The consequence is where a finding earns its rating and loses its reader. It earns the rating because Standard 14.3 evaluates significance from the effect: a finding is High or Low according to what the gap does or could do, not according to how many exceptions were counted. It loses the reader because the sentence that carries the effect is, in most reports, the sentence that begins “there is a risk that”, continues with a list of things that might happen, and ends without a number, a mechanism or a person. That sentence is true of every finding ever written, which is why it persuades nobody; the executive who reads that there is a risk of financial loss, reputational damage and regulatory sanction has read it forty times this year and has learned that it means the auditor could not say what would actually happen.
This guide is about writing consequences that say what would actually happen. It covers the three jobs the element has to do, its four components, the three tenses of consequence, eight methods for putting a number on it, how to state the consequences that have no dollar sign, the “risk that” problem and the sentences that replace it, the base rate sentence that makes severe findings credible, how the consequence maps to the rating anchors, a checklist, and ten consequences from the engagements on this site rewritten from their first drafts. It is the third of five guides on writing the elements of a finding, after conditions and causes and before recommendations and the makeovers, within the structure the five Cs masterclass sets out.
In this guide
- The three jobs of the consequence element
- The four components: mechanism, magnitude, likelihood, bearer
- Realized, estimated and exposed: the three tenses of consequence
- Eight methods for putting a number on it
- Consequences without a dollar sign
- Evidence for the consequence: what supports a number
- The consequence of what works
- The “risk that” problem, and the sentences that replace it
- Proportion: the base rate sentence
- Consequence and the rating anchors
- Writing the consequence for the reader who decides
- The consequence checklist
- Ten consequences rewritten
- Common mistakes
- Where to go next
The three jobs of the consequence element
The consequence does three jobs, and a sentence that does one of them well usually does the others. The first is to justify the rating: the reader should be able to read the consequence, read the scale’s definitions, and see which anchor the finding meets without the auditor telling them. The second is to make the reader care, which is not a rhetorical job but a practical one: the executive decides how much of her attention and budget the finding gets from the consequence, and a consequence she cannot picture gets neither. The third is to give any later decision its terms: if management accepts the risk, the acceptance record restates the consequence as the exposure being accepted, and if the finding is validated a year later, the consequence is what the validator tests whether the fix removed. A consequence written as “there is a risk of loss” fails all three, because it neither meets an anchor, nor paints a picture, nor states an exposure anyone could accept or remove.
The four components: mechanism, magnitude, likelihood, bearer
A consequence that lands has four components, and most weak ones are missing two. The mechanism is how the gap produces harm: the path from the condition to the loss, stated as a sequence a reader can follow. The magnitude is how much: the amount, the population, the duration, with a base beside it. The likelihood is how probable: realized already, likely given the population and the frequency, or possible given a trigger, stated in words the reader can weigh. The bearer is who suffers it: the organization, a customer, a counterparty, the public, a regulator’s confidence, because consequences to different bearers are rated and accepted differently. The table gives the four for one finding, and the sentence that assembles them.
| Component | The question | For the bank-detail change finding |
|---|---|---|
| Mechanism | By what path does the gap become harm? | A fraudster who has compromised or spoofed a vendor’s email sends a change of bank details; the clerk keys it; the next payment goes to the fraudster’s account; recovery depends on noticing within hours |
| Magnitude | How much, over what population, for how long? | Fourteen payments above 25,000 dollars were made within ten days of an unverified change in the period; the largest was 212,000 dollars; the payment population in any ten-day window averages 1.1 million dollars |
| Likelihood | Has it happened, is it likely, or is it possible? | Realized once: a business email compromise attempt for 62,000 dollars in the period, stopped by the bank rather than by the control; the attack is the most common payment fraud reported to the FBI, with 24,768 complaints in 2025 |
| Bearer | Who suffers it? | MidState, directly; the vendor, whose genuine invoice remains unpaid; the bank relationship, if recovery is repeatedly requested |
| Assembled | “An emailed change of bank details can be made effective by one clerk without verification, so a compromised vendor email would redirect the vendor’s next payment; fourteen payments above 25,000 dollars, the largest 212,000 dollars, were made within ten days of unverified changes in the period, and one attempt for 62,000 dollars was stopped by the bank rather than by MidState.” |
Realized, estimated and exposed: the three tenses of consequence
Consequences come in three tenses, and the sentence has to say which one it is in, because the reader weighs them differently and a consequence that blurs them is the one management disputes. The realized consequence is what has already happened: the 41 duplicate payments, the 286,000 dollars, the 241,000 recovered; it is stated as fact with its numbers, and it is the strongest tense because nobody can argue with a loss. The estimated consequence is a projection: the sample’s error rate applied to the population, or the exposure multiplied by an expected frequency; it is stated with its method and its range, because an estimate stated as a fact is the first thing a hostile reader attacks and the easiest thing to defend if the method is on the page. The exposed consequence is the population at risk: the 1.1 million dollars of payments in any ten-day window, the 2,590 vendor records, the 9,800 customer accounts; it is stated as the ceiling of what the mechanism could reach, with the likelihood beside it. A strong consequence usually contains two tenses: what has happened, and what is exposed; the estimate sits between them where the sampling method supports one.
