Significant deficiency examples in internal controls typically include former employees keeping active system access after leaving, complex or non-routine journal entries posted without independent review, large credit memos processed without a second set of eyes, weak reconciliations on complicated liability accounts, and staff running key financial controls without formal training. Each is a real breakdown in internal controls over financial reporting, serious enough to demand the audit committee’s attention, but not severe enough to be classified as a material weakness.
What a Significant Deficiency Is
Under PCAOB standards, control problems fall into three tiers. A control deficiency is the lowest: a design or operating flaw that on its own is unlikely to cause a meaningful misstatement. A significant deficiency is the middle tier: a deficiency, or a combination of deficiencies, less severe than a material weakness but important enough to merit attention from those overseeing financial reporting. A material weakness is the top tier: a deficiency where there is a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Reading through concrete examples is the fastest way to see where the middle tier sits.
IT and System Access Examples
IT controls often touch every financial reporting area through a single system, so a gap here can be pervasive even when no error has actually surfaced.
The classic example is poor user access management. Former employees who keep active login credentials after termination, or current employees who hold access to system functions well outside their job responsibilities, create an opening for unauthorized transactions. The risk is real, but it may not be material if the company runs daily transaction monitoring that would catch suspicious activity. That kind of detective control is often what keeps the issue at significant deficiency level rather than escalating it.
Change management for financial applications is another frequent one. When developers can push code into the production environment without an independent team reviewing the change, no one is verifying that the release works as intended. A coding error, or an intentional manipulation, could change how the system processes financial data. The absence of separation between development and production roles is a textbook significant deficiency.
Period-End Close Examples
Significant deficiencies show up most visibly during the close, when estimates, judgments, and non-routine entries stack up.
One recurring example: management reviews standard monthly accruals thoroughly but glosses over the detailed support behind unusual year-end entries, such as a goodwill impairment or a fair-value adjustment. These entries carry higher inherent misstatement risk. Skipping a rigorous review of the underlying assumptions means an error could slip through. The potential misstatement tends to be confined to a specific account, which is often what keeps it below the material weakness threshold.
Weak reconciliation procedures for complex liability accounts fit the same pattern. If the team runs a high-level variance analysis instead of reconciling the underlying data in detail, differences can hide inside the balance. A single account may not be large enough to produce a material misstatement, but the lack of rigor still needs to reach the audit committee.
Revenue and Inventory Examples
Revenue is a high-risk area by default. A common significant deficiency involves the absence of an independent review of credit memos above a set dollar threshold. If the credit manager can approve and process large revenue adjustments without anyone in accounting reviewing them, misstated net revenue becomes a realistic possibility. The exposure is bounded by credit memo volume rather than the full revenue stream, which usually keeps the classification below material weakness.
Inventory produces its own version. A frequent example is inadequate support for the valuation reserve on obsolete or slow-moving inventory. If the reserve runs off a formula whose inputs are refreshed only quarterly instead of monthly, the balance can sit stale for weeks. The delay may not produce a material error, but the reserve is operating too slowly to reflect current conditions, and that gap deserves governance attention.
Governance and Training Examples
Not every significant deficiency traces back to a specific control failing at a specific moment. Some are weaknesses in the foundation.
The absence of a formal training program for employees performing key financial controls is one. If the accounts payable clerk running the three-way match between purchase order, receiving document, and invoice learned the process informally and never received structured training, the reliability of the control depends entirely on one person’s habits. The risk is diffuse, spread across many transactions rather than concentrated in a single account, which typically keeps it below material weakness severity.
Another is the failure to perform a risk assessment for newly acquired business units. Companies sometimes lean on the parent’s existing controls for the first year after an acquisition without formally evaluating where the new subsidiary’s reporting risks actually lie. That leaves the company blind to control gaps in the acquired operation. Even without a misstatement, the exposure is significant enough to warrant discussion with the audit committee.
How Auditors Draw the Line
Classification is not mechanical. Auditors weigh two factors together: the likelihood that a misstatement could occur, and the magnitude if it did. A deficiency with a large potential impact but a very low probability may end up in a different category from one with a modest dollar impact but a high probability.
Compensating controls matter. If a preventive control is missing but a solid detective control catches the same type of error, the overall risk drops. Auditors have to evaluate whether the backup control actually works before deciding how to classify the gap.
PCAOB standards list conditions that indicate a deficiency is at least a material weakness, which effectively marks the ceiling of the significant deficiency category. These include fraud involving senior management, a restatement of previously issued financial statements, a material misstatement the auditor caught that the company’s controls missed, and ineffective oversight by the audit committee.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Absent those red flags, a more-than-trivial deficiency generally sits in the significant deficiency range.
Why the Classification Matters
The line between significant deficiency and material weakness carries real consequences.
A material weakness triggers an adverse opinion from the auditor on internal controls over financial reporting, a public statement that the controls are not effective.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements A significant deficiency does not. The auditor can still conclude that controls are effective overall despite its existence.
Disclosure works the same way. Material weaknesses must be reported in the company’s annual filing, and management cannot conclude that controls are effective while one exists.2eCFR. 17 CFR 229.308 – (Item 308) Internal Control Over Financial Reporting Significant deficiencies are communicated privately to management and the audit committee and do not appear in SEC filings unless they combine into a material weakness.3U.S. Securities and Exchange Commission. Office of the Chief Accountant and Division of Corporation Finance That is why companies push hard to keep an item classified as significant rather than material. Crossing the line turns an internal item into public information that can affect stock price and invite regulator attention.
Aggregation is the reason audit committees still treat significant deficiencies seriously. If several affect the same account or the same reporting assertion, PCAOB standards require the auditor to evaluate whether they collectively rise to a material weakness.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements Three items that individually stay below the threshold can, together, produce a reasonable possibility of a material misstatement.
What Happens After One Is Identified
Once the auditor identifies a significant deficiency, it must be communicated in writing to both management and the audit committee.4Public Company Accounting Oversight Board. AS 1305 – Communications About Control Deficiencies in an Audit of Financial Statements The written report describes the specific control that failed, why it was classified as significant rather than material, and the potential impact on the financial statements. The communication must go out before the auditor issues its report on internal controls over financial reporting.1Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements
Sarbanes-Oxley Section 302 adds a personal layer. The CEO and CFO must certify in each periodic report that they have disclosed all significant deficiencies in internal controls to the company’s auditors and audit committee, and they must indicate whether corrective actions have been taken since their last evaluation.5Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports
Remediation is management’s responsibility. That means identifying the root cause, designing a new or revised control, and assigning a specific process owner with a timeline the audit committee can track. Implementation usually combines system changes, updated policies, and training for the people running the new control. Design alone is not enough; the control has to work consistently over time.
Once the control is in place, management performs follow-up testing across enough transactions and a long enough period to provide real confidence rather than a spot check. Results go to both internal and external auditors. During the next audit cycle, the external auditor independently tests the remediated control. Until that independent confirmation happens, the significant deficiency stays open on the audit committee’s list.