top of page
Search

ICFR Problems: What SEC-Registered Companies Keep Getting Wrong

For more than two decades, public companies have been required to take Internal Control over Financial Reporting (ICFR) seriously.


Yet material weaknesses continue to appear in SEC filings, financial statements continue to be restated, and the SEC continues to bring enforcement actions involving inadequate internal accounting and financial-reporting controls.


This is not a theoretical problem.


Recent SEC data provide a striking picture. For fiscal years 2021 through 2024, SEC staff reported that management concluded ICFR was ineffective, on average, at approximately:

SEC filer category

Average reporting ineffective ICFR

Large Accelerated Filers

5.2%

Accelerated Filers

15.7%

Non-Accelerated Filers

41.8%

For 2024 alone, the rates were 4.5%, 14.2%, and 39.5%, respectively.



That should get the attention of every CFO, controller, Audit Committee and Internal Audit function.

ICFR problems remain widespread—and they are dramatically more prevalent among smaller SEC registrants.

What Is a Material Weakness?

The SEC's Financial Reporting Manual describes a material weakness as a deficiency, or combination of deficiencies, in ICFR for which there is a reasonable possibility that a material misstatement of annual or interim financial statements will not be prevented or detected on a timely basis.


That distinction matters.


A material weakness does not necessarily mean that a material financial-statement error has already occurred.


It means the control system isn't providing reasonable assurance that a material error would be prevented or detected in time.


In other words:

Material Misstatement Did Not Occur

does not necessarily mean

Controls Were Effective.


That is one of the most important concepts in ICFR assessment.


The Numbers Show That Company Size Matters

The SEC's 2026 economic analysis provides unusually useful insight into the prevalence of ICFR problems.


For non-accelerated filers, the percentage reporting ineffective ICFR was:

  • 2021 — 43.7%

  • 2022 — 40.9%

  • 2023 — 43.0%

  • 2024 — 39.5%


By comparison, large accelerated filers reported:

  • 2021 — 3.9%

  • 2022 — 5.6%

  • 2023 — 6.5%

  • 2024 — 4.5%.


That is a remarkable difference.


Why?


Smaller companies frequently face exactly the conditions that make effective ICFR difficult:

  • Limited accounting staff

  • Inadequate segregation of duties

  • Insufficient technical accounting expertise

  • Greater dependence on individual employees

  • Weak IT controls

  • Less-developed Internal Audit functions

  • Less formalized control documentation

  • Management override risk

  • Limited resources for control testing


The lesson is not that small public companies cannot maintain effective ICFR.


It is that limited resources do not eliminate the control requirement.


Problem No. 1: Companies Know They Have Material Weaknesses—and Don't Fix Them

One of the most troubling recent SEC cases involves Singularity Future Technology Ltd.

In January 2025, the SEC announced settled charges involving internal-control, disclosure-control, financial-reporting, and books-and-records failures.


What makes the case especially important for auditors is its duration.


According to the SEC, Singularity disclosed ineffective ICFR and disclosure controls and multiple material weaknesses in each of its prior eight fiscal years. The SEC said those problems contributed to a March 2023 financial-statement restatement—and that the material weaknesses still had not been remediated.


Eight years.


That moves the issue beyond:

“We discovered a control problem.”

It raises a much more serious governance question:

Why wasn't management able to fix it?

The SEC imposed a $350,000 civil penalty and required remediation and public reporting on that remediation. Failure to comply with the undertakings could trigger an additional $1 million penalty.


Persistent Material Weaknesses Are a Governance Problem

The SEC's broader data show that Singularity is an extreme example of a larger problem.


Among non-accelerated filers, approximately 25% had reported ineffective ICFR for four consecutive years culminating in 2024.


That represented more than two-thirds of the non-accelerated filers that reported ineffective ICFR in 2024.


Think about what that means.


A material weakness is identified.


Management develops corrective action.


Another year passes.


Still ineffective.


Another year.


Still ineffective.


