Skip to main content
Category: Ratings and Risk Tiering

Materiality Threshold

Also known as: Materiality Benchmark, Materiality Level
Simply put

A materiality threshold is a cutoff point used to decide whether an error, omission, or issue is large enough to matter to the people relying on financial information. Items above the threshold are treated as significant and warrant attention, while smaller items may be considered immaterial. It is most often expressed as a percentage applied to a financial base, such as net income.

Formal definition

In auditing, the materiality threshold is a quantitative benchmark, typically derived by applying a percentage to a chosen financial base (net income or earnings being among the most commonly used), that serves as a starting point for assessing whether misstatements or omissions could influence the decisions of users relying on the financial statements. Its determination involves the exercise of professional judgment rather than a mechanical calculation; per PCAOB AS 2105, materiality is considered in both planning and performing an audit. Percentage-based rules of thumb (for example, the SEC Staff Accounting Bulletin No. 99 reference to a 5% figure) are described as starting points only and not as definitive determinants of materiality, since qualitative factors may render an item below the threshold material. As applied here, the term addresses financial statement materiality in an audit context and does not by itself define thresholds for operational, security, geopolitical, or ESG risk unless separately specified.

Why it matters

In third-party and supply chain risk contexts, financial assessment of suppliers, vendors, and business partners frequently depends on audited financial statements, and the materiality threshold governs what those audits treat as significant. When a program relies on a counterparty's audited financials to gauge financial stability or going-concern risk, understanding that immaterial items may fall below the audit's threshold helps assessors calibrate how much assurance those statements actually provide. An issue judged immaterial to the financial statement users is not the same as an issue immaterial to a customer evaluating supplier resilience.

The threshold also matters because it is a matter of professional judgment rather than a fixed rule. Percentage-based rules of thumb, such as the 5% figure referenced in SEC Staff Accounting Bulletin No. 99, are described as starting points only and not as definitive determinants of materiality. SAB No. 99 makes clear that qualitative factors may render an item that falls below a quantitative threshold material. Risk professionals who treat a percentage cutoff as a bright line risk misreading what an audit opinion covers and overstating the assurance a clean opinion provides.

Finally, it is important to keep this term within its scope. As applied here, the materiality threshold addresses financial statement materiality in an audit context. It does not by itself define thresholds for operational, security, geopolitical, or ESG risk. A supplier issue that is immaterial to financial statements may still be highly material to service continuity or data protection, and conversely a financially immaterial item may carry disproportionate operational consequence. Programs that borrow the language of materiality for non-financial risk should define those thresholds separately and explicitly.

Who it's relevant to

Financial risk and credit analysts
Professionals who assess supplier or vendor financial health from audited statements need to understand that a materiality threshold defines what those audits treat as significant. Recognizing that items below the threshold may go unadjusted, and that the threshold reflects professional judgment rather than a fixed rule, helps analysts calibrate the assurance an audit opinion provides.
Procurement and third-party risk teams
Teams that rely on financial statements as one input into supplier due diligence should note that financial statement materiality does not, by itself, define thresholds for operational, security, geopolitical, or ESG risk. An item immaterial to a financial audit may still bear on supplier resilience and continuity, and non-financial risk thresholds must be defined separately.
Audit and assurance professionals
Auditors and those reviewing audit deliverables work directly with materiality under standards such as PCAOB AS 2105, applying it in both planning and performing an audit. They must weigh qualitative factors alongside quantitative benchmarks, consistent with SEC SAB No. 99's caution that percentage rules of thumb are starting points and not definitive determinants.

Inside Materiality Threshold

Quantitative Criteria
Numeric thresholds, such as annual spend, transaction volume, or percentage of a critical service supported, used to determine when a third-party relationship rises to a level warranting heightened scrutiny. Thresholds are typically set per program and risk tier rather than being universal figures.
Qualitative Criteria
Non-numeric factors that can render a relationship material regardless of spend, such as access to sensitive data, involvement in a critical business process, regulatory exposure, or difficulty of substitution. These often override quantitative measures alone.
Scope of Application
The specific decisions the threshold governs, for example whether a third party enters enhanced due diligence, ongoing monitoring, board-level reporting, or inclusion in a critical-supplier register. A materiality threshold defines a trigger point; it does not by itself specify the controls applied once crossed.
Risk-Domain Boundaries
The dimensions of risk to which the threshold applies. A threshold calibrated for financial exposure may not capture information security, operational, geopolitical, or ESG materiality, so many programs maintain domain-specific thresholds rather than a single blended one.
Governance and Ownership
The defined accountability for setting, approving, and periodically reviewing the threshold, including how changes are documented. Thresholds typically require periodic recalibration as the organization's exposure and risk appetite shift.

Common questions

Answers to the questions practitioners most commonly ask about Materiality Threshold.

