Material Weakness: When a Deficiency Becomes Reportable
A material weakness is a deficiency where a material misstatement could reach a report without being prevented, and without being detected in time, and where that chance is more than remote. All three are tests about what could happen. No misstatement needs to have occurred, and the size is measured on the reported number, not the loss. At Vindhya Commercial Bank Limited, invented, one finding of 42 met that test.
The banking version only sounds difficult. Start with the picture that makes the whole idea obvious. A smoke alarm in a house has a dead battery and nobody notices for a fortnight. There was no fire. Nothing burned, nobody was hurt, and if the question is what the dead battery cost, the honest answer is nothing at all. And yet any adult in that house would say something serious was wrong, and would say it without needing a fire to point at. The instinct behind that judgement is exactly right, and it is the whole of this guide. The judgement is about what the house could not have caught, not about what happened to it.
What exactly does the definition say, and how many tests are hiding in it?
The sentence people quote is short enough to sound like one idea. A material weaknessA deficiency where there is a reasonable possibility that a material misstatement would not be prevented or detected in time. exists where there is a reasonable possibilityA likelihood judgement sitting well above remote and well below certain, which nobody can express as a number. that a material misstatementAn error in a reported figure big enough to matter to somebody relying on it. would not be prevented or detected in time. Read once, that is a single mouthful of professional language. Read slowly, it is three separate questions wearing one sentence, and each of the three is answered with different evidence.
The first question is about likelihood: is the chance more than remote? The second is about size: could the wrong figure be big enough to matter to somebody relying on it? The third is about detection: would anything else in the institution have caught it before the number went out? Almost every argument heard about a material weakness is an argument about one of those three carried on as though it were about the others. Somebody says the chance is low; somebody answers that the amounts are enormous; somebody else says nothing went wrong. All three are talking past each other because nobody has said which test they are on.
So the discipline is dull and it works. The sentence splits into three. Each is answered one at a time, in order, with the evidence for each written down. Only when all three are answered does a rating follow. Done that way, the judgement stops being a contest of temperament between the cautious person and the pragmatic one, and becomes something two people can disagree about precisely. Precision is the most a judgement of this kind can ever offer.
How many separate tests does the definition contain, and what is each one about?
What counts as a reasonable possibility, and can anybody give a number?
The first argument in the room usually starts here, with somebody asking, reasonably enough, what probability is meant. Ten per cent? Twenty? The honest answer is that there is no number, and refusing to invent one is not an evasion. A reasonable possibility is a likelihood judgement that sits well above remote and well below certain, and the reason nobody can pin it to a percentage is that the thing being estimated is not the kind of thing anybody has a sample of. The question is not how often this failure happens; it is whether the chance of a wrong figure reaching a report is meaningfully more than remote.
Think about the smoke alarm again. Nobody in that household will produce a percentage for the chance of a fire in the next fortnight, and nobody needs one. The household will argue from facts instead: this alarm has failed before, the kitchen is busy, and there is no second alarm anywhere in the house. An argument from facts is not vaguer than a percentage. A percentage in that setting would simply be a made-up number wearing a decimal point, so the facts are the more honest of the two.
So what does a rater actually do instead? Three things, and they are all evidence rather than opinion. How often did the control fail, and over what period? Would anything else in the institution catch the failure, and did it? How long could a failure run before somebody noticed? Once those three are answered the likelihood question stops being a mood. Anybody offering a threshold percentage for a reasonable possibility is offering their own threshold, and none is stated in this guide.
Somebody asks what probability counts as a reasonable possibility. What is the honest answer?
What is the size test actually measured against?
Here is the mistake that costs raters the most credibility, and it is made by careful people. A control failed, an incident followed, the incident cost a known amount, so the weakness gets sized at that amount. Sizing the weakness at that amount feels rigorous. The amount is the wrong quantity.
At Vindhya Commercial Bank Limited, invented, the failed control is the one over collateral valuation in process PR3. The incident that came out of it is I10, and it cost Rs 1.4 crore net. The Rs 1.4 crore is real inside the invented record, and it is what this one instance happened to cost. A cost is not the answer to the size test. The size test asks a different question: how big could a wrong figure be, if the same failure produced one and nothing caught it? The size test is answered by the size of the book the control decides, not by the size of the loss the control happened to produce.
