Risk scoring and factors
Internal Audit → Risk Factors
This screen defines how the audit universe is risk-ranked, which in turn drives which entities make it into the annual plan. It does not score anything by itself — it configures the model.
The three layers
Universal factors are scored on every auditable entity: regulatory exposure, financial materiality, prior audit findings, time since last audit, strategic importance, process complexity, operational impact.
Category packs add factors that only apply to one entity type — fraud potential for financial operations, application criticality for IT, vendor dependency for supply chain.
Factor scope at the bottom of the page shows the same thing per factor: tick the categories a factor applies to. No ticks means it applies to everything.
How the score is calculated
Each factor is scored 1–5 on each entity. The composite is the weighted average, expressed out of 100:
composite = ( Σ(score × weight) / (5 × Σ weight) ) × 100
Weights are relative. Doubling every weight changes nothing — only the ratios matter. A factor at 1.50 counts 50% more than one at 1.00.
The result bands into a tier:
| Composite | Tier |
|---|---|
| 75 – 100 | Critical |
| 50 – 74 | High |
| 25 – 49 | Medium |
| 0 – 24 | Low |
Include universal factors
Each category has an Include universal factors checkbox.
- Ticked — entities in that category are scored on the universal factors plus the category's own.
- Unticked — only the category's own factors count.
An entity scored on five IT factors and an entity scored on nine factors including regulatory exposure both produce a number out of 100, and both appear in the same ranked list — but they are not measuring the same thing. Leave the box ticked unless you have a deliberate methodology reason not to, and record that reason.
Changing weights
Adjust a weight, then Save changes. Existing scores are not lost — the composite is recalculated from the factor scores already recorded, so re-weighting immediately re-ranks the universe without anyone re-scoring.