A practical risk control matrix template for Indian companies, with control owners, evidence, testing steps and examples for finance and compliance teams.
A weak control matrix can leave directors signing statements they cannot prove. Under Section 134(8) of the Companies Act, 2013, a company that defaults on the Board-report requirements can face a ₹3 lakh penalty, while every officer in default can face ₹50,000. The spreadsheet is not the legal requirement; the documented, working system behind it is what matters.
This guide gives Indian companies a copyable risk control matrix, or RCM, for translating financial and statutory risks into controls that can be owned, tested and evidenced. It is designed for founders, finance heads, compliance officers, company secretaries and CAs who need something more useful than “process followed” in an audit file.
Why Does an Indian Company Need a Risk Control Matrix?
A risk control matrix connects four things that are often kept in separate files:
- What could go wrong?
- Which control should prevent or detect it?
- Who performs the control, and how often?
- What evidence proves that the control operated?
Section 134(5)(e) of the Companies Act, 2013 requires a listed company’s Directors’ Responsibility Statement to address whether internal financial controls were adequate and operating effectively. Its explanation covers orderly business, policy adherence, asset protection, fraud and error prevention, accurate records, and timely financial information. Section 134(5)(f) separately addresses proper systems for compliance with applicable laws. The current Companies Act text on India Code is the primary reference.
Section 143(3)(i) requires the statutory auditor’s report to address whether the company has adequate internal financial controls with reference to financial statements and whether those controls operated effectively, subject to applicable exemptions and notifications. A company should confirm its precise reporting position with its statutory auditor; it should not treat an exemption from one reporting clause as permission to run uncontrolled processes.
Listed entities carry an additional obligation. Regulation 17(8) of the Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015 requires the CEO and CFO to give the Board the certificate in Part B of Schedule II. It covers financial statements, illegal or fraudulent transactions, internal controls and deficiencies. Check the latest text on the SEBI LODR regulations page.
An RCM gives management and auditors a traceable route from each material risk to the evidence. It does not, by itself, prove effectiveness. A beautifully coloured spreadsheet supported by no invoices, approvals, reconciliations or test results is decoration.
Copy This Risk Control Matrix Template into Excel or Sheets
Use one row for one control. If a risk needs a maker-checker approval and a monthly reconciliation, create two rows. Combining both into “management review” makes testing vague and exceptions easy to hide.
Field | What to record
RCM ID | Stable code such as P2P-01 or TAX-04
Legal entity and location | Company, branch, factory, warehouse or state covered
Process and subprocess | Procure-to-pay, payroll, GST, revenue, inventory, ROC or treasury
Risk statement | Specific event that could cause error, fraud, loss or non-compliance
Legal or policy source | Act, section, rule, notification, licence condition or approved policy
Account or obligation affected | Ledger balance, disclosure, return, licence, register or payment
Control objective | The result the control must achieve
Control activity | Exact steps performed, including review criteria
Control type | Preventive or detective; manual, automated or IT-dependent
Frequency or trigger | Per transaction, daily, monthly, quarterly, annual or event-based
Control owner | Named role accountable for performance
Reviewer | Independent role that checks the work, where required
Evidence retained | Report, approval, log, challan, acknowledgement or signed checklist
Key control? | Yes if failure could create a material or serious exposure
Test procedure | Inspection, reperformance, observation or system configuration check
Sample and period | Population, sample size and dates tested
Test result | Effective, exception found, not operated or not tested
Deficiency rating | Low, moderate, significant or material, using approved criteria
Remediation owner and date | Person responsible and committed completion date
Last updated | Date, editor and reason for change
This structure follows the substance of the Institute of Chartered Accountants of India’s guidance. ICAI says an RCM can capture risks, affected account balances, financial-statement assertions, controls, control frequency, responsibility for testing and reporting, and documents that evidence performance. See ICAI’s Guidance Note on Audit of Internal Financial Controls over Financial Reporting.
What Do Completed RCM Rows Look Like?
The examples below show the level of detail required. They are illustrations, not a substitute for testing applicability against the latest central, state and sector rules.
