Appendix A: Basis of findings rating and report classification

Finding rating matrix Low Impact Medium Impact High Impact
Highly likely
  • History of regular occurrence of the event.
  • The event is expected to occur in most circumstances.

Moderate

Significant

Significant
Likely
  • History of occasional occurrences of the event.
  • The event could occur at some time.

Low

Moderate

Significant
Unlikely
  • History of none or seldom occurrence of the event.
  • The event may occur only in exceptional circumstances.

Low

Low

Moderate
Impact Impact Consideration
High Financial impact likely to exceed $250,000 in terms of direct loss or opportunity cost.
Internal Control: Significant control weaknesses, which would lead to financial or fraud loss.
An issue that requires a significant amount of senior management/Board effort to manage such as:
  • Failure to meet key strategic objectives/major impact on strategy and objectives.
  • Loss of ability to sustain ongoing operations:
    • Loss of key competitive advantage/opportunity
    • Loss of supply of key process inputs
  • A major reputational sensitivity, e.g. market share, earnings per share, credibility with stakeholders and brand name/reputation building.

Legal/regulatory: Large scale action, major breach of legislation with very significant financial or reputational consequences.
Medium Financial impact likely to be between $75,000 to $250,000 in terms of direct loss or opportunity cost. Internal Control: Control weaknesses, which could result in potential loss resulting from inefficiencies, wastage, and cumbersome workflow procedures.
An issue that requires some amount of senior management/Board effort to manage such as:
  • No material or moderate impact on strategy and objectives.
  • Disruption to normal operation with a limited effect on achievement of corporate strategy and objectives
  • Moderate reputational sensitivity.

Legal/regulatory: Regulatory breach with material financial consequences including fines.