Free audit tool · IA QuickTools

A full risk & control matrix. Built in your browser. Seen by no one.

The RCM Workbench is a complete working matrix — risk register, control mapping, design- and operating-effectiveness test plans, an issues log with regulatory flags, and team hours — with a live residual-risk model underneath. No signup. No install. No server. Your data physically cannot leave this page.

  • 🔒 100% in-browser
  • No account
  • Free forever
  • CSV & JSON export
  • Dark mode
  • Focus mode

Works in every modern browser · happiest on a desktop

The Workbench · yours instantly — nothing to set up

Internal Audit Guide

Risk & Control Matrix Workbench

RCM Workbench v2 · internalauditguide.com · Tip: press F for distraction-free mode

Why auditors keep it open

More than a matrix. It’s the planning end of the audit.

“RCM” undersells it. Register, control matrix, DE/OE testing, issues log and team resourcing usually live in five different tabs of an expensive platform — here they’re one surface with a live model underneath, designed by someone who has actually cleared review notes.

Zero setup

Blank page to matrix in minutes

Nothing to configure, no manual to read. Open a worked example and reverse-engineer it, or start clean and add your first risk. References auto-number, and every control arrives with its own test plan already scaffolded.

The model

Scoring with judgment built in

Residual risk computes live from your control conclusions: key controls carry full weight, design and operation scale it, and assurance tiers discount likelihood — never impact. Disagree with the math? Override it. The override is flagged JDG and your rationale travels with the export. The model informs judgment; it never replaces it.

The craft

Small details, respected time

Global search across risks, controls and issues. Keyboard shortcuts. Undo on destructive actions, two-step deletes, an unsaved-changes guard. Autosave with a visible timestamp, sortable tables, board or table testing views, dark mode, a focus mode that hides the whole site — and print-clean output for the file.

The honest comparison

Feature for feature, this covers the planning core of platforms that cost tens of thousands a year.

Live residual modeling, structured DE/OE test plans, regulatory flagging, capacity tracking, clean exports — all in one place, all instant. To be fair to the big platforms: they earn their keep on multi-user workflow, system-enforced audit trail and hosted storage. But if what you need is the thinking surface — the place where the audit takes shape — you are looking at it, and it costs nothing.

The two worked examples pull double duty as teaching: a bank-style Treasury & Liquidity audit mid-fieldwork and the evergreen Procure-to-Pay cycle, written the way reviewers wish workpapers were written — risks as cause → event → consequence, controls properly weighted, tests concluded with evidence. Load one and you’re learning the tool and the craft at the same time.

Where it fits

Not here to replace your audit system. Unless you want it to.

There’s no license tier and no sales pitch behind this, so we can be honest about where it belongs. Four ways teams actually use it:

Companion

Alongside your GRC platform

AuditBoard, Archer, TeamMate, MetricStream — keep them. The Workbench is the thinking surface before the system of record: sketch the risk universe, shape coverage, draft the test plans, argue about residual ratings — then export clean CSVs that drop straight into your import templates. Nothing about it asks you to switch.

Replacement

The whole system, for a small shop

A two- or three-person audit function doesn’t need a six-figure platform to run a defensible RCM. Register, matrix, DE/OE testing, issues, hours — it’s all here, and JSON backups filed alongside your workpapers give you the audit trail. When you outgrow it, the CSVs come with you.

Learning

To learn — and to build the function

Standing up internal audit at a growing company, moving over from external, studying for the CIA? The methodology is explicit and inspectable, and the worked examples show what good looks like: risks written as cause → event → consequence, controls properly mapped, tests concluded with evidence.

Standalone

Completely on its own

One-off engagement, co-source gig, consulting project: open the page, build the matrix, export the file, erase everything on the way out. Nothing to procure, nothing to license, nothing to explain to IT — because nothing ever touched a server.

Private by architecture

There is no backend. That’s the feature.

0
servers behind the tool
0
accounts, logins, cookies-for-you
0
bytes of your work transmitted

An RCM names your weakest controls — it’s one of the most sensitive documents an audit team produces. So the Workbench is built the opposite way from a cloud app: everything you enter lives in your browser’s local storage, on your machine. There is no database behind this page, no login, no sync. A breach of ours could never expose your matrix, because we never have it. The page records an ordinary anonymous page view, like any article on this site; the content of your work never leaves your device.

That’s why it sits comfortably next to company policy. Restrictions on online tools exist because typical web apps transmit and store your input on someone else’s servers. This one transmits nothing — functionally it’s a spreadsheet on your laptop, not a cloud service. Your organization’s policy always governs, so if in doubt keep entries generic (R-001, role titles instead of names) and ask whoever owns the policy.

And don’t take our word for it — you’re an auditor. Open your browser’s developer tools, watch the Network tab while you work, and confirm that no request ever carries your entries. Independent verification is rather the point of the profession.

The trade-off: nobody can recover your work for you. Clearing browser data erases the matrix — download JSON backups from Data → Download backup and treat them like workpapers.

