Common Internal Control Failures - What Goes Wrong and Why

3-4 min read | Internal Audit | SOX
Internal controls rarely fail dramatically. They erode quietly - through staff changes, system upgrades, and the slow drift of "we'll fix it later." Here's what auditors keep finding, and what's actually driving it.
Every internal control failure has a story. Someone got too busy. A system got upgraded. A new hire didn't get trained. A process that worked for 50 employees quietly broke when the company hit 500.
The frustrating truth is that most internal control breakdowns aren't dramatic events - they're slow-moving gaps that pile up until an auditor walks in and finds them. Understanding what these failures look like, and why they happen, is the first step to catching them before they become a material weakness.
Let's walk through the most common ones.
1. Segregation of Duties — The Classic That Never Goes Away
40% of companies that disclosed material weaknesses in 2023 cited lack of segregation of duties as a primary theme - up from 34% the prior year, per KPMG's material weakness trends study.
Segregation of duties (SOD) means that no single person should be able to initiate, approve, and record a financial transaction. When those roles collapse into one person - usually because a company is small, understaffed, or going through rapid growth - the risk of undetected errors and fraud rises sharply.
The real-world version of this looks ordinary: an accountant who both prepares and approves journal entries, or a controller who can also create and pay vendors. Nobody intended to create a control gap. It just happened because it was convenient.
Watch for: ERP implementations where SOD conflicts weren't mapped out upfront. New system rollouts often inherit the same access problems from the old system - just in a shinier interface.
2. IT and Access Controls — The Growing Problem Area
55% of material weaknesses reported in 2023 involved IT, software, security, or access issues - a significant jump from 40% the prior year, according to KPMG's trends analysis.
IT controls are now inseparable from financial controls. When someone has system access they shouldn't have - or when access isn't revoked after an employee leaves - you have a control gap that sits quietly in your environment until something goes wrong.
Common access control failures include: former employees retaining system access after termination, users accumulating permissions across role changes, and IT teams deploying patches inconsistently across different systems. Each of these sounds administrative. Each of them has shown up as a material weakness in real audits.
Watch for: Access reviews that happen annually but not upon role changes or departures. User access should be reviewed when people move - not just once a year on a spreadsheet.
3. Controls That Stop Being Performed
This is simpler than it sounds, and more common than most organizations want to admit. A control exists on paper - it's documented, it's designed correctly - but the person responsible for performing it stopped doing it. They got busy. They changed roles. They left the company. And the control just... stopped.
An internal control failure happens when a required control doesn't operate as designed, doesn't operate consistently, or no longer addresses the underlying risk it was built for. An abandoned control is often harder to catch than a poorly designed one, because the documentation looks fine right up until the auditor asks for evidence of execution.
Watch for: Controls that were designed around specific individuals rather than roles. When the person owns the control rather than the position, turnover breaks the process every time.
4. Weak or Missing Risk Assessment Process
A SOX compliance program that doesn't start with a robust, ongoing risk assessment is building on sand. Many organizations treat risk assessment as a one-time setup task -something done during implementation and then filed away. But risks evolve. Business models change. New products, acquisitions, and regulations create new exposures that the original control framework never anticipated.
When risk assessment is static, controls drift out of alignment with actual risk. Auditors then find controls that are perfectly executed - for risks that no longer exist - while new exposures go unaddressed. It's a common and costly mismatch.
Watch for: Companies that have gone through significant changes - M&A, new market entry, major system changes - without a corresponding refresh of their risk and control framework.
5. Inadequate Documentation and Evidence
79% of material weaknesses in 2023 involved lack of accounting documentation, policy, or procedure as a contributing theme - the first year this figure declined, but still the most pervasive issue overall, per KPMG.
A control performed without evidence is, from an audit perspective, a control not performed. This is one of the most straightforward failures - and one of the most frequently cited. Missing workpapers, informal approvals via chat or verbal sign-off, exception logs that aren't maintained - all of these create documentation gaps that escalate quickly during fieldwork.
The problem is often cultural: teams that are operationally strong don't see the point of "paperwork." The point becomes very clear when an auditor asks to see evidence of a control that everyone agrees happened, but nobody documented.
Watch for: Over-reliance on informal channels - Slack messages, verbal approvals, email threads - as the primary evidence of control performance. If it isn't formally documented, it didn't happen in the audit's view.
Across all five of these failure types, one theme is consistent: the gap between designed and operating controls. Organizations often invest heavily in designing a control framework, then underestimate the ongoing effort required to keep it functioning as the business grows and changes around it.
The PCAOB has estimated that nearly 46% of reviewed audits will have one or more deficiencies. That's not a fringe problem - it's a structural one. And it signals that for many organizations, controls maintenance is still treated as a periodic exercise rather than a continuous discipline.
The Bottom Line
Internal control failures rarely announce themselves. They accumulate in the gaps between what was designed and what's actually happening on the ground - in role changes, system updates, busy quarters, and undocumented exceptions. Catching them early is significantly less expensive than remediating a material weakness after the fact. Studies suggest remediation can cost up to five times more than maintaining a sound control environment from the start.
The best audit programs treat controls as living systems - reviewed, tested, and adjusted regularly - rather than a compliance checklist completed once and revisited annually. That mindset shift is where most of the value lies.
Comments