Risk & Control Matrix (RCM) Templates

#Audit / Unit NameDescription / ScopeContext
12nd Line Operational Risk GovernanceEvaluate oversight roles, risk committees, and second-line monitoring of OR eventsFinance – ensures robust second-line structure and risk coordination
22nd Line Operational Risk – Control TestingAssess test plans, sampling, and second-line validation of key operational controlsFinance – focuses on second-line’s day-to-day control testing efforts
3Enterprise Risk Management (ERM) StrategyVerify board-approved ERM policy alignment with strategic goals, risk appetite coverageFinance – foundation for integrated risk approach across the institution
4ERM Emerging Risk & Scenario AnalysisConfirm processes for identifying emerging risks (geopolitical, cyber, climate), scenario design, and escalationFinance – forward-looking risk management helps strategic planning
5Risk Appetite Setting & CascadeCheck how top-level risk appetite statements translate into business-line-level limits, triggers, and MISFinance – ensures risk appetite is cascaded effectively to all lines
6Risk Oversight & Escalation ChannelsValidate the escalation matrix for risk events/incidents, near misses, and threshold breachesFinance – timely reporting to committees or board prevents major losses
7Interest Rate Risk – Trading BookEvaluate IRR metrics for short-term trading positions, VaR approach, limit structures, and backtestingFinance – specialized for treasury trading desks subject to interest rate fluctuations
8Interest Rate Risk – Banking Book Sub-SegmentsBreak down IRRBB by product segments (mortgages, consumer loans, corporate loans) for tailored stress testingFinance – deeper line-of-business segmentation of interest rate risk
9Asset-Liability Management (ALM) – Derivatives UsageAssess derivative strategies for hedging ALM mismatches, hedge documentation, and compliance with accounting rulesFinance – advanced ALM function with derivatives for stabilizing balance sheet
10ALM Governance & Limit ManagementCheck ALM committee structures, limit approvals, monthly ALCO packs, and policy reviewsFinance – core oversight ensuring consistent ALM strategy
11Treasury Liquidity – Cash Flow ForecastingEvaluate liquidity projections, day-to-day variance analysis, and short-term funding approachFinance – critical for meeting short-term obligations
12Treasury Liquidity – Stress Testing & Contingency PlansInspect stress scenario design, LCR/NSFR calculations, and funding contingency planningFinance – essential for Basel III or similar liquidity regulations
13Senior Management & Board Reporting – Data ValidationConfirm data accuracy, completeness, and lineage for board pack metrics (KRI, KPI, capital, liquidity)Finance – ensures top-level decisions rely on robust data
14Senior Management & Board Reporting – Timeliness & FormatReview production timelines, distribution lists, and user-friendliness (dashboards, trend visuals)Finance – ensures quick, clear insights to leadership
15Model Risk Management – Risk Models LibraryAudit the inventory, classification, and periodic reviews of PD, LGD, EAD, liquidity, and pricing modelsFinance – advanced quantitative risk environment (banking, insurance)
16Model Risk – Validation & Stress Model GovernanceCheck validation approach, independence, re-calibration frequency, documentation for scenario modelsFinance – advanced risk quant governance
17Credit Risk – Retail Lending ChannelsSeparate audits for credit cards, auto loans, mortgages – evaluate underwriting, scoring, portfolio performanceFinance – deeper, specialized approach to each retail product
18Credit Risk – Corporate & Commercial PortfoliosAssess credit facility structures, covenant tracking, watchlist processes, sector concentration oversightFinance – large-exposure and corporate-level lending risk
19Credit Risk – Specialized Lending (Project Finance, etc.)Focus on project finance, leveraged finance, real estate developments – check due diligence, stress assumptionsFinance – high-profile, high-risk lending segments
20Capital Adequacy – Pillar 1 & Pillar 2 ProcessesEvaluate RWA calculations, ICAAP documentation, capital planning horizon, and stress test alignmentsFinance – compliance with regulatory capital frameworks
21Financial Reporting – IFRS 9/CECL ProvisioningInspect expected credit loss models, staging criteria, macro overlays, disclosure correctnessFinance – ensures correct provisioning in line with IFRS 9 or CECL (US GAAP)
22Financial Reporting – Consolidation & IntercompanyCheck group consolidation, minority interests, eliminations of intercompany transactions, currency translationsFinance – crucial for multi-entity correctness
23SOX / ICFR – Process-Specific ControlsDrill-down audits for procure-to-pay, order-to-cash, record-to-report cycles with control testingFinance – ensures each major process has robust financial controls
24Accounts Payable – Vendor Setup & Invoice ApprovalEvaluate vendor onboarding, invoice matching (3-way), duplicates, and payment runsFinance – addresses a high-risk area for fraud and errors
