GRC & transformation
A future-state process, turned into risks, controls, and audit evidence
For Governance / GRC / SOX roles
A regulated finance process (procure-to-pay) is being redesigned. Change the process and you change the risks, the controls, the policy, and the evidence around it. Here is how I keep all of it aligned instead of finding the gaps in an audit.
The control lives with the step, not in a binder
Every step in the process carries a risk. Every risk needs a control. Every control needs an owner, a frequency, and a piece of evidence an auditor can pull. That is the matrix, and it stays current because it is built as the process is.
- 5 stepsprocure-to-pay, future state
- 1 risk eachrated by impact and likelihood
- 1 control eachowner · frequency · evidence
The approach
Map the process, identify the risks, design the controls, then prove they work.
- 01 Map the processThe future-state flow, step by step, with every decision and approval point.
- 02 Identify the risksWhat can go wrong at each step; rate by impact and likelihood.
- 03 Design the controlsPreventive or detective, an owner, a frequency, and how each one is evidenced, all into a risk-control matrix.
- 04 Prove it worksControl test steps, evidence requirements, and a gap log routed to owners.
The risk-control matrix
Pick a step to see its risk, the control that covers it, who owns it, and what evidence proves it ran.
- Risk
- Spend committed with no budget or authority behind it
- Rating
- High impact · likely without a control
- Control
- System budget check + approval matrix by amount; over-threshold routes to a second approver
- Type
- Preventive · automated
- Owner
- Procurement operations
- Frequency
- Every requisition
- Evidence
- Approval log with approver, amount, and timestamp; monthly exception report of overrides
- Risk
- PO raised to an unapproved, duplicate, or dormant vendor
- Rating
- High impact · medium likelihood
- Control
- Vendor master validation before PO; new-vendor requests go through due diligence and a separate approver
- Type
- Preventive
- Owner
- Vendor master data team
- Frequency
- Every PO; vendor master reviewed quarterly
- Evidence
- Vendor onboarding file; quarterly vendor master review sign-off; PO-to-approved-vendor match report
- Risk
- Invoice paid for something never delivered
- Rating
- High impact · medium likelihood
- Control
- Goods receipt required before an invoice can post; services confirmed by the requester
- Type
- Preventive
- Owner
- Receiving / requisition owner
- Frequency
- Every receipt
- Evidence
- GR document linked to the PO; open-GR aging report reviewed monthly
- Risk
- Duplicate invoice or overpayment against the PO
- Rating
- Medium impact · likely at volume
- Control
- Three-way match (PO / receipt / invoice) with tolerance; duplicate-invoice block on vendor + number + amount
- Type
- Preventive · automated
- Owner
- Accounts payable
- Frequency
- Every invoice
- Evidence
- Match results and tolerance exceptions; blocked-duplicate log
- Risk
- Payment sent to changed or fraudulent bank details
- Rating
- High impact · low likelihood, high severity
- Control
- Bank-detail changes require callback verification and a second approver; payments over threshold dual-approved
- Type
- Preventive
- Owner
- Treasury / AP
- Frequency
- Every bank-detail change; every payment run
- Evidence
- Change request with verification note; payment-run approval record; monthly bank-change report
Prove it works
Each control gets a test and an evidence requirement. What does not pass goes on a gap log with an owner and a date, not a footnote.
Test. Sample N transactions per control per period; re-perform the control; confirm the evidence exists and is complete.
Pass. Evidence present, control operated as designed, exceptions explained.
Gap. Logged with the control, the finding, an owner, a remediation, and a target date; re-tested after the fix.
Reporting. Control health and open gaps roll up to the process owner and to audit on a cadence.
The result
When the process changes, the matrix changes with it, and the evidence is already there when the auditor arrives, because it was designed in, not reconstructed after.
A generic procure-to-pay scenario. The step-by-step risk and control design, the evidence mapping, and the gap-log discipline are how I actually do this work.
Open to a senior full-time role. Hiring brief →