Common examples of internal control weaknesses include one accounts payable clerk who can add vendors and pay them, bank reconciliations that slip from monthly to quarterly, terminated employees whose system access lingers for months, purchase approvals routinely signed without review, and inventory counted only once a year. Each of these is a gap in the policies, procedures, or oversight that keep financial reporting accurate, protect assets, and keep an organization within the law. Some are nuisance findings. Others force a public company to disclose a material weakness in its annual report and drag the stock down roughly 5% over the next 120 trading days. Knowing which is which starts with how auditors classify what they find.
The Three Severity Tiers
Not every gap carries the same weight. The Public Company Accounting Oversight Board draws a clear line between three tiers, and the tier determines who has to hear about the problem and what the company must do next.
- A control deficiency exists when a control is missing from the design or not operating as intended, but the gap is minor enough that it doesn’t warrant formal reporting to the board or audit committee.
- A significant deficiency is a deficiency, or a combination of them, serious enough to “merit attention by those responsible for oversight of the company’s financial reporting,” but not severe enough to be a material weakness.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting
- A material weakness is a deficiency, or combination of deficiencies, where there is a “reasonable possibility” that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting
The examples that follow can land in any tier depending on severity and scope. A single access-rights error on one system is a deficiency. The same error repeated across every financial application is a potential material weakness.
Segregation of Duties Examples
This is the weakness auditors find most often, and it’s the one most directly tied to fraud. The core idea: no single person should control an entire transaction. Three functions belong in three different hands: authorizing a transaction, recording it, and having custody of the resulting asset.
The textbook example is an accounts payable clerk who can create a new vendor in the system, approve invoices from that vendor, and initiate payments. That combination lets one person set up a fictitious company, submit fake invoices, and pay themselves. According to the Association of Certified Fraud Examiners, organizations lose an estimated 5% of revenue to fraud each year, with a median loss of $145,000 per case and a typical scheme running 12 months before detection.2Association of Certified Fraud Examiners. Occupational Fraud 2024 – A Report to the Nations Weak segregation is a major reason schemes survive that long.
Other segregation failures that turn up repeatedly:
- In payroll, one person adds new employees, sets pay rates, and processes payroll runs. Ghost employees become trivial to create.
- In cash receipts, the person who opens incoming mail and lists checks also makes the bank deposit and posts to accounts receivable. Skimming a check and covering the shortage requires no help from anyone.
- In inventory, a warehouse manager who records receipts and also has physical custody can divert goods and adjust the records to hide the shortage.
The vendor master file deserves separate attention because a large share of payment fraud starts there. When changes to vendor bank account numbers or addresses don’t require independent verification, one compromised set of credentials can redirect legitimate payments. Organizations that never audit the vendor file for duplicates, dormant vendors, or vendors sharing addresses or bank accounts with employees carry a risk that grows with every payment they process.
Authorization and Processing Examples
Even when duties are separated, controls can still fail at the approval layer.
Ignored Approval Thresholds
A purchase order policy requiring dual approval above a set dollar amount is useless if procurement staff routinely skip the second signature. The control exists on paper but not in practice, and that gap is what auditors call a deficiency in operation: the design is fine, but it doesn’t work as designed.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting The same problem shows up with journal entries. If any accountant can post a six-figure adjusting entry without a reviewer’s sign-off, the financials are exposed to both manipulation and honest mistakes that nobody catches until the external audit.
Missing Credit Review on Sales
Revenue recognition weaknesses often trace back to the front end of the transaction. Shipping a large order to a new customer without a credit review means the company has already booked cost of goods sold before learning whether the customer can pay. The result is overstated revenue, an inflated receivable, and a write-off later that distorts the picture. Proper control puts the credit function ahead of fulfillment for any order above a set threshold.
Incomplete Supporting Documentation
Every payment should be backed by a purchase order, a vendor invoice, and confirmation that the goods or services actually arrived. When a three-way match isn’t required before payment, organizations pay for things they never received, pay twice for the same delivery, or pay amounts that don’t match what was agreed. Incomplete records also make it harder to substantiate deductions if the IRS examines the return, since the burden of proving income and expenses falls on the taxpayer.3Internal Revenue Service. Recordkeeping
IT Control Examples
IT controls sit under nearly every financial control in a modern organization. If someone can access, modify, or delete data without authorization, well-written accounting policies won’t save the numbers.
