of the Law Revision Counsel. 18 U.S. Code 1350 – Failure of Corporate Officers to Certify Financial Reports When a material weakness exists, the CEO and CFO are certifying a report that explicitly says their controls are not effective. That focuses attention on remediation.

How to Remediate and Prove It’s Fixed

Build a Plan Tied to the Root Cause

A written remediation plan has to address the root cause, not the symptom. If the deficiency was in the design, the plan needs to specify the new or revised control: what gets reviewed, by whom, how often, and what evidence gets retained. If the deficiency was operational, the plan needs to explain how execution will become consistent — additional training, reassigned responsibilities, or added supervisory review. Every plan needs a named owner and a firm completion deadline. Vague commitments do not survive audit scrutiny.

Implement and Start Collecting Evidence

Staff who will run the new control need hands-on training, not just an email attaching an updated policy. From day one, management has to collect the evidence that proves the control is being performed: signed checklists, system logs, reconciliation files with timestamps and reviewer identities. The clock for re-testing starts when the new control begins operating.

Re-Test Over an Adequate Period

You cannot simply declare a deficiency fixed. The remediated control must be tested over a period long enough to demonstrate that it is operating effectively. PCAOB standards make clear that the required period depends on the nature and risk of the control. A daily transaction-level reconciliation can generally be validated in a shorter window. Entity-level controls and controls over the period-end financial reporting process typically need to be tested in connection with an actual period-end close.8Public Company Accounting Oversight Board. AS 6115 – Reporting on Whether a Previously Reported Material Weakness Has Been Corrected

The re-test should use the same methodology and control objectives as the testing that uncovered the deficiency. For a material weakness, management can assert that the weakness no longer exists as of a specified date, but that date has to allow for enough evidence of operating effectiveness, which may mean waiting until one or more period-end closes have been completed under the new control.8Public Company Accounting Oversight Board. AS 6115 – Reporting on Whether a Previously Reported Material Weakness Has Been Corrected

Document the Full Lifecycle

The complete remediation record should be captured in a formal memorandum: the original deficiency, the root cause analysis, the remediation plan, the implementation date, the re-testing procedures, the results, and the conclusion. The external auditor will perform independent testing before agreeing that the deficiency is remediated, and the quality of the internal documentation directly affects how much additional work the auditor has to do.

Which Companies Are Actually Subject to All of This

SOX Section 404(a) reaches broadly. Every company that files annual reports under the Securities Exchange Act has to include management’s assessment of ICFR.6GovInfo. Sarbanes-Oxley Act of 2002 – Section 404

Section 404(b), the auditor attestation requirement, reaches less far. Non-accelerated filers, emerging growth companies, and smaller reporting companies with annual revenues below $100 million are exempt from the attestation requirement.6GovInfo. Sarbanes-Oxley Act of 2002 – Section 404 The exemption reduces compliance cost but does not eliminate the underlying obligation. Exempt companies still have to perform and report management’s own assessment, and they still have to disclose any material weakness they identify. Private companies are outside SOX 404 altogether, but the classification framework and remediation approach described above are drawn from the same auditing standards their auditors apply.