7.3 Methods to Evaluate and Prioritize Risks and Controls

Key Takeaways

  • Evaluate identified risks with likelihood, impact, and velocity, then compare inherent risk with residual risk after considering existing controls.
  • Heat maps and risk-and-control matrices are methods to prioritize; they feed work-program hours and do not replace professional judgment or Topical Requirement applicability decisions.
  • High residual risk should attract concentrated testing; spreading equal samples across all subprocesses is a frequent CIA Part 2 trap on A5d.
  • Plan control reliance only when you will test those controls; otherwise perform more substantive procedures on the activity's outcomes.
  • Ranking risks and allocating hours is not the same as judging work-program adequacy (Chapter 10) or assessing organizational structure and culture (Chapter 8).
Last updated: August 2026

Identifying pervasive and emerging risks is wasted if every item gets the same sample. A5d asks you to determine appropriate methods and criteria to evaluate and prioritize the risks and controls you have already identified. This section is the scoring and ranking step. It is not Chapter 8 (whether a flat, remote, or decentralized structure changes the picture) and not Chapter 10 (whether the finished work program is adequate). Those chapters consume this ranking; they do not replace it.

Why Prioritization Is the Point of the Assessment

GIAS Standard 13.2 does not require you to test everything you listed. It requires you to assess significance and then decide which risks to include. Significance is a professional judgment using explicit criteria, not a feeling that "payroll is always high risk." The criteria you can defend on the exam are likelihood, impact, velocity, inherent versus residual rating, alignment with the activity's risk appetite and tolerance, Topical Requirement items that survived the applicability test, prior findings, and the severity of people/process/system change from Section 7.2. Methods are the tools—scores, heat maps, matrices—that make those criteria visible and link them to hours.

Likelihood, Impact, and Velocity

Likelihood is how probable the event is in the period and process you are auditing, given the current design and environment. Impact is how bad it is if it occurs—misstatement, operational stoppage, regulatory penalty, or loss of confidentiality—scaled to this activity, not to a generic enterprise disaster. A halted payroll run can be high impact for payroll even if the same outage would be moderate for a low-volume marketing site.

Velocity is how fast the risk crystallizes once a control fails. Ransomware that can stop the pay run in hours is high velocity. A slow bonus over-accrual that becomes material only over several quarters is lower velocity. High velocity can justify earlier or more continuous procedures even when annual likelihood is only moderate, because detection delay equals impact. Velocity is not a culture score and not a reason to skip likelihood and impact; it is a third axis when timing of harm matters (cyber availability, unauthorized wires, fraud that drains cash).

A simple, defensible model is a 1–5 scale on each axis, then a combined score such as likelihood × impact, with velocity used to break ties and pull items up when harm is fast. The exam rarely requires a branded software tool. It does require you to state the criteria and apply them consistently across the activity.

Inherent Versus Residual Risk

Inherent risk is the risk before considering the controls that currently exist for this activity (or assuming those controls fail). Residual risk is the risk after considering how well those controls are expected to reduce likelihood or impact, given what you already know about design and recent change. Prioritize residual risk for testing hours. Inherent risk still matters: it tells you how bad the activity is if controls are missing, and it keeps you from "auditing the control" while ignoring a high-inherent process with no compensating detection.

Ghost employees in payroll often have high inherent risk (cash out the door, whole population). If hire-to-pay matching and monthly reconciliations look well designed and owners are stable, residual may be moderate—and you may plan to rely on those controls, which means you must test them. If the reconciler just left and matching was automated last month with no parallel run, residual stays high even though inherent did not change. Copying last year's residual rating is not a method; it is a skipped assessment.

Do not drop a high-inherent risk from the engagement merely because management says residual is low. Residual is your evaluation for planning, using management's claims as an input. Management's formal acceptance of residual risk for reporting purposes is a later communication topic (CIA Part 3), not a free pass to skip testing on Part 2.

