ISA 265 – Communicating Deficiencies in Internal Control to Those Charged with Governance and Management deals with the auditor’s responsibility to communicate appropriately to those charged with governance and management deficiencies in internal control that the auditor has identified in an ‘audit’ of financial statements.
Last Updated – August, 2026

Auditing & Assurance Standards
ISA 265 – Communicating Deficiencies in Internal Control
A practical, paragraph-by-paragraph guide to the auditor’s duty to report control weaknesses to management and those charged with governance; what counts as a deficiency, when it becomes “significant,” and how the communication must be written.
What Is ISA 265? (Overview and Objective)
ISA 265 – Communicating Deficiencies in Internal Control to Those Charged with Governance and Management was introduced through the IAASB’s Clarity Project and became effective for audits of periods beginning on or after 15 December 2009. Before ISA 265, practice varied widely: some firms sent a single management letter at year-end, others said nothing unless asked. The standard replaced that inconsistency with a defined threshold, the significant deficiency and a defined process for reporting it.
To communicate appropriately to those charged with governance and management the deficiencies in internal control that the auditor has identified during the audit and that, in the auditor’s professional judgment, are of sufficient importance to merit their attention.
Key Definitions
Two terms carry the entire standard. Getting them right is the difference between a routine observation and a governance-level red flag.
Exists when a control is designed, implemented, or operated in a way that cannot prevent, or detect and correct, misstatements in the financial statements on a timely basis, or when a control needed to achieve that objective is missing entirely.
A deficiency, or combination of deficiencies, that in the auditor’s professional judgment is important enough to warrant the attention of those charged with governance. There is no fixed dollar threshold; significance is a matter of judgment informed by the likelihood and magnitude of potential misstatement.
Scope of ISA 265 and Effective Date
ISA 265 applies to every audit of financial statements where the auditor has obtained an understanding of internal control and performed procedures on its design or operation, which in practice is nearly every audit conducted under the ISAs. It does not require the auditor to search for deficiencies beyond what is necessary to form the audit opinion; the auditor is not expressing an opinion on the effectiveness of internal control as a whole.
The standard sits alongside three others that shape how much work is done on controls in the first place: ISA 315 (identifying and assessing the risks of material misstatement), ISA 330 (the auditor’s response to assessed risks), and ISA 260 (broader communication with those charged with governance, of which the control-deficiency letter is one component).
Requirements of ISA 265
ISA 265 asks the auditor to do four things, in sequence, for every deficiency noted during the audit:
- Identify deficiencies in internal control while performing risk assessment and further audit procedures.
- Evaluate whether, individually or in combination, they amount to a significant deficiency.
- Communicate significant deficiencies, in writing, to those charged with governance on a timely basis.
- Communicate other deficiencies worth management’s attention, to the appropriate level of management, in writing or orally, on a timely basis.
The auditor also has to explain, within the communication itself, why the exercise happened at all, that the audit included consideration of internal control in order to design appropriate procedures, not to express an opinion on the effectiveness of internal control, and that only the deficiencies identified during that limited scope are being reported.
How ISA 265 Identifies Significant Deficiencies
ISA 265 does not hand the auditor a checklist for what makes a deficiency “significant”, the judgment is deliberately qualitative. The application material does, however, point to recurring factors that experienced auditors weigh together:
- The likelihood that the deficiency could result in a material misstatement in the financial statements.
- The susceptibility to loss or fraud of the related asset or liability.
- The subjectivity and complexity of the amounts affected, including the size of estimates involved.
- The volume of activity exposed to the deficiency, occurring or expected to occur.
- The interaction between the deficiency and other deficiencies, since several minor gaps can combine into one significant one.
- Whether the deficiency touches financial statement close, senior management override, or other high-risk points in the reporting cycle.
Communication Requirements Under ISA 265
ISA 265 is specific about form. A verbal mention in the closing meeting does not satisfy the standard for significant deficiencies, it has to be in writing, and the writing has to do more than list problems. At minimum, the communication should:
- Describe each significant deficiency and explain its potential effects clearly enough for a non-specialist reader to understand the risk.
- Provide sufficient information to let the recipient understand the context of the communication specifically, that the purpose of the audit was to express an opinion on the financial statements, and that internal control was considered only to design appropriate audit procedures.
