ISA 265 – Communicating Deficiencies in Internal Control to Those Charged with Governance and Management

ISA 265 – Communicating Deficiencies in Internal Control to Those Charged with Governance and Management deals with the auditor’s responsibility to communicate appropriately to those charged with governance and management deficiencies in internal control that the auditor has identified in an ‘audit’ of financial statements.

Last Updated – August, 2026

ISA 265
International Standard on Auditing · IAASB Clarified Standards

Auditing & Assurance Standards

ISA 265 – Communicating Deficiencies in Internal Control

A practical, paragraph-by-paragraph guide to the auditor’s duty to report control weaknesses to management and those charged with governance; what counts as a deficiency, when it becomes “significant,” and how the communication must be written.

Standard
ISA 265
Issuing Body
IAASB
Effective For
Periods beginning on/after 15 Dec 2009
Category
Reporting & Communication
Related
ISA 260, ISA 315, ISA 330
01

What Is ISA 265? (Overview and Objective)

ISA 265 – Communicating Deficiencies in Internal Control to Those Charged with Governance and Management was introduced through the IAASB’s Clarity Project and became effective for audits of periods beginning on or after 15 December 2009. Before ISA 265, practice varied widely: some firms sent a single management letter at year-end, others said nothing unless asked. The standard replaced that inconsistency with a defined threshold, the significant deficiency and a defined process for reporting it.

Objective, in the standard’s own structure

To communicate appropriately to those charged with governance and management the deficiencies in internal control that the auditor has identified during the audit and that, in the auditor’s professional judgment, are of sufficient importance to merit their attention.

02

Key Definitions

Two terms carry the entire standard. Getting them right is the difference between a routine observation and a governance-level red flag.

Deficiency in internal control

Exists when a control is designed, implemented, or operated in a way that cannot prevent, or detect and correct, misstatements in the financial statements on a timely basis, or when a control needed to achieve that objective is missing entirely.

Significant deficiency in internal control

A deficiency, or combination of deficiencies, that in the auditor’s professional judgment is important enough to warrant the attention of those charged with governance. There is no fixed dollar threshold; significance is a matter of judgment informed by the likelihood and magnitude of potential misstatement.

03

Scope of ISA 265 and Effective Date

ISA 265 applies to every audit of financial statements where the auditor has obtained an understanding of internal control and performed procedures on its design or operation, which in practice is nearly every audit conducted under the ISAs. It does not require the auditor to search for deficiencies beyond what is necessary to form the audit opinion; the auditor is not expressing an opinion on the effectiveness of internal control as a whole.

The standard sits alongside three others that shape how much work is done on controls in the first place: ISA 315 (identifying and assessing the risks of material misstatement), ISA 330 (the auditor’s response to assessed risks), and ISA 260 (broader communication with those charged with governance, of which the control-deficiency letter is one component).

04

Requirements of ISA 265

ISA 265 asks the auditor to do four things, in sequence, for every deficiency noted during the audit:

  1. Identify deficiencies in internal control while performing risk assessment and further audit procedures.
  2. Evaluate whether, individually or in combination, they amount to a significant deficiency.
  3. Communicate significant deficiencies, in writing, to those charged with governance on a timely basis.
  4. Communicate other deficiencies worth management’s attention, to the appropriate level of management, in writing or orally, on a timely basis.

The auditor also has to explain, within the communication itself, why the exercise happened at all, that the audit included consideration of internal control in order to design appropriate procedures, not to express an opinion on the effectiveness of internal control, and that only the deficiencies identified during that limited scope are being reported.

05

How ISA 265 Identifies Significant Deficiencies

ISA 265 does not hand the auditor a checklist for what makes a deficiency “significant”, the judgment is deliberately qualitative. The application material does, however, point to recurring factors that experienced auditors weigh together:

  • The likelihood that the deficiency could result in a material misstatement in the financial statements.
  • The susceptibility to loss or fraud of the related asset or liability.
  • The subjectivity and complexity of the amounts affected, including the size of estimates involved.
  • The volume of activity exposed to the deficiency, occurring or expected to occur.
  • The interaction between the deficiency and other deficiencies, since several minor gaps can combine into one significant one.
  • Whether the deficiency touches financial statement close, senior management override, or other high-risk points in the reporting cycle.
A governance-level warning sign Certain deficiencies call the integrity or competence of management itself into question; evidence of fraud, intentional non-compliance with laws or regulations, or an inability to oversee financial statement preparation. Where that is the case, ISA 265 recognises it may not be appropriate to route the communication through management at all; it goes directly to those charged with governance.
06

Communication Requirements Under ISA 265

ISA 265 is specific about form. A verbal mention in the closing meeting does not satisfy the standard for significant deficiencies, it has to be in writing, and the writing has to do more than list problems. At minimum, the communication should:

  • Describe each significant deficiency and explain its potential effects clearly enough for a non-specialist reader to understand the risk.
  • Provide sufficient information to let the recipient understand the context of the communication specifically, that the purpose of the audit was to express an opinion on the financial statements, and that internal control was considered only to design appropriate audit procedures.
  • State plainly that the audit was not designed to, and does not, express an opinion on the effectiveness of internal control.
  • Make clear that the matters reported are limited to those deficiencies the auditor identified during the audit and considered significant enough to warrant attention, not a comprehensive inventory of every control in the organisation.