| Tense | What it states | How it is stated | Example |
|---|---|---|---|
| Realized | Harm that has occurred | As fact, with amount, count and any recovery | “41 confirmed duplicate payments, 286,000 dollars, of which 241,000 was recovered in the quarter” |
| Estimated | Harm likely across the population, projected from evidence | With the method and a range | “Projecting the sample’s 9 percent capitalization error to the year’s 2.1 million dollars of expensed repairs above the threshold gives an understatement of assets in the range of 150,000 to 230,000 dollars” |
| Exposed | The population the mechanism could reach | As a ceiling, with the likelihood beside it | “Every one of the 2,590 active vendor records can have its bank details changed through the legacy path at the acquired depots; five were in the year” |
Eight methods for putting a number on it
Consequences without numbers are opinions, and most consequences can be given a number by one of eight methods. The method is stated in the sentence or the file, because a number whose derivation is visible is defended in a minute and a number whose derivation is hidden is argued about for a meeting.
| Method | How it works | Example from the engagements |
|---|---|---|
| Actual loss and recovery | Count and value what happened; state what was recovered and what was not | “14 duplicate payments totaling 23,800 dollars; 21,000 recovered” |
| Exposure times frequency | The population at risk in a period, multiplied by how often the mechanism operates | “1.1 million dollars of payments in any ten-day window; 46 changes a year, 31 unverified” |
| Projection from a sample | The sample’s rate applied to the population, with the sampling method’s confidence and a range | “Nine of 40 expensed repairs above the threshold met the capitalization test; across the 2.1 million dollars expensed above it, an understatement of 150,000 to 230,000 dollars” |
| Leakage rate on a base | The amount found as a rate of the spend or revenue it came from, extended to the untested remainder | “41,000 dollars of contract-price leakage on 8 million dollars of tested spend; 38 million dollars of contracted spend untested” |
| Cost to detect and remediate after the fact | The hours and fees the organization spent, or would spend, cleaning up | “The investigation and recovery of the diverted pay run cost 90 hours of finance and legal time against a 4,100-dollar loss” |
| Penalty and contractual schedules | The fine, interest, or contractual remedy the gap triggers, from the schedule | “Forty award payments made through accounts payable bypassed withholding of about 8,000 dollars, on which penalties and interest apply from the schedule” |
| Comparison to a benchmark | The organization’s figure beside a published or peer figure, cited | “The close completed on day eleven against a calendar of eight; APQC’s benchmark puts bottom performers at ten days or more” |
| The one that happened elsewhere | A realized instance of the mechanism in a peer, a regulator’s enforcement, or the organization’s own history, cited | “The FBI’s Internet Crime Complaint Center recorded 3.05 billion dollars of business email compromise losses in 2025; the attempt against MidState was one of that kind” |
Consequences without a dollar sign
Some consequences have no dollar sign and the temptation is to reach for the abstract nouns: reputational damage, regulatory sanction, loss of stakeholder confidence. The nouns are not wrong; they are unspecified, and the rule for specifying them is the same as for money: name the mechanism, the magnitude in whatever unit applies, the likelihood and the bearer. A regulatory consequence names the regulator, the requirement, the finding it would produce and the consequence of that finding, which in a bank means the difference between an observation and a matter requiring attention that the MRA lifecycle guide describes. A reputational consequence names the audience that would learn of the failure, how they would learn, and what they would do: the retail customers whose store managers received gifts, the audit committee that has been told the close takes eight days, the examiner who reads a certification signed over an exception. An operational consequence names the process that stops and for how long: twelve hours without refrigeration at a plant, one payroll cycle missed. A consequence to people names the people: the drivers working fifteen-hour days, the customers whose payments were posted to someone else’s account. The evidence for a non-financial consequence is usually an instance of it happening to someone: a peer’s enforcement action, an examiner’s letter, the organization’s own history; a consequence with no instance and no mechanism is the “risk that” sentence with a longer noun.