- State plainly that the audit was not designed to, and does not, express an opinion on the effectiveness of internal control.
- Make clear that the matters reported are limited to those deficiencies the auditor identified during the audit and considered significant enough to warrant attention, not a comprehensive inventory of every control in the organisation.
Where local law, regulation, or the terms of the engagement require it, this communication may need to go to different parties or use a different format, ISA 265 explicitly defers to those requirements rather than overriding them.
Timing and Recipients
“Timely” is the standard’s own word, a significant deficiency reported after the financial statements are issued has lost most of its value to governance. In practice, auditors aim to communicate significant deficiencies no later than the completion of the audit, and often flag urgent matters as soon as they are identified rather than waiting for a single year-end letter.
| Deficiency type | Recipient | Required form |
|---|---|---|
| Significant deficiency | Those charged with governance | In writing, on a timely basis |
| Other deficiency worth attention | Appropriate level of management | In writing or orally, on a timely basis |
| Deficiency implicating management integrity | Those charged with governance directly | In writing, bypassing management as appropriate |
ISA 265 vs Management Letter
Many firms already sent a “management letter” long before ISA 265 existed, so the two are often confused. The management letter was, and largely still is, a matter of firm practice and client service, useful but not mandated by a specific ISA in the way the significant-deficiency communication now is.
| ISA 265 communication | Traditional management letter | |
|---|---|---|
| Basis | Mandatory under a specific ISA | Firm practice / client service, not itself mandated by a single standard |
| Trigger | Significant deficiencies specifically | Any observation worth raising, significant or not |
| Required recipient | Those charged with governance, for significant items | Usually management |
| Content rules | Prescribed minimum content per ISA 265 | Format left to firm judgment |
In practice, many firms combine both purposes into one letter, using ISA 265’s required content for significant deficiencies and adding lower-level observations as supplementary comments, provided the two are clearly distinguished for the reader.
Examples of Internal Control Deficiencies Under ISA 265
The standard is principles-based, so it deliberately avoids a fixed list of “significant” items. That said, certain patterns recur often enough across audits to be worth naming as illustrations, not as an exhaustive catalogue:
- Segregation of duties gaps, one individual able to initiate, approve, and record the same transaction.
- Absent or ineffective reconciliations, particularly of bank accounts, intercompany balances, or subledgers to the general ledger.
- Weak IT access controls, including former employees retaining system access or excessive administrator rights.
- Missing review of manual journal entries, especially those posted directly to the general ledger outside routine processing.
- Inadequate controls over accounting estimates, where assumptions are neither documented nor independently challenged.
- Ineffective monitoring controls, where a control exists on paper but nobody actually reviews the exception reports it produces.
None of these is automatically “significant”, that always depends on the specific facts, the entity’s size, and the likelihood and magnitude of resulting misstatement discussed above.
Frequently Asked Questions
Does ISA 265 require the auditor to look for control deficiencies?
No. The auditor only reports deficiencies identified while performing risk assessment and audit procedures under ISA 315 and ISA 330. ISA 265 does not create a separate obligation to search for weaknesses beyond that scope.
Can a significant deficiency be communicated orally instead of in writing?
No. Significant deficiencies must be communicated in writing. Oral communication is permitted only for other, less significant deficiencies raised with management.
Is the significant-deficiency letter the same as a material weakness report under other frameworks?
They are related concepts but not identical, and terminology varies by jurisdiction and framework. Auditors working under both the ISAs and a local regime, such as US PCAOB standards, need to check both sets of requirements rather than assuming they align exactly.
What happens if a deficiency was reported last year and hasn’t been fixed?
The application material notes the auditor may consider whether previously communicated deficiencies that remain unremediated affect this year’s evaluation of significance, since an uncorrected deficiency can compound in importance over time.
Who has to receive the communication if governance and management are the same people?
In smaller entities this overlap is common. ISA 265 still expects the communication to identify that both roles are being addressed, even where the individuals are the same, so the recipient understands the matter is being raised in their governance capacity as well as their management capacity.

(Qualified) Chartered Accountant – ICAP
Master of Commerce – HEC, Pakistan
Bachelor of Accounting (Honours) – AeU, Malaysia