CORAA
CORAA University / Free rating matrix

Internal audit issue rating matrix

Score observations consistently before report issue: impact, likelihood, control weakness, recurrence, compliance sensitivity and pervasiveness, with a documented override trail.

Rating profile

The defaults are illustrative. Replace every example observation and treat the calculated rating as a draft before partner, CAE or audit committee review.

High
1
Medium
1
Low
1
Overrides
0
Issue rating matrix
RefCycleObservation titleConditionFinancial impactLikelihoodControl weaknessRecurrenceCompliancePervasivenessScoreSuggestedOverrideOverride rationaleApproved byApproval dateOwnerStatus
23/30High
20/30Medium
11/30Low
Rating rationale

IA-001: IA-001 is rated High on a score of 23/30. Main drivers: financial impact, likelihood, control weakness, pervasiveness.

IA-002: IA-002 is rated Medium on a score of 20/30. Main drivers: control weakness, recurrence.

IA-003: IA-003 is rated Low on a score of 11/30. No individual driver is scored 4 or 5.

Rating discipline

Score consistently with judgement

The matrix creates consistency; it does not replace evidence. Override the suggested rating when facts justify it, but retain the rationale so the final report rating can survive management and audit committee review.

Use this after the control gap register or sampling plan, then move final ratings into the observation report pack.

How an internal audit issue rating matrix should work

An issue rating matrix helps internal audit apply consistent severity logic across observations. It should consider impact, likelihood, control weakness, recurrence, compliance sensitivity and pervasiveness, not only the rupee value of an exception.

The suggested rating should remain reviewable. If the auditor overrides the score, the report file should retain why the rating changed and who approved the judgement.

This generator creates an editable scoring matrix, rating rationale sheet and audit committee summary. It is useful for P2P, O2C, R2R, H2R, treasury, inventory, compliance, ITGC and continuous monitoring observations.

Worked example - bank approval weakness

A P2P review identifies that bank portal approvers are not matched to the ERP authority matrix. Financial impact, likelihood, control weakness and pervasiveness are all high enough to drive escalation.

Inputs
Financial impact4/5
Control weakness5/5
Total score23+/30
Output
Suggested ratingHigh
Report actionEscalate owner, due date and interim mitigation
The rating is driven by authority misalignment and payment risk, not merely by whether a duplicate or unauthorised payment was already found.

Common mistakes

Rating only by money value
A low-value exception can still be high risk when it indicates access weakness, compliance breach, management override or recurring process failure.
No override trail
Manual judgement is expected, but the reviewer should see why the final rating differs from the matrix output.
Confusing issue rating with management priority
Management urgency may differ from audit severity. Keep the audit rating evidence-based and track action priority separately where needed.
Ignoring recurrence
Repeat observations and unresolved prior-period issues often deserve stronger escalation even when the current sample count looks small.

Frequently asked questions

How should internal audit rate observations?+
Rate observations using evidence-backed criteria such as impact, likelihood, control weakness, recurrence, compliance sensitivity and pervasiveness. Final rating should be reviewed before report issue.
What score is High in this matrix?+
This tool suggests High at 23 to 30, Medium at 15 to 22 and Low below 15. The thresholds are a practical template, not a statutory rule.
Can the suggested rating be overridden?+
Yes. The auditor, partner, CAE or reviewer may override the suggested rating when facts justify it. The rationale should be retained in the workpaper.
Should all compliance issues be High?+
No. Compliance sensitivity is one driver. Rating still depends on impact, likelihood, recurrence, control design, pervasiveness and management response.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditApplicable from April 1, 2026; supports planning, evidence, documentation, review and reporting for internal audit work.
ICAI
ICAI IASB - Standards on Internal Audit publicationsLists current and legacy standards covering internal controls, evidence, documentation, review, reporting and monitoring prior issues.
The IIA - Global Internal Audit StandardsThe 2024 standards became effective for internal audit functions on January 9, 2025.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Control design gap registerSampling plan generatorObservation report generatorDashboard pack generatorCORAA Internal Audit
Share this tool
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.