Audit Finding Severity Calculator
Rate an audit finding on control importance, pervasiveness, exposure, regulatory impact and recurrence, with an SLA and escalation route.
Inputs
Finding Rating
High
Severity Score
70.4%
Adjusted Severity
3.52of 5
Remediation SLA
60days
Deficiency Classification
Significant deficiency — less severe than a material weakness, but important enough to report to those charged with governance
Escalation Route
Head of function, plus inclusion in the audit committee summary report
Repeat Finding Note
Repeat finding — a 15% uplift is applied because management's previous response did not hold, which is itself a governance issue
Step by step
Values used
Importance of the failed control = 4 — Key control, no alternative; Pervasiveness = 4 — Multiple business units; Financial or data exposure behind the finding = 750,000 $; Regulatory or contractual implication = 3 — Contractual commitment; Likelihood of recurrence if untreated = 4 — Likely; Compensating control strength = 30 %; Repeat of a previously reported finding = Yes
Audit Finding Severity
Adjusted severity = (0.25 × control importance + 0.20 × pervasiveness + 0.20 × exposure band + 0.20 × regulatory implication + 0.15 × recurrence) × compensating-control factor × repeat uplift.
Rating and SLA
Rating thresholds on the 1–5 adjusted scale: 4.2 and above critical, 3.2 high, 2.2 medium, below that low, with SLAs of 30, 60, 90 and 180 days.
Finding Rating
= High
Severity Score
= 70.4
Adjusted Severity
= 3.52 of 5
Remediation SLA
= 60 days
Deficiency Classification
= Significant deficiency — less severe than a material weakness, but important enough to report to those charged with governance
Escalation Route
= Head of function, plus inclusion in the audit committee summary report
How it works
Pervasiveness and recurrence do most of the work in separating a one-off slip from a broken process, and a compensating control can only halve the severity because it was not designed for this risk and has not been tested against it. The repeat uplift exists because a finding that comes back is evidence about the management response, not just about the control. Consistent finding ratings are what make an audit report actionable rather than negotiable, and the SLA and escalation route follow from the rating so that severity has consequences. These are management estimates to support consistency, not an auditor's formal opinion.
Formulas
Audit Finding Severity
Adjusted severity = (0.25 × control importance + 0.20 × pervasiveness + 0.20 × exposure band + 0.20 × regulatory implication + 0.15 × recurrence) × compensating-control factor × repeat uplift.
- mitig
- 1 − 0.5 × compensating control strength; a compensating control halves severity at best, it never removes it
- repeat uplift
- ×1.15 when the same finding has been reported before
- exposureScore
- Financial or data exposure mapped to a 1–5 band
Rating and SLA
Rating thresholds on the 1–5 adjusted scale: 4.2 and above critical, 3.2 high, 2.2 medium, below that low, with SLAs of 30, 60, 90 and 180 days.
- adjusted
- Weighted severity after mitigation and repeat uplift
- slaDays
- Remediation window that matches the rating
Frequently Asked Questions
How is Audit Finding Severity calculated?
Adjusted severity = (0.25 × control importance + 0.20 × pervasiveness + 0.20 × exposure band + 0.20 × regulatory implication + 0.15 × recurrence) × compensating-control factor × repeat uplift. Pervasiveness and recurrence do most of the work in separating a one-off slip from a broken process, and a compensating control can only halve the severity because it was not designed for this risk and has not been tested against it. The repeat uplift exists because a finding that comes back is evidence about the management response, not just about the control.
Why does Audit Finding Severity matter?
Consistent finding ratings are what make an audit report actionable rather than negotiable, and the SLA and escalation route follow from the rating so that severity has consequences. These are management estimates to support consistency, not an auditor's formal opinion.
What values do I need to enter?
This calculator takes 7 inputs: Importance of the failed control, Pervasiveness, Financial or data exposure behind the finding, Regulatory or contractual implication, Likelihood of recurrence if untreated, Compensating control strength, Repeat of a previously reported finding. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does a repeat finding score higher?
Because the failed control is no longer the only issue. Management previously accepted a remediation plan that did not work, which means either the root cause was misdiagnosed or the plan was never delivered — and both are governance findings that an audit committee should see.
Are material weakness and significant deficiency the right words for a non-financial audit?
They come from financial reporting, but the distinction travels well: is there a reasonable possibility that something important goes undetected, or is this a gap worth reporting but bounded? Use whatever terms your methodology defines, and apply the same thresholds every time.
You might also need
- Audit Coverage CalculatorCommonly used together
- Control Effectiveness CalculatorCommonly used together
- Exception Risk CalculatorCommonly used together
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC
- ISO 27001 Compliance CalculatorAlso in Compliance & GRC