Evidence for the consequence: what supports a number
A consequence is challenged more often than a condition, because it reaches beyond what was observed, and it survives the challenge when its file is as good as the condition’s. The realized instance has its own evidence: the bank’s letter about the stopped attempt, the recovery correspondence, the investigation summary where there was one, filed with the finding. The exposure has the population figures it rests on: the payment file that gives 1.1 million dollars in a ten-day window, the vendor master count, the receivables aging, each with its extract date. The estimate has its method on a page: the sample, the rate, the population, the arithmetic and the range, with the sampling memo referenced, so that a reviewer can re-perform it. The benchmark has its citation, with the year of the data and the definition the benchmark uses, because a benchmark quoted without its definition is quoted wrong more often than not. And the instance elsewhere has its source: the enforcement action, the regulator’s report, the industry survey, with the date. The reviewer’s test is whether every number in the consequence traces to one of those, and whether the tense claimed matches the evidence held: a realized loss needs the loss, an estimate needs the method, an exposure needs the population. A consequence whose largest number has no trace is the sentence the closing meeting will spend twenty minutes on, and it should be the sentence the reviewer spends five on first.
One habit makes the evidence easy to assemble: the consequence is drafted in the same week as the cause, while the interviews are fresh and the population files are open, and its numbers are written into the finding record beside the condition’s. The life of a finding puts the evaluation of all four elements at stage 4, within three working days of corroboration, and the consequence is the element that suffers most when that interval stretches into the draft week, because the population figures that made it easy to state have by then been replaced by memory.
The consequence of what works
Reports say what is working, and the sentence that says it also has a consequence, written to the same standard. “Dual control over the payment run operated in all ten runs sampled” is a condition; its consequence is that a payment cannot be released by one person, which is why the report can say that the vendor master finding, serious as it is, does not extend to the release of the money, and the reader who is deciding how alarmed to be needs that sentence as much as the alarming ones. Positive consequences bound the negative ones, and a report that states them makes its ratings more credible, because the reader can see the auditor weighing rather than accumulating. The rule is the same in both directions: mechanism, magnitude, likelihood, bearer, and no adjective doing the work of a number.
The “risk that” problem, and the sentences that replace it
“There is a risk that” is the phrase that marks a consequence the auditor has not thought through, and its removal is the single most useful edit in audit writing. The replacement is a sentence whose subject is the mechanism and whose verb is what it does: “an emailed change can redirect a payment”, “a credit memo can conceal a diverted receipt”, “an idle line carried at cost overstates assets until someone asks”. The table sets the weak form against the strong for the same finding, and the pattern in the strong column is always the same: a mechanism, a number, a tense and a bearer, in a sentence that could be false and is not.
| Weak | What it fails to say | Strong |
|---|---|---|
| “There is a risk that unauthorized payments may be made.” | How, how much, how likely, to whom | “One clerk can redirect any vendor’s next payment by keying an emailed change; fourteen payments above 25,000 dollars followed unverified changes in the period, and one attempt for 62,000 dollars was stopped by the bank rather than by the control.” |
| “There is a risk of financial misstatement.” | Which balance, by how much, in which direction | “Receivables are carried net of an allowance whose coverage of balances over ninety days has fallen from 52 to 38 percent; the re-performed allowance is 300,000 to 450,000 dollars higher, and the difference reaches the audited accounts.” |
| “This could result in reputational damage.” | With whom, through what, and then what | “Fourteen gifts to retail customers’ store managers were paid through expenses coded as meals; under the customers’ own supplier codes those gifts are prohibited, and two of the chains audit supplier conduct annually.” |
| “There is a risk that the audit committee is not fully informed.” | Of what, and with what effect on its decisions | “The committee has been told for two years that the close takes eight days; it takes eleven, and the three days are spent correcting reconciliations the committee believes are done in-period.” |
| “Non-compliance with policy may occur.” | Policy is a criterion, not a consequence | “Splitting a project into four contracts under the tender threshold awarded 380,000 dollars of related scope without competition, and the pricing obtained cannot be shown to be market-based.” |
Proportion: the base rate sentence
Every consequence with a number needs the sentence that puts the number in proportion, and the sentence works in both directions. “30,900 dollars of exceptions” alarms; “30,900 dollars of exceptions on 2.6 million dollars of spend, 1.2 percent, with 60 percent of the amount attributable to nineteen submitters” informs, and it makes the reader trust the auditor’s next number. Proportion is not softness. It is precision about magnitude, and it is what makes the severe findings believable: a report that gives the base rate on its small findings is believed when it says a finding is large. The base rate belongs in the consequence element of each finding and once more in the executive summary, where the anatomy of a report puts it beside the three messages; the two should agree.
