The question
Listing control weaknesses is not hard. Any reasonably careful reader can generate a long list of things an organisation isn't doing. The list is also close to useless on its own, because it gives management no way to decide what to fix first, and a remediation plan that treats every gap as equally urgent is a plan that gets abandoned.
The question I was actually interested in was the ordering: which gaps leave the most exposure open, as distinct from which gaps are the most conspicuous. Those are very often different gaps.
Why COSO
COSO is the framework most internal control work in the US is assessed against, including management's assessment under Sarbanes-Oxley Section 404. It breaks internal control into five components, which in turn resolve into seventeen principles. The value of using it here is that it forces coverage: it is much harder to overlook an entire category of control when you are walking a structured checklist than when you are reading a governance document looking for problems.
| Component | What it asks | Where gaps usually hide |
|---|---|---|
| Control environment | Is there a culture, structure and tone that makes control possible at all? | Board independence, delegated authority that was never written down |
| Risk assessment | Are objectives clear enough that risks to them can be identified and sized? | Fraud risk treated as a compliance formality; change not reassessed |
| Control activities | Are the policies and procedures that address those risks actually in place? | Segregation of duties in small teams; IT general controls |
| Information & communication | Does relevant, quality information reach the people who need it, in time? | Upward reporting of bad news; whistleblower routes that bypass the subject |
| Monitoring activities | Is the system itself being evaluated, and are deficiencies escalated? | Findings logged but never closed out; no follow-up on remediation |
Method
Map the existing structure onto the seventeen principles
Every documented control is assigned to the principle it is meant to support. Principles with nothing mapped to them are the first finding: an uncovered principle is a gap by definition, before any testing happens.
Separate design from operation
A control can fail in two different ways, and conflating them produces bad remediation. If a control is badly designed, it would not catch the problem even if performed perfectly. If it is badly operated, the design is sound but it isn't being done consistently. The first needs a new control; the second needs supervision. Testing design first avoids the trap of tightening enforcement on a control that was never going to work.
Classify severity
Using the standard three-tier scale: a deficiency, a significant deficiency (serious enough to warrant attention by those overseeing financial reporting), and a material weakness (a reasonable possibility that a material misstatement would not be prevented or detected in time). The distinction is about the magnitude of what could go undetected, not about how careless the failure looks.
Score residual risk, not inherent risk
Inherent risk is the exposure before controls. Residual risk is what survives the controls that do exist, and it is residual risk that should drive the ordering. A frightening inherent risk with three overlapping compensating controls is a lower priority than a modest one sitting completely uncovered.
Rank and sequence remediation
Residual risk sets the priority; effort and dependency set the sequence. Some fixes unlock others: a documented delegation-of-authority matrix has to exist before approval thresholds can be tested against anything.
The gap register
This is the deliverable. The ordering is the point of it: the rows are sorted by residual risk, not by component, so it reads as a work queue rather than as an audit checklist.
| # | Component | Gap identified | Design or operating | Severity | Residual risk | Remediation |
|---|---|---|---|---|---|---|
| 01 | Control activities | One role both initiates and approves vendor payments under the approval threshold | Design | Material weakness | 16.0 | Split initiation from approval; lower the threshold; require dual authorisation above it |
| 02 | Monitoring | Prior-period findings are logged, but no owner or closure date is assigned to any of them | Operating | Significant deficiency | 12.6 | Assign a named owner and due date per finding; standing review item at the audit committee |
| 03 | Control environment | Delegation of authority is held by convention and never formally documented | Design | Significant deficiency | 10.5 | Publish a delegation matrix; reconcile actual approvals against it quarterly |
| 04 | Information & communication | The whistleblower channel routes to the line manager, so a report about that manager has no path | Design | Significant deficiency | 8.0 | Route to the audit committee; add an anonymous external intake |
| 05 | Risk assessment | Fraud risk assessed annually as a compliance exercise and never refreshed when processes change | Operating | Deficiency | 7.2 | Trigger reassessment on system, process or personnel change rather than on the calendar |
Residual risk is scored on a 1–5 likelihood and impact scale, discounted by the effectiveness of whatever control does exist. The ordering it produces is the argument of this page: finding 01 ranks first not because it is the most egregious on paper but because nothing else in the structure compensates for it, while finding 05 sits last despite being a real deficiency because two adjacent controls partially cover the same exposure.
Coverage by component
| Component | Principles covered | Gaps found | Highest severity |
|---|---|---|---|
| Control environment | 4 / 5 | 1 | Significant deficiency |
| Risk assessment | 3 / 4 | 1 | Deficiency |
| Control activities | 2 / 3 | 1 | Material weakness |
| Information & communication | 2 / 3 | 1 | Significant deficiency |
| Monitoring activities | 1 / 2 | 1 | Significant deficiency |
The gaps that scored highest were not the ones that looked worst on the page. Controls that were absent entirely were easy to spot and often low-exposure; the expensive ones were controls that existed, were documented, and were quietly not being performed, because everyone, including the people relying on them, believed they were.
Limitations
- Documentation is not operation. Reviewing a control structure on paper tells you what should happen. Only testing a sample of transactions tells you what does.
- Management override sits outside the framework. COSO explicitly acknowledges that a sufficiently senior person can circumvent almost any control. No gap register catches that.
- Judgement in scoring. Likelihood and impact are assigned, not measured. Two competent reviewers will produce different orderings, and the ranking is only as defensible as the reasoning written beside it.
- A point in time. Control environments drift. A review is a photograph, and the organisation keeps moving after the shutter closes.
Next iteration
I'd test a transaction sample rather than reviewing documentation alone; the single biggest weakness of the exercise is that it assesses design far more confidently than operation. I'd also map each gap to the specific financial statement assertion it threatens, which is what makes a register legible to an auditor rather than just to management.