Process | Risk | Control activity | Frequency | Owner | Evidence
Vendor master | Employee creates a fictitious vendor and diverts payment | A user independent of vendor creation verifies PAN, bank proof and approval against the onboarding request before activation | Per vendor | Finance controller | Request, verification record, system approval log
Procure-to-pay | Invoice is paid twice | ERP blocks duplicate vendor-invoice-number combinations; accounts payable reviews the weekly duplicate-payment exception report | Per transaction and weekly | AP manager | System configuration and signed exception report
GST input tax credit | Credit is claimed without satisfying documentary or receipt conditions | Tax team reconciles purchase register, valid tax documents and receipt records before the return is approved | Monthly | Indirect tax lead | Reconciliation, exception closure and approval
ROC annual return | Annual return is filed after the statutory period | Company secretary maintains an AGM-linked filing calendar; CFO reviews filing acknowledgement before closure | Annual | Company secretary | Board-approved calendar and MCA acknowledgement
Payroll | Unauthorised employee or bank change reaches payroll | HR initiates changes; payroll maker validates support; separate approver releases the bank file | Each payroll run | Payroll manager | Change report, approval log and bank-file release record
Inventory | Stock loss is hidden by book adjustments | Team independent of custody performs cycle counts; controller reviews differences above the approved threshold | Monthly | Plant finance head | Count sheets, variance report and approved adjustments
The ROC row should separate obligations. Section 92(4) generally requires filing the annual return within 60 days of the annual general meeting. Under Section 92(5), delay attracts ₹10,000 plus ₹100 per continuing day, capped at ₹2 lakh for the company and ₹50,000 for an officer in default. Financial statements are separately due, usually within 30 days of the AGM under Section 137.
How Do You Build an RCM That Auditors Can Actually Test?
1. Fix the scope before listing controls
Define the entities, locations, period, processes and applications in scope. Record exclusions. For financial controls, start with material accounts, disclosures and fraud risks. For statutory compliance, start with triggers such as entity type, turnover, employee count, activity, state and licences.
2. Write risks as events, not labels
“GST risk” cannot be tested. “Input tax credit is claimed on blocked expenditure” identifies a failure. “Vendor payment risk” is equally weak; “payment is released to an unapproved bank account” tells the reader which control is needed.
Use: Because of [cause], [event] may occur, resulting in [consequence]. Include both legal and business consequences.
3. Map each risk to an assertion or obligation
Financial RCMs use assertions such as existence, completeness, accuracy, valuation, cut-off and presentation. A statutory RCM maps to an obligation: file, pay, renew, display, train, inspect or report. Record the full law, provision, jurisdiction and version date.
4. Describe the control so another person can repeat it
“CFO reviews monthly” says almost nothing. State which report is reviewed, what the reviewer compares, the threshold for investigation, how exceptions are resolved and where approval is retained.
A testable description reads: “Within five working days of month-end, the financial controller compares the bank reconciliation’s unmatched items with the prior month, investigates items older than 30 days and signs the locked report after all items above ₹1 lakh have a documented action.” The thresholds should reflect the company’s materiality and policy; they are not statutory amounts.
5. Classify controls without confusing the labels
A preventive control stops an error, such as an access restriction or approval limit. A detective control finds one, such as a reconciliation. For an IT-dependent manual control, also test whether the system report is complete and accurate; a screenshot alone does not prove that.
6. Identify the key controls
Mark a control as key when its failure could allow a material misstatement, significant fraud or serious legal breach and no reliable backup reduces the risk. Labelling everything “key” only creates an expensive testing programme.
7. Agree the evidence before the control operates
Evidence must show who performed the control, when, what was reviewed, which exceptions arose and how they closed. Retain logs, approvals, reconciliations and acknowledgements for the period applicable under the relevant law and policy; there is no universal retention period.
8. Obtain process-owner sign-off
Each process owner should confirm that the description matches reality. A control copied from an audit template is not an existing control until the company actually performs it.
How Should You Test Controls and Record Failures?
Test both design and operation. Design asks whether the control, if performed as written, would address the risk. Operating effectiveness asks whether it actually ran consistently, by an authorised person, with appropriate evidence.
Use four common test methods:
- Inspection: Examine approvals, reconciliations, logs or filing receipts.
- Observation: Watch a control being performed, while recognising that behaviour may change when observed.
- Reperformance: Independently repeat the reconciliation, calculation or report filter.
