Skip to content
SOCIALGOV
civictech

What a risk-limiting election audit actually proves

A risk-limiting audit does not check every ballot — it hand-counts just enough of them to guarantee, with a stated confidence, that a wrong outcome would be caught.

What a risk-limiting election audit actually proves
Auditors hand-count a random sample of ballots, with observers watching every sheet.

A risk-limiting audit (RLA) is a statistical hand count of a random sample of paper ballots that gives a mathematical guarantee: if the machine count named the wrong winner, the audit has a high, pre-set chance of correcting it. Most states that run RLAs set the risk limit between 1 and 10 percent, meaning the procedure would catch a wrong outcome with 90 to 99 percent probability. Colorado became the first state to run one statewide in 2017, and more than a dozen states have used RLAs in at least one election since, as of 2025.

Why does an audit need statistics at all?

Because hand-counting everything is slow and expensive, and because the goal is a guarantee, not a guess. The audit treats the machine tallies as a hypothesis to test against paper. If the reported margin is large, the true count is unlikely to be close, so a small random sample of ballots is enough to confirm it. If the margin is narrow, the sample grows. The sample size is calculated from the margin itself, so the procedure spends effort exactly where the outcome is most in doubt. This is the core idea that separates an RLA from a fixed-percentage hand count, which audits the same share of ballots whether the race was a landslide or a tie.

What does "risk limit" mean in plain terms?

The risk limit is the worst-case probability that the audit fails to catch a wrong outcome. Set the limit at 5 percent and the audit is designed so that, if the reported winner is actually the loser, there is at most a 5 percent chance the sample misses it — a 95 percent chance the audit escalates and corrects the result. Two things are worth noting. First, the guarantee runs in one direction: a passing RLA proves the reported outcome is right within that confidence, but a hand recount of every ballot is the only procedure that checks the exact tally. Second, the guarantee assumes the sample is genuinely random and the paper trail is intact, which is why chain-of-custody procedures matter as much as the math.

What are the main types of risk-limiting audits?

Three designs are in common use, and the differences come down to what gets sampled.

Audit typeWhat is sampledWorks best when
Ballot pollingIndividual ballots, hand-marked tallies compared to the reported margin onlyBallots are not linked to cast-vote records; simplest but needs the largest samples
Batch comparisonWhole batches (precincts, boxes) counted by hand against the machine's batch totalsBallots are stored in batches with machine subtotals; good for older systems
Ballot comparisonIndividual ballots compared to the machine's recorded vote for that exact ballotThe system exports per-ballot records (cast-vote records); most efficient

Ballot-polling audits are the easiest to run because they need no software from the voting system, which is why most states start there. Ballot-comparison audits are the most efficient — a narrow-margin race might need only a few hundred ballots — but require voting equipment that can export its own record of each ballot.

Related stories: How voter registration lists are maintained, and who checks them · How election results get certified, county by county.

How does the sample grow during an audit?

RLAs are sequential. Auditors draw a random sample, hand-count it, and run a calculation called a risk-measuring statistic that asks: could the reported margin plausibly be wrong given what we just saw? If the answer is a confident no, the audit stops and the outcome stands. If the sample looks off, the audit escalates — more ballots are drawn, in increasing rounds, until either the count is confirmed or every ballot in the contest has been hand-counted, which is a full recount by another name. In a state like Colorado, this escalation happens over several public days with the samples drawn from a verified random seed, often dice rolled on camera or digits derived from publicly published data, so the randomness itself is auditable.

When does the audit happen relative to certification?

Before, in every state that mandates it. Post-election audits are part of the canvass-and-certification window: counties or the state run the audit on the provisional or unofficial tally, and certification happens only after the audit confirms the outcome or the full hand count replaces it. That ordering is the point — an RLA is a check on the official result, not a postscript to it. If an audit fails to confirm, the escalation process catches it before the result becomes official.

What an RLA does not do

It is worth being precise about the limits. An RLA checks the contest or contests selected for audit — often the top race on the ballot — not every contest. It audits the paper, so it cannot detect tampering that altered the paper trail itself; that is what pre-election logic-and-accuracy testing, chain-of-custody rules, and physical security are for. And it cannot audit ballots that do not exist: jurisdictions without voter-marked paper ballots cannot run a meaningful RLA at all, which is why paper trails are the precondition for every audit law on the books.

Can the public watch an RLA happen?

Yes, and observation is part of the design. Audits are run in public spaces under state open-meetings rules in most states, political party observers and members of the public can watch the hand counting, and the random seed used to draw the sample is typically generated in view — Colorado, for example, has used publicly streamed random number draws and published the seed so anyone can reproduce the sample selection. Counties post round-by-round results during multi-day audits. If you want to see one, your secretary of state's election division publishes the audit schedule and the risk limit for each contest before the audit starts, and the final audit report becomes a public record after certification.

Frequently Asked Questions

What is a risk-limiting audit?
A statistical procedure that hand-counts a random sample of paper ballots to confirm the outcome of an election. If the reported winner were wrong, the audit would detect it with a stated probability — typically 90 to 99 percent.
Does a passing audit prove the exact vote totals?
No. It proves the reported outcome — who won — is correct within the audit's confidence level. Confirming exact totals requires a full hand recount of every ballot.
Which states use risk-limiting audits?
More than a dozen states have used RLAs in at least one election since Colorado ran the first statewide RLA in 2017. Some states require them by law; others run them voluntarily.
Why is the risk limit often 5 or 10 percent?
Lower risk limits require larger samples and more work. States commonly choose between 1 and 10 percent, balancing statistical confidence against the cost of hand counting.