Consequence and the rating anchors
The severity ratings guide anchors each rating to a combination of magnitude and likelihood, and the consequence element is written so that the reader can place the finding on that grid without help. A High consequence is one where the mechanism has operated or is likely to, and the magnitude reaches a threshold the scale defines in money, in regulatory terms or in harm to people: the diverted payment that happened, the material control in a declaration that cannot be shown to operate. A Medium consequence is a mechanism that could operate with a plausible trigger, or one that has operated at a magnitude below the threshold: the contract-price leakage, the allowance understated below materiality. A Low consequence is a mechanism bounded by other controls or by its own scale: the two unrecognized leases, the metric that measured the plan. Writing the consequence with the four components makes the placement almost mechanical, and it exposes the finding whose rating was set from the condition’s exception count rather than from its effect, which is the most common rating error and the easiest to correct once the consequence is on the page.
Writing the consequence for the reader who decides
The consequence is read by the executive who will fund the fix and the committee that will ask about it, and it should be written in the terms they decide in. An executive decides in money, time, customers and regulators; a committee decides in the organization’s objectives and in the questions it will be asked. A consequence written in the auditor’s terms, control objectives and assertions, is accurate and inert. The translation is not simplification; it is the last step of the analysis, the step where “the completeness assertion over liabilities is at risk” becomes “goods received before year-end and invoiced after it were not accrued in nine cases, 52,000 dollars, inside the pattern the external auditor raised last year, and a larger instance would move the reported result”. The reader who decides can act on the second sentence and cannot act on the first. Two disciplines make the translation reliable. Write the consequence to the specific reader named on the distribution list, and if the report has several, write it to the most senior, because the others will understand it. And end the consequence with the thing that would change if the finding were fixed, stated positively, because that is what the executive is buying: “a verified change before any payment would have stopped the attempt at the clerk’s desk instead of at the bank”.
The consequence checklist
Consequence checklist. 1. The mechanism is stated as a path a reader can follow from the condition to the harm. 2. The magnitude has a number and a base, or the reason no number is possible is stated. 3. The tense is clear: realized, estimated with its method and range, or exposed with its likelihood. 4. The likelihood is stated in words the reader can weigh: has happened, is likely, is possible with a named trigger. 5. The bearer is named. 6. The phrase “there is a risk that” does not appear. 7. No abstract noun stands alone: every reputational, regulatory or operational consequence names the audience, the requirement or the process, and an instance. 8. The base rate sentence is present and agrees with the executive summary. 9. The rating anchor the consequence meets is visible without being named. 10. The consequence would be the exposure statement in a risk acceptance record and the test in a validation, without rewriting. 11. It is written in the terms the deciding reader decides in. 12. Every number traces to the file, and the estimated ones trace to a method.
