Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

internal audit findings rating scale — Internal Audit Findings Rating Scale: Examples and Template

Internal Audit Findings Rating Scale: Examples and Template

An internal audit findings rating scale is the part of the methodology that turns a list of exceptions into a message the board can act on. The Global Internal Audit Standards require every finding to be rated for significance and prioritised, but they do not prescribe the scale. The IIA leaves the design to the chief audit executive (CAE), which means every function has to build its own and apply it consistently.

This guide sets out what Standards 14.3, 14.5 and 15.1 require, then works through an example internal audit findings rating scale that a function could adopt: a likelihood and impact matrix, four significance bands, four priorities and four conclusion levels. Treat the numbers as a starting point to calibrate, not as IIA requirements.

What this guide covers

internal audit findings rating scale explained
An example likelihood and impact matrix for rating internal audit findings.

What the Standards require of an internal audit findings rating scale

Standard 14.3 sets the core obligations. Each potential finding must be evaluated for significance. Where possible, auditors work with management to identify the root cause and the potential effects. Significance has to reflect both how probable the risk is and how far it could affect governance, risk management or control. Any significant risk must be reported as a finding; whether lesser risks are reported is decided under the function’s methodology. Each finding is then prioritised using the methodology the CAE has established.

The implementation guidance adds useful detail. Before rating, auditors assess whether existing controls are adequately designed and operating, then judge the residual risk that remains. Risk tolerance and any other factors the organisation treats as important should also be weighed. A rating or ranking is described as a helpful way to communicate significance and to help management order its actions.

That is the full extent of the rule. No number of levels, no labels, no colour scheme. An internal audit findings rating scale that rests on likelihood and impact, is documented in the methodology, and is applied the same way across engagements meets the requirement. One that changes from auditor to auditor does not.

An example internal audit findings rating scale

The example internal audit findings rating scale below uses two four-point dimensions. Likelihood runs from 1 (Rare) to 4 (Almost certain). Impact runs from 1 (Minor) to 4 (Severe). Multiplying them gives a score from 1 to 16, which falls into one of four bands.

Likelihood \ Impact 1 Minor 2 Moderate 3 Major 4 Severe
4 Almost certain 4 Medium 8 High 12 Critical 16 Critical
3 Likely 3 Low 6 Medium 9 High 12 Critical
2 Possible 2 Low 4 Medium 6 Medium 8 High
1 Rare 1 Low 2 Low 3 Low 4 Medium

The bands and the priorities attached to them are where an internal audit findings rating scale becomes useful to management. The response times below are illustrative; your board and senior management should agree the real ones.

Band (score) Priority Meaning Example response
Critical (12–16) P1 Exposure that could defeat a key objective or breach a legal obligation Containment agreed before the report issues; reported to the audit committee at its next meeting; target within 30 days
High (8–9) P2 Material control weakness in a significant process Action plan with named owner in the report; target within 90 days
Medium (4–6) P3 Weakness that needs fixing but is contained by other controls Target within 180 days
Low (1–3) P4 Improvement opportunity or minor lapse Next process review cycle; may be raised in a management letter

Defining impact and likelihood

An internal audit findings rating scale is only as consistent as its definitions. For impact, write criteria across several dimensions: financial loss as a threshold tied to the board’s risk appetite, regulatory consequence, operational disruption, reputational harm, and health and safety. A finding takes the highest impact level it reaches on any dimension. For likelihood, define each level by expected frequency over a stated period, and include a qualitative description for risks that are hard to express as a frequency.

Wherever possible, build the internal audit findings rating scale on the definitions in the organisation’s enterprise risk matrix. Management then reads audit ratings in the same language as its own risk register, and the risk-based internal audit plan and the findings it produces use one vocabulary.

Applying the internal audit findings rating scale: a worked example

During an accounts payable engagement, testing shows quarterly access reviews for the payments system were not performed for two quarters. Three people who left the organisation still had active accounts with payment-entry rights.

