Risk Control Matrix (RCM) that maps risk to control, precisely.
Designing and implementing Risk Control Matrices that map business process risks to specific controls — providing the foundation for IFC/ICFR reporting, internal audit, and a defensible internal control framework.
Contact UsA Risk Control Matrix is the foundational document that maps each identified risk in a business process to the specific controls designed to mitigate that risk. It answers the three core questions of internal control: what can go wrong in this process, what control exists to prevent or detect it, and is that control working effectively? Without a well-designed RCM, internal audit has no structured basis, IFC/ICFR reporting has no documentation, and management has no clear view of its control landscape.
For listed companies and certain unlisted companies required to report on Internal Financial Controls over Financial Reporting, the RCM is not optional — it is the primary evidence base for the auditor's IFC opinion. For all other companies, it is one of the most practical tools available to management for understanding and managing operational and financial risk.
NDS Advisors designs and implements Risk Control Matrices from scratch or reviews and updates existing RCMs — across financial reporting processes, operational processes, IT general controls, and compliance processes. Our RCMs are practical, current, and designed to drive real assurance activity rather than sit in a drawer.
Our Risk Control Matrix (RCM) Services
RCM Design from Scratch
End-to-end design of a Risk Control Matrix for all key business processes — identifying risks, documenting controls, assigning control owners, and rating control effectiveness.
Existing RCM Review & Update
Review and update of an existing Risk Control Matrix — updating for process changes, new risks, regulatory developments, and audit findings.
IFC/ICFR Documentation
Design of the complete IFC/ICFR documentation suite — including process narratives, risk and control matrices, test of design, and test of effectiveness evidence.
Process Narrative Documentation
Preparation of process narratives describing how key business processes work — the precondition to identifying risks and mapping controls.
Control Testing Framework
Design of a control testing programme that uses the RCM to drive systematic testing of control design and operating effectiveness.
Control Deficiency Assessment
Assessment and classification of identified control gaps — distinguishing control deficiencies, significant deficiencies, and material weaknesses.
IT General Controls RCM
Risk and control mapping for IT general controls — covering access management, change management, computer operations, and data security.
Internal Audit Plan from RCM
Design of a risk-based internal audit plan derived from the RCM — ensuring the internal audit programme covers the highest-risk areas and key controls.
Our Process
Process Identification & Scoping
Identifying all in-scope business processes — financial reporting, operational, compliance, and IT — and agreeing on the prioritisation and scope of the RCM.
Process Walkthrough
Conducting structured walkthroughs of each in-scope process — documenting the flow of transactions, key decision points, and existing controls.
Risk Identification
Identifying all risks within each process — including fraud risks, error risks, compliance risks, and IT risks — mapped to financial statement assertions where applicable.
Control Mapping
Mapping each identified risk to one or more existing controls — documenting control description, control type, frequency, owner, and evidence of operation.
RCM Finalisation & Training
Finalising the RCM with control owners, training the internal audit and finance teams on its use, and embedding it into the ongoing audit and control monitoring cycle.
Why It Matters
Frequently Asked Questions
Map your risks to your controls — clearly and completely.
Talk to our team about designing or updating your Risk Control Matrix for IFC reporting, internal audit, and management assurance.