The book is Rs 8,640 crore of secured advances. Set against the balance sheet it stops being an abstraction. Net advances at the reporting date are Rs 57,600 crore, so the book the control values is 15.0 per cent of them. Total assets are Rs 96,000 crore, so the same figure is 9.0 per cent of the whole institution. Both shares are true, and they differ because their bases differ. A share means nothing until somebody names what it is a share of. Every one of these figures belongs to one invented bank.
A rater sizes the weakness at Rs 1.4 crore, being the loss the incident produced. What has gone wrong?
The contrast between the two measures is not subtle, and people still reach for the wrong one under pressure, so the two are worth seeing side by side once. Rs 1.4 crore sits comfortably among the thirteen operational loss events the invented bank recorded in the year: it is the fourth smallest of them, well below the largest at Rs 15.4 crore and above the smallest at Rs 0.6 crore. Rs 8,640 crore does not sit on that chart at all. The book sits on the balance sheet instead. The two numbers cannot share an axis, and a rater who puts them in the same sentence without saying so has already lost the argument.
What do the words prevented or detected in time actually add?
Detection is the leg people skip, and it is the leg that usually settles the case. The definition does not ask whether the control failed. The definition asks whether the failure would have been caught. Failing and being caught are different questions, and the second is about the whole institution rather than about one control.
Notice that the phrase offers two chances, not one. PreventedStopped before it happened, which is the first of the two chances the test asks about. means the error never got made: something in the process stopped it as it was entered. Detected in timeCaught before the number was reported, which is the second chance and carries a deadline. means the error got made and something else found it before the number went out. For this leg of the test to be met, both chances have to be empty, and the second one carries a deadline that the first does not.
The deadline is the point everybody misses. In time does not mean eventually. In time means before the number was reported. A reconciliation that finds the error next month is a real and useful thing, and what it produces is a correction rather than a detection. Corrections matter. By the time a correction is made, somebody has already relied on the wrong figure, so a correction is not what the test asks about. A street vendor who counts the till at closing time has a detective control. A street vendor who counts the till a week after handing the month figures to a lender has a correction, and the lender has already lent.
A monthly reconciliation would have caught the error, but only after the quarterly numbers had gone out. Does that count as detected in time?
Does a misstatement have to have happened at all?
No, and the conditional wording of the definition is where that answer comes from. The definition is written in the conditional throughout: a reasonable possibility that a misstatement would not be prevented or detected. Nothing in it requires that one occurred. A material weakness is a statement about the state of the controls, not a statement about the state of the accounts.
Lay it out as a two by two and the point becomes almost visual. On one side, did a misstatement actually occur, yes or no. On the other, would the institution have caught it, yes or no. The rating lives entirely in the bottom row, where the controls would not have caught it, and it lives there whichever column the case sits in. A clean set of numbers moves the case across the columns. Moving across the columns is not moving up a row.
The household version fits exactly, once more. The house did not burn down. The alarm was still dead. Nothing about the absence of a fire tells anybody anything at all about the battery, and anybody who says the alarm must have been fine because there was no fire has answered a question nobody asked.
How does the test land on this bank's one material weakness?
Vindhya Commercial Bank Limited, invented, tested 214 key controls across nine processes and came out with 42 findings. Exactly one of the 42 sat at the top step of the bank's own four point scale. One finding in 42 is 2.4 per cent of the findings, and 1 control in 214 is 0.5 per cent of the population tested. The four point scale, and the steps below the top one, are settled separately. The three tests are applied below to that one finding.
The facts first, and all of them belong to the invented record. The control over collateral valuation in process PR3 did not operate for 11 working days. Three hundred and forty loans were wrongly marked. No monitoring controlA control whose job is to notice that another control has stopped working. detected it. Four months earlier the same valuation feed had gone stale for 2 working days, a data quality check had caught it, and nobody had raised it as an issue. The incident is I10 and it cost Rs 1.4 crore net.
Test one, likelihood. The same feed failed twice inside twelve months, and on neither occasion did the institution respond the way it should have. Twice in twelve months is not remote. Nor is it a certainty, and it does not need to be. Test two, size. The control decides how Rs 8,640 crore of secured advances is valued, and a wrong mark on that book feeds a provision, and a provision is a reported number. Test three, detection. Nothing prevented the feed going stale and nothing detected it for 11 working days. Three tests, three answers, and only then the rating.
