Share this guide
Link copiedA risk-limiting audit, or RLA, is a post-election audit that manually examines a random sample of voter-verifiable paper records and uses statistical evidence to test whether the reported election outcome is correct. If the evidence is not strong enough, the audit expands and can continue to a full hand count.
Its defining feature is the risk limit: a pre-set maximum chance that the audit will stop without correcting the outcome when the reported outcome is actually wrong.
What problem does a risk-limiting audit solve?
A post-election audit provides an independent check after voting. Risk-limiting audits focus on one question: Is the reported outcome correct?
Traditional tabulation audits often examine a predetermined number or percentage of ballots. That may be more than necessary in a wide-margin contest or too little to provide strong evidence in a close contest.
An RLA adapts to the evidence. If a random sample provides sufficient statistical evidence that the reported outcome is correct, the audit stops. If not, more ballots are examined.
What does the “risk limit” actually mean?
Suppose an audit has a 5% risk limit. That does not mean there is a 95% probability that the reported result is correct.
It means that if the reported outcome is wrong, there is at most a 5% chance that the audit will stop without correcting it. In that situation, the procedure has at least a 95% chance of leading to correction.
A smaller risk limit requires stronger evidence before the audit can stop. All else being equal, a 1% risk limit generally requires examining more ballots than a 10% risk limit.
What does an RLA need before it can begin?
An RLA depends on trustworthy paper records and a way to select them randomly.
Voter-verifiable paper records
Auditors need paper records that provide independent evidence of voter selections, such as voter-marked paper ballots or other suitable voter-verifiable records.
A voter-verified paper audit trail is one form associated with certain electronic voting systems. The records must also be preserved so that the audit trail can be trusted.
A ballot manifest
A ballot manifest lists how ballots are organised and where they are stored.
It can show, for example, how many ballots are in each container or batch. This lets auditors connect randomly selected ballot numbers to physical ballots that can be retrieved for examination.
A random selection method
The sample must be selected randomly from the ballots being audited.
Some procedures publicly generate a random seed, for example by rolling ten-sided dice. Software then uses that seed to create a reproducible random selection. The purpose is to make the sample unpredictable in advance and independently reproducible.
How does a risk-limiting audit work?
The exact procedure varies, but the basic process has six stages.
1. Set the contest and risk limit
Officials identify the contest or contests to audit and the risk limit that will apply.
The reported margin matters because a close contest provides less room for counting error.
2. Account for the ballots
Officials prepare or verify the ballot manifest and make sure the relevant paper records are available and properly preserved.
3. Select ballots randomly
A random-selection process identifies ballots or batches for examination. Random selection matters because choosing convenient precincts or ballots can produce a sample that does not represent the full contest.
4. Examine the selected records by hand
Human auditors interpret the selected paper records under established rules.
Depending on the RLA method, they may examine the votes in the sample directly or compare each ballot with its corresponding cast vote record, or CVR.
5. Evaluate the statistical evidence
The audit tests whether the sample provides enough evidence to satisfy the risk limit.
If the risk limit has not yet been met, that does not automatically mean the reported outcome is wrong. It means more evidence is needed.
6. Stop or expand the audit
If the evidence is sufficient, the audit stops. Otherwise another round examines additional ballots.
The process continues until the risk limit is satisfied or the audit escalates to a full hand count that determines the outcome.
What are the main types of risk-limiting audit?
The U.S. Election Assistance Commission (EAC) describes three common approaches.
Ballot-polling RLA
A ballot-polling audit examines a random sample of individual ballots and uses the votes found in that sample to test the reported outcome.
It does not require matching each ballot to an individual CVR, although it will generally examine more ballots than an efficient comparison audit.
Ballot-level comparison RLA
A comparison audit compares the human interpretation of each randomly selected ballot with the voting system's CVR for that same ballot.
This can be highly efficient because discrepancies are tied to individual ballots. The jurisdiction must be able to associate ballots with their CVRs while preserving ballot secrecy.
