This page defines how assurance ratings, finding ratings, evidence sufficiency, priority, and overdue status are determined within AuditFlow OS.

It helps users make assurance judgements that are consistent, traceable, and evidence-based across cyber, AI, data, governance, third-party, and IS4-style reviews.


Purpose

This methodology provides a standard approach for:

All audit ratings should be supported by evidence, findings, and clear reasoning.


Assurance Rating Scale

Overall assurance should be based on control design, control operation, evidence sufficiency, finding severity, and residual risk.

Assurance Rating Definition Typical Characteristics
Substantial Assurance Controls are well designed and operating effectively. Residual risk is low and evidence is sufficient to support a high level of confidence. Controls consistently applied, limited exceptions, complete evidence, no significant unmanaged risk.
Moderate Assurance Controls are generally designed and operating, but weaknesses exist that reduce confidence. Residual risk is moderate and improvement is required. Some control gaps, inconsistent execution, partial evidence, issues not severe enough to invalidate the overall control environment.
Limited Assurance Control weaknesses are significant. Control design or operation is insufficient in key areas. Residual risk is high and assurance is materially reduced. High-risk findings, incomplete evidence, weak governance, repeated control failure, inconsistent or ineffective implementation.
No Assurance Controls are absent, ineffective, or not evidenced. No reliable reliance can be placed on the control environment. No meaningful evidence, no effective control operation, unmanaged high-risk exposure, severe breakdown in governance or oversight.

Rating Rules