25Accounts Payable – Expense ReimbursementsSpecifically target T&E claims, policy compliance, receipt matching, out-of-policy claimsFinance – potential leakages and misuse in T&E
26Revenue Recognition – Subscription/Recurring ModelsConfirm revenue recognition rules for subscription services, deferral of revenues, discount/promotion accuracyFinance – modern business models need careful revenue deferral
27Revenue Recognition – Project-Based BillingInspect milestone-based or percentage-of-completion revenue, contract terms, change orders, WIPFinance – ensures correct POC or milestone-based approach
28Fixed Assets & CAPEX – Project ApprovalsCheck capital request gating, ROI analyses, budget vs. actual trackingFinance – large-scale CAPEX often needs robust oversight
29Fixed Assets – Disposal & Write-Off ProcessFocus on disposal authorizations, gain/loss calculations, asset retirement obligationsFinance – ensures no unaccounted assets or undervalued write-offs
30Tax Compliance – Transfer Pricing ImplementationVerify transfer pricing policies, intercompany margins, local file documentation, and Master File complianceFinance – multinational tax environment
31Tax Compliance – Indirect Taxes (VAT, GST)Inspect transaction-level compliance, input credit reconciliation, cross-border complexitiesFinance – critical for consumer-facing or cross-border business
32Hedge Accounting – Documentation & TestingConfirm formal hedge designations, hedge effectiveness testing results, rebalancing of hedge relationshipsFinance – specialized IFRS 9 or US GAAP hedge accounting rules
33Treasury – FX Exposure & HedgingEvaluate identification of FX exposures, forward contract usage, revaluation, limit monitoringFinance – ensures no large unhedged currency mismatches
34Mortgage Servicing – Escrow & Insurance TrackingFocus on escrow collection accuracy, timely insurance renewals, escrow analysis statements to borrowersFinance – compliance for mortgage servicers
35Factory/Plant Safety Audit – Production LinesAssess PPE usage, safety training logs, hazard identification, and incident trackingNon-finance – essential for manufacturing or industrial settings
36HR – Payroll & Compensation AuditValidate payroll runs, timesheet approvals, commission or bonus structures, tax withholdingsNon-finance – a universal HR function but critical to cost and compliance
37HR – Recruitment & Onboarding ProcessCheck job requisition approvals, background checks, orientation programs, new-hire documentationNon-finance – ensures correct workforce intake approach
38HR – Offboarding & Termination ControlsEnsure exit interviews, system access removal, final payments, knowledge transferNon-finance – prevents security risk from ex-employees and handles final pay
39HR – Performance Management & PromotionsEvaluate performance appraisal consistency, promotion criteria, pay adjustments, documentationNon-finance – ensures fairness and transparency in promotions
40Data Privacy & GDPR – Subject Access Request HandlingInspect process for responding to data subject requests (access, erasure, rectification)Non-finance – specialized data protection domain
41Data Privacy & GDPR – Consent ManagementCheck if user consent for data usage is captured, tracked, and revocation is managed properlyNon-finance – compliance for marketing, data analytics, or e-commerce
42IT General Controls – Identity & Access Management (IAM)Evaluate user provisioning, role-based access controls, termination revocation, privileged account monitoringNon-finance – universal for secure IT environment
43ITGC – Change Management ProcessCheck developer access, code merging, test environments, and emergency changes for system updatesNon-finance – ensures stable production environment
44ITGC – Backup & Disaster RecoveryReview backup schedules, storage encryption, DR site readiness, annual DR testingNon-finance – essential for operational resilience
45IT Application Controls – Core ERP SystemInspect data input validations, business rules, interface reconciliations, role-based approvals in the ERPFinance or non-finance – depends on ERP modules but typically includes finance data
46Cybersecurity – Network Perimeter & Firewall ConfigValidate firewall rule reviews, network segmentation, intrusion detection usage, patching of perimeter devicesNon-finance but vital to mitigate cyber threats
47Cybersecurity – Ransomware PreparednessCheck anti-ransomware tools, offline backups, incident response runs, privileged account minimizationNon-finance domain focusing on modern cyber threat
48Business Continuity – Pandemic ReadinessAssess the continuity plan for pandemics, remote work capabilities, staff shortage scenariosNon-finance – real-world scenario planning
49Third-Party Vendor Mgmt – Contract LifecycleEvaluate RFPs, vendor onboarding checks, contract SLAs, renewal triggers, vendor risk classificationNon-finance – supply chain or outsourcing environment
