SOX ITGC Deficiencies: When One Becomes a Material Weakness
An IT general control failure becomes a material weakness when there is a reasonable possibility that it will let a material misstatement of your financial statements go unprevented or undetected, and PCAOB AS 2201 sets that bar lower than most first-time issuers expect: Appendix A says there is a reasonable possibility of an event "when the likelihood of the event is either 'reasonably possible' or 'probable,' as those terms are used in Financial Accounting Standards Board Statement No. 5". Not likely. Reasonably possible. Paragraph .64 then removes the comfort teams reach for first: "The severity of a deficiency does not depend on whether a misstatement actually has occurred but rather on whether there is a reasonable possibility that the company's controls will fail to prevent or detect a misstatement." So both sentences we hear in the week after fieldwork are wrong: "nothing was misstated, so it cannot be a material weakness", and "the access review failed, so it is one".
What follows is that evaluation in the order it is performed, and what each landing spot obliges you to do.
Key takeaways
- The threshold is a reasonable possibility of material misstatement, which AS 2201 ties to "reasonably possible" or "probable", not to what happened.
- An ITGC deficiency is judged through the controls that depend on it, which is why one finding lands two rungs apart at two companies.
- Compensating controls reduce severity only at a precision that would catch a misstatement that could be material. Most of the ones offered do not.
- Four indicators in .69, plus the prudent official test in .70, end the argument whichever way the likelihood analysis was trending.
- The rung sets obligations: a material weakness bars an effective ICFR conclusion, and a significant deficiency still reaches your auditors and audit committee.
The three rungs, and who defines them
There are three, and only two are defined in regulation.
A control deficiency is the base state: the control does not operate as designed, or its design would not achieve the objective even if it did. Most findings never leave this rung.
A significant deficiency is defined in Exchange Act Rule 12b-2 as "a deficiency, or a combination of deficiencies, in internal control over financial reporting that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight of the registrant's financial reporting." AS 2201 carries the same words at .A11.
A material weakness is defined in that same rule as "a deficiency, or a combination of deficiencies, in internal control over financial reporting such that there is a reasonable possibility that a material misstatement of the registrant's annual or interim financial statements will not be prevented or detected on a timely basis." AS 2201 .A7 matches it.
Read the middle definition again: it has no independent test. It is defined downward from material weakness and upward from "worth the audit committee's attention". The only technical judgment in the ladder is therefore the material weakness judgment; everything under it is a question about audience. Teams arguing for a week over deficiency versus significant deficiency are arguing about who gets told.
Severity is likelihood and magnitude, not whether anything broke
AS 2201 .62 tells the auditor to evaluate the severity of each deficiency "to determine whether the deficiencies, individually or in combination, are material weaknesses as of the date of management's assessment". Paragraph .63 gives severity two inputs and only two: whether there is a reasonable possibility that controls will fail to prevent or detect a misstatement of an account balance or disclosure, and the magnitude of that misstatement.
Magnitude is the input teams underuse. Paragraph .66 points at the financial statement amounts or total of transactions exposed to the deficiency, and at the volume of activity in that account balance or class of transactions. That is a scoping question wearing a severity costume, and it is where a defensible argument usually lives. A change management gap in the system that calculates revenue for the whole book is exposed to the whole book; the same gap in a system touching one immaterial accrual is exposed to that accrual. Same control, same failure rate, different severity, and the difference is arithmetic, not opinion.
The trap is .64. Because severity does not turn on whether a misstatement occurred, "we reconciled and the numbers were right" is not a defense; it is evidence about outcome offered in a test about possibility. Retire it before you make it in front of your audit committee.
Why an ITGC finding is judged by what depends on it
IT general controls do not produce line items. They make other things trustworthy. AS 2110 .B1 says it plainly, requiring the auditor to understand the extent of manual and automated controls "including the IT general controls that are important to the effective operations of the automated controls." AS 2201 .47 works the same seam from the risk side: an automated control "would generally be expected to be lower risk if relevant information technology general controls are effective."
