0% found this document useful (0 votes)
8 views16 pages

General Risk Control Matrix Template

This document provides a template for a risk control matrix that allows mapping of risks to both existing and proposed controls. It includes sections for risks and controls currently in place, those agreed but not yet implemented, and those proposed. The template also includes space to capture two different risk analyses and their impact on risk size before and after controls. Users can customize columns for control information and macros are included to sync risk listings between the risk analyses and controls sheets.

Uploaded by

Samer Abu-Awadh
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
8 views16 pages

General Risk Control Matrix Template

This document provides a template for a risk control matrix that allows mapping of risks to both existing and proposed controls. It includes sections for risks and controls currently in place, those agreed but not yet implemented, and those proposed. The template also includes space to capture two different risk analyses and their impact on risk size before and after controls. Users can customize columns for control information and macros are included to sync risk listings between the risk analyses and controls sheets.

Uploaded by

Samer Abu-Awadh
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as XLS, PDF, TXT or read online on Scribd

General risk control matrix

For a good introduction tof this kind of risk-control matrix refer to the web page
"Matrix Mapping: the easiest and best way to map internal controls" at
[Link]/matrices.

The main advantage of this style is that it allows you to cope, easily, with the
common situation of having a many:many relation between risks and controls.

This template has two features not described in that article.

First, in this template there are three distinct groups of controls: those already in
place, those agreed but not yet operating (i.e. in development), and those proposed
but not yet agreed on.

After each set of controls there are revised summaries of the level of control
provided.

Second, there is space for two risk analyses. There's no need to do two, but if
alternative perspectives could be useful there's no reason for not using both together
and mapping controls to both of them.

Furthermore, if you want to migrate from one risk analyis to another, having the
ability to show two during a changeover period might be very useful.

Several columns are provided for capturing information about controls and you can
use, ignore, or add to them as you wish.

One special feature of this design is that macros (on the buttons) bring the risks
used as headings in the Controls sheet into line with the risks in the risk analysis
sheets.

Whenever you change a risk analysis use the appropriate button at the end to bring
the two back into agreement.

You need to decide what single metric of risk 'size' you will use and update the
headings to make clear what your choice is. I've just used the word 'size' as a place
holder.

When you add extra page headings and decoration please make sure you don't
insert any rows above the headings on any page, or insert columns into the risk
analysis pages. If you do, this will confuse the macro. To sort it out you could
change the relevant constants in the macro code, which are explained at the start of
module 1. If you don't know what I'm talking about, it's best to avoid inserting rows
or columns that will move any heading!
Please feel free to contact me with any queries or suggestions at
matthew@[Link]
Sort Control group Control Control ID Ref to detail

CONTROLS CURRENTLY IN PLACE


1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc

CONTROLS IN DEVELOPMENT
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc

CONTROLS PROPOSED
1 Monitoring Business monitoring report: debtors m1
2 Monitoring Process monitoring report: process stats m2
etc etc etc
xxxx
Perform-
Owner - Owner - To do Performance ance
operational development Frequency Sampling date evidence rating
Risk ref r1.1 r1.2 r1.3 r1.4
Short
ra1 name r1 r2 r3 r4

Development risk
Operation cost cost analysis 1 Size 10 20 30 40

Size after existing controls 10 20 30 40

Size after all agreed controls 10 20 30 40

Size after proposed controls 10 20 30 40


r1.5 Risk ref r2.1 r2.2 r2.3
Short
r5 ra2 name r1 r2 r3

risk
50 analysis 2 Size 10 100 10

50 Estimate of remaining risk 10 20 30

50 Estimate of remaining risk 10 20 30

50 Estimate of remaining risk 10 20 30


r2.4 r2.5

r4 r5

100 10

40 50

40 50

40 50
Classification

Sub- Accountable
Ref Category category Short name Definition for risk
r1.1 r1 defin 1
r1.2 r2 defin 2
r1.3 r3 defin 3
r1.4 r4 defin 4
r1.5 r5 defin 5
Size with
Size with controls in Size with
Size with no existing development proposed new
controls controls too controls too
10 10 10 10
20 20 20 20
30 30 30 30
40 40 40 40
50 50 50 50
Classification

Sub- Accountable
Ref Category category Short name Definition for risk
r2.1 r1 Defin 1
r2.2 r2 Defin 2
r2.3 r3 Defin 3
r2.4 r4 Defin 4
r2.5 r5 Defin 5
Size with
Size with controls in Size with
Size with no existing development proposed new
controls controls too controls too
10 10 10 10
100 20 20 20
10 30 30 30
100 40 40 40
10 50 50 50

You might also like