One footnote before the worked case is left behind. The question comes up whenever a rater has several lesser findings and no obvious top one. A rater may argue that a number of smaller findings, taken together, reach the same conclusion that no single one of them reaches alone. The move is called aggregationTreating several lesser findings together, which is a judgement the rater has to argue rather than compute., and it changes nothing about the method here: the three tests are still answered one at a time, on the combined facts rather than on one incident. Aggregation is an argument to be made and written down, never an arithmetic that adds ratings up.
Which single fact about this bank material weakness does most of the work in the rating?
The size test is the leg that stays abstract longest, so it is worth making it something that can be moved rather than something merely read. The control decides Rs 8,640 crore. Suppose an average error of some size ran across that book. How big would the error have to be before the money it moved reached figures already familiar from this bank? The answers are startling, and they are the whole reason the size test looks at the book rather than at the loss.
The failed control decides how Rs 8,640 crore of secured advances is valued. What average percentage error across that book would move the Rs 1.4 crore this incident actually cost?
An average error moved across the book, set against the figures already known
One control: an average percentage error in the collateral mark, running from 0 to 15.00 per cent across the Rs 8,640 crore of secured advances the failed control decides. One consequence: the value that error would move, drawn against six figures already locked in this invented bank. The error rate comes from the dial alone. The invented record holds no error rate and no misstatement figure.
An average error of 0.016 per cent across the Rs 8,640 crore book would move Rs 1.4 crore, which has just reached crossing 1, the net loss incident I10 booked.
Why does this case support no misstatement figure at all?
Now the discipline that matters most in this guide, and it runs against the grain of everything a numerate reader wants to do next. Having established that the control decides Rs 8,640 crore, the obvious move is to multiply something by something and produce a misstatement figure. The multiplication is not available. A wrong collateral mark does not become a misstatement one for one, and this invented record contains nothing that would let anybody say how much of one survives the journey.
Following the chain shows where the information runs out. A stale feed produces a mark that is out of date. The mark feeds a provision, and how a provision is computed from a mark is a separate subject with its own rules, judgements and floors. The provision then feeds a reported number, along with everything else that feeds it. At each of those two steps something is applied to the mark, and this bank never measured what came out. There is no error rate in the invented record and no misstatement figure, so the dial in the calculator above belongs to the reader rather than to the bank.
The refusal is not squeamishness. Showing the book is showing the raw material of the size test. Asserting a result the evidence does not carry is a different act altogether. The figure will be quoted long after the caveat is forgotten, so a rater who writes a misstatement figure this record cannot support has done more damage than one who writes none.
Who reports what, and to whom?
A material weakness is reportableSomething a reporting duty requires to be stated rather than merely recorded inside the institution., and that word is doing real work. Findings below the top step are recorded, tracked and closed inside the institution. A finding at the top step reaches a report that people outside the institution read, and that is the practical consequence of the rating.
In India the duty splits in two and the two halves are separate. The Companies Act places a reporting duty on the board in respect of internal financial controls, and it places a separate reporting duty on the auditor. The two duties are not one duty shared between two parties. The text of both, the applicability, the exemptions and the form of the report all sit with the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that govern how the auditor does this work, including anything about materiality in it, sit with the Institute of Chartered Accountants of India at icai.org. Anything that binds a bank in addition comes from the Reserve Bank of India at rbi.org.in. Applicability and form change, and the binding text in each case sits with the body named, at the source.
Inside the invented bank there is a third movement that is easy to overlook. The assessment of internal financial controls goes to committee G3, the audit committee. The same committee receives the findings and the ageing of open issues. The audit committee is where a rating stops being a working paper and becomes something a board level body has seen. Who sits on that committee, and how it relates to the other seven, is a separate subject and is not settled here.
Who carries the Indian reporting duty on internal financial controls, and which body holds the text?
What does a material weakness never mean?
The objection that sounds unanswerable, and answers nothing
The objection arrives in every room, from somebody sensible, and it goes like this. The numbers were reported. Nobody has identified an error in any of them. The loss was Rs 1.4 crore, the fourth smallest of the thirteen incidents in the year. No customer lost money. So where, exactly, is the material misstatement?
Every one of those statements is true, and not one of them touches the test. The definition asks whether there is a reasonable possibility that a material misstatement would not be prevented or detected in time. The definition asks about the state of the controls. A clean set of numbers is entirely consistent with a control that stopped working for 11 working days with nothing in the institution noticing, and it is precisely that silence the rating is about.
