CORAA
Resources · Internal Audit Reporting

Internal audit deficiency evaluation.

A weak control finding is not finished when someone chooses High, Medium or Low. Internal audit should evaluate whether the issue is a design gap, operating failure, repeat deficiency, aggregation matter, accepted residual risk or committee-reportable weakness.

Open rating matrixOpen IFC readiness
Downloads

Deficiency evaluation pack workbook

Download the Excel/PDF pack for deficiency classification, aggregation, escalation, workpaper fields, remediation route and workflow handoff.

Decision steps

Evaluate before rating sequence

Define the failed objective

State the risk, assertion, policy requirement, compliance obligation or governance expectation the control was meant to address.

Classify design vs operation

Separate a missing/weak control design from a control that exists but failed, was late, unsupported or not reviewed.

Measure exposure and likelihood

Assess value, population, frequency, stakeholder impact, compliance exposure, fraud pathway and probability of recurrence.

Check compensating controls

Identify whether another control prevents or detects the same risk with reliable evidence and timely owner review.

Aggregate related issues

Combine similar deficiencies across cycles, locations, systems, owners, vendors or periods before final severity.

Conclude and route

Assign rating, management action, retest plan, accepted-risk status and reporting route to senior management or Audit Committee.

Rating logic

Use precise deficiency labels labels

Internal audit uses these labels to flag indicators for management readiness, remediation and internal reporting. Statutory conclusions remain with management, the Board and the statutory auditor as applicable.

Design deficiency

Control is missing, too weak, not assigned, not frequent enough, or cannot address the stated risk even if performed.

Operating deficiency

Control is designed but failed in operation, lacked evidence, was bypassed, performed late or reviewed by the wrong person.

Repeat deficiency

The same weakness reappears after prior closure, or the same root cause affects multiple observations.

Significant deficiency indicator

A weakness important enough for governance attention because of exposure, frequency, recurrence, control reliance or compliance impact.

Material weakness indicator

A deficiency or combination of deficiencies may create a reasonable possibility of material misstatement not being prevented or detected.

Scope limitation

Internal audit cannot evaluate the control because evidence, population, access or management representation is unavailable.

Aggregation

Small issues can become one larger weakness combine

Same root cause

Multiple observations point to the same ownership, system, policy, training, approval or monitoring breakdown.

Same financial assertion

Weaknesses affect completeness, accuracy, cut-off, existence, valuation, rights/obligations or presentation in one reporting area.

Same system dependency

Several process failures rely on the same report, access role, workflow, interface, job or master-data field.

Same owner or location

Issues cluster under one process owner, shared service centre, branch, plant, project or outsourced provider.

Same fraud pathway

Different exceptions create one route for override, false billing, ghost employee, duplicate payment or unauthorised change.

Same governance consequence

Combined issues could change committee reporting, statutory audit coordination, management representation or accepted-risk treatment.

Escalation

When rating is not enough route

High exposure or legal impact

Escalate when rupee value, regulatory consequence, fraud exposure or stakeholder impact exceeds management-level tolerance.

Repeat after closure

Escalate when prior remediation was accepted but the same control, owner or root cause failed again.

No reliable compensating control

Escalate when management relies on informal review, verbal confirmation or after-the-fact clean-up.

Management disagrees with rating

Preserve both management response and internal audit view; route disagreement to the agreed governance forum.

Evidence is blocked

Escalate source-report, access, population or evidence limitations before the report is softened.

Residual risk is accepted

Route accepted risk to the accepted-risk register with authority, expiry, compensating controls and committee flag.

Workpaper fields

What the file should retain evidence

Observation ID

Unique reference tied to RCM test, sample, monitoring rule, walkthrough or committee action.

Deficiency type

Design deficiency, operating deficiency, repeat deficiency, significant deficiency, material weakness indicator or scope limitation.

Risk and assertion

Risk statement, assertion/control objective, affected process and financial/compliance exposure.

Evidence basis

Population, sample, exception count, screenshots, reports, approvals, logs and reviewer conclusion.

Aggregation link

Related observations, same root cause, same system dependency, same owner or combined governance impact.

Compensating controls

Alternate control, owner, frequency, evidence and whether it actually mitigates the same risk.

Final rating rationale

Why the issue is High/Medium/Low or a significant-deficiency/material-weakness indicator in context, including override if used.

Action and retest route

Owner, due date, remediation design, closure evidence, retest plan, accepted-risk status and escalation route.

Product reuse

Reusable product fields workflow

ArtifactModuleLikely fields
Deficiency evaluatorObservation workflowType, severity, exposure, recurrence, compensating control, aggregation and override rationale.
Aggregation engineRisk analyticsRoot cause, owner, system, assertion, cycle, location and fraud-pathway clustering.
Escalation routerGovernance workflowRating, blocked evidence, management disagreement, repeat status, accepted risk and committee flag.
Retest plannerATR workflowAction design, closure evidence, retest period, sample basis, result and repeat-finding status.
Dashboard metricCommand centreOpen deficiencies, repeats, significant items, material indicators, accepted risks and overdue remediation.
Related resources

Use this with ratings, IFC and remediation next

IFC / ICFR Controls Readiness

Use deficiency logic when financial-reporting controls fail readiness testing.

Issue Rating Matrix Generator

Score impact, likelihood, recurrence, control weakness and compliance sensitivity.

Control Design Gap Register

Capture missing or weak controls before they become operating-test failures.

Root Cause & Remediation Plan

Turn deficiencies into owner-led, retestable action plans.

Closure Evidence & Retesting Checklist

Retest remediated deficiencies before accepting closure or residual risk.

Risk Acceptance & Escalation Register

Route accepted residual risk with authority, expiry and committee visibility.

Audit Committee Reporting Pack

Escalate significant deficiencies, repeats, limitations and accepted risk.

FAQ

Common questions answers

What is a deficiency in internal audit?

A deficiency is a control weakness, missing control, failed control, unsupported control, delayed review, evidence limitation or governance gap that prevents internal audit from concluding the risk is properly controlled.

How should internal audit distinguish design deficiency from operating deficiency?

A design deficiency means the control is absent or incapable of addressing the risk. An operating deficiency means the control exists but did not operate as designed, was late, unsupported, bypassed or reviewed inadequately.

When should deficiencies be aggregated?

Deficiencies should be aggregated when they share root cause, owner, system dependency, assertion, location, fraud pathway or governance consequence. Aggregation prevents several medium issues from hiding one larger control failure.

Does internal audit decide whether an IFC weakness is a material weakness?

Internal audit can classify indicators for management readiness and internal reporting, but statutory audit conclusions remain with the statutory auditor and management/Board reporting remains under the Companies Act framework as applicable.