Reducing Manual Work by Fixing Data Flow, Not Adding Tools
Most manual work in business operations exists because data stops at a system boundary and a person carries it across. Fixing that…
A risk control matrix maps each business risk to the specific control that mitigates it, names the control owner, states how the control is evidenced, and records how often it is tested. Its practical value is that it turns audit preparation from a scramble into a retrieval exercise, because the evidence requirement was defined before the auditor asked.
A usable risk control matrix is a table, not a narrative. Each row is a single risk with a single control, and the columns force the questions that audits later ask. The discipline is in refusing to leave a cell empty: a control with no named owner has no owner, and a control with no defined evidence cannot be tested.
The evidence column is the one that changes audit outcomes. Stating in advance that a control is evidenced by a specific report, run monthly, retained for seven years, means the evidence exists in the form the auditor needs. Deciding what the evidence is after the request arrives usually means reconstructing it.
Preventive controls stop the event: a system configuration that blocks a purchase order above a threshold without approval. Detective controls find it after the fact: an exception report of postings outside normal hours. Corrective controls restore the position: a documented procedure for reversing an incorrect posting.
Balance matters. A matrix consisting almost entirely of detective controls indicates an environment that discovers problems reliably and prevents very few of them, which is expensive to run and uncomfortable to explain.
| Type | Acts | Example | Cost profile |
|---|---|---|---|
| Preventive | Before the event | System-enforced approval limit | Low ongoing, higher to configure |
| Detective | After the event | Monthly exception report review | Ongoing effort every period |
| Corrective | After detection | Documented reversal procedure | Incurred only when needed |
The recurring finding in ERP environments is that a single user can create a vendor, raise a purchase order and approve payment. Segregation of duties analysis maps role assignments against conflicting function pairs and identifies where one person holds both sides.
In small organisations, complete segregation is often impossible, and pretending otherwise produces a matrix nobody believes. The workable approach is to document the conflict, apply a compensating detective control such as management review of a specific report, and record that decision. An auditor accepts a documented compensating control; they do not accept an undocumented gap.
The matrix decays as soon as processes change and nobody updates it. Tie review to a fixed cadence, typically annual, plus a trigger on any significant system or process change.
Test results belong in the matrix itself rather than a separate file. A matrix showing when each control was last tested and what the result was answers most of an auditor’s opening questions without further work.
A table mapping each identified business risk to the control that mitigates it, with columns for control owner, control type, frequency, evidence produced and the date and result of the last test. It is used to demonstrate that risks are identified, controls exist, and controls are operating rather than merely documented.
Ensuring no single user can complete a transaction end to end where that would enable fraud or error to go undetected, such as creating a vendor, raising a purchase order and approving payment. It is enforced through role design and checked by analysing role assignments against a list of conflicting function pairs.
Document the conflict, apply a compensating detective control such as periodic management review of a specific exception report, and record the decision and its rationale in the matrix. Auditors accept documented compensating controls where segregation is genuinely impractical; they do not accept an undocumented gap.
Most manual work in business operations exists because data stops at a system boundary and a person carries it across. Fixing that…
A dashboard gets used when each metric on it is tied to a decision someone makes and an action they can take.…
Evaluate an IT consulting partner on the people who will actually do the work, not on the firm's credentials or the pitch…
If this article covers a problem you are dealing with, tell us where you have got to and we will tell you what we would do next.