0% found this document useful (0 votes)
8 views6 pages

Process Risk Control Matrix Template

The document outlines a process risk control matrix template that categorizes controls into three groups: those currently in place, those in development, and those proposed. It includes sections for capturing control information, assessing inherent risks, and summarizing control levels. Additionally, users can modify control objectives and add extra ones as needed.

Uploaded by

Chinh Le Dinh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views6 pages

Process Risk Control Matrix Template

The document outlines a process risk control matrix template that categorizes controls into three groups: those currently in place, those in development, and those proposed. It includes sections for capturing control information, assessing inherent risks, and summarizing control levels. Additionally, users can modify control objectives and add extra ones as needed.

Uploaded by

Chinh Le Dinh
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd

Process risk control matrix

For a full description of this kind of risk-control matrix refer to the web page "Matrix
Mapping: the easiest and best way to map internal controls" at
[Link]/matrices.

In this template there are three distinct groups of controls: those already in place,
those agreed but not yet operating (i.e. in development), and those proposed but not
yet agreed on.

After each set of controls there are revised summaries of the level of control
provided.

Several columns are provided for capturing information about controls and you use,
ignore, or add to them as you wish.

The set of control objectives can also be changed, and you can even add extra ones
if you like.

Another refinement you could add is to insert an assessment of the inherent risk
involved with each step and each control objective. Then add more summary
formulae to study how the risk levels stack up to the control levels.
Sort Control group Control Control ID Ref to detail

CONTROLS CURRENTLY IN PLACE


1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc

Summary scores C
A
V
U

CONTROLS IN DEVELOPMENT
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc

Summary scores C
A
V
U

CONTROLS PROPOSED
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc

Summary scores C
A
V
U
xxxx
Perform-
Owner - Owner - To do Performance ance
operational development Frequency Sampling date evidence rating
Objectives Process steps

Development
Operation cost cost C A V U Step A Step B Step C Step D Step E

1 0 1 1 1 1 1
1 1 0 1 1 1 1

Summary scores 1 C 1 1 1 2 1
2 A 0 1 0 1 1
3 V 1 0 1 1 0
4 U 1 1 1 2 1

1 1 1 1 1 1
1 1 1 1 1 1 1

Summary scores C 2 2 2 3 2
A 1 2 1 2 2
V 2 1 2 2 1
U 2 2 2 3 2

1 1 1 1 1 1
1 1 1 1 1 1 1

Summary scores C 3 3 3 4 3
A 2 3 2 3 3
V 3 2 3 3 2
U 3 3 3 4 3
ps

Step F Step G

1
1

1 1
1 0
0 1
1 1

1
1

2 2
2 1
1 2
2 2

1
1

3 3
3 2
2 3
3 3

You might also like