Another year.


Still ineffective.


At some point this stops being merely an accounting problem.


It becomes an entity-level control and governance problem.


The Audit Committee should be asking:

Why has remediation taken this long?
Does management have the necessary resources?
Does management understand the root cause?
Who owns remediation?
What milestones were established?
Has Internal Audit independently validated corrective action?
Are we repeatedly treating symptoms rather than causes?

Those are governance questions.


Problem No. 2: The Control Exists on Paper but Doesn't Prevent the Fraud

The SEC's 2024 case involving CIRCOR International provides another valuable ICFR lesson.


According to the SEC, a former finance director manipulated accounting records and falsified the financial results of a business unit before those results entered CIRCOR's consolidated financial statements.


The alleged methods included:

  • Manipulating account reconciliations

  • Falsifying certifications

  • Fabricating bank-confirmation documents

  • Misleading management

  • Misleading the independent auditors.


That is important.


There were reconciliations.


There were certifications.


There were bank confirmations.


Yet those apparent controls were manipulated.


The SEC found that CIRCOR lacked sufficient internal accounting controls relating to financial-statement preparation, reconciliation processes and bank-account access. The deficiencies allowed the fraud to go undetected and resulted in millions of dollars of overstatement.


This demonstrates a fundamental principle of control assessment:

The existence of a control is not evidence that the control is effectively designed or operating.

Ask How the Control Could Be Defeated

An effective ICFR assessment should not simply ask:

“Do we perform bank reconciliations?”

Ask:

Who prepares them?
Who reviews them?
What evidence does the reviewer inspect?
Can the preparer manipulate the supporting documentation?
Does the reviewer independently access the bank information?
Can one employee control both the accounting records and the evidence used to verify those records?

That is the difference between control documentation and control analysis.


Problem No. 3: Certifications Can Become Rituals

The CIRCOR case provides another warning.


The SEC alleged that certifications were falsified.


Organizations frequently rely on certifications:

“I certify that controls operated effectively.”

Fine.


But what is the certification based upon?


If employees simply sign the certification because they signed it last quarter, the certification may become a compliance ritual rather than a control.


Internal Audit should test the evidence underlying management certifications.


Ask:

What did you actually do before signing this?

That question can be illuminating.


Problem No. 4: Companies Confuse Remediation With Promises

One of the most common responses to a material weakness is:

“Management has implemented a remediation plan.”

That sounds reassuring.


But a plan isn't remediation.


Hiring someone isn't necessarily remediation.


Writing a policy isn't necessarily remediation.


Installing software isn't necessarily remediation.


Training employees isn't necessarily remediation.


A material weakness is remediated when the controls are appropriately designed, implemented and have operated effectively for enough time to support the conclusion that the weakness has actually been corrected.


The proper progression is:


Material Weakness

Root Cause

Corrective Action

Control Redesign

Implementation

Operating History

Testing

Evidence

Conclusion


Skipping from corrective action directly to “remediated” creates risk.


Problem No. 5: Companies Don't Get to Ignore Entity-Level Controls

ICFR problems often get treated as transaction-level problems.

  • Accounts Payable.

  • Revenue.

  • Payroll.

  • Inventory.

  • Journal Entries.


But some of the most serious problems begin above those processes.


Consider the COSO Control Environment:

  • Governance

  • Management philosophy

  • Accountability

  • Competence

  • Authority

  • Ethics

  • Oversight


Weakness at that level can undermine dozens of transaction controls simultaneously.


This is why persistent material weaknesses should cause an Audit Committee to ask whether it is looking at an entity-level control failure rather than a collection of isolated accounting problems.


Problem No. 6: ITGC Problems Can Infect ICFR

Modern financial reporting depends on technology.


The financial statements may ultimately appear in a PDF, but the numbers originate and move through:

  • ERP systems

  • Databases

  • Spreadsheets

  • Interfaces

  • Cloud applications

  • Consolidation systems

  • Reporting applications


That makes Information Technology General Controls—ITGCs—fundamental to ICFR.


