Blog
Written by

Naman Mathur
Published on

Every audit firm names the same three causes of a material weakness and prescribes the same fix: hire more people, write better policies, modernize the tech. Here's why that advice keeps failing, and what actually closes the gap for good.
Key takeaways
Trace the pattern: the same three root causes show up in nearly every material weakness disclosure: understaffed teams, weak segregation of duties, and inadequate technology or documentation.
See where it concentrates: roughly 70% of material weaknesses trace back to one process, the close.
Know the severity tiers: a material weakness is the most severe of three deficiency levels; not every control gap rises to that level.
Question the standard fix: the advice is the same everywhere, and it depends on people executing a change-management project perfectly, under the same conditions that caused the failure.
Fix it structurally: automation closes the root cause at the process level instead of relying on that execution.
What counts as a material weakness
A material weakness is a deficiency in internal control over financial reporting severe enough that there is a reasonable possibility a material misstatement will not be prevented or detected in time.
The definition comes from the SEC and PCAOB frameworks; PCAOB AS 1305 governs how auditors communicate these deficiencies. What makes a weakness "material" is not that an error occurred, but that the control environment could plausibly let a material one through. And unlike lesser findings, it triggers mandatory public disclosure under SOX 302 and 404. We cover the definition, the disclosure mechanics, and the events that predict a finding in depth in Predicting Material Weakness; this article is about why they happen and why they resist fixing.
Material weakness vs. significant deficiency
Control deficiencies come in three severity tiers, and only the top tier forces public disclosure. A material weakness means a material misstatement could plausibly slip through; a significant deficiency is serious enough to escalate internally but falls short of that bar.
Topic | What it covers | Where it fits | Common confusion |
|---|---|---|---|
Control deficiency | A single control or component falls short of its objective | Baseline finding, usually not disclosed externally | Assumed to carry the same weight as a material weakness |
Significant deficiency | Important enough to flag to those overseeing financial reporting | Middle tier, reported to the audit committee | Mistaken for a material weakness |
Material weakness | Reasonable possibility a material misstatement goes undetected | Top tier, must be disclosed under SOX 302/404 | Confused with any minor control gap |
Severity is one axis; there is a second. Any deficiency at any tier is either a design deficiency, the control as designed cannot achieve its objective, or an operating deficiency, the control is designed properly but is not performed correctly or consistently, per Deloitte's guidance on evaluating deficiencies. The distinction matters for remediation, because the standard playbook mostly fixes design, and most failures happen in operation.
The current state of material weaknesses
Disclosure rates spiked hard in the SPAC era and have since fallen, but the level remains high and the repeat-offender problem hasn't gone away.
Baker Tilly's analysis of SEC filings, covering more than 5,000 management assessments and 3,000 auditor assessments from 2020 to 2024, shows over 26% of filers reporting adverse ICFR assessments in 2021, driven largely by the wave of companies that went public through SPACs with controls unready for public-company scrutiny. The rate has declined since, to just over 15% in 2024, as that cohort remediated or delisted and newer entrants arrived better prepared.
The improvement is real but the composition is stubborn. KPMG's analysis of recent trends finds the same categories dominating disclosures year after year, with close and reporting deficiencies at the top, and a meaningful share of disclosures coming from companies reporting the same weakness for a second or third year. The rate falls; the causes don't change.
The three root causes behind most material weaknesses
Strip the language out of hundreds of disclosures and three causes account for most of them: not enough qualified people, duties that aren't separated, and technology or documentation that can't support the control.
Understaffed or under-skilled teams. The disclosure language is "insufficient qualified accounting personnel". The reality is one controller reviewing complex revenue recognition they had no time to understand, or a technical accounting question, a business combination, an impairment, landing on a team with nobody who has done one. The control exists on paper; the capacity to perform it doesn't.
Weak segregation of duties. The same person prepares the journal entry and approves it, or initiates the payment and reconciles the bank account. In small and fast-growing teams this is rarely negligence; it is arithmetic. Five people cannot cleanly separate duties designed for fifteen, so someone reviews their own work and the control becomes ceremonial.
Inadequate technology or documentation. The close runs on spreadsheets held together by one person, reviews happen but leave no evidence, and system access is broader than anyone can justify. When the auditor asks for proof a control operated, the honest answer is that it probably did, which is a finding.
Why the standard fixes fail traces to three structural mechanisms. First, hiring fixes capacity, not process: new people inherit the same manual close, and the control still depends on humans executing perfectly under deadline pressure, now with onboarding risk added. Second, policies fix design, not operation: a beautifully documented control that nobody has time to perform fails exactly as the undocumented one did, just with better paperwork, and operating deficiencies are where the failures live. Third, technology projects fail on execution: bolting a tool onto a broken process means running a change-management program with the same overstretched team whose overstretch caused the weakness, during live closes they cannot pause.
Common forms of material weakness
By domain, the disclosures cluster in four places: revenue recognition, IT and systems controls, financial reporting and close, and the control environment itself.