50Third-Party Vendor Mgmt – Onsite AssessmentsCheck if high-risk vendors undergo onsite or virtual audits, security checks, continuity provisionsNon-finance – deeper vendor oversight
51Audit Analytics & CAATs (Computer-Assisted Audit Techniques)Confirm usage of data analytics in audits, continuous monitoring scripts, tool governanceFinance or non-finance – modernizing the audit approach
52Fraud Risk Assessment – Financial TransactionsInspect fraud risk frameworks, anomalies in AP, AR, T&E, suspicious patterns, whistleblower hotline follow-upsFinance – targeted at potential internal/external fraud
53Fraud Risk Assessment – Non-Financial AreasEvaluate inventory theft risk, collusion in procurement, false vendor schemes, intangible asset misappropriationNon-finance – broad-based fraud detection beyond financial statements
54AML (Anti-Money Laundering) – KYC & CDDCheck know-your-customer, customer due diligence processes, watchlist screening, and suspicious activity reportingFinance – regulated banks or money service businesses
55AML – Transaction Monitoring SystemsValidate effectiveness of AML transaction monitoring software, detection thresholds, false positive handlingFinance – ensures robust monitoring for money laundering patterns
56Sanctions Compliance – OFAC/UN/EUInspect screening processes for sanctioned individuals/entities, blocked property management, escalation channelsFinance – critical for global banks operating across multiple jurisdictions
57Corporate Card & Purchasing Card (P-Card) ProgramCheck issuance policy, transaction monitoring, monthly statement reviews, misuse detectionFinance – a potential area for expense abuse, usually part of T&E or procurement function
58Treasury – Intercompany Loans & Cash PoolingEvaluate cross-entity lending rates, approvals, pooling structures, and netting arrangementsFinance – ensures compliant, arm’s-length intercompany funding
59Mortgage Underwriting – Specialized Lending (FHA/VA etc.)Evaluate compliance with government-insured loan guidelines, additional disclosures, adherence to LTV/DTI rulesFinance – more granular approach to mortgage specifics
60Pension & Benefits Fund OversightInspect funding status, investment strategies, benefit disbursement controls for employee pension or 401(k) plansFinance – ensures employee benefit obligations are properly managed
61HR – Succession Planning & Talent ManagementCheck leadership pipeline identification, training programs, high-potential staff trackingNon-finance – crucial for organizational continuity
62HR – Diversity & Inclusion InitiativesAssess D&I policies, representation metrics, pay equity analysis, and action plans for improvementNon-finance – corporate culture and social responsibility
63HR – Workforce Planning & ForecastingEvaluate forecasting of staffing needs, budget vs. actual headcount tracking, contingent workforce usageNon-finance – strategic approach to ensuring the right skill sets
64Health & Safety – Chemical Handling & StorageFor labs or manufacturing, verify MSDS usage, chemical inventory logs, proper disposal methodsNon-finance – specialized EHS domain
65Health & Safety – Personal Protective Equipment (PPE)Inspect availability, training, and enforcement of PPE requirements for hazardous worksitesNon-finance – workplace safety compliance
66Environment – Carbon Footprint & Emissions TrackingCheck greenhouse gas inventory, emission factors, offset strategies, external reportingNon-finance – part of ESG initiatives
67Environment – Waste Management & RecyclingValidate disposal vendors, recycling policies, e-waste handling, hazardous waste logsNon-finance – key for manufacturing, labs, or large campuses
68IT Governance – Strategy & RoadmapEvaluate IT steering committee, alignment of IT projects with corporate strategy, ROI metricsNon-finance – ensures strategic alignment of IT investments
69ITGC – Patch Management & Vulnerability ScanningInspect patch cycle timeliness, vulnerability scanning results, remediation processesNon-finance – crucial for security hygiene
70Cloud Governance – Multi-Cloud StrategyCheck cloud vendor selection, cost optimization, deployment consistency, key risk acceptanceNon-finance – advanced cloud usage
71Cybersecurity – Identity Federation & SSOEvaluate single sign-on solutions, SAML/OAuth, role-based provisioning, multifactor enforcementNon-finance – user-friendly but needs robust security
72Cybersecurity – Penetration Testing ProgramConfirm scope of pentests, vendor qualifications, remediation tracking, and retestingNon-finance – advanced security approach
73BCP/DR – Crisis Communication & Stakeholder EngagementAssess crisis messaging templates, contact trees, media handling, management escalation for major disruptionsNon-finance – critical for brand and operational resilience
74Logistics – Warehouse Automation & RoboticsVerify control over automated picking, sorting systems, error handling logs, and maintenance schedulesNon-finance – advanced supply chain technology domain
