For the audit engagements of the Year 2015 plan onwards, the classification of audit issues by risk level (low-medium-high) will adopt the same criteria used by business units to classify impact level of their operation risk incidents (1-2-3-4-5). The objective of this change is to increase transparency of audit risk rating and prepare for merging audit reporting process into ORM incident workflow which will accelerate audit results communication, and improve overall audit effectiveness