1. Home
  2. Blog
  3. How a Risk Control Matrix Improves Audit Readiness
Process & Resourcing

How a Risk Control Matrix Improves Audit Readiness

A risk control matrix maps each business risk to the specific control that mitigates it, names the control owner, states how the control is evidenced, and records how often it is tested. Its practical value is that it turns audit preparation from a scramble into a retrieval exercise, because the evidence requirement was defined before the auditor asked.

What the matrix actually contains

A usable risk control matrix is a table, not a narrative. Each row is a single risk with a single control, and the columns force the questions that audits later ask. The discipline is in refusing to leave a cell empty: a control with no named owner has no owner, and a control with no defined evidence cannot be tested.

The evidence column is the one that changes audit outcomes. Stating in advance that a control is evidenced by a specific report, run monthly, retained for seven years, means the evidence exists in the form the auditor needs. Deciding what the evidence is after the request arrives usually means reconstructing it.

  • Risk described in business terms with its potential impact
  • Control that mitigates it, described specifically enough to test
  • Control type: preventive, detective or corrective
  • Whether the control is automated in a system or performed manually
  • Named owner, by role and by person
  • Frequency of operation and of testing
  • Evidence produced, where it is stored and for how long
  • Date and result of the most recent test

Preventive, detective and corrective

Preventive controls stop the event: a system configuration that blocks a purchase order above a threshold without approval. Detective controls find it after the fact: an exception report of postings outside normal hours. Corrective controls restore the position: a documented procedure for reversing an incorrect posting.

Balance matters. A matrix consisting almost entirely of detective controls indicates an environment that discovers problems reliably and prevents very few of them, which is expensive to run and uncomfortable to explain.

Control types and their characteristics
Type Acts Example Cost profile
Preventive Before the event System-enforced approval limit Low ongoing, higher to configure
Detective After the event Monthly exception report review Ongoing effort every period
Corrective After detection Documented reversal procedure Incurred only when needed

Segregation of duties

The recurring finding in ERP environments is that a single user can create a vendor, raise a purchase order and approve payment. Segregation of duties analysis maps role assignments against conflicting function pairs and identifies where one person holds both sides.

In small organisations, complete segregation is often impossible, and pretending otherwise produces a matrix nobody believes. The workable approach is to document the conflict, apply a compensating detective control such as management review of a specific report, and record that decision. An auditor accepts a documented compensating control; they do not accept an undocumented gap.

Keeping it alive

The matrix decays as soon as processes change and nobody updates it. Tie review to a fixed cadence, typically annual, plus a trigger on any significant system or process change.

Test results belong in the matrix itself rather than a separate file. A matrix showing when each control was last tested and what the result was answers most of an auditor’s opening questions without further work.

FAQ

Common questions

What is a risk control matrix?

A table mapping each identified business risk to the control that mitigates it, with columns for control owner, control type, frequency, evidence produced and the date and result of the last test. It is used to demonstrate that risks are identified, controls exist, and controls are operating rather than merely documented.

What is segregation of duties in an ERP context?

Ensuring no single user can complete a transaction end to end where that would enable fraud or error to go undetected, such as creating a vendor, raising a purchase order and approving payment. It is enforced through role design and checked by analysing role assignments against a list of conflicting function pairs.

What if a small team cannot segregate duties properly?

Document the conflict, apply a compensating detective control such as periodic management review of a specific exception report, and record the decision and its rationale in the matrix. Auditors accept documented compensating controls where segregation is genuinely impractical; they do not accept an undocumented gap.

Keep reading

Related articles

Working on something like this?

If this article covers a problem you are dealing with, tell us where you have got to and we will tell you what we would do next.