There is a mirror image of the same error, and it is just as common in the opposite direction: reading a reported material weakness as a finding that the accounts are wrong. A reported material weakness is not that either. Both mistakes come from the same place: reading a statement about controls as a statement about numbers. In this bank the evidence for the rating is eleven working days of silence and one earlier silence four months before it, rather than any figure in the accounts at all.
Nobody has found an error in the reported numbers. Does that settle whether there is a material weakness?
A conclusion of this kind will be read by people who have never seen one, so being explicit about its limits is worth the space. The conclusion does not say the reported numbers are wrong. Nor does it say anybody was dishonest, careless or incompetent. Nor does it say a loss occurred, and in this bank the loss that did occur was among the smallest of the year. The conclusion says that if something had gone wrong, this institution would probably not have caught it before it was reported, in a period that has now closed.
The last clause matters more than it looks. A material weakness is a statement about a period, not a permanent property of an institution. The finding is dated, the remediation is dated, and the next assessment asks the same three questions again on the facts as they then stand.
A bank reports a material weakness. What has it not said?
Who actually picks this up, and what do they do with it?
Three very different readers meet the same three word phrase and take three different things from it, and none of them is reading it the way the rater wrote it.
The independent director on the audit committee reads it as a question about detection capacity. She is not asking what the incident cost; she has the loss log for that. A failure that ran 11 working days unnoticed once is a failure pattern rather than an event, so she is asking what else in this institution has no monitoring control over it. Her next question in the room is usually the right one: how many other controls in these nine processes have nothing watching them?
The credit analyst at another institution, looking at this bank as a counterparty rather than as an employer, reads it as an adjustment to how much weight the reported numbers can bear. He does not conclude that the figures are wrong. He concludes that one particular figure, the valuation of a large secured book, rests on a process that failed without being noticed, so he leans harder on evidence that does not come through that process. A material weakness does not change a number for an outside reader; it changes how much that reader is willing to lean on it.
The lender to a small business does the same thing at a scale anybody can picture. A shopkeeper applying for a working capital line has neat monthly figures. The lender asks who counts the stock and how often, and gets the answer that the owner counts it whenever there is time. Nothing in the figures is wrong. The lender has just learned that nothing in that shop would have caught an error before the figures reached him, so he still asks for a stock statement certified by somebody else. The reasoning of this whole guide is his, conducted over a counter.
And the household, one last time: the mechanism does not change with scale. Somebody notices the smoke alarm battery has been dead for a fortnight. Nobody argues about whether there was a fire. The household buys a battery, and then asks whether there is a second alarm anywhere in the house. Asking about the second alarm is the monitoring question, and it is the only one worth asking.
What is named here, and where the binding version lives
The definition and the three tests above are written jurisdiction free and work in any setting where somebody reports on controls. Every control count, finding, rating, book and loss in this guide belongs to Vindhya Commercial Bank Limited, invented, and none of it is an industry norm or a supervisory expectation.
In India the Companies Act places a reporting duty on the board in respect of internal financial controls and a separate reporting duty on the auditor. The text of the requirement, its applicability, its exemptions and the form of the report are held by the Ministry of Corporate Affairs at mca.gov.in. The assurance standard and the guidance note that govern the auditor's work on internal financial controls, including anything said there about materiality, are held by the Institute of Chartered Accountants of India at icai.org. Anything that binds a bank in addition, on top of the company law duty, comes from the Reserve Bank of India at rbi.org.in.
Section numbers, rule numbers, thresholds, materiality levels, exemptions, form numbers and effective dates all change, and each binds only in the version the issuing body currently holds. No percentage is set anywhere for a reasonable possibility, and applicability and form must be read at the source.
Sources
| Source | Document | Site |
|---|---|---|
| Ministry of Corporate Affairs | The Companies Act reporting duty on internal financial controls, its applicability, exemptions and the form of the report | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and the guidance note on reporting on internal financial controls, including materiality in that work | icai.org |
| Reserve Bank of India | What binds an Indian bank in addition on internal control, risk management arrangements and provisioning | rbi.org.in |
| Bank for International Settlements | The Basel Committee standards behind bank capital, liquidity and the operational risk event categories the loss record uses | bis.org |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