Access Management Failures
The most common IT weakness is failing to remove access promptly when an employee leaves or changes roles. A departed accounts payable supervisor with remote access to the payment system six months after termination is an obvious risk, and it happens constantly because removal depends on HR notifying IT, and that handoff breaks. Federal security guidance requires organizations to uniquely identify and authenticate each user and tie that identity to their actions in the system.4IDManagement.gov. Security Controls Mapping of Special Publication 800-53 Revision 5, Identification and Authentication Shared logins break that requirement outright. When five people share one credential, there is no way to know who initiated a transaction.
Poor Change Management
Pushing a software update or configuration change into the production environment without testing it first can corrupt transaction data, break automated controls, or open security holes. Effective change management requires a test environment, a documented approval path, and a rollback plan. Skipping any of those is a weakness that can halt financial processing entirely.
Untested Backups
Many organizations run daily backups but never test whether the backups actually restore. An untested backup is an assumption, not a control. The weakness becomes catastrophic when ransomware or a hardware failure forces restoration and the team finds the backups are corrupt, incomplete, or inaccessible. Storing backups in the same physical location as production compounds it: one fire or flood can take out both.
Delayed Patching
Failing to apply security patches to financial systems within a reasonable timeframe leaves known vulnerabilities open. Cyber insurance underwriters now routinely deny claims when investigations reveal the breach exploited a vulnerability the organization knew about but hadn’t patched.
Monitoring and Reconciliation Examples
Preventive controls stop errors before they happen. Monitoring controls catch what slips through. When monitoring fails, problems can run for months.
Late or Skipped Reconciliations
Reconciling a bank account quarterly instead of monthly can leave an unauthorized transaction undetected for up to 90 days. For a cash account, that delay can be the difference between catching a $3,000 irregularity and finding a six-figure embezzlement. Cash, intercompany balances, and revenue clearing accounts need monthly reconciliation at minimum, with someone other than the preparer reviewing the work.
Rubber-Stamp Approvals
A supervisor who signs off on a payroll journal entry without reviewing time records, or approves an expense report without checking receipts, is performing a ritual rather than a control. The signature exists; the protection does not. This one is especially dangerous because it looks compliant on paper, so it survives walk-through testing and only surfaces during detailed transaction testing.
Ignored Exception Reports
Automated systems generate exception reports for a reason: a payment processed outside standard terms, a journal entry posted after the close, a login attempt from an unusual location. When those reports pile up unread, the organization has built a detection system and then disabled it. The fix isn’t better software. It’s assigning clear ownership for reviewing each report and requiring documented follow-up on every flagged item.
No Follow-Up on Audit Findings
When auditors identify a weakness, management acknowledges it in a remediation plan, and nothing changes, the weakness persists and a new one appears: a broken self-correction process. Auditors must communicate significant deficiencies and material weaknesses in writing to those charged with governance within 60 days of the audit report’s release.5American Institute of Certified Public Accountants. AU-C Section 265 – Communicating Internal Control Related Matters Identified in an Audit That paper trail matters. If the same finding appears the next year, the auditor knows management was informed and chose not to act, which pushes the severity assessment higher.
Infrequent Physical Inventory
Counting inventory once a year and relying on estimated shrinkage for the other eleven months is guessing at cost of goods sold. Cycle counting, where a portion of inventory is counted on a rotating schedule, catches theft, spoilage, and recording errors far sooner.
Control Environment Examples
The examples above sit on top of a foundation called the control environment. When the foundation is weak, the specific controls tend to fail regardless of how they read on paper.
Indifference at the Top
The most damaging weakness is often invisible on a flowchart: leadership that treats compliance as a nuisance. This shows up as a missing or unenforced code of conduct, inconsistent discipline for policy violations, or executives who openly dismiss audit findings. When staff see leadership ignoring the rules, they reasonably conclude the rules are decorative. GAO standards put it directly: the board and senior management “establish the tone at the top regarding the importance of internal control and expected standards of conduct.”
Routine Management Override
Every control system needs a way for management to override a control when business circumstances demand it. The weakness isn’t the override; it’s when overrides become routine. A CFO who regularly approves purchases above normal limits without documentation, or a controller who posts adjusting entries without review, teaches the organization that controls are optional.
Understaffed Control Functions
An internal audit team of two people responsible for testing controls across a multinational organization is a weakness no amount of talent overcomes. Testing becomes a checkbox exercise focused on the highest-risk areas, and everything else goes unreviewed for years. The same problem appears in accounting departments where one person handles journal entries and bank reconciliations because nobody else is available. Staffing forces exactly the role concentration that segregation of duties is supposed to prevent.
