Skip to main content

Risk Scoring

Risk scoring determines how often each auditable entity should be audited. Higher-risk entities are audited more frequently.

Risk levels and audit cycles

Risk LevelAudit Cycle
HighEvery year
ModerateEvery 2 years
LowEvery 3 years

Risk factors

Each entity is scored across multiple risk factors. Your organization can customize which factors are used and their weights in SettingsRisk Factors.

Common risk factors include:

  • Inherent risk — The natural risk level of the activity
  • Control environment — Strength of existing controls
  • Regulatory exposure — Degree of regulatory scrutiny
  • Financial impact — Potential financial loss
  • Change / complexity — Recent changes or high complexity
  • Prior audit results — Findings from previous audits

Scoring an entity

  1. Open an entity in the Audit Universe
  2. Go to the Risk Assessment tab
  3. Score each risk factor (typically on a scale)
  4. The overall risk level is calculated automatically based on factor weights
  5. Save the assessment
Who can score

Risk scoring requires Senior Auditor or higher permissions.

AI-assisted scoring

LOQI can suggest risk scores based on:

  • Uploaded documents (regulations, prior audit reports)
  • Risk registers imported from external sources
  • Historical audit data

Click Suggest Scores to get AI recommendations, then review and adjust.

Importing risk registers

If your organization maintains a risk register externally:

  1. Click Import Risk Register in the Audit Universe
  2. Upload an Excel or CSV file with entity names and risk data
  3. Map columns to LOQI's fields
  4. Review and confirm the import