The Risk and Control Matrix (RCM) Explained, With Examples

The risk and control matrix is where an audit stops being a topic and becomes testable work. It links what the process is supposed to achieve, what could stop that, what the business does about it, and what you will do to check.

The four levels, in order

An RCM reads top to bottom: the process objective, the risks to that objective, the controls management operates against those risks, and the audit procedures you will perform to test those controls. Every level exists because of the one above it. A control with no risk above it is a control nobody needs; a procedure with no control above it is work with no purpose.

Write risks as events, not topics

"Fraud" is a topic. "Payments are made to fictitious suppliers because vendor master changes are not independently reviewed" is a risk: an event, a cause, and an implied consequence. Risks written as events produce obvious controls; risks written as topics produce vague ones.

Separate inherent risk from residual risk

Inherent risk is exposure before controls; residual risk is what remains after the controls operate as designed. Recording both is what lets you explain why a high-inherent-risk area received limited testing — the controls were strong — rather than looking like an oversight.

Rate likelihood and impact on a defined scale

A 1–5 likelihood and 1–5 impact scale multiplied into a 1–25 rating is the common approach. What matters is that the bands are defined once and applied everywhere: if a 20 is "severe" in one engagement and "high" in another, the ratings cannot be aggregated for reporting.

Make procedures specific enough to repeat

"Test access controls" is not a procedure. "Select 25 users granted access during the period, and confirm each has documented approval from the system owner before the grant date" is. The test is whether a different auditor could perform it and reach the same conclusion.

Reuse the matrix, but tailor it

A proven RCM for a process is worth keeping as a template, but applying it unchanged to a different entity is how audits miss what is actually different. Apply the template, then walk the process and adjust before testing.

Keep reading

More internal audit guides