Audit

SA 265 Internal Control Deficiencies: How Auditors Evaluate and Communicate Findings

A practical SA 265 guide to identifying internal-control deficiencies, assessing significance, deciding who should receive the finding, drafting the written communication and handling repeat issues.

SA 265 Internal Control Deficiencies: How Auditors Evaluate and Communicate Findings

Internal-control findings are easy to describe and harder to classify. An auditor may find that a reconciliation is not reviewed, access rights are too broad, a key approval is missing, or an error reached the ledger without being detected. The SA 265 question is whether the matter is a deficiency in internal control, whether it is significant enough to merit the attention of those charged with governance, who should receive the communication, and what that communication should contain.

ICAI's current standards repository includes SA 265, Communicating Deficiencies in Internal Control to Those Charged with Governance and Management. The official SA 265 text sets out the definitions, significance assessment and communication requirements used in the workflow below.

What counts as a deficiency in internal control?

SA 265 treats a deficiency as existing when a control is designed, implemented or operated in a way that cannot prevent, or detect and correct, financial-statement misstatements on a timely basis, or when a necessary control is missing. A finding can therefore arise from bad design, failed operation or absence of a control.

A significant deficiency is not defined by a fixed rupee threshold. It is a deficiency, or combination of deficiencies, that in the auditor's professional judgment is important enough to merit the attention of those charged with governance. A control failure can therefore be significant even when no actual misstatement has been found.

Do not confuse SA 265 with an opinion on internal controls

In a financial-statement audit, the auditor considers internal control to assess risk and design audit procedures. SA 265 makes clear that this consideration is not, by itself, performed to express an opinion on the effectiveness of internal control. The communication is limited to deficiencies identified during the audit that the auditor concludes should be reported.

A practical SA 265 evaluation workflow

1. Describe the control objective and actual failure

Avoid vague wording such as controls are weak. State what the control should achieve, what was missing or failed, how the exception was identified, and which financial-statement risk or assertion may be affected.

2. Assess significance using likelihood and potential magnitude

SA 265 says significance depends not only on whether a misstatement occurred, but also on the likelihood that one could occur and its potential magnitude. Relevant factors can include susceptibility to loss or fraud, subjectivity of estimates, financial-statement amounts exposed, transaction volume, importance of the control to financial reporting, cause and frequency of exceptions, and interaction with other deficiencies.

Controls over fraud prevention, significant accounting policies, related-party transactions, unusual transactions and period-end reporting deserve close attention. Several smaller weaknesses affecting the same process may also create a more serious combined risk.

3. Decide who must receive the communication

Significant deficiencies identified during the audit must be communicated in writing to those charged with governance on a timely basis. They must also be communicated to management at an appropriate level of responsibility, ordinarily in writing, unless direct communication to management would be inappropriate.

Other deficiencies that are not significant may still merit management's attention. SA 265 allows those other matters to be communicated orally in appropriate circumstances. The recipient should have enough responsibility and authority to evaluate the matter and take remedial action.

4. Write the finding so the reader can act on it

For significant deficiencies, the written communication must describe the deficiency and explain its potential effects. It must also give enough context for recipients to understand that the audit was designed to express an opinion on the financial statements, that internal control was considered to design audit procedures rather than to express an opinion on control effectiveness, and that the matters reported are limited to deficiencies identified during the audit that were considered important enough to report.

SA 265 does not require the auditor to quantify the potential effects. Where useful, the auditor may include suggested remedial action, management's actual or proposed response, and whether implementation was verified.

Worked example: vendor-master change controls

Assume a company allows changes to vendor bank details without independent approval. During testing, the audit team also finds one payment made to an incorrect bank account and later recovered. The auditor should not jump directly from the exception to a label of significant deficiency.

  1. Define the deficiency: the vendor-master process lacks independent approval over bank-detail changes.
  2. Identify the exposure: unauthorised changes could redirect payments and create fraud or misstatement risk.
  3. Assess significance: consider payment values, transaction volume, user access, frequency of vendor changes, compensating controls, prior incidents and related deficiencies.
  4. Decide recipients: if the matter is significant, communicate it in writing to those charged with governance and appropriate management unless that is inappropriate.
  5. Explain potential effects: describe the risk without implying that a loss is certain or inventing an unsupported monetary exposure.

SA 265 does not create a universal rule that every vendor-master weakness is significant. Classification depends on the facts and professional judgment.

Smaller entities still require a real significance assessment

Smaller entities may have less formal controls and limited segregation of duties. SA 265 recognises that owner-manager oversight can sometimes compensate, but also notes the potential for management override. A finding should therefore be evaluated in the entity's actual governance and control context, not downgraded merely because the business is small.

How to handle repeat findings

A significant deficiency communicated in a previous audit must be communicated again if remedial action has not been taken. SA 265 also notes that failure to act without a rational explanation may itself represent a significant deficiency.

For previously reported deficiencies that were not significant, repetition is not always required. Re-communication may still be appropriate if management changes, new information changes the prior understanding, or the unresolved deficiency becomes significant in the current circumstances.

Common SA 265 mistakes

  • Writing generic observations without linking them to a control objective and financial-reporting risk.
  • Calling every control exception significant without considering likelihood, magnitude and surrounding controls.
  • Assuming no misstatement means no significant deficiency.
  • Sending significant findings only to operational management and omitting those charged with governance.
  • Communicating a significant deficiency orally but never completing the required written communication.
  • Implying that the financial-statement audit provides an opinion on internal-control effectiveness.
  • Ignoring combinations of smaller deficiencies affecting the same balance, assertion or reporting process.

SA 265 working-paper checklist

  1. Document the process, control objective and identified deficiency.
  2. Identify the affected account, disclosure, assertion or reporting risk.
  3. Evaluate likelihood, potential magnitude, fraud susceptibility, transaction volume and other relevant factors.
  4. Consider whether multiple deficiencies combine into a significant deficiency.
  5. Record the professional judgment supporting the classification.
  6. Identify the appropriate management level and those charged with governance.
  7. For significant deficiencies, prepare a timely written communication describing the matter, potential effects and audit-scope context.
  8. Track prior-year significant deficiencies and remedial action.

Practical takeaway

SA 265 works best as a disciplined judgment process: identify the control failure precisely, assess its likelihood and potential reporting impact, consider related deficiencies, classify its significance, communicate it to the right people in the right form, and document why that conclusion was reached. A strong control-deficiency memo helps governance understand the risk without overstating what the auditor tested or what the finding proves.

Related Articles

Subscribe To Our Newsletter

Subscribe us to get updates on latest Jobs Openings, News, Articles, Notices/ Circulars

Submit

© 2026 CA Samaaj. All rights reserved.

Join Whatsapp Group of CA Samaaj