A risk-limiting audit (RLA) is a post-election tabulation auditing procedure which can limit the risk that the reported outcome in an election contest is incorrect. It generally involves (1) storing voter-verified paper ballots securely until they can be checked, and (2) manually examining a statistical sample of the paper ballots until enough evidence is gathered to meet the risk limit. Advantages of an RLA include: samples can be small and inexpensive if the margin of victory is large; there are options for the public to watch and verify each step; and errors found in any step lead to corrective actions, including larger samples, up to a 100% hand count if needed. Disadvantages include: the sample needs to be a large fraction of all ballots to minimize the chance of missing mistakes, if any contest is close; and it is hard to check computer totals publicly, except by releasing computer records to the public. If examining sampled ballots shows flaws in ballot storage, the usual approach cannot recover correct results, and researchers recommend a re-vote if the number of ballots held in flawed storage is enough to change winners. An alternative to re-votes is to create and verify backups of the paper ballots soon after they are voted, so there is an alternative to flawed storage of the original ballots. As with other election audits, the goal is to identify not only intentional alterations of ballots and tallies, but also bugs in election machines, such as software errors, scanners with blocked sensors or scanners skipping some ballots. The approach does not assume that all ballots, contests or machines were handled the same way, in which case spot checks could suffice. The sample sizes are designed to have a high chance of catching even a brief period when a scratch or fleck of paper blocks one sensor of one scanner, or a bug or hack switches votes in one precinct or one contest, if these problems affect enough ballots to change the result. Comparisons can be done ballot-by-ballot or precinct-by-precinct, though the latter is more expensive.
Categories of audits
There are three general types of risk-limiting audits. Depending on the circumstances of the election and the auditing method, different numbers of ballots need to be hand-checked. For example, in a jurisdiction with 64,000 ballots tabulated in batches of 500 ballots each, an 8% margin of victory, and allowing no more than 10% of any mistaken outcomes to go undetected, method 1, ballot comparison, on average, needs 80 ballots, method 2, ballot polling, needs 700 ballots, and method 3, batch comparison, needs 13,000 ballots (in 26 batches). The methods are usually used to check computer counts, but methods 2 and 3 can also be used to check accuracy when the original results were hand-counted. The steps in each type of risk-limiting audit are:
Ballot comparison. Election computers provide their interpretation of each ballot ("cast vote record"); humans check computers' cast vote records against stored physical ballots in a random sample of ballots; an independent computer tabulates all cast vote records independently of earlier tabulations to get new totals; humans report any differences in interpretations and total tallies. Ballot polling. Humans count a random sample of ballots; humans report any difference between manual percentage for the sample and computer percentage for the election. Batch comparison. Election results provide total for each batch of ballots (e.g. precinct); in a random sample of batches humans hand-count all ballots; for 100% of batches humans check by manual addition or independent computer if the election's initial summation of batches was correct; humans report any difference between original tallies and audit tallies. All methods require:
Procedure to re-count all paper ballots more accurately if errors are detected. This is usually planned as a 100% manual count, but could involve fixing or replacing erroneous computers, doing a new computer count, and auditing that, until an audit shows no problem. Auditing all types of ballots, including military, absentee, provisional, etc. Clarifying which contests were audited and which were not, or auditing all contests or a large enough random sample of contests so the chance of missing erroneous results is acceptably low. Auditing a large enough random sample of ballots so the chance of missing mistakes is acceptably low. Selecting a random sample after initial results are public, because telling hackers in advance which contests and ballots will be in the sample, lets them freely hack other contests and ballots. Selecting the random sample before results are final, so errors can be fixed. Doing the manual check immediately when the sample is selected; if insiders have altered computer files, they could use any delay to change sampled ballots to match the erroneous computer files, thus hiding the errors. Having enough security on the ballots during transportation and storage, so neither insiders nor outsiders can change them. Having enough independent participants select different digits of the random number seed, so no one can control the seed and hence the random number series which selects the random sample. Having the public see all steps, including the content of ballots and computer records while officials examine them, to know they are counted accurately. The last three items are hard in one-party states, where all participants may be swayed by the ruling party. Hand-checking ballots (method 1) identifies bugs and hacks in how election computers interpret each ballot, so computer processing can be improved for future elections. Hand-counting ballots (methods 2 and 3) bypasses bugs and hacks in computer counts, so it does not identify exactly what mistakes were made. Independently totaling cast vote records (method 1) or batch totals (method 3) identifies bugs and hacks in how election computers calculate totals. Method 2 does not need this independent totaling step, since it has a large enough sample to identify winners directly. Colorado uses method 1 in most counties. Colorado uses no audit method in one county which hand-count ballots in the first place. Risk-limiting audits are a results audit to determine if votes were tabulated accurately, not a process audit, to determine if good procedures were followed.
… excerpt ends here. Continue reading the full article.




