0% found this document useful (0 votes)
11 views14 pages

General Risk Control Matrix Template

This document provides a template for a general risk control matrix. The template allows mapping of risks to existing, in-development, and proposed controls. It includes space for two separate risk analyses and macros to synchronize the risks across sheets. The template is intended to help manage the many-to-many relationship between risks and controls and track control development and risk estimation over time.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views14 pages

General Risk Control Matrix Template

This document provides a template for a general risk control matrix. The template allows mapping of risks to existing, in-development, and proposed controls. It includes space for two separate risk analyses and macros to synchronize the risks across sheets. The template is intended to help manage the many-to-many relationship between risks and controls and track control development and risk estimation over time.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd

General risk control matrix

For a good introduction tof this kind of risk-control matrix refer to the web page
"Matrix Mapping: the easiest and best way to map internal controls" at
[Link]/matrices.
The main advantage of this style is that it allows you to cope, easily, with the
common situation of having a many:many relation between risks and controls.
This template has two features not described in that article.
First, in this template there are three distinct groups of controls: those already in
place, those agreed but not yet operating (i.e. in development), and those proposed
but not yet agreed on.
After each set of controls there are revised summaries of the level of control
provided.
Second, there is space for two risk analyses. There's no need to do two, but if
alternative perspectives could be useful there's no reason for not using both together
and mapping controls to both of them.
Furthermore, if you want to migrate from one risk analyis to another, having the
ability to show two during a changeover period might be very useful.
Several columns are provided for capturing information about controls and you can
use, ignore, or add to them as you wish.
One special feature of this design is that macros (on the buttons) bring the risks used
as headings in the Controls sheet into line with the risks in the risk analysis sheets.
Whenever you change a risk analysis use the appropriate button at the end to bring
the two back into agreement.
You need to decide what single metric of risk 'size' you will use and update the
headings to make clear what your choice is. I've just used the word 'size' as a place
holder.
When you add extra page headings and decoration please make sure you don't
insert any rows above the headings on any page, or insert columns into the risk
analysis pages. If you do, this will confuse the macro. To sort it out you could
change the relevant constants in the macro code, which are explained at the start of
module 1. If you don't know what I'm talking about, it's best to avoid inserting rows or
columns that will move any heading!
Please feel free to contact me with any queries or suggestions at
matthew@[Link]
Sort Control group Control Control ID Ref to detail
CONTROLS CURRENTLY IN PLACE
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc
CONTROLS IN DEVELOPMENT
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc
CONTROLS PROPOSED
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc
xxxx
Owner -
operational
Owner -
development Frequency Sampling
To do
date
Performance
evidence
Perform-
ance
rating
Risk ref r1.1 r1.2 r1.3 r1.4
ra1
Short
name r1 r2 r3 r4
Operation cost
Development
cost
risk
analysis 1 Size 10 20 30 40
Size after existing controls 10 20 30 40
Size after all agreed controls 10 20 30 40
Size after proposed controls 10 20 30 40
r1.5 Risk ref r2.1 r2.2 r2.3
r5 ra2
Short
name r1 r2 r3
50
risk
analysis 2 Size 10 100 10
50 Estimate of remaining risk 10 20 30
50 Estimate of remaining risk 10 20 30
50 Estimate of remaining risk 10 20 30
r2.4 r2.5
r4 r5
100 10
40 50
40 50
40 50
Ref Category
Sub-
category Short name Definition
Accountable
for risk
r1.1 r1 defin 1
r1.2 r2 defin 2
r1.3 r3 defin 3
r1.4 r4 defin 4
r1.5 r5 defin 5
Classification
Size with no
controls
Size with
existing
controls
Size with
controls in
development
too
Size with
proposed new
controls too
10 10 10 10
20 20 20 20
30 30 30 30
40 40 40 40
50 50 50 50
Ref Category
Sub-
category Short name Definition
Accountable
for risk
r2.1 r1 Defin 1
r2.2 r2 Defin 2
r2.3 r3 Defin 3
r2.4 r4 Defin 4
r2.5 r5 Defin 5
Classification
Size with no
controls
Size with
existing
controls
Size with
controls in
development
too
Size with
proposed new
controls too
10 10 10 10
100 20 20 20
10 30 30 30
100 40 40 40
10 50 50 50

You might also like