Invert that and you have the evaluation. If the ITGCs are weak, the automated controls above them stop being lower risk, and every conclusion that leaned on them has to be re-earned. The question is never "how bad is this access failure". It is what the failure let someone do to a record that matters, and what else relied on it.
That is why an unmonitored privileged account with write access to the general ledger is a different animal from an orphaned read-only account in a reporting tool, though both are the same offboarding miss on the same report. A smaller dependency graph is a smaller exposure, and drawing it before the finding arrives is most of the work. It sits inside the scoping in our SOX ITGC guide for first-time issuers.
Compensating controls, and the precision test
AS 2201 .68 requires the auditor to "evaluate the effect of compensating controls when determining whether a control deficiency or combination of deficiencies is a material weakness", then sets the bar: "To have a mitigating effect, the compensating control should operate at a level of precision that would prevent or detect a misstatement that could be material."
Precision is the entire sentence. A monthly management review of the financial statements is not precise; it surfaces nothing below the reviewer's own tolerance, which sits above materiality for a single account. A monthly reconciliation of the ledger to a subledger, run by someone independent of the people holding the excessive access, investigated to a stated threshold and documented, is precise, and precise about the thing the ITGC failure put at risk.
Three ways the argument fails:
- Same people. The compensating control is performed by the group whose over-broad access created the finding. It compensates for nothing.
- No evidence. The control is real, it happens, and nobody can produce a dated artifact showing it happened in the periods that matter. An untestable control cannot mitigate a tested one.
- Precise about the wrong thing. The finding is unauthorised program changes and the offered compensator is a cash reconciliation. It catches a class of problem, just not this class.
Before the meeting, write down what misstatement the failure could produce, then name the control that would catch it below materiality. If you cannot write the first sentence, you do not have a compensating control argument.
Four indicators that end the argument
Paragraph .69 lists indicators of material weaknesses, and they behave differently from the likelihood analysis: when one is present, the analysis stops trending and starts concluding. They are identification of fraud, whether or not material, on the part of senior management; restatement of previously issued financial statements to correct a material misstatement; identification by the auditor of a material misstatement in the current period that internal control would not have detected; and ineffective oversight of financial reporting and internal control by the audit committee.
The third is the ITGC killer. If your auditor finds a material misstatement through their own substantive work and your controls would not have caught it, the elegance of your control design stops being the subject.
Paragraph .70 is the backstop: if a deficiency "might prevent prudent officials in the conduct of their own affairs from concluding that they have reasonable assurance that transactions are recorded as necessary to permit the preparation of financial statements in conformity with generally accepted accounting principles", the auditor treats it as an indicator of a material weakness. That is the standard's own defense against clever arithmetic.
What each rung obliges you to do
The rung is not a label. It attaches consequences.
Material weakness. Item 308 of Regulation S-K requires management's annual report on internal control over financial reporting to carry its assessment of effectiveness, and states that "Management is not permitted to conclude that the registrant's internal control over financial reporting is effective if there are one or more material weaknesses". No partial credit, no "effective except for". That runs off management's own assessment, so it does not wait on an auditor: the attestation has statutory carve-outs and the assessment does not.
Significant deficiency. Nothing enters the annual report, which is where most teams stop reading. The Section 302 certification your CEO and CFO sign, prescribed at Item 601(b)(31)(i), has them state they have disclosed to the registrant's auditors and to the audit committee "All significant deficiencies and material weaknesses in the design or operation of internal control over financial reporting which are reasonably likely to adversely affect the registrant's ability to record, process, summarize and report financial information". A significant deficiency that IT logged as a ticket and never escalated is a certification problem sitting under two signatures.
Control deficiency. Track it, fix it, and keep the record, because of aggregation: AS 2201 judges deficiencies individually or in combination, and several affecting the same account balance or disclosure raise the likelihood of misstatement and may together be a material weakness. Five separately unremarkable access findings in one revenue system are one argument you have not had yet.
Where this reasoning runs out
This is the auditor's framework, and before a 404(b) attestation applies, the person running it is you. No process removes that conflict; the mitigation is having someone outside the reporting line, usually the audit committee, review severity conclusions before they are final.