- Inquiry: Ask the owner how the process works. Inquiry alone is rarely enough.
For recurring controls, define the population before choosing samples. Record the period, population count, selection method and items tested. If one sample fails, investigate the cause and determine whether the failure is isolated or systemic. Do not quietly replace it with another sample until the file looks clean.
Rate deficiencies using criteria approved by management and aligned with the audit approach. Capture the failed control, affected period, exposure, compensating controls, immediate containment, root cause, remediation owner and target date. Retest after remediation; “closed by owner” is not independent evidence.
What Review Calendar Keeps the Matrix Current?
An RCM becomes stale when regulations, people or systems change. Use this minimum cycle:
- Monthly: Owners perform monthly controls and clear exceptions.
- Quarterly: Process heads review overdue evidence, failed controls and remediation.
- Half-yearly: Compliance and finance reassess key controls, access rights and major legal changes.
- Annually: Management refreshes scope, risks, materiality and control ownership before the statutory audit cycle.
- Event-based: Update immediately after a new law, threshold crossing, acquisition, new state, new factory, ERP change, fraud, notice or major audit finding.
For listed entities, align the timetable with Regulation 17(8) certification and Board or Audit Committee reporting. For other companies, align it with the Board-report, statutory audit, internal audit and secretarial audit calendar that applies to the entity.
Which RCM Mistakes Create False Comfort?
- One risk mapped to ten vague controls: Keep only controls that directly reduce the risk.
- Department names as owners: “Finance” is not accountable. Use a role such as financial controller.
- No distinction between performer and reviewer: A maker approving their own work defeats the control.
- Evidence created after the audit request: Contemporaneous evidence is stronger than a retrospective memo.
- Old legal citations: Record the notification or version date and review when rules change.
- Controls that exist only on paper: Walk through one real transaction before accepting the row.
- No system-report validation: Test source, filters, access and completeness for reports used in controls.
- Exceptions marked closed without retesting: Require independent confirmation that the repaired control works.
The goal is not a larger spreadsheet. It is fewer, clearer controls that reduce important risks and leave evidence a reviewer can follow.
Frequently Asked Questions
Is a risk control matrix mandatory under the Companies Act?
The Act does not prescribe a spreadsheet called an RCM. Sections 134 and 143 create responsibilities and reporting requirements around compliance systems and internal financial controls. An RCM is a practical way to document risks, controls, ownership, evidence and testing.
Is an RCM only for listed companies?
No. Listed companies face specific Board and SEBI requirements, but private and unlisted companies also benefit from controlled payments, reliable reporting and documented statutory compliance. Applicability of each legal reporting clause and exemption must be checked for the company.
What is the difference between an RCM and a risk register?
A risk register prioritises risks, owners and treatment plans. An RCM goes deeper into the control activity, frequency, evidence and testing. A company may link the high-level risk ID in its register to several detailed RCM rows.
Can one control address several risks?
Yes, if it genuinely addresses each risk. List the linked risks and test the full purpose. Do not assume that a monthly management review covers every risk merely because senior management attends it.
How often should an RCM be updated?
Review it at least annually and whenever a law, process, system, entity, location or key person changes. Control performance and exceptions should be monitored at the frequency stated in each row.
Can a company maintain the RCM in Excel?
Yes. Excel or Google Sheets is sufficient for a smaller company if edit access, version history, ownership and evidence links are controlled. As entities, locations and obligations grow, a dedicated system reduces duplicate files and missed change updates.
Who should own the master RCM?
One coordinating function, often finance controls, internal audit, risk or compliance, should own the structure and review cycle. Individual process owners remain accountable for performing controls and retaining evidence.
Turn the Template into a Living Compliance System
A risk control matrix template works only when every important row has a specific risk, one accountable owner, timely evidence and a test result. Start with the processes that can stop cash, licences, reporting or operations. Test a small set properly before expanding the file.
The harder problem is keeping the legal-source and review-trigger columns current across central, state, municipal and sector regulators. Check your compliance posture free at complianceradar.in to identify which obligations apply to your business and build a control calendar around them.
This article is general operational guidance, not legal or audit advice. Confirm applicability, exemptions and current amended law with a qualified professional for your company.