What is a Risk Control Matrix?
A Risk Control Matrix is a structured document that links each significant risk in a process to the controls in place to address it. It typically captures the process, sub-process, risk description, control description, control type, frequency, owner, evidence, and the financial or operational assertion impacted.
How is RCM different from SOPs?
SOPs describe how a process should be executed step by step. RCMs focus on what could go wrong in those steps and which controls mitigate those risks. Together they form a strong control environment — SOPs guide operations, while RCMs enable risk and control assessment.
Which processes typically need an RCM?
RCMs are commonly built for core financial and operational cycles such as Procure to Pay, Order to Cash, Inventory and Warehousing, Fixed Assets, Hire to Retire, Treasury, Tax, Financial Close and Reporting, IT General Controls, and key entity-level controls.
What is the link between RCM, IFC, and ICFR?
Internal Financial Controls (IFC) under the Companies Act and Internal Controls over Financial Reporting (ICFR) for listed entities require management to document, test, and report on controls. RCMs are the primary tool used to document and test those controls in a structured, auditable manner.
What is the difference between preventive and detective controls?
Preventive controls are designed to stop errors or fraud from occurring — for example, system validations or maker-checker approvals. Detective controls identify issues after they have happened — for example, reconciliations, exception reports, or post-event reviews. A well-balanced RCM has both.
How are controls tested in an RCM?
Controls are tested through Test of Design and Test of Operating Effectiveness. Test of Design checks whether a control is properly designed to address the risk. Test of Operating Effectiveness checks whether the control is performed consistently and as intended over a period using a sample of transactions or events.
How often should an RCM be updated?
RCMs should be reviewed at least annually and updated whenever there are significant changes in business processes, ERP systems, regulations, organisational structure, or risk profile. Continuous monitoring tools and internal audits often feed updates into the RCM throughout the year.