How Risk Scores Are Computed: Factor Weights and Thresholds
The factor model behind the risk engine: audit and litigation weights, the five weighted defensibility criteria, the A-to-F bands and the status thresholds.
This is the factor model behind the Predictive Risk Engine: the factors and weights for each score, the score bands, and the thresholds that set them.
Read this as arithmetic, not as statistics. Every weight and threshold below is a hand-set product heuristic chosen to give a sensible ordering of files. None of them is a fitted coefficient, a measured audit rate or a validated predictor, and no accuracy figure attaches to the output.
The inputs are what the study recorded: the parameters (jurisdiction, TP margin) and the stored analysis result — the statistics block (median, IQR, CV, quartiles, the benchmark-reliability figure), the accepted comparables and their recorded PLI / related-party / revenue values, the arm’s-length conclusion, the recorded screened and accepted counts, and the presence of a column mapping and industry analysis. Anything the study did not record is scored through a fallback — neutral in most cases, pessimistic in one (see Acceptance Rate below) — or stays out of the arithmetic.
Audit probability: the six factors
Plan feature: This capability requires the
predictive_riskplan feature (see Plan Features).
Each factor scores 0-100; the total is the sum of the weighted contributions, capped at 100. The five scored weights add up to 1.0, so the total is already on the 0-100 scale; the sixth factor is reported with a weight of zero and contributes nothing.
Comparables are counted over the accepted set that carry a recorded PLI — a company row without that figure is absent from the sample-size and loss-share denominators.
| Factor | Weight | Score rule |
|---|---|---|
| Jurisdiction Regulatory Risk | 25% | The jurisdiction’s audit-risk value (table below); a jurisdiction with no entry takes a neutral 50, which means unrated, not average risk |
| Margin Deviation from Median | 20% | The deviation of the tested-party margin from the pool median in percent, doubled, capped at 100; 50 when the margin or the median is missing |
| Related Party Transaction Exposure | 15% | The related-party values recorded on the accepted comparables as a share of their recorded revenue, scaled by 1.5, capped at 100; 20 when no such data is recorded |
| Persistent Loss Indicators | 20% | The share of PLI-bearing accepted comparables at or below zero, scaled by 4, capped at 100; 10 when none are loss-making |
| Comparability Variability (CV) | 20% | The recorded coefficient of variation scaled by 1.5, capped at 100; 15 when the CV is zero |
| Sample Size Adequacy | 0% (informational) | Below 4 comparables scores 90, below 8 scores 65, below 15 scores 35, 15 and above scores 10 |
Risk levels: High Risk at 60 and above, Moderate Risk at 35 and above, Low Risk below 35.
Note what the RPT factor is: intensity recorded on the comparables, not the tested party’s own related-party volume — the tested party’s RPT data is not read by this score.
Jurisdiction risk values
Jurisdictions are normalised to the platform’s canonical names before the lookup, so alias spellings resolve to the same entry. Both tables are heuristic enforcement-intensity estimates seeded for the platform’s curated jurisdictions — just under 80 entries on the audit side and just over 70 on the litigation side — and they are independent of each other. A jurisdiction missing from a table scores 50 there; some entries exist in only one table (Luxembourg carries a litigation value of 40 and no audit value, so it is unrated on audit).
A representative excerpt, with the original six anchors:
| Jurisdiction | Audit risk | Litigation risk |
|---|---|---|
| India | 75 | 80 |
| China | 70 | 55 |
| Australia | 65 | 60 |
| Brazil | 65 | 60 |
| USA | 60 | 70 |
| France | 60 | 55 |
| Mexico | 60 | 50 |
| Argentina | 60 | 55 |
| Russia | 60 | 55 |
| Nigeria | 55 | 45 |
| Saudi Arabia | 55 | 45 |
| Japan | 55 | 45 |
| Germany | 50 | 55 |
| Netherlands | 50 | 40 |
| UK | 45 | 50 |
| Switzerland | 45 | 35 |
| Sweden | 40 | 30 |
| Singapore | 35 | 30 |
| Finland | 35 | 25 |
| UAE | 30 | 20 |
| Macau | 25 | 20 |
| Any jurisdiction with no entry | 50 (unrated) | 50 (unrated) |
Litigation probability
Litigation is built on the audit score, not from scratch:
- Base — half the audit score, plus 30% of the jurisdiction’s litigation-risk value.
- Conclusion adjustment — plus 15 if the arm’s-length conclusion is below-range, plus 8 if above-range.
- Reliability penalty — plus 10 if the recorded benchmark reliability score is below 40; when no reliability figure is recorded it reads as 50 and the penalty does not apply.
- Cap — the total is capped at 100.
Risk levels: Critical at 65 and above, High at 45 and above, Moderate at 25 and above, Low below 25.