Unclear Lines of Authority
When two managers each believe the other owns the intercompany reconciliation, it doesn’t happen. Ambiguous ownership is one of the quietest control failures because no alarm sounds when a task is simply never performed. It usually surfaces during an audit, months later, when the auditor asks who owns the control and gets a different answer from each person asked.
What Small Organizations Can Do Instead
Small businesses face a structural problem. A five-person accounting department can’t always avoid giving one employee responsibilities that would be split among three at a larger company. Many of the examples above will feel impractical at that scale.
The answer isn’t to accept the risk. GAO standards acknowledge that smaller entities face “greater challenges in segregating duties because of its concentration of responsibilities and authorities” and advise management to respond by adding review layers, sampling transactions and supporting documents, taking periodic asset counts, and checking supervisor reconciliations.6Government Accountability Office. Standards for Internal Control in the Federal Government
The compensating controls that tend to work:
- Having someone outside the accounting function open and review bank statements each month catches unauthorized payments the person processing transactions would never self-report.
- Requiring two people to approve any payment above a set threshold means the check or wire doesn’t go out on one person’s signature, even if that person handles the whole AP process.
- Software that automatically matches invoices to purchase orders and flags exceptions removes reliance on one person’s judgment and creates an electronic trail.
- Unannounced reviews of petty cash, inventory, or expense reports create uncertainty for anyone considering fraud. A scheduled annual count is easy to plan around; a surprise one is not.
None of these fully replaces proper segregation, and an auditor will still note the underlying role concentration. But documented compensating controls show management identified the risk and took reasonable steps, which matters both for the audit opinion and in any future dispute over whether negligence occurred.
What These Weaknesses Cost
For publicly traded companies, the CEO and CFO must personally certify in every annual and quarterly report that they have evaluated the company’s internal controls, disclosed any significant deficiencies or material weaknesses to the auditors and audit committee, and presented their conclusions on effectiveness.7Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports Each annual report also carries an internal control report in which management assesses effectiveness as of the fiscal year end; larger public companies must have the external auditor attest to that assessment as well.8GovInfo. 15 USC 7262 – Management Assessment of Internal Controls SEC Rule 13a-15 backs this up by requiring quarterly evaluation of disclosure controls and annual evaluation of internal controls using a recognized framework like COSO.9eCFR. 17 CFR 240.13a-15 – Controls and Procedures
The penalties are personal. An officer who knowingly certifies a report that doesn’t comply can face fines up to $1 million and up to 10 years in prison. Willful certification raises the ceiling to $5 million and 20 years.10Office of the Law Revision Counsel. 18 USC 1350 – Failure of Corporate Officers to Certify Financial Reports Those attach to the individual who signed.
Market and audit costs follow disclosure. Companies that report a material weakness face higher audit fees, often for years after remediation, because auditors expand testing when they can’t rely on controls. Stock performance research shows affected companies underperform by roughly 5% over the 120 trading days after the announcement, translating to roughly 10% annualized underperformance compared with firms that have effective controls. The initial announcement may move the stock less than 1%, but the drag builds as investors reassess reporting reliability.
For any business, public or private, weak controls can bring tax consequences. The IRS imposes a 20% accuracy-related penalty on any underpayment attributable to negligence, which the statute defines to include “any failure to make a reasonable attempt to comply” with the tax code.11Office of the Law Revision Counsel. 26 USC 6662 – Imposition of Accuracy-Related Penalty on Underpayments Failing to maintain adequate books and records is treated as an indicator of negligence when the IRS decides whether to apply that penalty.12Taxpayer Advocate Service. Annual Report to Congress – Accuracy-Related Penalty Under IRC 6662(b)(1) and (2) The penalty can be avoided if the taxpayer shows reasonable cause and good faith, but the key factor is whether the taxpayer made a real effort to get the liability right. An organization with no controls over its financial data has a hard time making that argument.
Cyber insurance is the newest layer. Insurers require multi-factor authentication on all remote and administrative access, endpoint detection and response tools, documented patch management, tested backups, security awareness training, and a written incident response plan. Incomplete deployment counts as non-compliance. A company that certifies full MFA coverage on its application but leaves one server unprotected can have a ransomware claim denied on the basis of misrepresentation.