How are you thinking regarding risk ratings being used for the findings within an Audit Report? Are there any changes to the approach?

761 views1 Upvote5 Comments
Sort By:
CFO in Travel and Hospitality9 months ago
Risk ratings are always beneficial in understanding the importance of a finding and how critical it can be for the company. This can also give enough guideline to focus on either improving an existing control or introduce a new one to bring down the risk to lower possible.
Vice President, Internal Audit in Banking9 months ago
I agree that risk ratings are beneficial in allowing stakeholders to develop risk-based remediation plans (or risk acceptance decisions) and prioritize resources. We have adopted the risk ratings scale in our organization's risk management standards to promote consistency amongst assurance providers.
SVP Corporate Audit in Energy and Utilities9 months ago
We use risk ratings for every audit finding that we report.  This is used to drive the speed of implementation of the remediating actions.  However, no matter what the risk rating is the actions need to be completed by the due date, with the Board getting an update each quarter of progress against implementation of actions and any overdue actions.
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Vice President - Internal Audit and Enterprise Risk Management in Healthcare and Biotech8 months ago
We rate every finding in our audit reports as we find that it helps out senior leaders understand relative severity in order to assist with prioritization and resourcing taken within the context of the broader set of initiatives their teams are working on.   We've recently revisited our rating scales to ensure that they are still appropriate given the overall company risk appetite. We also made updates to the language we use for our ratings, to improve our ability to communicate the ratings to our internal clients.
SVP - External and Regulatory Audit8 months ago
We risk rate all findings that rise to the level of an "issue". That criticality rating drives overall audit rating - Satisfactory, unsatisfactory, needs improvement. All Med and High issues are reported to the Audit Committee, based on status updates from management. Risk definitions are tied to ERM framework. 

Content you might like


Print Edition64%


Audio Books (I prefer to listen)8%

Something else?1%

View Results
6.6k views6 Comments
294 views1 Upvote
IT Manager in Construction4 months ago
Do you can add some examples of what you are thinking about?
Read More Comments
48.8k views6 Upvotes33 Comments

Market Research12%

Build a Team47%

Build a MVP24%

Make a Business Plan12%

Prepare a Pitch Deck1%

another action (mention in comments)

View Results
5k views2 Upvotes3 Comments