3.5 Identifying Control Weaknesses, Limitations & ISA 265 Reporting
Key Takeaways
- ISA 265 requires external auditors to communicate in writing significant deficiencies in internal control identified during the audit to Those Charged With Governance (TCWG) and management.
- A deficiency in internal control exists when a control is designed, implemented, or operated in such a way that it fails to prevent, or detect and correct, misstatements in the financial statements on a timely basis.
- A 'significant deficiency' is a deficiency or combination of deficiencies that, in the auditor's professional judgment, is of sufficient importance to merit the attention of TCWG.
- Management Letters (or Letters of Internal Control Deficiencies) follow a standard structure detailing the Observed Weakness, Financial/Operational Risk, and Practical Recommendation.
- Written communications under ISA 265 must state clearly that the audit purpose was to express an opinion on the financial statements, not to express an opinion on the overall effectiveness of internal control.
3.5 Identifying Control Weaknesses, Limitations & ISA 265 Reporting
Identifying internal control weaknesses is an essential byproduct of a financial statement audit. While the auditor's primary objective under International Standards on Auditing (ISAs) is to render an opinion on the financial statements, ISA 265, Communicating Deficiencies in Internal Control to Those Charged with Governance and Management, establishes clear standards for reporting control deficiencies.
Evaluating Control Deficiencies under ISA 265
During the audit, the auditor performs risk assessment procedures, walkthroughs, and tests of controls. When these procedures reveal flaws in control design or execution, the auditor evaluates their severity.
Definitions under ISA 265
- Deficiency in Internal Control: Exists when:
- A control is designed, implemented, or operated such that it cannot prevent, or detect and correct, misstatements in financial statements on a timely basis; or
- A control necessary to prevent, or detect and correct, misstatements on a timely basis is missing.
- Significant Deficiency in Internal Control: A deficiency or combination of deficiencies in internal control that, in the auditor's professional judgment, is of sufficient importance to merit the attention of Those Charged With Governance (TCWG).
Categorizing Deficiencies: Deficiency vs. Significant Deficiency
Determining whether a control deficiency is "significant" requires professional judgment. Indicators of a significant deficiency include:
- The likelihood of the deficiency leading to material misstatements in the future.
- The susceptibility of the related asset or liability to loss or fraud.
- The volume of activity that has occurred or could occur in the account balance.
- Identification of senior management fraud (whether or not material).
- Re-issuance or correction of previously issued financial statements due to material misstatement.
- Ineffective oversight by TCWG (e.g., Audit Committee failing to meet or review reports).
| Indicator | Minor / Operational Deficiency | Significant Control Deficiency |
|---|---|---|
| Impact on Financial Statements | Low probability of material error | High risk of material misstatement |
| Reporting Recipient | Operational Management / Department Heads | Board Audit Committee & Board Directors (TCWG) |
| Reporting Format | Verbal or informal written memo | Mandatory formal written communication under ISA 265 |
| Example | Petty cash voucher missing department code stamp | Storekeeper handles inventory, updates stock ledger, and conducts physical counts single-handedly |
Requirements of ISA 265: Written Communication to TCWG
When the auditor identifies one or more significant deficiencies, ISA 265 mandates formal written communication to TCWG in a timely manner (typically prior to or upon approval of financial statements).
Required Contents of the ISA 265 Communication
The written report (commonly called the Management Letter or Letter of Internal Control Weaknesses) must include:
- Description of Deficiencies: A clear explanation of each significant deficiency and its potential effects/risks.
- Sufficient Context: Explicit statements explaining that:
- The purpose of the audit was to express an opinion on the financial statements.
- The audit included consideration of internal control relevant to the preparation of financial statements to design audit procedures, but not for expressing an opinion on the effectiveness of internal control.
- The matters reported are limited to those deficiencies that the auditor identified during the audit and concluded to be of sufficient importance to merit reporting to TCWG.
Exam Key Point: External auditors do NOT issue a separate public audit opinion on internal controls under standard ISA audits in Bangladesh (unlike US Sarbanes-Oxley 404 requirements), unless specifically required by specialized banking or financial sector regulations.
Structure of a Management Letter (Letter of Control Weaknesses)
A standard ICAB Management Letter formats each identified weakness into a structured three-part format:
- WEAKNESS / FINDING: What was observed during audit testing.
- RISK / CONSEQUENCE: Potential financial loss, misstatement, or fraud vulnerability.
- RECOMMENDATION: Practical remedial step for management implementation.
Example Management Letter Findings (Bangladesh Corporate Audit Context)
| Ref | Observed Weakness / Finding | Financial / Operational Risk | Auditor's Recommendation |
|---|---|---|---|
| 1 | Unsegregated Accounts Payable Processing: Accounts payable clerk creates vendor master files and approves vendor payments without independent manager review. | Risk of unauthorized vendor creation and fraudulent disbursements leading to financial loss. | Restrict vendor creation permissions to HR/Procurement. Require finance manager dual approval for all payments. |
| 2 | Lack of Physical Stock Reconciliation: Physical inventory count variances at the Chittagong warehouse were not reconciled against general ledger perpetual records. | Stock theft or damaged inventory may remain unrecorded, overstating inventory valuation and understating cost of sales. | Implement monthly mandatory stock reconciliation reports reviewed and signed off by the Chief Financial Officer (CFO). |
| 3 | Unrestricted Access to Master Data: System administration passwords for the Tally/SAP ERP software are shared among accounting staff without individual user logging. | Inability to establish audit trails for unauthorized transaction alterations or backdated journal entries. | Implement individual user accounts, mandatory strong passwords, and automated system audit logging. |
Inherent Limitations of Internal Controls & Audit Scope
Auditors must remind management that internal control systems have inherent limitations:
- Human Error & Carelessness: Misinterpretation of instructions or system input mistakes.
- Collusion: Circumvention of controls by two or more employees acting together.
- Management Override: Intentional bypassing of controls by senior leadership to alter financial results.
- Cost Considerations: The constraint that control implementation costs must not outweigh expected risk-reduction benefits.
ICAB Audit Practice Framework Summary
| Phase | Action Required by ICAB Auditor |
|---|---|
| Discovery | Document control deficiencies in audit working papers during walkthroughs or control testing. |
| Evaluation | Assess likelihood and magnitude of misstatements to classify deficiencies. |
| Drafting | Draft Management Letter using Finding-Risk-Recommendation structure. |
| Discussion | Discuss draft findings with executive management to verify facts and obtain management responses. |
| Final Issuance | Issue formal written ISA 265 report to Those Charged With Governance (Audit Committee). |
According to ISA 265, which type of control deficiency MUST be communicated in writing to Those Charged With Governance (TCWG)?
Which three components form the standard structure of an audit finding presented in an external auditor's Management Letter (Letter of Control Weaknesses)?
What mandatory context statement must be included in the written ISA 265 communication provided to Those Charged With Governance?