Skip to content
Specialized Audit · The Classic Partners LLP

Risk Control Matrix (RCM) Services

Process-level Risk Control Matrices that map every key risk to the control that mitigates it — built for Internal Financial Controls (IFC) reporting under Section 143(3)(i), internal audit scoping, and IPO or investor due-diligence readiness.

Quick answer

A Risk Control Matrix (RCM) is a structured document that lists, for each key financial or operational process, the risks that could lead to a material error or fraud, the controls in place to mitigate each risk, who owns the control, how often it operates, and whether it is preventive or detective. It is the working paper on which Internal Financial Controls (IFC) testing under Section 143(3)(i) of the Companies Act, SOX-style control assessments, and internal audit control testing are all built. The Classic Partners LLP builds and tests RCMs across your key processes — procurement-to-pay, order-to-cash, record-to-report, payroll and treasury — and documents the design and operating effectiveness of each control.

What we do

The control documentation your auditor, board and investors ask for

When your statutory auditor reports on Internal Financial Controls, when an internal audit function scopes its annual plan, or when an investor's due-diligence team asks "what controls do you actually have," the answer has to exist on paper — process by process, risk by risk. A Risk Control Matrix is that answer.

We build RCMs from scratch for companies that don't yet have documented controls, and we refresh existing RCMs where processes, systems or ownership have changed since the last update — followed by walk-throughs and sample-based testing of operating effectiveness.

  • Process-level risk identification (P2P, O2C, R2R, payroll, treasury)
  • Control objective, activity, type and frequency mapped per risk
  • Design effectiveness walk-throughs
  • Operating effectiveness sample testing
  • Gap register with remediation owner and target date
  • Ready-to-use input for IFC reporting and internal audit scoping
Where an RCM is used

Who needs a documented Risk Control Matrix

An RCM is not a standalone statutory filing — it's the evidence base behind several compliance and assurance requirements.

Use caseWhy an RCM is neededTypical requester
IFC reportingStatutory auditor must report on design and operating effectiveness of internal financial controls under Sec. 143(3)(i)Listed and certain unlisted companies
Internal audit scopingRisk-based internal audit plans are built on the highest-risk, weakest-control processes identified in the RCMCompanies with an internal audit function under Sec. 138
IPO / fundraise readinessInvestors and merchant bankers expect documented process controls as part of due diligenceCompanies preparing to raise capital or list
ERP / system implementationNew systems need controls re-mapped and tested before go-liveCompanies migrating to a new ERP or CBS
Group reporting standardsMNC subsidiaries reporting into a parent's global control frameworkIndian subsidiaries of foreign groups
Scope of work

What our RCM engagement covers

Each process is documented, walked through and tested — not just described.

RI

Risk Identification

Process-level risk workshops to identify financial reporting, fraud and operational risks specific to your business.

CM

Control Mapping

Every risk mapped to its control activity, control owner, frequency and type — preventive or detective, manual or system.

WT

Design Walk-throughs

Process walk-throughs to confirm controls are designed to actually address the risk they're meant to mitigate.

OE

Operating Effectiveness Testing

Sample-based testing across the period under review to confirm controls operated consistently, not just on paper.

GR

Gap Register

Design and operating gaps logged with severity, root cause, remediation owner and target closure date.

HO

Handover to Auditors

RCM and testing evidence formatted for direct use by your statutory auditor or internal audit function.

How we work

Our four-stage RCM process

Built to be reused every year, not redone from scratch.

1

Process mapping

Understand your key processes, systems and existing documentation to scope which processes need an RCM.

2

Risk & control documentation

Workshops with process owners to document risks and the controls that currently exist to mitigate them.

3

Testing

Walk-throughs for design effectiveness, then sample-based testing for operating effectiveness.

4

Reporting & handover

Gap register, remediation plan and a reusable RCM template handed over to your finance and audit teams.

Why The Classic Partners

RCMs your statutory auditor will actually accept

Built by the same team that signs IFC opinions — not a generic template exercise.

Auditor-ready output

RCMs formatted to directly support your statutory auditor's IFC testing and reporting.

Practical, not theoretical

Controls tested through real walk-throughs and samples, not a checklist filled from a template.

Fixed fee, written upfront

Scoping call, then a written quote covering all in-scope processes.

Reusable framework

The RCM is built to be refreshed annually, not rebuilt from zero each cycle.

Remediation follow-through

Gaps come with an owner and a target date, and we track closure at the next cycle.

One firm, all compliance

Works alongside our internal audit and statutory audit practices.

NS

Reviewed by CA Nainit Savla Founder & Lead Partner, The Classic Partners LLP — B.Com, Associate Chartered Accountant (ICAI), ex-KPMG Real Estate Advisory. Leads internal financial controls and risk advisory engagements.

FAQs

Risk Control Matrix questions CFOs ask us

Straight answers before you commission an RCM.

An RCM itself is not filed as a standalone statutory document. It's the working paper that supports statutory obligations that are mandatory — such as your auditor's report on Internal Financial Controls under Section 143(3)(i), and the risk-based scoping of an internal audit function under Section 138.
An SOP describes how a process should be performed. An RCM starts from the risks that could go wrong in that process and maps each one to the specific control that mitigates it, who owns it, and how it's tested — it's an audit and assurance document, not an operating manual.
Procurement-to-pay, order-to-cash, record-to-report, payroll and treasury are the processes most commonly prioritised, since they carry the highest risk of material misstatement or fraud and are the first areas an auditor or investor will ask about.
No — a well-built RCM is designed to be refreshed, not rebuilt. Each year we update it for process, system or ownership changes and re-test operating effectiveness, which is faster and less disruptive than starting from scratch.
Yes. We hand over the RCM in a format your internal audit function or finance team can maintain and test independently in future cycles, along with the testing methodology we used.

Ready to build your Risk Control Matrix?

Tell us which processes you want covered and why — IFC, internal audit or investor readiness. You'll get a fixed quote within one working day.

Scroll to Top