  1. Criteria and condition. Policy requires a quarterly review. Two were missed and three leaver accounts remained live.
  2. Root cause, agreed with management. Leaver notifications for contractors went to the contracting manager and never reached IT. The missed reviews followed a change of system owner with no handover.
  3. Likelihood. With the review absent and the leaver process broken, misuse of a live account is rated Likely (3).
  4. Impact before other controls. Unauthorised payments could be material: Major (3). Score 9, High.
  5. Residual risk. The workflow enforces a second approver on every payment, which was tested and found effective. A leaver could enter but not release a payment, so impact falls to Moderate (2). Score 6, Medium, P3.

The final rating is Medium, but the root cause, a broken leaver process, may affect other systems. That observation belongs in the report even if the finding itself is not High, and it may influence the conclusion.

Two points from the example apply to any internal audit findings rating scale. First, rate the residual risk after testing the controls that are actually in place, not the theoretical worst case, and show the reasoning in the workpaper so a reviewer can follow each step. Second, keep the rating and the root cause separate: a Medium finding can still point to a process failure that deserves the board’s attention.

From the internal audit findings rating scale to a conclusion

Standard 14.5 requires an engagement conclusion that summarises the auditors’ judgement on the overall significance of the findings taken together. For assurance work it must state a view on whether governance, risk management and control in the area are effective, and it must say so when they are. A clean report should not read as a list of nothing found.

The implementation guidance mentions that a conclusion scale can be part of the CAE’s methodology. A four-level example to pair with the scale above:

  • Effective: no findings above Low; controls are designed and operating as intended.
  • Generally effective: Medium findings only, none of which individually or together threaten the area’s objectives.
  • Partially effective: one or more High findings, or several Medium findings sharing a root cause.
  • Not effective: any Critical finding, or High findings that undermine a key objective of the area.

These are guides to judgement, not arithmetic. Standard 14.5 calls for professional judgement on the aggregated findings, so a conclusion that departs from the guide should record why.

Reporting ratings under Standard 15.1

For assurance engagements, Standard 15.1 requires the final communication to set out the findings with their significance and prioritisation, any scope limitations, and the conclusion on effectiveness. It must also name the individuals responsible for each action and the planned completion dates, and acknowledge actions management took before the report was issued.

In practice, each finding in the report should show where it sits on the internal audit findings rating scale, along with its priority, root cause, owner and date. The ratings then drive follow-up under Standard 15.2 and the content of periodic reports to the board.

Governing your internal audit findings rating scale

  • Approve and publish it. Put the internal audit findings rating scale in the methodology manual and share it with the audit committee so the board knows what a High means.
  • Calibrate it. Periodically review a sample of ratings across auditors to check they apply the scale the same way. This is a natural part of the quality assurance and improvement program.
  • Change ratings on evidence only. Management may disagree with a rating. Standard 14.4 expects a methodology for handling disagreement; new evidence can move a rating, negotiation should not.

For the wider structure the scale sits in, see our guide to the Global Internal Audit Standards, and read the source text on the IIA’s complete Global Internal Audit Standards page.

Frequently asked questions

Does the IIA prescribe an internal audit findings rating scale?

No. Standard 14.3 requires significance to reflect likelihood and impact and findings to be prioritised by the CAE’s methodology, but the levels, labels and thresholds are the function’s choice.

Should we use three, four or five levels?

Any number works if it is defined and consistent. Four levels avoid a default middle rating, which forces a decision on borderline findings.

Can management change a finding’s rating?

Management can provide new evidence, and the rating should move if the evidence changes likelihood or impact. The rating belongs to internal audit; where disagreement remains, record both positions.

How does the internal audit findings rating scale relate to the engagement conclusion?

The scale rates individual findings; the conclusion judges the area as a whole. The conclusion draws on the ratings but is a separate professional judgement under Standard 14.5.

Our Internal Audit Toolkit provides 87 editable templates built on the 2024 Standards and the four issued Topical Requirements. For rating and reporting findings, it includes the Finding Significance Rating Scale, the Finding Sheet, the Engagement Conclusion and Rating Guide, the Recommendations and Management Action Plan, the Final Audit Report – Assurance and the Action Tracking Register. It is $99, in Word and Excel, so you can set your own thresholds and labels.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.