Risk · Internal Controls

Risk Control Matrix (RCM) that maps risk to control, precisely.

Designing and implementing Risk Control Matrices that map business process risks to specific controls — providing the foundation for IFC/ICFR reporting, internal audit, and a defensible internal control framework.

Contact Us

A Risk Control Matrix is the foundational document that maps each identified risk in a business process to the specific controls designed to mitigate that risk. It answers the three core questions of internal control: what can go wrong in this process, what control exists to prevent or detect it, and is that control working effectively? Without a well-designed RCM, internal audit has no structured basis, IFC/ICFR reporting has no documentation, and management has no clear view of its control landscape.

For listed companies and certain unlisted companies required to report on Internal Financial Controls over Financial Reporting, the RCM is not optional — it is the primary evidence base for the auditor's IFC opinion. For all other companies, it is one of the most practical tools available to management for understanding and managing operational and financial risk.

NDS Advisors designs and implements Risk Control Matrices from scratch or reviews and updates existing RCMs — across financial reporting processes, operational processes, IT general controls, and compliance processes. Our RCMs are practical, current, and designed to drive real assurance activity rather than sit in a drawer.

Our Risk Control Matrix (RCM) Services

RCM Design from Scratch

End-to-end design of a Risk Control Matrix for all key business processes — identifying risks, documenting controls, assigning control owners, and rating control effectiveness.

Existing RCM Review & Update

Review and update of an existing Risk Control Matrix — updating for process changes, new risks, regulatory developments, and audit findings.

IFC/ICFR Documentation

Design of the complete IFC/ICFR documentation suite — including process narratives, risk and control matrices, test of design, and test of effectiveness evidence.

Process Narrative Documentation

Preparation of process narratives describing how key business processes work — the precondition to identifying risks and mapping controls.

Control Testing Framework

Design of a control testing programme that uses the RCM to drive systematic testing of control design and operating effectiveness.

Control Deficiency Assessment

Assessment and classification of identified control gaps — distinguishing control deficiencies, significant deficiencies, and material weaknesses.

IT General Controls RCM

Risk and control mapping for IT general controls — covering access management, change management, computer operations, and data security.

Internal Audit Plan from RCM

Design of a risk-based internal audit plan derived from the RCM — ensuring the internal audit programme covers the highest-risk areas and key controls.

Our Process

1

Process Identification & Scoping

Identifying all in-scope business processes — financial reporting, operational, compliance, and IT — and agreeing on the prioritisation and scope of the RCM.

2

Process Walkthrough

Conducting structured walkthroughs of each in-scope process — documenting the flow of transactions, key decision points, and existing controls.

3

Risk Identification

Identifying all risks within each process — including fraud risks, error risks, compliance risks, and IT risks — mapped to financial statement assertions where applicable.

4

Control Mapping

Mapping each identified risk to one or more existing controls — documenting control description, control type, frequency, owner, and evidence of operation.

5

RCM Finalisation & Training

Finalising the RCM with control owners, training the internal audit and finance teams on its use, and embedding it into the ongoing audit and control monitoring cycle.

Why It Matters

Provides the foundation for IFC/ICFR reporting and audit
Gives management a complete view of the control landscape
Drives a structured, risk-based internal audit programme
Identifies control gaps before they result in audit findings
Documents control ownership and accountability clearly
Supports CARO 2020 and statutory auditor requirements
Reduces time and cost of external audit through documented controls
Enables continuous monitoring of key controls over time

Frequently Asked Questions

A Risk Control Matrix is a structured document that maps each risk in a business process to the controls designed to prevent or detect it. It is the foundation of any internal control framework — giving management, internal auditors, and external auditors a comprehensive, structured view of what can go wrong in each process and what is in place to stop it.
An RCM is not explicitly required by statute, but it is effectively essential for companies that must report on Internal Financial Controls over Financial Reporting — which includes all listed companies and certain unlisted companies. The IFC auditor's opinion must be supported by documented evidence of control design and testing, and the RCM is the primary vehicle for that documentation.
At minimum, an RCM for IFC/ICFR purposes should cover all financial reporting processes — revenue recognition, procure-to-pay, payroll, fixed assets, treasury, financial close and reporting, and inventory. Depending on the business, operational processes and IT general controls may also be included. We help clients determine the appropriate scope based on the financial statement risk profile.
A control deficiency exists when a control is not designed or operating effectively enough to prevent or detect a misstatement. A significant deficiency is a more serious gap — less severe than a material weakness but important enough to merit attention from those responsible for financial oversight. A material weakness is a deficiency where there is a reasonable possibility that a material misstatement of financial statements will not be prevented or detected — requiring disclosure in the audit report.
The RCM should be updated at least annually — and whenever there are significant changes to business processes, the control environment, the organisation structure, or the applicable regulatory requirements. An outdated RCM that does not reflect actual processes provides false assurance and may result in adverse IFC findings.
Yes — and this is one of its most valuable uses. A risk-based internal audit plan derived from the RCM prioritises audit coverage on the processes and controls with the highest residual risk. This ensures the internal audit programme focuses where assurance is most needed, rather than rotating through processes on an arbitrary schedule.

Map your risks to your controls — clearly and completely.

Talk to our team about designing or updating your Risk Control Matrix for IFC reporting, internal audit, and management assurance.