Every audit produces a number. The question is whether that number means anything. A compliant item weighted the same as a critical safeguard produces scores that flatter bad sites and fail good ones. Scoring policy is where audits earn their credibility.
Weights should follow risk
Each checklist item carries a weight - how much it counts toward the final score. The rule of thumb: weight should track consequences. A life-safety item on a construction site dwarfs an administrative paperwork check, and the scoring policy should say so. Without explicit weights, every item secretly weighs the same, and the score silently measures checklist length rather than risk.
Thresholds make the score a verdict
Once weighted, answers produce a score from 0-100. The pass threshold - the score at or above which the audit passes - is a business decision, not a math one. A regulator-fined industry sets a harder bar than a retail merchandising program, and both are legitimate. What is never legitimate is reporting the score while hiding the verdict, because the same score can pass in one program and fail in another.
Auto-fails: the score cannot overrule safety
Certain findings should fail an audit regardless of arithmetic. One Critical non-conformance - a missing fire suppression system, a breached isolation protocol - must fail the audit even when the weighted score lands in the nineties. Auto-fail triggers encode this: they are evaluated before the score, and their presence overrides it. This is also why a result must always report both Score and Outcome: the outcome is never derivable from the score alone.
Sub-scores and the frozen result
Management teams also need granularity: a section-level sub-score shows which part of the operation dragged the total down, guiding corrective focus. And because templates evolve, the result must be frozen at approval - the moment a report is approved, its score, outcome, and breakdown stop recomputing, so an audit approved under one policy cannot be silently re-scored under a later one.
Well-designed scoring is invisible: auditors just answer, and management just reads. The craft is in the policy underneath - weights that match risk, thresholds that match appetite, and auto-fails that protect people. Get those three right, and the number on the report earns the room.