Ten consequences rewritten
| First draft | Missing | Rewritten |
|---|---|---|
| “There is a risk that ghost employees may be paid.” | Everything but the noun | “Nine employee records shared bank accounts or had no timekeeping activity while being paid; one driver’s pay went to a depot clerk’s account for four periods, 6,800 dollars, and the same pattern across 1,400 employees would be invisible until a payroll analytic was run, which none had been.” |
| “Inadequate credit memo controls could lead to loss.” | Mechanism and magnitude | “A representative can issue and approve a credit that clears a customer’s balance, which is the mechanism by which a diverted receipt is concealed; 610 unsupported credits totaling 410,000 dollars were issued in the year, 0.1 percent of revenue, concentrated in fourteen accounts served by two representatives.” |
| “The organization may be exposed to regulatory criticism.” | Which regulator, what requirement, what result | “The examiner’s last letter asked for suspense aging; 312 items older than ninety days, 8.7 million dollars gross, would be reported at the next examination, and 22 certifications signed over open exceptions convert a process weakness into a question about the accuracy of what the board is told.” |
| “Failure to capitalize assets results in misstatement.” | Direction, amount, materiality | “Nine of 40 expensed repairs above 5,000 dollars met the capitalization test, 96,000 dollars; assets are understated, not overstated, by an amount below materiality, and the same habit across three plants’ repair budgets, 2.1 million dollars a year, would be a recurring understatement of 150,000 to 230,000 dollars.” |
| “Sole-source awards may not represent value for money.” | Magnitude and evidence | “57 sole-source awards worth 2.9 million dollars were made without a demonstrated market check; on the six where the audit found alternative suppliers in twenty minutes, the incumbent’s renewal price fell 11 percent when competed, which applied across the population would be about 300,000 dollars a year.” |
| “The close may not be completed accurately.” | Mechanism and consequence to the reader | “190 entries a month are booked after the deadline to correct what the reconciliations missed; four of the external auditor’s six adjustments in the year, 1.7 million pounds net, arose from two accounts that the internal status report had shown as unexplained for most of the year.” |
| “Dormant vendor reactivation poses a fraud risk.” | Mechanism and realized instance | “A dormant record reactivated with new bank details inherits the trust of its payment history; nine of 23 reactivations in the year had no fresh verification and two were followed by payments after a bank change, which is indistinguishable in the data from the takeover pattern; both proved genuine, by luck rather than by control.” |
| “Weak approval controls could result in unauthorized expenditure.” | Everything specific | “Six approvers clearing 44 percent of expense volume at six seconds a report cannot be reading them; 94 percent of policy flags were approved unchanged, and the 30,900 dollars of exceptions found, 1.2 percent of spend, is the floor of what an unread approval permits, not the ceiling.” |
| “Non-compliance with the change management policy was noted.” | A criterion offered as a consequence | “41 period re-openings approved by email after the fact let 1,900 subledger lines post after the lock; each is a cut-off error the close cannot catch, and nine unaccrued invoices totaling 1.1 million pounds at year-end were among them.” |
| “The certification process could be improved.” | A recommendation offered as a consequence | “22 account owners certified accounts with open exceptions their own tool displayed; the quarterly assurance the audit committee and the examiners receive does not reflect the program’s records, and the examiner will find the difference before the committee does.” |
Common mistakes
Beginning with “there is a risk that”. Listing three abstract nouns instead of one mechanism. Stating an estimate as a fact, or a fact as a possibility. Omitting the base rate, so that a true number reads as unfair. Writing the consequence in control language for a reader who decides in money. Setting the rating from the exception count and writing a consequence to match it. Leaving out the realized instance because it was small, when a small realized instance is the best evidence a mechanism exists. Omitting the bearer, so that a consequence to customers reads as a consequence to the organization. Padding a Low finding’s consequence to justify a rating it does not deserve, which teaches the reader to discount every consequence in the report. And the mistake that produces most of the others: writing the consequence in the draft week rather than in the week the cause was found, when the mechanism was fresh and the numbers were on the desk.
Where to go next
Write the mechanism, put a number on it by one of the eight methods, say which tense it is in, name who bears it, add the base rate, and check the anchor. The elements before it are in writing airtight conditions and writing cause statements; the element after it is in writing recommendations; all four are assembled in the finding makeovers; the scale the consequence is placed on is in the severity ratings guide; and the argument a strong consequence prevents is in the negotiating findings guide.
Related guides
- Writing airtight conditions — the facts the consequence extends
- Writing cause statements that point to the fix — the mechanism’s origin
- Writing recommendations management can actually implement — what removes the consequence
- Finding makeovers — five findings rewritten element by element
- The 5 C’s of audit findings — the structure
- Finding severity ratings — the anchors the consequence is placed against
- Evaluating control deficiencies — magnitude and likelihood in the SOX vocabulary
- Risk acceptance by management — the consequence restated as an exposure to accept
- Negotiating audit findings — the rating appeal and how a strong consequence answers it
- Audit sample sizes demystified — when an estimate can be projected
- The MRA and MRIA lifecycle — what a regulatory consequence actually is
- How to audit payment operations and wire transfers — the business email compromise numbers behind the worked example
- Anatomy of an internal audit report — where the base rate appears twice
- Writing guides and findings and reporting guides — the full collections
Leave a Reply