Revenue recognition weaknesses follow complexity: multi-element arrangements, usage-based pricing, contract modifications, anywhere judgment meets volume. IT general control weaknesses are about access and change management: who can touch the systems that produce the numbers, and whether changes to them are controlled. Financial reporting and close weaknesses cover the mechanics this article is mostly about: reconciliations not performed or not reviewed, journal entries without approval, period-end processes that depend on heroics. And control environment findings are the umbrella category: management override risk, insufficient board oversight, a culture where controls yield to deadlines. The domains differ; the underlying three causes recur in each.
Why material weakness concentrates in the close
Roughly 70% of material weaknesses trace back to close and reporting controls specifically, a concentration first quantified in SEC-era disclosure data and persisting in current analyses.
The concentration is structural. The close is where every upstream process converges, under the hardest deadline in the finance calendar, executed by the same small team every month. All three root causes intersect there simultaneously: capacity is thinnest exactly when the workload peaks, segregation of duties buckles under time pressure, and spreadsheet-driven processes leave the least evidence precisely where the most is needed. A weakness anywhere else in the business gets caught, or not, at the close; a weakness in the close has nothing downstream to catch it.
The standard remediation playbook, and why it doesn't always stick
The playbook is consistent across every audit firm: assess root cause, design new controls, hire or reallocate people, document everything, test until effective. It is correct, and it frequently doesn't hold.
The framework itself is sound: Baker Tilly's prevention guidance and Deloitte's remediation roadmap both stress the same discipline, and both are explicit that there are no quick fixes. A remediated control must operate for enough cycles to be tested for sustained effectiveness, which means remediation is measured in quarters even when the fix is designed in weeks.
Here is the uncomfortable part: nothing directly forces the fix. There is no regulatory penalty for carrying a material weakness, only for misstating results or disclosure failures. The pressure is reputational and financial, and it competes with everything else on the CFO's desk. The academic record shows the consequence: research published in Auditing: A Journal of Practice & Theory on the failure to remediate previously disclosed material weaknesses documents that a substantial share of companies disclose the same weakness in consecutive years, with remediation failure concentrated where resources are thinnest, which is to say, at exactly the companies most likely to have the weakness in the first place. The playbook depends on sustained, well-resourced human execution. The weakness exists because sustained, well-resourced human execution wasn't available.
How Stacks closes these gaps structurally
Each root cause maps to a mechanism that removes the dependence on perfect execution, rather than demanding more of it.
The capacity problem is addressed by automation doing the work, not by policy asking people to do more of it. Reconciliations match on live ERP data, journal entries are prepared with support attached, accruals and close tasks run on schedule, so the team's hours move from mechanical preparation to review and judgment, which is where a lean team's capacity belongs.
The segregation problem is enforced by the platform, not the org chart. Role-based approvals and maker-checker flows are built into every task: the preparer cannot approve their own work because the workflow will not allow it, which converts segregation of duties from a staffing question into a configuration.
The evidence problem disappears because the audit trail is a byproduct of the work. Every match, entry, review, and sign-off is timestamped and immutable as it happens. When the auditor tests whether a control operated, the answer is a log, not a recollection, which is the difference between SOX as a badge and SOX as evidence.
Why choose Stacks for material weakness remediation
Stacks remediates at the level where 70% of the problem lives: the close itself.
Rather than adding a controls tool beside the close, the platform runs the close: reconciliations, journal entries, accruals, intercompany, and reporting, with the controls embedded in the same workflow that does the work. That resolves the structural trap in the standard playbook. Remediation stops being a change-management project executed by an overstretched team and becomes the operating model of the process; sustained effectiveness stops being a discipline to maintain and becomes what the system does by default, close after close. The evidence for the auditor accumulates continuously, the remediated controls operate identically whether the quarter is calm or brutal, and none of it depends on the one person who knows the spreadsheet. Teams are live in weeks, which matters when the remediation clock is measured in tested quarters.
FAQs for causes and remediation of material weakness
What's the difference between a material weakness and a significant deficiency? Severity and audience. A significant deficiency is serious enough to report to the audit committee but stays internal. A material weakness means a material misstatement could plausibly go undetected, and it must be disclosed publicly in SEC filings. The same control gap can be classified as either, depending on the likelihood and magnitude of potential misstatement.
How long does it take to remediate a material weakness? Typically several quarters at minimum. Designing the fix can be fast; the constraint is that the remediated control must operate over enough reporting cycles to be tested for sustained effectiveness. A weakness disclosed at year-end usually cannot be certified as remediated until well into the following year, and complex fixes span multiple years.
Does hiring more accountants fix a material weakness? Sometimes, and rarely alone. Hiring addresses the capacity root cause, but new staff inherit the same manual process, and the control still depends on consistent human execution under close pressure. Where the weakness stems from segregation of duties or evidence gaps, headcount without process change tends to produce a better-staffed version of the same deficiency.
Can a material weakness recur after it's been remediated? Yes, and the research says it happens regularly: a substantial share of companies disclose the same weakness in consecutive years. Recurrence concentrates where remediation relied on temporary effort, consultants, overtime, heroics, rather than structural change, because the effort recedes and the original conditions return.
Do companies have to disclose a material weakness? Public companies do. SOX Sections 302 and 404 require management to assess internal control over financial reporting and disclose material weaknesses in their filings; for most larger filers the external auditor also attests. There is no penalty for having a weakness, only for failing to disclose it, which is partly why remediation timelines stretch.

