Build a Risk-Control Matrix That Tests the Right Thing
Draft a risk-control matrix row with objective, risk, control, assertion, evidence, and test.
A junior auditor inherits an RCM where every test says "inspect evidence." The audit manager cannot tell whether the tests prove approvals, completeness, accuracy, or timely review. The internal audit skill is deciding what evidence would change a governance decision, not collecting comfort material. COSO objective-risk-control-evidence chain The weak RCM lists a control name and a generic procedure, but it never says which assertion the evidence supports. That creates review rework and can produce false assurance because the auditor may inspect documents that exist without proving they were timely, complete, accurate, or independently reviewed. Objective State the business objective in…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in