Where local law, regulation, or the terms of the engagement require it, this communication may need to go to different parties or use a different format, ISA 265 explicitly defers to those requirements rather than overriding them.

07

Timing and Recipients

“Timely” is the standard’s own word, a significant deficiency reported after the financial statements are issued has lost most of its value to governance. In practice, auditors aim to communicate significant deficiencies no later than the completion of the audit, and often flag urgent matters as soon as they are identified rather than waiting for a single year-end letter.

Recipients and required form of communication
Deficiency typeRecipientRequired form
Significant deficiencyThose charged with governanceIn writing, on a timely basis
Other deficiency worth attentionAppropriate level of managementIn writing or orally, on a timely basis
Deficiency implicating management integrityThose charged with governance directlyIn writing, bypassing management as appropriate
08

ISA 265 vs Management Letter

Many firms already sent a “management letter” long before ISA 265 existed, so the two are often confused. The management letter was, and largely still is, a matter of firm practice and client service, useful but not mandated by a specific ISA in the way the significant-deficiency communication now is.

Two related, but distinct, communications
ISA 265 communicationTraditional management letter
BasisMandatory under a specific ISAFirm practice / client service, not itself mandated by a single standard
TriggerSignificant deficiencies specificallyAny observation worth raising, significant or not
Required recipientThose charged with governance, for significant itemsUsually management
Content rulesPrescribed minimum content per ISA 265Format left to firm judgment

In practice, many firms combine both purposes into one letter, using ISA 265’s required content for significant deficiencies and adding lower-level observations as supplementary comments, provided the two are clearly distinguished for the reader.

09

Examples of Internal Control Deficiencies Under ISA 265

The standard is principles-based, so it deliberately avoids a fixed list of “significant” items. That said, certain patterns recur often enough across audits to be worth naming as illustrations, not as an exhaustive catalogue:

  • Segregation of duties gaps, one individual able to initiate, approve, and record the same transaction.
  • Absent or ineffective reconciliations, particularly of bank accounts, intercompany balances, or subledgers to the general ledger.
  • Weak IT access controls, including former employees retaining system access or excessive administrator rights.
  • Missing review of manual journal entries, especially those posted directly to the general ledger outside routine processing.
  • Inadequate controls over accounting estimates, where assumptions are neither documented nor independently challenged.
  • Ineffective monitoring controls, where a control exists on paper but nobody actually reviews the exception reports it produces.

None of these is automatically “significant”, that always depends on the specific facts, the entity’s size, and the likelihood and magnitude of resulting misstatement discussed above.

10

Frequently Asked Questions

Does ISA 265 require the auditor to look for control deficiencies?

No. The auditor only reports deficiencies identified while performing risk assessment and audit procedures under ISA 315 and ISA 330. ISA 265 does not create a separate obligation to search for weaknesses beyond that scope.

Can a significant deficiency be communicated orally instead of in writing?

No. Significant deficiencies must be communicated in writing. Oral communication is permitted only for other, less significant deficiencies raised with management.

Is the significant-deficiency letter the same as a material weakness report under other frameworks?

They are related concepts but not identical, and terminology varies by jurisdiction and framework. Auditors working under both the ISAs and a local regime, such as US PCAOB standards, need to check both sets of requirements rather than assuming they align exactly.

What happens if a deficiency was reported last year and hasn’t been fixed?

The application material notes the auditor may consider whether previously communicated deficiencies that remain unremediated affect this year’s evaluation of significance, since an uncorrected deficiency can compound in importance over time.

Who has to receive the communication if governance and management are the same people?

In smaller entities this overlap is common. ISA 265 still expects the communication to identify that both roles are being addressed, even where the individuals are the same, so the recipient understands the matter is being raised in their governance capacity as well as their management capacity.

This guide summarises the requirements of ISA 265, Communicating Deficiencies in Internal Control to Those Charged with Governance and Management, as issued by the International Auditing and Assurance Standards Board (IAASB). It is written for study and practice reference. Always consult the current authoritative text of the standard, and any applicable local auditing requirements, before relying on it for an actual engagement.