Materiality
Also known as: Significance threshold, Tolerable error, Performance materiality
It is the threshold above which missing or incorrect information in a report would influence the decisions of a stakeholder. In auditing, it defines what constitutes a significant error versus a trivial one. This allows practitioners to focus on risks that could meaningfully impact an organization's compliance posture or financial standing.
Why it matters
Setting this threshold too high leads to overlooked systemic failures, while setting it too low wastes resources on insignificant details. An auditor who ignores a material weakness must issue a qualified opinion in reports such as SOC 2 or ISO 27001 certifications. Such failures can result in breached contractual SLAs with clients or regulatory fines from bodies like the FTC or GDPR supervisors. Ultimately, the CISO or CFO is held accountable for these inaccuracies during board-level reviews.
In practice
The Lead Auditor determines this threshold during the planning phase of the engagement. They review historical error rates and organizational risk appetite to document a Materiality Worksheet. Evidence requested typically includes previous audit reports, financial statements, or data breach logs from the prior year. This process produces a materiality matrix used to determine sample sizes for control testing. In first-year engagements, auditors rely on industry benchmarks; in repeat engagements, they refine the threshold based on known historical performance and changes in company scale.
Worked example
FinSecure Ltd underwent a SOC 2 Type II audit for the period of January 1 to December 31, 2023. The auditor requested evidence that all new employees completed security training within 30 days of hire. Out of 500 hires, they found 485 complied, but 15 failed to complete it. Because the threshold for a material deviation was set at 5% and this error rate was only 3%, the auditor deemed the failure immaterial. The final report noted the deficiency as an observation but maintained an unqualified opinion on the control's effectiveness.
Common mistakes
- Using a one-size-fits-all percentage across different domains regardless of risk level, which leads to over-auditing low-risk areas.
- Confusing this concept with "severity" in vulnerability management; a high-severity bug may not be material if it exists only in an isolated lab environment.
- Failing to document the rationale for the chosen threshold, leaving auditors unable to defend their sampling decisions during peer reviews.
- Treating every single finding as significant regardless of scale, which creates audit fatigue and obscures critical risks from management.
Frequently asked questions
What is the difference between quantitative and qualitative materiality?
Quantitative refers to a hard number or percentage threshold, such as a 5% error rate in a sample. Qualitative considers the nature of the error, such as a small financial discrepancy caused by intentional fraud rather than an accident.
How does this differ from risk appetite?
Risk appetite is a strategic decision on how much risk an organization is willing to accept to achieve its goals. This term refers to a measurement tool used by auditors to decide if a specific deviation is significant enough to report.
How do I calculate the threshold for a compliance audit?
Start with a benchmark, such as total revenue or the total number of records processed in a system. Apply a percentage based on industry standards or historical error rates found in previous internal audits.
What evidence proves that this threshold was applied correctly?
The primary evidence is the Audit Planning Memorandum or Materiality Worksheet. This document must show the calculation logic and the auditor's sign-off before any testing begins.
When should the level be adjusted during an audit?
It should be re-evaluated if new information emerges that changes the risk profile, such as a major corporate acquisition or a significant data breach discovered mid-engagement.
More terms
Risk appetite · Common controls framework · Compensating control · Control mapping · Risk assessment · Subprocessor · Continuous auditing · Qualified opinion