Weak controls over:

  • User access

  • Privileged access

  • Program changes

  • System development

  • Interfaces

  • Data

  • Computer operations

can undermine the reliability of automated controls and system-generated reports used throughout the ICFR environment.


The issue is no longer:

“Does IT have controls?”

It is:

“Which financial-reporting controls depend upon IT, and what happens to our ICFR conclusion if those IT controls are unreliable?”

Problem No. 7: Management May Underestimate the Importance of Monitoring

COSO's fifth component is Monitoring Activities.


This is where many organizations struggle.


A control is designed.


Implemented.


Tested.


Declared effective.


And then everybody moves on.


But controls deteriorate.


Employees leave.


Systems change.


Processes change.


Companies acquire businesses.


Responsibilities shift.


Workarounds emerge.


A control that operated effectively two years ago isn't necessarily operating effectively today.

Monitoring is how management determines whether the internal-control system continues to function.


Auditor Attestation Appears to Make a Difference

The SEC's 2026 analysis contains another finding worth highlighting.


Companies subject to auditor ICFR attestation reported substantially lower rates of ineffective ICFR than non-accelerated filers, which generally are not subject to the auditor attestation requirement.


The SEC appropriately cautions against assuming that the difference is entirely caused by auditor attestation. Companies in the categories differ in other respects.


Nevertheless, SEC staff observed that the requirement for an auditor to assess management's ICFR assessment may provide an incentive for management to strengthen its controls.


That makes intuitive sense.


There is a substantial difference between management saying:

“We believe our controls work.”

and knowing:

“Our external auditor is independently evaluating this conclusion.”

Independent challenge matters.


Management and Auditors Usually Agree on Ineffective ICFR

Another fascinating SEC finding concerns disagreements between management and auditors.


For registrants where both management and auditor ICFR assessments were available, SEC staff found only two instances of disagreement across the registrants and years included in its analysis.


Why?


One reason is structural.


If the auditor identifies a material weakness, management and the Audit Committee become aware of it.


Likewise, management communicates identified material weaknesses.


The result is that management's and the auditor's year-end conclusions normally converge.


That does not make the auditor's work redundant.


It demonstrates why communication among management, the external auditor and Audit Committee is a critical ICFR control mechanism.


Restatements Should Trigger Hard Questions

The SEC identifies a restatement of previously issued financial statements to correct a material misstatement as an indicator of a material weakness.


That makes sense.


If a material misstatement got through the system and into issued financial statements, management should ask:

Which control was supposed to prevent or detect this?

Then:

Why didn't it?

This is where root-cause analysis becomes critical.

The answer should not simply be:

“Human error.”

That explains almost nothing.


Why was the error possible?


Why wasn't it detected?


Was the control badly designed?


Was it not performed?


Was the reviewer insufficiently competent?


Was the information used in the review unreliable?


Was the review insufficiently precise?


Was there management override?


Was an IT dependency overlooked?


Those questions lead toward the actual root cause.


SEC Enforcement Shows That Remediation Matters

The CIRCOR case also demonstrates what happens when a company responds appropriately after discovering serious problems.


The SEC did not impose a civil penalty on CIRCOR. The Commission cited the company's prompt self-reporting, substantial cooperation and remedial measures.


Those measures included strengthening internal accounting controls and hiring additional experienced finance and accounting personnel.


Compare that with the Singularity case, where material weaknesses persisted for years.

The message is difficult to miss:

Identifying a control failure is bad. Failing to correct a known control failure can be considerably worse.

What Should Internal Audit Be Doing?

Internal Audit should not wait until the external auditor identifies a material weakness.


A strong Internal Audit program can evaluate ICFR throughout the year.