What’s inside

Everything the planning end of an audit needs.

Risk register & heatmap

5×5 inherent and residual scoring on a live heatmap you can click into. Filter by process, category, band or coverage gap; sort by whatever hurts most.

Control matrix

The working paper itself: every risk with its mapped controls, effectiveness glyphs, testing status and open issues, grouped by process. Coverage gaps surface themselves.

DE & OE testing

Per-control test plans — approach, samples, step checklists you tick off as evidence lands, budget vs. actual hours — on a kanban board or a table.

Issues log

Findings with severity, type, remediation owners and due dates — plus regulatory flags (SOX, MRA, MRIA, consent order) that roll up to the dashboard.

Team & hours

Assign testers and reviewers, set capacity, and watch load bars and unassigned-hours warnings before they become a resourcing conversation.

Exports & backups

One-click CSVs of the RCM, the test plan and the issues log — shaped for pivot tables and GRC import templates — plus a portable JSON backup of everything.

Three minutes

From blank page to working matrix.

  1. Open a worked example — Treasury & Liquidity Risk or Procure-to-Pay — to walk a realistic audit mid-fieldwork, or start blank. Either way you’re inside the tool in one click.
  2. Add risks first. Controls hang off risks, and a test plan is scaffolded automatically for every control you create. References number themselves.
  3. Rate design and operating effectiveness and watch residual risk recompute live. When the math disagrees with your judgment, override it — flagged JDG, rationale attached.
  4. Export. CSVs for Excel or your GRC platform, a JSON backup for your records — and press F anytime for a distraction-free full view.

The math

How the scoring works — in one breath.

Inherent risk is likelihood × impact on 5-point scales — a 1–25 score (Low 1–4 · Moderate 5–9 · High 10–15 · Critical 16–25). Each linked control contributes weight: full for key controls, half for non-key, scaled by its design and operating conclusions. The summed weight sets an assurance tier, and the tier discounts residual likelihood. Impact is deliberately never reduced — controls rarely change how bad an event would be, only how often it happens.

The full methodology, with exact weights and thresholds, is one click away under Methodology inside the tool — nothing about the math is a black box.

Questions auditors actually ask

Straight answers.

Is it really free? What’s the catch?

Really free — no trial, no tier, no email wall. The Workbench is how Internal Audit Guide shows its work; the site earns through its content, not through the tool.

Can this site see what I type?

No — verifiably. Everything lives in your browser’s local storage on your device. There is no server component and no account, so there is nothing on our side to read; the page records an ordinary anonymous page view, like any article. Check it yourself in your browser’s developer tools: no network request carries your entries. One honest caveat: we can only vouch for us. If you’re on a company-managed device, your organization’s own monitoring can see anything you do on that machine — with this tool or any other. What the Workbench guarantees is that it adds zero exposure of its own.

Does using it violate my company’s policy on online tools?

Policies restricting online tools usually target apps that transmit and store your input on third-party servers. The Workbench transmits nothing, which is why it’s generally compatible with such policies — but your organization’s policy always governs. When in doubt, keep entries generic (R-001, role titles) and ask whoever owns your data policy.

Can my team work on one matrix together?

Not simultaneously — there are no accounts, by design. The working pattern: one owner keeps the master copy, passes JSON backups around for input, and consolidates. For true multi-user collaboration, build the plan here, then move it into your GRC platform via the CSV exports.

Can I use it for SOX 404 scoping and testing?

Yes — it’s a planning surface, and SOX work fits it well: flag SOX-relevant risks and controls, record design and operating conclusions, build DE/OE test steps, and export the matrix into your SOX tool of record. SOX-flagged items roll up on the dashboard so regulatory exposure stays visible.

Which browsers work? What about my phone?

Any modern browser from roughly 2023 onward — Chrome, Edge, Firefox, Safari, desktop or tablet. Phones work too, but a control matrix is a wide document by nature, so the tool will gently suggest a bigger screen. Dark mode, a focus mode and a full-screen mode are built in (full screen isn’t available on iPhone — Apple doesn’t support it for web apps).

What happens if I clear my browser cache or use incognito?

Clearing site data erases the matrix, and private windows discard it when they close — that’s the flip side of nothing ever being uploaded. The tool reminds you to download JSON backups; treat them like workpapers and you can restore on any machine.

Keep learning

The Workbench pairs with the library.

Risk Management & ERM covers frameworks, risk appetite and the risk-and-control matrix itself; the RCM templates give you a downloadable starting point; What is COSO? supplies the control-framework backdrop. For after the fieldwork: tracking internal audit issues and issue validation. New to terms like DE and OE? Start with internal audit jargon explained — and find more free tools on IA QuickTools.

Workbench v2 — July 2026: dark mode and accent colours, focus and full-screen modes, keyboard shortcuts, safer deletes, an unsaved-changes guard, backup reminders, sortable tables and print-friendly views. Your existing work carries over untouched.