Article

Finding Criticality and Internal Audit Report Ratings: how to build an objective system

How to ensure two auditors always rate the same finding the same way.

Two different auditors, faced with the same finding, sometimes assign a different criticality rating. And two audit departments within the same organization may rate a similar risk using scales that are not comparable to each other. This problem, far from being anecdotal, is one of the most common sources of erosion in reporting credibility before the Audit Committee. This article proposes a practical model for rating findings and building a report rating system that is objective, traceable, and defensible.

Why finding criticality is one of the weakest points in audit reporting

The rating assigned to a finding determines its correction priority, the level of follow-up it receives, and in many cases whether it needs to be escalated to the Audit Committee. When that judgment depends on each individual auditor's personal assessment without a shared framework, the result is inconsistent even within the same department.

The problem of subjectivity across auditors

It is common for a more experienced auditor to rate as "medium" a finding that a more cautious colleague would rate as "high." Without a documented scale with clear criteria, both ratings are defensible at the moment they are issued, but generate an inconsistency that becomes obvious when reports are compared against each other.

The impact on Audit Committee credibility

When the Audit Committee detects that finding criticality varies depending on who wrote the report, the immediate consequence is a loss of confidence in the reporting as a whole. This affects not just the perception of a single report, but the general view of the department's methodological rigor.

What an objective rating system requires

Clear, documented evaluation criteria

Each criticality level must be defined with a concrete description, not an open-ended label. The difference between a "high" and a "medium" finding must be explainable with specific examples and thresholds, not just the auditor's intuition.

Consistent rating scales

The scale used (whether three, four, or five levels) must be the same across the entire department and applied uniformly across all engagements, regardless of the process reviewed or the auditor responsible. Changing scales depending on the type of work introduces unnecessary noise when comparing results over time.

Linking finding criticality to the report rating

The final report rating must derive from a clear rule based on the individual criticality of findings, not from an overall intuitive assessment by the auditor at engagement close. This link is what makes the rating traceable and reproducible under external review.

A practical model for rating findings

A robust rating model combines at least three dimensions, each evaluated independently before arriving at the final criticality level.

Dimension 1: Potential impact

Measures the consequence the finding would have if it materialized: estimated financial loss, regulatory exposure, reputational impact, or operational disruption. Defining clear numerical or qualitative ranges for each level ensures that two auditors reach the same conclusion when faced with the same scenario.

Dimension 2: Likelihood of materialization

Assesses how likely the identified weakness is to actually cause harm, considering process frequency, existing compensating controls, and the history of related prior incidents.

Dimension 3: Scope or breadth of the finding

Determines whether the weakness is isolated (a single case) or systemic (affecting an entire process, area, or subsidiary). A finding with low individual impact but high breadth may warrant a higher criticality than it would if it were a single instance.

Dimension Key question Example variable
Potential impact What would happen if it materialized? Estimated financial loss, regulatory exposure
Likelihood How likely is it to occur? Compensating controls, incident history
Scope Is it isolated or systemic? Number of affected areas, processes, or subsidiaries

How to move from finding ratings to the report rating

Common aggregation methods

Two main approaches are used to build the report rating from individual findings. The first, based on the worst case, assigns to the report the criticality of the most severe finding identified. The second, based on a weighted matrix, combines the number and severity of all findings to produce an aggregate score. Both methods are valid, but the department must choose one and apply it consistently across all engagements.

Why a single critical finding can drive the overall rating

In most serious methodologies, a single very high criticality finding is sufficient to affect the overall report rating, regardless of how many minor findings were also identified. This rule prevents a process with one serious isolated risk from receiving, by averaging, an overall rating that is misleadingly positive.

Common mistakes when rating findings

  • Defining criticality levels without concrete examples. A scale with labels like "high, medium, low" but no detailed descriptions still leaves the final decision to individual judgment.
  • Not periodically reviewing consistency across auditors. The department's quality assurance program should include a specific review of whether different auditors rate comparable findings in a comparable way.
  • Changing the scale between engagements or between years. This breaks the ability to compare risk evolution in the same process over time.
  • Ignoring the scope dimension. Focusing only on the individual impact of each finding, without considering whether it is systemic, can lead to underestimating risks that affect the entire organization.

Key control point: if reviewing the last twelve months of reports does not make it possible to explain, with data, why a finding received a particular criticality rating, the rating system needs to be formalized before the next External Quality Assessment.

An audit management platform that integrates the rating model directly into the workflow applies the same rules to all auditors, calculates the report rating automatically, and maintains a comparable history of risk evolution by process.

Checklist for building an objective rating system

  1. Is each criticality level defined with concrete examples and thresholds, not just a label?
  2. Is the rating scale the same for all auditors and all engagements?
  3. Does the model consider at least impact, likelihood, and scope of the finding?
  4. Is there a documented rule for deriving the report rating from individual finding criticality?
  5. Can a single isolated critical finding affect the overall rating, rather than being diluted in an average?
  6. Is consistency of rating across different team members reviewed periodically?

Conclusion

An objective finding rating system does not eliminate the auditor's professional judgment, but it does frame it within verifiable and reproducible criteria. This is precisely what the Global Internal Audit Standards expect from the function's reporting: consistent, traceable communication that is comparable over time. Investing in formalizing this model not only improves the technical quality of reports, but directly strengthens the confidence the Audit Committee places in the department.