Security Pie

The ramblings of three security curmudgeons

Words I like: Significant Deficiency & Control Deficiency

without comments

The road to/from deficiency

The road to/from deficiency

I found the following definition of “significant deficiency” in a GAO report and I liked it. If you are outside of the US or not regulated by US regulations, you can change the reference regulations mentioned in the first sentence:

A significant deficiency is a control deficiency, or combination of control deficiencies, that adversely affects the entity’s ability to initiate, authorize, record, process, or report financial data reliably in accordance with U.S. generally accepted accounting principles such that there is more than a remote likelihood that a misstatement of the entity’s financial statements that is more than inconsequential will not be prevented or detected.

Then, it also explains what a control deficiency is:

A control deficiency exists when the design or operation of a control does not allow management or employees in the normal course of performing their assigned functions to prevent or detect misstatements on a timely basis.

Written by sharon

June 8th, 2009 at 1:01 pm

Posted in Risk Management

Tagged with ,