Somewhere in Item 9A of your last annual report there is a paragraph that names a control that did not operate, and a plan to fix it. It was drafted by finance, reviewed by counsel, discussed with the audit committee, and read by the auditor. Everyone in that chain treated it as a governance sentence. It is also something else: a commitment to produce a specific kind of record, by a specific date, in a volume an auditor can sample.
Records at that volume are produced by systems. The disclosure therefore contains a software obligation, with a deadline, that nobody in the room reads as one — because the room contains a controller, a CFO, an audit partner and a committee chair, and it does not contain anyone whose job is building software.
Over the trailing twelve months, SEC full-text search returns 682 filings disclosing a material weakness and 139 filings reporting non-reliance on previously issued financial statements. Those are filings rather than companies, so the unique-company count is lower. The population is still large, and it is concentrated in exactly the kind of company that has no internal product team to hand the obligation to.

What The Paragraph Actually Commits You To
A remediation plan is judged, in the end, by an evidence test. The auditor is not asked whether your process improved. Under the standard governing audits of internal control over financial reporting (PCAOB, AS 2201), the auditor forms an opinion on whether the control operated effectively over a period, which means selecting from a population and inspecting what each selection left behind. The standard on audit evidence (PCAOB, AS 1105) sets what counts: evidence must be sufficient and appropriate, and inspection of records is one of the few procedures that produces it.
Read together, those two standards convert your remediation paragraph into a set of concrete requirements. There must be a population that can be listed. Each item in it must carry the identity of the person who performed the step, the date it was performed relative to the period it belongs to, the version of the input that was used, and the identity of a different person who reviewed it. The records must be retained long enough to be sampled, and they must have been created when the work happened rather than assembled afterwards.
That is a specification. It is not a policy.
The auditor is not testing whether the control was performed. They are testing whether the performance left a record they can pull.
Remediation Plans Are Written In The Wrong Language
Most remediation plans are written in three registers, and none of the three produce a record.
- Staffing. "We have hired a technical accounting manager." A capable person raises the quality of judgement. It does not create a population to sample.
- Policy. "We have documented the review procedure." A document describes how a control should run. It is not evidence that any instance of it did.
- Enhanced review. "Management has implemented additional review over the reconciliation process." This is the most common sentence and the weakest. It commits to attention, which is unobservable after the fact and depletes precisely when the period closes.
A fourth register exists and appears far less often: the step is changed so that performing it produces a record the performer cannot skip. This is the only register that reliably changes the audit result, and it is the one that requires software.
| What the plan says | What a tester can pull |
|---|---|
| We hired a senior analyst | An organization chart |
| We documented the procedure | A document, undated in practice |
| Management performs additional review | An email, if it was kept |
| The step cannot complete without a stamped approval | A list, with names, times, versions and exceptions |
Only the last row survives contact with a sample.
Why The Gap Survives Every Meeting
The uncomfortable part is that everyone in the discussion is telling the truth. The controller says the reconciliation is reviewed, and it is — carefully, by someone who understands it. The auditor says they cannot test it, and they cannot, because the review left an email, a saved file and a memory. Both statements are correct, and neither one produces the next action, because the next action is a small piece of software and nobody in the conversation owns software.
Information technology is not the missing owner either. That group owns the enterprise system, the network and the endpoints. The step that failed almost never lives inside the enterprise system — it lives in the twenty percent of the process the enterprise system was never built to do, where a spreadsheet became the system of record for one slice of the close.
The research on where these weaknesses appear should be read by anyone deciding how urgently to act. The determinants of weaknesses in internal control over financial reporting (Doyle, Ge & McVay, Journal of Accounting and Economics, 2007) found disclosed weaknesses concentrated in firms that are smaller, younger, financially weaker, more complex, growing rapidly, or restructuring. That is a description of a company between sixty and two hundred million dollars in revenue that has just acquired something. The effect of internal control deficiencies on firm risk and cost of equity (Ashbaugh-Skaife, Collins, Kinney & LaFond, Journal of Accounting Research, 2009) reports that firms disclosing deficiencies carry higher cost of equity, and that the effect moves when the deficiencies are remediated. Internal control weaknesses and information uncertainty (Beneish, Billings & Hodder, The Accounting Review, 2008) points the same direction. Remediation is not only a compliance activity; it is priced.