Batch-level comparison RLA
A batch-level comparison audit selects groups of ballots and compares hand-counted totals for those batches with the voting system's reported batch totals.
It can be useful where results can be associated with batches but not with individual ballots.
Why do close elections require more auditing?
An RLA is sensitive to the contest margin.
In a wide-margin contest, relatively small counting errors are unlikely to change the winner, so a modest sample may provide strong evidence quickly.
In a very close contest, much smaller errors could change the outcome. More evidence is therefore needed before the audit can stop.
The final workload also depends on what the sample reveals. Discrepancies that overstate the reported winner's margin can cause the audit to expand.
Is an RLA the same as a traditional audit?
No.
A traditional tabulation audit often hand-counts a predetermined sample of paper records and compares those results with the original totals.
An RLA is adaptive. Its sample size is tied to the contest margin, the evidence found in the sample and a statistical stopping rule based on the risk limit.
Both can support post-election verification, but they use different methods to evaluate the result.
Is a risk-limiting audit the same as a recount?
No.
A recount is an additional count of votes, commonly triggered by state law, a close margin, a candidate request or a court order.
An RLA normally begins by examining a sample. However, if the audit cannot obtain sufficient evidence, it can expand to a full hand count. At that point, the hand count determines the outcome.
Do all U.S. states use risk-limiting audits?
No. States use different post-election audit methods.
The National Conference of State Legislatures reported in April 2026 that all 50 states and Washington, D.C., conduct some type of post-election audit. At that time, seven states had statutory requirements for risk-limiting audits, while several others allowed them as an option or had conducted pilot programmes.
States also differ on the contests audited, risk limits, timing, responsible officials and procedures for handling discrepancies.
An RLA is therefore a family of statistical audit methods, not one identical nationwide procedure.
Related ESG terms
- Risk-Limiting Audit
- Post Election Audit
- Ballot Manifest
- Random Seed
- Cast Vote Record
- Comparison Audit
- Tabulation Audit
- Audit Trail
- Recount
- Voter-Verified Paper Audit Trail
Frequently asked questions
1. Does an RLA prove that every vote was counted perfectly?
No. An RLA tests whether the reported outcome is correct; it does not prove that every individual ballot was interpreted perfectly. Small discrepancies can exist without changing who won. If the statistical evidence is insufficient, the audit expands and can reach a full hand count.
2. What happens if an RLA finds discrepancies?
A discrepancy does not automatically mean the outcome is wrong. The audit incorporates it into the statistical test. Depending on what is found, additional ballots may need to be examined. If sufficient evidence cannot be obtained, the process can escalate to a full hand count.
3. Why must ballots be selected randomly?
Random selection prevents auditors from checking only particular precincts, batches or ballots that may not represent the contest. It allows the statistical method to draw valid conclusions from a sample. A ballot manifest then helps officials locate the selected physical ballots.
4. Can an RLA be performed without paper ballots?
An RLA requires a trustworthy voter-verifiable audit trail that can be examined independently of electronic tabulation. In practice, this generally means paper ballots or suitable voter-verifiable paper records. A paperless system without an independent voter-verifiable record cannot support this form of audit.
Sources and further reading
- U.S. Election Assistance Commission — Post-Election Tabulation Audits: A Practical Guide for Beginners and Beyond
- U.S. Election Assistance Commission — Clearinghouse Resources on Audits & Recounts
- National Institute of Standards and Technology — Auditing Use Case
- National Institute of Standards and Technology — A Gentle Introduction to Risk-Limiting Audits
- National Conference of State Legislatures — Post-Election Audits
- National Conference of State Legislatures — Risk-Limiting Audits
ESG editorial note: Election Security Glossary is an educational and reference resource. It is not an election authority and does not provide legal advice or official voting instructions. Audit requirements, risk limits and procedures vary by jurisdiction; consult the relevant election authority for rules that apply to a specific election.