Is a materiality threshold the same as a risk tier?
No. A materiality threshold defines the point at which a third-party relationship, exposure, or event is significant enough to warrant heightened attention, escalation, or reporting. Risk tiering, by contrast, classifies relationships into segments (for example, critical, high, medium, low) that drive the depth and cadence of due diligence and monitoring. The two often interact, a threshold may help determine which tier a supplier lands in, but they are distinct constructs. A relationship can be low-tier yet cross a specific materiality threshold for a single dimension (such as data access), and treating the two as interchangeable can cause programs to miss exposures that tiering alone does not surface.
Does crossing a materiality threshold mean the relationship is high-risk?
Not necessarily. A materiality threshold typically signals significance or the need for closer scrutiny, escalation, or disclosure, not that residual risk is high. Materiality is often assessed against inherent characteristics (such as spend, criticality, or scope of data or access) before controls are considered. A relationship can exceed a materiality threshold and still carry acceptable residual risk once controls and mitigations are accounted for. Conflating materiality with a high-risk conclusion can lead to overreaction on material-but-well-controlled relationships and underattention to lower-materiality exposures that nonetheless carry weak controls.
How do organizations decide where to set materiality thresholds?
In many programs, thresholds are calibrated against a mix of quantitative and qualitative factors, which may include annual spend, revenue dependency, volume or sensitivity of data accessed, operational criticality, substitutability, and potential regulatory or reputational impact. Some organizations set separate thresholds for different risk dimensions rather than a single blended figure, because a relationship material for information security may not be material for financial exposure and vice versa. Thresholds are typically approved by risk governance bodies and documented so their basis is defensible, but the specific values depend on the organization's risk appetite, sector, and regulatory context.
Can a single materiality threshold cover all risk types?
Rarely with adequate precision. Because materiality depends on the dimension being assessed, financial, operational, information security, geopolitical, ESG, or regulatory, a single blended threshold can obscure exposures that are significant on one axis but not others. Many programs use dimension-specific thresholds so that, for example, a supplier with modest spend but broad access to sensitive systems still triggers the appropriate scrutiny. Where a single threshold is used for simplicity, its limitation is that it may under- or over-weight relationships whose significance is concentrated in one risk category.
How often should materiality thresholds be reviewed?
Thresholds can become stale as spend patterns, dependencies, regulatory expectations, and risk appetite change, so many programs review them on a defined cadence and after significant events such as material acquisitions, restructuring, or regulatory shifts. A threshold set at onboarding does not necessarily remain appropriate over the life of a relationship; the significance of a supplier can rise as reliance deepens or as new data or services come into scope. Periodic revalidation, combined with reassessment triggered by change, helps keep thresholds aligned with current conditions, though the appropriate frequency varies by program and sector.
What role do materiality thresholds play in escalation and reporting?
Materiality thresholds are often used to route relationships or events to the appropriate level of governance, determining, for instance, which engagements require senior or board-level approval, enhanced due diligence, or inclusion in regulatory or internal reporting. Depending on jurisdiction and sector, some reporting or oversight expectations are themselves framed around materiality, so thresholds may need to align with those external definitions where they apply. It is worth noting that regulatory notions of materiality can differ from an organization's internal thresholds, and one should not assume an internally set threshold satisfies a specific regulatory reporting obligation without confirming the applicable requirements.

Common misconceptions

A materiality threshold is a single fixed dollar figure that applies across the whole program.
In many programs materiality is determined by a combination of quantitative and qualitative criteria that vary by risk domain and risk tier. A relationship below a spend threshold can still be material due to data access or process criticality, and a single blended figure often misses these cases.
Once a third party falls below the materiality threshold, it carries no meaningful risk.
A threshold governs the intensity of scrutiny, not the presence of risk. Sub-threshold relationships can still fail, and aggregated exposure across many smaller vendors may itself become material. Falling below the line reduces monitoring effort but does not eliminate underlying risk.
Setting a materiality threshold satisfies regulatory expectations for identifying critical or important suppliers.
Regulatory expectations for what constitutes a critical or important relationship differ across regions and sectors, and a threshold is an internal calibration tool rather than a compliance guarantee. Programs typically need to reconcile their internal thresholds with applicable regulatory definitions, which may not align.

Best practices

Define separate materiality thresholds for distinct risk domains, financial, information security, operational, geopolitical, and ESG, rather than relying on a single blended figure that may obscure domain-specific exposure.
Combine quantitative triggers with qualitative override criteria, such as sensitive data access or process criticality, so that low-spend but high-impact relationships are not overlooked.
Document the governance for the threshold, including who owns it, how it is approved, and the cadence for recalibration against changing exposure and risk appetite.
Clarify what the threshold triggers versus what it does not, distinguishing the point at which enhanced scrutiny begins from the specific due diligence and ongoing monitoring controls applied afterward.
Account for aggregation effects by periodically reviewing whether concentrations of individually sub-threshold relationships collectively rise to a material level.
Reconcile internal thresholds with the critical or important supplier definitions used in applicable jurisdictions and sectors, noting where they differ rather than assuming alignment.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide