When the auditor finishes, the business receives two documents, not one: the auditor’s report, which is attached to the financial statements and read by everyone, and the management letter, which only you read. The first says whether your statements are fair; the second says where your money and information leak, and which gap in your internal control will turn next year into a bigger finding or a qualification of the opinion. Yet in many businesses the letter is read once and filed.
This guide explains what the management letter is and its basis in the auditing standards, how it differs from the auditor’s report and the management representation letter, the findings that recur most in small and medium-sized businesses, and how to read and act on it so that it does not come back next year.
First: what is the management letter, and what is its basis?
The International Standards on Auditing adopted in the Kingdom require the auditor to communicate in writing and on a timely basis to those charged with governance the significant deficiencies in internal control identified during the audit, and to communicate to management the other deficiencies that merit its attention (ISA 265). A deficiency exists when a control is designed, implemented or operated in a way that is unable to prevent, or detect and correct, misstatements in the financial statements on a timely basis, or when a control necessary to do so is missing; a deficiency is significant when, in the auditor’s professional judgement, it merits the attention of those charged with governance.
The letter has a limit that should be understood: an audit is not designed to identify all deficiencies in internal control, only what is needed to form an opinion on the statements. The letter therefore sets out what the auditor noticed along the way, not a comprehensive evaluation of the control system; that evaluation is a separate engagement.
Second: three documents that are often confused
| Document | From whom to whom | Content | Who sees it |
|---|---|---|---|
| Auditor’s report | From the auditor to the partners or the general assembly | The opinion on the fairness of the financial statements, management’s position on enabling the auditor, and any violations of the Law or the articles noted (Companies Law Art. 20(5)) | Public: partners, the bank, ZATCA and anyone the statements are given to |
| Management letter | From the auditor to those charged with governance and management | Deficiencies in internal control identified during the audit, their potential effects and the auditor’s recommendations (ISA 265) | Private: management and the partners or the audit committee |
| Management representation letter | From management to the auditor | Written acknowledgement of management’s responsibility for the statements and that all information was provided (ISA 580) | The audit file |
There is a fourth level of communication that precedes the letter: the auditor must inform those charged with governance of the auditor’s responsibilities, the planned scope and timing of the audit, and the significant findings — such as difficulties encountered, uncorrected misstatements and matters discussed with management (ISA 260). If none of that reaches you from your auditor, ask.
Third: the findings that recur most in small and medium-sized businesses
- No segregation of duties: the same person collects cash, records it and reconciles the bank account, so no control detects error or manipulation.
- Bank reconciliations not prepared monthly, or prepared and reviewed by nobody but the preparer.
- An undocumented authority matrix: who approves payments, approval limits, and dual bank signatures.
- Petty cash without surprise counts and without a limit on what is held.
- Inventory counts without written procedures: count differences, slow-moving and damaged items, and who approves adjustments.
- A fixed asset register that is not updated or does not match the assets actually present.
- Related-party transactions without contracts, prior approval or disclosure.
- Revenue: cut-off between the two years, and reconciliation of e-invoices to the books and to the VAT returns.
- Payroll: approval of payroll changes, the GOSI reconciliation, and end-of-service benefits.
- Systems: broad access rights, shared passwords, and backups that are never tested.
Fourth: how to read the letter — and how to respond
- Rank by effect, not by count. One finding on segregation of duties over cash is more serious than ten formal ones; start with what the auditor classified as a significant deficiency.
- Ask for the cause, not the symptom. A late bank reconciliation is a symptom; the cause may be understaffing or the absence of supervisory review.
- Assign an owner and a date to every item and record management’s response formally; the auditor includes management’s response in the final letter and follows it up the next year.
- Separate what can be fixed at once from what needs a decision: closing an access right is a daily decision; hiring a second accountant to segregate duties is a decision for the partners.
- Tie the findings to the next statutory deadline: what is not fixed before year end will show in the count, the confirmations and the next audit, and may turn from a finding into a scope limitation that affects the opinion — see types of auditor opinion.
Fifth: what the auditor does not do in this file
The auditor recommends but does not implement; designing and operating controls is management’s responsibility, and the Law prohibits the auditor from performing technical, administrative or consulting work in the company they audit except as the regulations allow (Companies Law Art. 20(3)), to preserve independence. If you need someone to design payment policies, build the authority matrix or evaluate internal control comprehensively, that is a separate engagement with another firm or with an advisory team independent of the audit team — see our risk consulting service. The auditor is also bound to keep the company’s secrets confidential (Art. 20(6)), so the management letter goes to no one but its addressees.
Sixth: recurring mistakes
- Reading the letter as criticism of the accountant instead of as a risk map.
- Treating the symptom in one item and leaving the cause that generates ten symptoms.
- A generic management response with no owner and no date, so the same finding returns next year marked “repeated”.
- Asking the auditor to design the controls or keep the books to clear the findings, which the Law prohibits.
- Filing the letter without presenting it to the partners or the audit committee, so the most valuable output of the audit never reaches them.
Frequently asked questions
What is the difference between the management letter and the auditor’s report?
The auditor’s report is a public document attached to the financial statements in which the auditor expresses an opinion on their fairness, including management’s position on enabling the auditor and any violations of the Law noted, under Article 20 of the Companies Law. The management letter is a private document in which the auditor informs management and those charged with governance of the deficiencies in internal control noted during the audit and the auditor’s recommendations, under ISA 265.
Is the auditor required to issue a management letter?
The standards require the auditor to communicate in writing and on a timely basis to those charged with governance the significant deficiencies identified during the audit, and to communicate to management the other deficiencies that merit its attention. If nothing worth communicating is found, no letter may be issued.
Does a management letter mean the financial statements are unsound?
No. The letter deals with internal control, not the fairness of the statements; an unmodified opinion may be issued alongside a long management letter, because the auditor compensated for weak controls with additional procedures on the balances. But persistent deficiencies can later become a limitation on the scope of the audit.
Does the management letter reveal every gap in internal control?
No. An audit is not designed to identify all deficiencies, only what is needed to form an opinion on the financial statements, so the letter is limited to what the auditor noticed during the work. A comprehensive evaluation of internal control is a separate engagement.
Can the auditor design the procedures they recommend?
No. Designing and operating controls is management’s responsibility, and Article 20 of the Companies Law prohibits the auditor from performing technical, administrative or consulting work in the company they audit except as the regulations allow, to preserve independence.
Who should see the management letter?
Executive management and those charged with governance — the partners, the board or the audit committee where one exists. It is confidential and is not given to third parties, and it is best presented at the meeting that approves the financial statements together with a remediation plan with an owner and a date for every item.
How we help
At Al-Mousa & Al-Tamimi Certified Public Accountants we deliver with the audit report a management letter ranked by effect, with a description, the potential effect, our recommendation and management’s response for every finding, and we follow up its status the following year. When a business needs its controls designed or comprehensively evaluated, a team independent of the audit team does that work to preserve independence.
See our external audit service · Read next: preparing your business for its first audit · Audit, review or compilation? · Contact us
Sources: International Standards on Auditing adopted in the Kingdom — SOCPA (ISA 260, 265 and 580; Arabic); Companies Law, Royal Decree No. M/132 dated 1/12/1443H — Saudi Laws Portal (Article 20; Arabic). This article is general guidance and is not a substitute for advice on a specific case.
