CORAA
CORAA University / Internal audit working paper

Internal audit RCM builder

Generate a first-pass risk and control matrix across P2P, O2C, R2R, H2R, Inventory, Fixed Assets, Statutory Compliance, Treasury and ITGC. Export the RCM to Excel for fieldwork and PDF for review notes.

Engagement profile
Select cycles

Start with the risk scorer or open the internal audit resource hub.

How it works

An RCM links process risks to controls, then converts those controls into test procedures and evidence requests. It is the bridge between the approved internal audit scope and actual fieldwork.

This builder starts with common control points for core finance and operations cycles. The exported Excel should be tailored to the entity ERP, delegation matrix, prior findings, locations and approved SOW before testing begins.

Worked example

A company selects P2P, R2R, Statutory Compliance and ITGC for the first quarter internal audit.

Inputs
Selected cyclesP2P, R2R, Statutory Compliance, ITGC
Output formatExcel workbook plus PDF summary
Output
WorkpaperCycle-wise RCM with test and evidence columns
UseAssign tests, record sample basis and document reviewer notes

Common mistakes

Using a generic RCM without tailoring
The RCM must reflect the entity ERP, approval matrix, locations, volumes and known incidents.
Skipping evidence columns
A control without test and evidence requirements is not ready for fieldwork.
Treating the RCM as the report
The RCM documents testing. Observations and management responses still need separate evaluation and reporting.

Frequently asked questions

What is an internal audit RCM?+
An internal audit RCM is a risk and control matrix. It maps each process risk to the control that should address it, the test procedure, evidence requirement, test result and reviewer conclusion.
Should an RCM be prepared before fieldwork?+
Yes. The RCM should normally be prepared after scope finalisation and before fieldwork so sample selection, evidence requests and testing responsibilities are clear.
Can this RCM replace professional judgement?+
No. It is a starting workpaper. The internal auditor must tailor it to the approved scope, ERP, process design, legal context and risk assessment.

Authoritative sources

ICAI
ICAI IASB - Compendium of Standards on Internal AuditICAI lists the February 2026 Compendium as applicable from 1 April 2026.
MCA
Companies (Accounts) Rules, 2014 - Rule 13Rule 13(2) requires scope, functioning, periodicity and methodology to be formulated with the internal auditor.
Always confirm against the latest version of the source. Regulations evolve and amendments are common.
Related calculators
Internal audit risk scorerInternal audit SOW generatorInternal audit resources
Share this tool
Last reviewed: 2026-08-27 · For informational purposes only — not professional advice.