Materiality
Also known as: Significance threshold, Tolerance level, Materiality limit
Materiality is the threshold used to determine if an error, omission, or deficiency is significant enough to impact the decisions of a reasonable stakeholder. In audit and compliance, it distinguishes trivial issues from those that fundamentally compromise the integrity of a system, report, or control environment. It allows practitioners to focus resources on risks that truly matter rather than every minor discrepancy.
In practice
An auditor uses materiality to decide if a discovered security gap is a critical failure requiring immediate reporting or a minor observation. For example, one missing patch on an isolated test machine may be immaterial, whereas the same missing patch on a production database containing PII is material.