The view also lists named contributing factors and mitigation suggestions. The contributing factors are display labels, and only some of them are arithmetic: a jurisdiction at 60 or above, a below-range conclusion, a CV of 50 or above, a reliability figure below 40 and fewer than 8 accepted comparables can each appear in the list, but only the jurisdiction value, the conclusion and the reliability figure move the number. When nothing trips, the list reads “Standard risk profile for this jurisdiction”.
Defensibility: the weighted criteria
The grade is the weighted mean of five weighted criteria — each criterion’s score times its weight, divided by the sum of the weights, which is 1.0 — so the overall score lands on the same 0-100 scale. A sixth criterion, documentation completeness, is reported with a weight of zero and contributes nothing to the mean:
| Criterion | Weight | Score bands |
|---|---|---|
| Sample Size | 20% | Counted over the accepted comparables with a recorded PLI: 20 or more scores 100, 12 or more 80, 8 or more 60, 4 or more 35, below 4 scores 10 |
| Comparability (CV) | 25% | The recorded CV: below 15 scores 100, below 25 scores 85, below 40 scores 65, below 55 scores 40, else 20 |
| Range Tightness (IQR/Median) | 20% | The IQR-to-median ratio from the statistics block: below 0.3 scores 100, below 0.5 scores 80, below 0.7 scores 60, below 1.0 scores 40, else 20. With no usable median the ratio reads as 1.0 and lands in the lowest band |
| Tested Party Margin Placement | 20% | The margin stored with the analysis result, against the recorded lower/upper quartile: within the interquartile range scores 95, within 20% of its bounds scores 70, outside scores 30; when the margin or the median is not recorded the criterion takes a neutral 50 |
| Acceptance Rate | 15% | Accepted over screened, from the counts stored with the analysis result: 70% or more scores 95, 50% or more 75, 30% or more 50, else 25. When the screened total is not recorded the rate reads as 0% and the criterion takes its lowest band — the one non-neutral fallback in the model |
| Documentation Completeness | 0% (informational) | Column mapping present adds 50, industry analysis present adds 50 |
Grade bands:
| Grade | Score | Label |
|---|---|---|
| A | 85 and above | Excellent |
| B | 70 and above | Strong |
| C | 55 and above | Adequate |
| D | 35 and above | Weak |
| F | below 35 | Inadequate |
The scorecard also returns a range analysis — the 25th-75th figures, the IQR, the CV and the sample size — straight from the statistics block.
How to read a factor’s status
Within the audit score, each factor carries a status — high, moderate or low — which colours the bar in the breakdown. The thresholds are per factor, and some read the factor’s own score while others read the underlying value:
| Factor | High when | Moderate when |
|---|---|---|
| Jurisdiction Regulatory Risk | the audit value is 65 or above | 40 or above |
| Margin Deviation from Median | the score is 60 or above | 30 or above |
| Related Party Transaction Exposure | the score is 60 or above | 30 or above |
| Persistent Loss Indicators | more than 20% of the pool is loss-making | more than 10% |
| Comparability Variability (CV) | the CV is 50 or above | 25 or above |
| Sample Size Adequacy | fewer than 4 comparables | fewer than 8 |
The status is the at-a-glance flag; the weight and the contribution are what move the total.
FAQ
Where do the inputs come from? The study’s parameters (jurisdiction, TP margin) and the stored analysis result: its statistics block (median, IQR, CV, quartiles, benchmark reliability), the accepted comparables and their recorded PLI / related-party / revenue values, the arm’s-length conclusion and the recorded counts. A study whose result is not marked successful is not scored at all.
Why is margin deviation measured against the median? The median is the pool’s centre, and pricing far from it is the exposure the rule set is meant to surface — that is the reasoning behind the weight, not a measured relationship to audit selection. The factor scales the deviation directly, so the distance moves the score linearly up to the cap.
Do the audit and defensibility scores move together? Partly by construction: both read the CV and the sample size, so a thin or wide pool raises the audit index and lowers the defensibility grade at once. The litigation index inherits half of the audit index outright. They are three views over overlapping inputs, not three independent measurements.
Can the weights be configured by the firm? No — the weights and the thresholds are the product’s fixed rule set, applied identically to every tenant. Identical rules make the scores computed the same way everywhere; they are not tuned or calibrated against observed outcomes, and no accuracy figure attaches to any band.
See it working in your workspace
Sign in to run the steps above on a real study — or book a demo and we will walk the workflow end to end.
Related docs
Predictive Risk Engine: Audit, Litigation, Defensibility
Three deterministic risk scores per study: an audit exposure index, a dispute index and the A-to-F defensibility grade, read together as a triage set.
Read docAccess and Security Logs
The firm-level security event log: logins, failed logins, MFA events, role changes, invitations, ledger exports and API key activity, with IP and user-agent context.
Read doc