Skip to content
USA DAILY NEWS 24
elections

Risk-Limiting Audits: The Statistical Check on Election Results

A risk-limiting audit hand-examines a random sample of ballots large enough that, if the reported outcome is wrong, the audit has a known maximum chance of failing to catch it — the only post-election audit with a statistical guarantee attached.

Risk-Limiting Audits: The Statistical Check on Election Results
The sample size scales with the margin: wide results confirm in minutes, narrow ones escalate toward a full hand count.

A risk-limiting audit, or RLA, is a post-election audit with a statistical guarantee: officials hand-examine a randomly selected sample of paper ballots, and the sample size is set so that if the reported outcome is wrong, there is a known, bounded maximum probability — the "risk limit," commonly 5 or 10 percent — that the audit would nonetheless stop and confirm it. Colorado became the first state to run a statewide risk-limiting audit in 2017, roughly a dozen states have adopted RLA statutes or rules since, and the design rests on a condition every other audit skips: the reported result must be checked against paper ballots that were actually cast.

What makes an audit "risk-limiting"?

The mathematics of the stopping rule. Traditional fixed-percentage audits hand-count a set share of precincts — 1 or 5 percent — regardless of the margin, which means the workload tells you nothing about the chance of catching an error: a 2-vote margin and a 40,000-vote margin get the same sample. An RLA inverts that. The audit draws a growing random sample until the accumulated evidence shows, at a stated confidence level, that a full hand count would confirm the reported outcome; narrow margins demand larger samples, wide margins clear quickly. If the sample instead suggests the reported outcome is wrong, the audit expands and ultimately escalates to a full hand count, which then replaces the machine count under state law. The "risk limit" is the residual chance that an incorrect outcome survives: a 10 percent risk limit guarantees the audit catches a wrong outcome at least 90 percent of the time, in the statistical long run.

What are the main RLA designs?

Three, each trading efficiency against infrastructure:

  • Ballot comparison. The strongest and most efficient: the audit compares the machine's interpretation of each sampled ballot against a human interpretation of the same ballot. It requires ballot-level records — individual ballot images or cast-vote records tied to physical ballots — so it works only where the voting system exports them, and a small sample can confirm even narrow margins.
  • Ballot polling. The most portable: auditors draw random physical ballots and simply record the votes on them, as if counting a poll, until the sample statistically supports the reported outcome. It needs no ballot-level records, but wide margins are what make it cheap, and it examines far more ballots than comparison in comparable conditions.
  • Batch comparison. The middle design: auditors hand-count randomly selected batches — precincts or device totals — and compare the totals to the machine's reported batch results, using known statistical bounds on batch-level error to decide when to stop.

All three assume the sampled ballots are drawn from a verified pool: every physical ballot counted in the result must be in the population the sample draws from, which puts the weight on documented chain of custody and a ballot accounting reconciliation before any sampling starts.

Which states use them?

A growing minority with legal force behind it. Colorado ran the first statewide RLA in 2017 and has run one every general election since under its 2009 audit statute as implemented; Rhode Island adopted RLAs in 2017; Virginia mandated them statewide for 2021 after piloting in 2019-2020; and Michigan, Nevada, Georgia, Oregon, Washington, and several others run RLAs or RLA-style audits under statute, administrative rule, or post-2020 directives. The 2020 cycle accelerated adoption: Georgia's presidential audit — a full hand count that year, followed by adoption of RLA rules — and the post-election litigation environment pushed more legislatures to prefer audits with a statistical pedigree over fixed-percentage spot checks that a court cannot interpret. Where no RLA law exists, the fallback remains traditional audits: fixed-percentage hand counts, canvass-based checks, and California's uniquely demanding 1 percent manual tally.

Related stories: Provisional Ballots: When They Count and How They Are Verified · The Certification Calendar: When Election Results Become Official.

What can an audit catch, and what can't it?

It bounds outcome-level error, not everything. An RLA detects miscounting — tabulation errors, misconfigured equipment, tally mistakes — with a quantified confidence, and it is the only audit design that can state that confidence. It does not by itself detect ballot boxes that were never counted, ballots inserted after the fact outside the chain of custody, or errors confined to unsampled races; the design limits are why election authorities pair RLAs with ballot reconciliation, in which the number of ballots counted is reconciled against check-in records and sealed container logs. Audits also presuppose a faithful paper trail — ballot marking devices and hand-marked paper both qualify, pure paperless DRE machines do not — which is why the RLA movement and the shift away from paperless voting after 2016 are one policy story, not two.

Why did RLAs spread when they did?

Because the 2016 and 2020 cycles converted an academic idea into a legal requirement. The method matured in the statistics literature in the 2000s, but adoption followed security pressure: the 2016 election’s foreign interference findings and the subsequent replacement of paperless voting machines made auditable paper trails a federal policy priority, and post-2020 litigation over recount mechanics made the difference between interpretable and uninterpretable audits visible to every legislature. Election security officials and secretaries of state became the method’s main institutional advocates, and the adoption pattern followed the paper: states with statewide paper ballot systems moved first because the audit’s assumptions were already satisfied, while states mid-transition scheduled RLAs as the finish line of their equipment upgrades. The design’s appeal to officials is also administrative — a stopping rule removes the discretionary judgment of “how many precincts look close enough,” replacing it with a number anyone can reproduce.

How does an audit run in practice?

As a public procedure with a schedule:

  1. Compliance and reconciliation. Officials confirm ballot accounting — ballots received, cast, spoiled, and counted reconcile — and seal the pool the sample will draw from.
  2. Random seed. A public random number, often generated from published dice rolls, drives a seeded pseudorandom selection of ballots or batches, so anyone can reproduce the sample.
  3. Sampling and counting. Bipartisan teams interpret sampled ballots under written rules, entering results into audit software that computes when the risk limit is met.
  4. Stop or escalate. Meeting the risk limit ends the audit and confirms the result; falling short expands the sample, and confirmed escalation leads to a full hand count whose totals become the official result.

For the 2026 cycle the practical takeaway is the same as the statistical one: audits confirm outcomes with stated confidence when margins and paper trails allow it, and they are scheduled — not reactive — machinery, running inside the certification calendar whether or not anyone disputes the result.

Frequently Asked Questions

What does a 5 percent risk limit mean?
It is the maximum probability that the audit confirms an outcome that is actually wrong. A 5 percent risk limit guarantees the procedure detects any incorrect outcome at least 95 percent of the time in repeated runs; a 10 percent limit, at least 90 percent. The limit is chosen in advance by rule, and lower risk limits require larger hand-counted samples.
How is a risk-limiting audit different from a recount?
A recount recounts ballots to correct or confirm a specific margin, usually in a close race, and a full recount replaces the count entirely. An RLA runs regardless of margin, examines a statistical sample, and confirms the outcome with stated confidence — escalating to a full hand count only when the evidence points that way. Audits are routine; recounts are triggered.
What happens if an audit finds a problem?
The audit expands: more ballots are sampled, and if the accumulated evidence contradicts the reported outcome, the procedure escalates to a full hand count of the affected contest. Under state audit laws that hand count's totals then become the official result, and equipment or process failures found along the route feed into the certification record and any required corrective action.
Do all states run risk-limiting audits?
No. Roughly a dozen states have adopted RLAs through statutes or rules — Colorado, Rhode Island, Virginia, Michigan, Nevada, Georgia, and others — while the rest use traditional post-election checks such as fixed-percentage hand counts or precinct spot checks. Every state requires some post-election audit or canvass review, but only the RLA design carries a statistical guarantee.