3.5 Identifying Control Weaknesses, Limitations & ISA 265 Reporting

Key Takeaways

  • ISA 265 requires external auditors to communicate in writing significant deficiencies in internal control identified during the audit to Those Charged With Governance (TCWG) and management.
  • A deficiency in internal control exists when a control is designed, implemented, or operated in such a way that it fails to prevent, or detect and correct, misstatements in the financial statements on a timely basis.
  • A 'significant deficiency' is a deficiency or combination of deficiencies that, in the auditor's professional judgment, is of sufficient importance to merit the attention of TCWG.
  • Management Letters (or Letters of Internal Control Deficiencies) follow a standard structure detailing the Observed Weakness, Financial/Operational Risk, and Practical Recommendation.
  • Written communications under ISA 265 must state clearly that the audit purpose was to express an opinion on the financial statements, not to express an opinion on the overall effectiveness of internal control.
Last updated: August 2026

3.5 Identifying Control Weaknesses, Limitations & ISA 265 Reporting

Identifying internal control weaknesses is an essential byproduct of a financial statement audit. While the auditor's primary objective under International Standards on Auditing (ISAs) is to render an opinion on the financial statements, ISA 265, Communicating Deficiencies in Internal Control to Those Charged with Governance and Management, establishes clear standards for reporting control deficiencies.

Evaluating Control Deficiencies under ISA 265

During the audit, the auditor performs risk assessment procedures, walkthroughs, and tests of controls. When these procedures reveal flaws in control design or execution, the auditor evaluates their severity.

Definitions under ISA 265

  1. Deficiency in Internal Control: Exists when:
    • A control is designed, implemented, or operated such that it cannot prevent, or detect and correct, misstatements in financial statements on a timely basis; or
    • A control necessary to prevent, or detect and correct, misstatements on a timely basis is missing.
  2. Significant Deficiency in Internal Control: A deficiency or combination of deficiencies in internal control that, in the auditor's professional judgment, is of sufficient importance to merit the attention of Those Charged With Governance (TCWG).

Categorizing Deficiencies: Deficiency vs. Significant Deficiency

Determining whether a control deficiency is "significant" requires professional judgment. Indicators of a significant deficiency include:

  • The likelihood of the deficiency leading to material misstatements in the future.
  • The susceptibility of the related asset or liability to loss or fraud.
  • The volume of activity that has occurred or could occur in the account balance.
  • Identification of senior management fraud (whether or not material).
  • Re-issuance or correction of previously issued financial statements due to material misstatement.
  • Ineffective oversight by TCWG (e.g., Audit Committee failing to meet or review reports).
IndicatorMinor / Operational DeficiencySignificant Control Deficiency
Impact on Financial StatementsLow probability of material errorHigh risk of material misstatement
Reporting RecipientOperational Management / Department HeadsBoard Audit Committee & Board Directors (TCWG)
Reporting FormatVerbal or informal written memoMandatory formal written communication under ISA 265
ExamplePetty cash voucher missing department code stampStorekeeper handles inventory, updates stock ledger, and conducts physical counts single-handedly

Requirements of ISA 265: Written Communication to TCWG

When the auditor identifies one or more significant deficiencies, ISA 265 mandates formal written communication to TCWG in a timely manner (typically prior to or upon approval of financial statements).

Required Contents of the ISA 265 Communication

The written report (commonly called the Management Letter or Letter of Internal Control Weaknesses) must include:

  1. Description of Deficiencies: A clear explanation of each significant deficiency and its potential effects/risks.
  2. Sufficient Context: Explicit statements explaining that:
    • The purpose of the audit was to express an opinion on the financial statements.
    • The audit included consideration of internal control relevant to the preparation of financial statements to design audit procedures, but not for expressing an opinion on the effectiveness of internal control.
    • The matters reported are limited to those deficiencies that the auditor identified during the audit and concluded to be of sufficient importance to merit reporting to TCWG.

Exam Key Point: External auditors do NOT issue a separate public audit opinion on internal controls under standard ISA audits in Bangladesh (unlike US Sarbanes-Oxley 404 requirements), unless specifically required by specialized banking or financial sector regulations.


Structure of a Management Letter (Letter of Control Weaknesses)

A standard ICAB Management Letter formats each identified weakness into a structured three-part format:

  1. WEAKNESS / FINDING: What was observed during audit testing.
  2. RISK / CONSEQUENCE: Potential financial loss, misstatement, or fraud vulnerability.
  3. RECOMMENDATION: Practical remedial step for management implementation.

Example Management Letter Findings (Bangladesh Corporate Audit Context)

RefObserved Weakness / FindingFinancial / Operational RiskAuditor's Recommendation
1Unsegregated Accounts Payable Processing: Accounts payable clerk creates vendor master files and approves vendor payments without independent manager review.Risk of unauthorized vendor creation and fraudulent disbursements leading to financial loss.Restrict vendor creation permissions to HR/Procurement. Require finance manager dual approval for all payments.
2Lack of Physical Stock Reconciliation: Physical inventory count variances at the Chittagong warehouse were not reconciled against general ledger perpetual records.Stock theft or damaged inventory may remain unrecorded, overstating inventory valuation and understating cost of sales.Implement monthly mandatory stock reconciliation reports reviewed and signed off by the Chief Financial Officer (CFO).
3Unrestricted Access to Master Data: System administration passwords for the Tally/SAP ERP software are shared among accounting staff without individual user logging.Inability to establish audit trails for unauthorized transaction alterations or backdated journal entries.Implement individual user accounts, mandatory strong passwords, and automated system audit logging.

Inherent Limitations of Internal Controls & Audit Scope

Auditors must remind management that internal control systems have inherent limitations:

  • Human Error & Carelessness: Misinterpretation of instructions or system input mistakes.
  • Collusion: Circumvention of controls by two or more employees acting together.
  • Management Override: Intentional bypassing of controls by senior leadership to alter financial results.
  • Cost Considerations: The constraint that control implementation costs must not outweigh expected risk-reduction benefits.

ICAB Audit Practice Framework Summary

PhaseAction Required by ICAB Auditor
DiscoveryDocument control deficiencies in audit working papers during walkthroughs or control testing.
EvaluationAssess likelihood and magnitude of misstatements to classify deficiencies.
DraftingDraft Management Letter using Finding-Risk-Recommendation structure.
DiscussionDiscuss draft findings with executive management to verify facts and obtain management responses.
Final IssuanceIssue formal written ISA 265 report to Those Charged With Governance (Audit Committee).
Loading diagram...
ISA 265 Control Deficiency Evaluation & Reporting Workflow
Test Your Knowledge

According to ISA 265, which type of control deficiency MUST be communicated in writing to Those Charged With Governance (TCWG)?

A
B
C
D
Test Your Knowledge

Which three components form the standard structure of an audit finding presented in an external auditor's Management Letter (Letter of Control Weaknesses)?

A
B
C
D
Test Your Knowledge

What mandatory context statement must be included in the written ISA 265 communication provided to Those Charged With Governance?

A
B
C
D