A practical approach is:

1. Understand significant financial-reporting risks.

2. Map those risks to COSO principles and key controls.

3. Evaluate entity-level controls.

4. Test design effectiveness before operating effectiveness.

5. Evaluate IT dependencies and ITGCs.

6. Test management review controls at the appropriate level of precision.

7. Examine control exceptions for root cause.

8. Identify recurring deficiencies.

9. Independently validate remediation.

10. Report significant unresolved issues to the Audit Committee.


Internal Audit should be particularly skeptical when it hears:

“We've had that material weakness for several years, but we're working on it.”

That is exactly when additional assurance may be needed.


The Audit Committee Should Have an ICFR Dashboard

An Audit Committee should be able to see the condition of ICFR without reading hundreds of pages of SOX documentation.


A useful dashboard might include:

ICFR Measure

Current Status

Material weaknesses

Number/open duration

Significant deficiencies

Number/open duration

Repeat deficiencies

Number

Controls failing testing

Percentage

Remediation plans overdue

Number

ITGC deficiencies

Number

Key controls dependent on deficient ITGCs

Number

Restatements

Number

Late management certifications

Number

High-risk remediation awaiting validation

Number

The most important column may be:

Age of the deficiency.

A material weakness open for 30 days and one open for four years represent very different governance situations.


Five Questions the Audit Committee Should Ask

The SEC experience of the past several years suggests five particularly useful questions:


1. Which material financial-reporting risks are not adequately controlled today?

Not last year. Today.


2. Which control deficiencies have occurred repeatedly?

Repeat findings suggest remediation is ineffective.


3. Which material weaknesses have remained open for more than one reporting period?

Ask why.


4. Has Internal Audit independently validated management's remediation?

Management declaring its own remediation successful isn't the strongest assurance model.


5. What could cause us to restate our financial statements next year?

That question forces the discussion toward risk rather than compliance.


The Bigger Lesson: ICFR Assessment Is a Management Process, Not a SOX Project

This may be the most important lesson from the SEC data.


ICFR is sometimes treated as an annual project:


January — Scope

Spring — Document

Summer — Test

Fall — Remediate

December — Certify


Then start over.


That mindset misses the point.


ICFR is an ongoing management control system protecting financial reporting.


COSO gives management the architecture:


Control Environment

Risk Assessment

Control Activities

Information & Communication

Monitoring


And ICFR assessment asks whether those components and the underlying principles are present, functioning and operating together.


The Bottom Line

The last several years demonstrate that SEC-registered companies continue to struggle with ICFR.


The SEC's own recent analysis shows ineffective ICFR averaging about 5% among large accelerated filers, 16% among accelerated filers, and an extraordinary 42% among non-accelerated filers during 2021–2024.


Those numbers should eliminate any notion that material weaknesses are rare anomalies.


The recurring problems are familiar:

  • Weak entity-level controls

  • Insufficient accounting resources

  • Poor segregation of duties

  • Weak ITGCs

  • Inadequate management review

  • Control circumvention

  • Insufficient monitoring

  • Weak remediation

  • Repeat deficiencies

  • Failure to address root causes


The progression for management should be straightforward:


Identify Risk

Design Control

Implement Control

Test Control

Identify Deficiency

Determine Root Cause

Remediate

Retest

Monitor

Report to Governance


The lesson for Audit Committees is even simpler:

A material weakness should not merely be disclosed. It should be fixed.

And when the same material weakness appears year after year, the Audit Committee should stop asking when management expects to close it and start asking:

Why has our governance system allowed this control problem to persist?

That is when an ICFR problem becomes a governance problem.

 
 
 

Recent Posts

See All
What the CIA Taught Me About Audit Tradecraft

I learned the real meaning of tradecraft while designing a training-tracking system for new intelligence officers at the Central Intelligence Agency. The system had to track more than completed course

 
 
 

Comments


Subscribe Form

Thanks for submitting!

479-200-4373

  • Facebook
  • Twitter
  • LinkedIn
  • Twitter
  • LinkedIn
  • Facebook

©2026 by The Accountware Group. Proudly created with Wix.com

bottom of page