Severity is judged as of the date of management's assessment, so a control fixed in November was still deficient before it. Whether it can be called effective at year end depends on whether it operated long enough to be tested, which is the same population arithmetic as how audit sampling works. A monthly control repaired in week fifty leaves one occurrence to test.
And none of this substitutes for your auditor's judgment on your facts. Where your read and theirs diverge, put your likelihood and magnitude analysis in writing and ask which input they see differently.
Where Top Floor fits
The work that benefits from outside help is narrow: mapping the dependency graph so a finding can be sized against what relies on it, building compensating control arguments that survive the precision test in .68, and writing the severity analysis before the auditor conversation rather than during it. That is SOX readiness and ITGC work, alongside broader audit readiness where frameworks share evidence, and fractional security leadership where nobody internal is senior enough to hold a line with an audit committee.
Now the part against our own interest. Do not buy the severity conclusion. It belongs to management, your CEO and CFO certify it, and an outside memo transfers none of it. If you have a controller who understands the account exposure and a head of IT who can produce the dependency map, you already have the two people the analysis requires; a third opinion mostly buys reassurance.
Two more cases for keeping your money. If the finding is one control in one system with a small, provable transaction exposure, size it against .63 and .66 yourself and take it to your auditor; that is an afternoon, not an engagement. And if a national firm already runs your audit readiness beside a separate auditor, adding a boutique to the same conversation adds a voice, not a capability. For programme cost, model your own scope in the budget planner rather than adopting anyone's average, ours included.
How to decide this week
1. Write the misstatement sentence. For each open finding, finish this in one line: "this deficiency could allow ... to be recorded incorrectly in ...". If nobody can finish it, you have a hygiene issue, not a financial reporting one.
2. Size the exposure. Pull the transaction volume and balance for the accounts that sentence names. That is the .66 input, and the one you can get right without judgment.
3. Test the compensating control for precision, not existence. What size of misstatement would it reliably catch, and is the evidence dated and independent?
4. Check the .69 indicators before concluding anything. Any one of them and the conclusion is made for you.
Then put all four on one page per finding and send it to your auditor before they ask. As of August 2026, the fastest way to make a bad finding worse is still to arrive with a position and no analysis: the auditor builds one instead, on their assumptions and their timetable, and you spend a quarter arguing with a document you did not write.
Frequently asked questions
Is a failed user access review a material weakness?
Not by itself. Severity depends on the reasonable possibility of a material misstatement and on its magnitude, per AS 2201 .63, so the answer turns on what the access could have done to financial records and how much money moved through the exposed accounts. Size it against .63 and .66, test any compensating control for precision, and check the .69 indicators.
What is the difference between a significant deficiency and a material weakness?
A material weakness creates a reasonable possibility that a material misstatement will not be prevented or detected on a timely basis. A significant deficiency is defined in Exchange Act Rule 12b-2 as less severe than that, "yet important enough to merit attention by those responsible for oversight". The lower rung has no independent threshold of its own: it is defined relative to material weakness above and audit committee attention below. So the only technical judgment is the material weakness judgment, and the rung beneath it is about who needs to be told.
Do we have to disclose a significant deficiency publicly?
No. Item 308 of Regulation S-K carries the disclosure consequences of a material weakness and does not require public disclosure of significant deficiencies. They are not private, though. The Section 302 certification form at Item 601(b)(31)(i) has the certifying officers state that they have disclosed to the auditors and the audit committee all significant deficiencies and material weaknesses reasonably likely to adversely affect the ability to record, process, summarize and report financial information. An unescalated one stops being an IT problem and becomes a certification problem.
Does a material weakness go away once we fix the control?
Not on the date of the fix. Severity is evaluated as of the date of management's assessment, so a control deficient for most of the year does not become effective retroactively when it is remediated in the fourth quarter. Whether it can be concluded effective at the assessment date turns on whether it produced enough testable occurrences by then, which is why a monthly control repaired in March and one repaired in December leave you in different positions. Plan remediation backwards from the assessment date.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.