Welcome to Communication on Internal Control!

Hi there! Welcome to one of the most practical and "real-world" parts of the Audit and Assurance (AA) exam. Think of yourself not just as an auditor checking boxes, but as a professional advisor. During an audit, you will inevitably find things that aren't working quite right in a company’s systems. This chapter is all about how you tell the "bosses" about those problems.

Understanding this is vital because, in the AA exam, you are almost always asked to identify internal control deficiencies and provide recommendations. Learning the formal communication rules helps you structure your exam answers perfectly!

1. The Basics: What is ISA 265?

Everything we discuss here is guided by ISA 265: Communicating Deficiencies in Internal Control to Those Charged with Governance and Management. This standard tells the auditor exactly what their responsibilities are when they find a "hole" in the client's internal control system.

Who are we talking to?

In the world of ACCA, we distinguish between two groups:

1. Those Charged with Governance (TCWG): These are the "big bosses," usually the Board of Directors or the Audit Committee. They oversee the strategic direction and accountability of the entity.
2. Management: These are the people running the business day-to-day. They are responsible for actually implementing and maintaining the controls.

Analogy: Imagine a restaurant. The Management is the Restaurant Manager who makes sure the kitchen is clean every day. TCWG are the owners of the restaurant chain who make sure the manager is doing their job properly.

2. Deficiency vs. Significant Deficiency

Don't worry if these terms sound similar; there is a specific threshold you need to know. Not every tiny error needs to be reported to the top bosses.

What is a Deficiency?

A deficiency exists when a control is designed or operated in a way that it fails to prevent, or detect and correct, misstatements in the financial statements on a timely basis. It also exists if a necessary control is simply missing.

What makes it "Significant"?

A significant deficiency is a deficiency (or a combination of deficiencies) that, in the auditor’s professional judgment, is important enough to merit the attention of Those Charged with Governance (TCWG).

How do we decide if it’s significant?
The auditor considers:
• The likelihood of the deficiency leading to a material misstatement.
• The susceptibility to loss or fraud of the related asset.
• The subjectivity and complexity of determining estimated amounts.
• The financial statement amounts exposed to the deficiency.

Quick Review: If it's a minor slip-up, tell management. If it's a big deal that could lead to huge errors or fraud, it’s "significant" and must go to TCWG.

3. The Communication Process

How and when do we tell the client about these issues?

The Timeline

The auditor must communicate significant deficiencies in writing to TCWG on a timely basis. This usually happens at the end of the audit, but if a deficiency is very serious (like finding out the safe is left unlocked every night!), the auditor should report it immediately.

The Format: The "Letter of Weakness"

Significant deficiencies must be communicated in writing. This document is often called a Management Letter or a Letter of Weakness. For the exam, you should remember the "OCR" structure for describing a deficiency:

O - Observation: Describe what is wrong (e.g., "The warehouse is left unlocked at night").
C - Consequence: Explain what could go wrong because of this (e.g., "Inventory could be stolen, leading to a material misstatement of assets").
R - Recommendation: Tell them how to fix it (e.g., "The warehouse should be locked, and access logs should be maintained").

Did you know? Using the OCR structure in your exam is the best way to score full marks in the "Internal Control" constructive response questions!

4. What Must Be Included in the Written Communication?

According to ISA 265, the written report to TCWG must include:

1. A description of the deficiencies and an explanation of their potential effects (The "O" and "C" from our OCR above).
2. Sufficient information to allow TCWG and management to understand the context of the communication.

Specifically, the auditor must explain that:
• The purpose of the audit was to express an opinion on the financial statements.
• The audit included consideration of internal control only to design audit procedures, not to express an opinion on the effectiveness of internal control.
• The matters being reported are limited only to those the auditor identified during the audit.

Why do we say this? Because we don't want the client to think we checked every single control. We only checked enough to do our audit! This protects the auditor from being blamed if a different, unspotted control fails later.

5. Common Mistakes to Avoid

Confusing the audience: Remember, significant deficiencies go to TCWG. Lesser deficiencies go to management.
Vague Recommendations: In the exam, don't just say "Fix the system." Be specific, like "Implement a password policy requiring at least 8 characters."
Forgetting the "So What?": When describing a deficiency, always explain the consequence. If you don't say why it matters (e.g., "This could lead to fraud"), you won't get the full marks.

Summary Checklist

Key Takeaways:
ISA 265 is the rulebook for reporting control issues.
Significant deficiencies must be reported in writing to TCWG.
• Use the OCR (Observation, Consequence, Recommendation) approach.
• Always include a disclaimer that the audit is not designed to find every control weakness.
• Communication should be timely.

Don't worry if this seems a bit formal at first. Just remember: see a problem, explain why it's a problem, and suggest a fix. You've got this!