And remediation is not automatic. Work on the remediation of material weaknesses (Goh, Contemporary Accounting Research, 2009) found that timely remediation is associated with specific governance conditions rather than with the passage of time. Companies do sit with the same paragraph for a second year, and the second disclosure is materially worse than the first, because the market now has evidence about follow-through rather than about accounting.
Read The Paragraph As A Specification
The useful exercise takes about ninety minutes and needs the controller, one person who actually performs the step, and one person who can read a requirement.
Take each sentence of the remediation plan and rewrite it in this form: who performs the step, over what population, in what order relative to other steps, producing what record, retained where, reviewed by whom, before what date. Any sentence that cannot be rewritten this way is not a remediation commitment. It is an intention, and it will be tested as one.
The sentences that can be rewritten will fall into two groups. Some describe records your existing systems already produce, and the work is to find and retain them. The rest describe records that do not exist anywhere, and each of those is a small, bounded piece of software: a form that will not submit without a stamped approver, a queue that holds exceptions until someone dispositions them, a log that records what was used and when.
That second group is usually one workflow. It is rarely a platform, and it is almost never an enterprise system implementation. Twelve filings in the trailing twelve months use the exact phrase "manual processes and spreadsheets" — a small number, because most companies describe the same condition without naming it that plainly.
First Steps
- Print the remediation paragraph and mark every verb. Circle each one that describes attention — reviews, monitors, oversees, ensures. Those are the sentences that will not survive a sample.
- For one circled verb, ask the person who performs the step to show you the last three instances. Not the procedure. The instances. What they can produce in five minutes is what the auditor will get.
- Write the specification form for that one step — who, what population, what order, what record, retained where, reviewed by whom, before what date. If it fits on one page, it is buildable this quarter.
Turn The Sentence Into A Deliverable
The obligation in your filing has a date attached to it, and dates are the one thing a remediation plan cannot renegotiate quietly. The distance between a plan written in policy language and one written as a specification is normally a single conversation with somebody who builds this kind of system, followed by four weeks of work.
A fifteen-minute call — nothing paid, nothing signed — takes one remediation sentence apart: what the record must contain, where it comes from, what has to be built, and what it costs. If the honest answer is that your existing systems already produce the evidence and the work is retention and reporting, that is what we will say, and it will have saved you a build.
Where something does have to be built, that work runs as a monthly engineering partnership, with the targets each release must meet written down before it starts. Paid-for deliverables transfer to you monthly, and the documentation and run guide come with them. After that, $15,000 a month puts one accountable person on keeping it running, with a written monthly report of what ran and what changed — which is itself the kind of artifact an audit committee likes to receive. The next step is to read your own paragraph as the specification it already is, and see how short it turns out to be.
References
- Public Company Accounting Oversight Board. AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements. PCAOB Auditing Standards.
- Public Company Accounting Oversight Board. AS 1105: Audit Evidence. PCAOB Auditing Standards.
- Doyle, J., Ge, W., & McVay, S. Determinants of Weaknesses in Internal Control over Financial Reporting. Journal of Accounting and Economics, 2007.
- Ashbaugh-Skaife, H., Collins, D. W., Kinney, W. R., & LaFond, R. The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity. Journal of Accounting Research, 2009.
- Beneish, M. D., Billings, M. B., & Hodder, L. D. Internal Control Weaknesses and Information Uncertainty. The Accounting Review, 2008.
- Goh, B. W. Audit Committees, Boards of Directors, and Remediation of Material Weaknesses in Internal Control. Contemporary Accounting Research, 2009.
- U.S. Securities and Exchange Commission. EDGAR Full-Text Search. Filing counts cited are from full-text search over the trailing twelve months.