Control Reliance Versus More Substantive Work

Control reliance means you intend to take comfort from controls and therefore design tests of those controls (and usually smaller or more targeted tests of the underlying activity outcomes). More substantive work means you test the activity's outcomes more directly—reconciliations to bank evidence, existence of employees, recalculation of overtime, matching of wires to approved beneficiaries—because you will not rely, or cannot yet rely, on the controls.

Choose reliance only when (1) design appears able to prevent or detect the risk, (2) you plan procedures to test operating effectiveness, and (3) change and emerging-risk analysis did not destroy the basis for reliance. If design is missing, owners are gone, or the system just went live, do not rely; expand substantive procedures and walk-throughs. Reliance is not cheaper hours with no testing. Untested reliance is not a criterion—it is a documentation failure.

Heat Maps and the Risk-and-Control Matrix

Two methods dominate exam answers because they are visible and auditable.

A risk-and-control matrix lists each significant risk, related assertions or process steps, existing controls, inherent rating, control reliance decision, residual rating, and the planned response. It is the working paper that proves A5d happened. Topical Requirement criteria that you included sit in the same rows as any other risk.

A heat map plots likelihood against impact (sometimes with velocity as color or a third label). Items in the high-high cell get concentrated hours. Low-low items get limited procedures or monitoring. The map is a communication and ranking tool, not a finding. An example for a payroll engagement after the Section 7.1 matrix and a recent go-live:

Risk in this payroll engagementLikelihoodImpactVelocityResidualPlanned emphasis
Privileged access / segregation of duties in the new engineHighHighHighHighHeavy: access tests, dual-period samples
Ghost employees / occurrence of wagesMediumHighMediumHighExistence tests; rely only if matching is tested
Hosted-vendor ransomware / pay-run availabilityMediumHighHighHighSpecialist procedures; backup/fail-over evidence
FLSA overtime classificationMediumHighLowMediumTargeted classification sample
Parking-reimbursement codingLowLowLowLowAnalytical review only

The heat map and the matrix must agree. If the map shows privileged access as high residual, the matrix cannot assign it the same three-item sample as parking reimbursements.

Linking Rankings to Work-Program Hours

Prioritization is finished only when hours and procedure depth follow residual risk. High residual and high velocity get more time, more experienced staff, and often specialists. Low residual gets lighter procedures. That allocation is an input to the work program. Whether the program that results is adequate—coverage, mix of tests, resources—is Chapter 10. Here, the exam wants the logic: hours are a function of residual risk, not of equal fairness across process steps.

The trap: spreading tests evenly. Twenty-five samples from every subprocess, or equal hours for financial, operational, IT, cyber, and regulatory types, ignores the assessment you just completed. Equal spread is appropriate only if residual ratings are actually equal—an almost nonexistent payroll or treasury fact pattern. Another trap is testing only easy, well-documented controls ("we always vouch time sheets") while leaving high-residual access and vendor-availability risks to a future IT audit. If those risks relate to this activity, they compete for this engagement's hours unless you document a scoped-out rationale.

When two risks score similarly, break ties with velocity, change, Topical Requirement applicability, and whether a control failure would be pervasive across assertions. Then write the ranking in the planning file so fieldwork cannot quietly revert to last year's equal samples.

Loading diagram...
From inherent risk to hours: reliance versus substantive work
Illustrative testing hours: concentrated residual-risk plan vs even spread
Test Your Knowledge

Inherent risk for ghost employees in payroll is high, but automated hire-to-pay matching and monthly reconciliations appear well designed and owners are stable. How should that affect prioritization?

A
B
C
D
Test Your Knowledge

Which work-program choice best reflects a completed engagement risk assessment?

A
B
C
D
Test Your Knowledge

A ransomware event could halt the payroll run within hours, while a slow over-accrual of bonuses would take quarters to become material. How should velocity affect prioritization?

A
B
C
D