Public Sector Audit Risk Assessment Tool
This tool provides a rapid, structured risk assessment across ten key dimensions of public sector audit readiness. Developed in alignment with OECD audit governance principles and INTOSAI standards, it is intended for use by internal audit units, supreme audit institutions, and public sector finance teams conducting preliminary risk reviews. Answer each question honestly — the tool generates an instant risk score and a printable summary for your audit committee.
Audit Risk Assessment Checklist
10 questions — estimated completion time: 3 minutes
1 Has your organisation undergone a significant restructuring, leadership change, or merger in the past 18 months?
Organisational instability is a leading indicator of increased control risk.
2 Are there documented gaps or deficiencies in your internal control framework that remain unresolved?
Unresolved control findings from prior audits compound current-year risk.
3 Does your entity manage large volumes of grants, subsidies, or transfer payments to third parties?
Third-party disbursements require enhanced oversight and accountability mechanisms.
4 Has your IT infrastructure or major information system changed significantly in the past two years?
New systems introduce data integrity risks and require updated IT audit procedures.
5 Is there a material budget variance (>10%) between planned and actual expenditure in the current period?
Large unexplained variances may indicate errors, misappropriation, or poor planning.
6 Has your organisation received qualifications, adverse opinions, or 'emphasis of matter' paragraphs in prior audit reports?
Prior audit issues significantly elevate inherent and detection risk.
7 Are procurement procedures and contract management processes fully documented and independently reviewed?
Procurement is one of the highest-risk areas in public sector auditing.
8 Do staff responsible for financial reporting lack adequate training in current accounting standards (e.g., IPSAS)?
Competency gaps in finance teams are a key driver of misstatement risk.
9 Has your entity experienced any fraud, financial irregularities, or whistleblower reports in the past three years?
Fraud history indicates elevated control environment and ethical climate risks.
10 Is there a lack of a functioning audit committee or an internal audit unit with adequate independence and resources?
Absence of effective oversight structures is the single strongest predictor of audit risk.
Please answer all 10 questions before generating your report.
Detailed Response Summary
| # | Risk Indicator | Response |
|---|
Frequently Asked Questions
What standards does this tool align with?
This tool draws on the OECD Principles of Budgetary Governance, INTOSAI's International Standards of Supreme Audit Institutions (ISSAIs), and the Committee of Sponsoring Organisations (COSO) Internal Control Integrated Framework. The ten risk indicators were selected to reflect the most commonly cited risk factors in OECD member country audit reports and peer review findings.
How should I interpret my risk score?
Each "Yes" answer adds one risk point (maximum 10). Scores 0–2 indicate Low Risk: standard audit procedures are likely sufficient. Scores 3–5 indicate Moderate Risk: enhanced audit procedures and documented risk responses are recommended. Scores 6–8 indicate High Risk: significant audit attention and remediation plans are required. Scores 9–10 indicate Critical Risk: immediate escalation to the audit committee or governing body is advised.
Can this tool replace a formal risk assessment?
No. This tool is a rapid preliminary screening instrument, not a substitute for a comprehensive risk assessment conducted by qualified audit professionals. It is designed to identify areas warranting further investigation and to support audit planning discussions. All findings should be validated through substantive audit procedures.
Is the data from this assessment stored or transmitted?
No data is transmitted or stored. This tool runs entirely in your browser (client-side JavaScript). Your responses are held only in local memory and are deleted when you close or refresh the page. The printable summary is generated locally and not sent to any server.
Who is this tool designed for?
This tool is designed for audit committees, chief audit executives, heads of internal audit units, comptrollers general, public sector finance directors, and other governance professionals involved in planning and overseeing public sector audits. It is equally useful for external stakeholders conducting preliminary due diligence on public entities.