75Fleet Management – Telematics & GPS MonitoringCheck route optimization, driver performance data usage, mileage recording, potential privacy concernsNon-finance – transport domain with data analytics aspect
76Customer Service – Omnichannel & EscalationInspect chat, email, phone, social media complaint resolution, system integrations, escalation triggersNon-finance – brand reputation and customer satisfaction
77Marketing – Digital Advertising & PPCEvaluate spend tracking, ROI analysis, compliance with ad platforms’ guidelines (e.g., Google Ads)Non-finance – cost management in marketing campaigns
78Marketing – Affiliate & Partnership ProgramsCheck contract terms, affiliate performance monitoring, commission payouts, potential brand riskNon-finance – ensures legit affiliates, prevents brand or reputational risk
79Product Development – Agile Scrum ProcessAssess sprint planning, backlog prioritization, daily standups, sprint retros, DevOps integrationNon-finance – relevant to software or product teams
80R&D – Intellectual Property (Patents & Trademarks)Inspect patent filing processes, trademark usage monitoring, external counsel coordinationNon-finance – crucial for IP-driven industries
81Social Media – Crisis Handling & Rapid ResponseEvaluate how social media teams handle viral negative events, disclaimers, brand guidelines, escalation to PRNon-finance – modern brand protection
82Legal & Regulatory – Litigation ManagementReview legal case tracking, outside counsel fees, settlement approvals, e-discovery approachNon-finance – corporate legal function oversight
83Procurement – Strategic Sourcing & Vendor NegotiationsInspect advanced sourcing strategies, vendor negotiations, cost-saving initiativesNon-finance – major cost center, potential for big savings or corruption
84Procurement – Contract Compliance (Post-Award)Validate vendor performance vs. contract terms, penalty clauses, service-level achievementsNon-finance – ensures vendor accountability
85Facilities – Fire & Emergency SystemsCheck fire alarm systems, sprinkler coverage, evacuation routes, periodic drillsNon-finance – critical EHS domain
86Facility Management – Energy Efficiency & Green BuildingEvaluate building automation systems, LEED or similar certifications, ROI on energy-saving upgradesNon-finance – cost saving, ESG synergy
87Travel & Expense Management – Policy AdherenceInspect flight/hotel booking compliance, meal allowances, out-of-policy approvals, traveler safetyNon-finance – broad T&E domain, complements finance AP audits
88Government & Public Sector Grants AuditFor public entities, confirm awarding of grants, compliance with usage restrictions, reporting obligationsNon-finance – specifically for government or nonprofit sectors
89Nonprofit – Program Effectiveness & OutcomesEvaluate if donations/funds are used effectively per mission, outcome measurement, overhead ratioNon-finance – philanthropic or NGO context
90Education – Student Data Privacy & FERPA ComplianceCheck student record confidentiality, access logs, parental consent for disclosuresNon-finance – specialized for academic institutions
91Education – Research Grants & FundingInspect grant writing, milestone tracking, resource allocation, compliance with federal or philanthropic funding constraintsNon-finance – ensures accountability in higher education research projects
92Healthcare – HIPAA Privacy & SecurityValidate patient health info protection, HIPAA access logs, breach notification proceduresNon-finance – healthcare domain with strict privacy rules
93Healthcare – Billing & Coding AccuracyCheck coding guidelines (ICD, CPT), claim submission processes, denial management, upcoding risksNon-finance – healthcare revenue cycle management
94Pharma – Clinical Trial ComplianceAssess trial protocols, subject consent, data integrity, adverse event reportingNon-finance – specialized R&D environment
95Pharma – Drug Safety & PharmacovigilanceEvaluate post-marketing surveillance for adverse drug reactions, signal detection, regulatory reportingNon-finance – ensures drug safety oversight for public health
96Agriculture & Food – Supply Chain TraceabilityInspect traceability from farm to fork, batch labeling, recall readinessNon-finance – critical for safety/quality in food supply chain
97Agriculture & Food – Quality Control & Testing LabsValidate in-house or outsourced testing labs, sampling frequency, contamination action plansNon-finance – ensures product safety and compliance with standards
98Automotive – Vehicle Recall & Warranty ManagementCheck recall processes, VIN tracking, warranty claim reviews, cost recovery from suppliersNon-finance – brand protection and regulatory compliance in auto industry
99Casino & Gaming Operations – Gaming Floor ControlsAssess chip/cash security, table game surveillance, machine payout verification, AML complianceNon-finance – specialized for gaming licensing and AML obligations
100Mining & Extractives – Environmental Impact & Permit ComplianceEvaluate permit adherence, reclamation plans, water usage, local community engagementNon-finance – high environmental and social impact domain