← All work

GRC & transformation

A future-state process, turned into risks, controls, and audit evidence

For Governance / GRC / SOX roles

A regulated finance process (procure-to-pay) is being redesigned. Change the process and you change the risks, the controls, the policy, and the evidence around it. Here is how I keep all of it aligned instead of finding the gaps in an audit.

The control lives with the step, not in a binder

Every step in the process carries a risk. Every risk needs a control. Every control needs an owner, a frequency, and a piece of evidence an auditor can pull. That is the matrix, and it stays current because it is built as the process is.

  • 5 stepsprocure-to-pay, future state
  • 1 risk eachrated by impact and likelihood
  • 1 control eachowner · frequency · evidence

The approach

Map the process, identify the risks, design the controls, then prove they work.

  1. 01 Map the processThe future-state flow, step by step, with every decision and approval point.
  2. 02 Identify the risksWhat can go wrong at each step; rate by impact and likelihood.
  3. 03 Design the controlsPreventive or detective, an owner, a frequency, and how each one is evidenced, all into a risk-control matrix.
  4. 04 Prove it worksControl test steps, evidence requirements, and a gap log routed to owners.

The risk-control matrix

Pick a step to see its risk, the control that covers it, who owns it, and what evidence proves it ran.

Risk
Spend committed with no budget or authority behind it
Rating
High impact · likely without a control
Control
System budget check + approval matrix by amount; over-threshold routes to a second approver
Type
Preventive · automated
Owner
Procurement operations
Frequency
Every requisition
Evidence
Approval log with approver, amount, and timestamp; monthly exception report of overrides

Prove it works

Each control gets a test and an evidence requirement. What does not pass goes on a gap log with an owner and a date, not a footnote.

Test. Sample N transactions per control per period; re-perform the control; confirm the evidence exists and is complete.

Pass. Evidence present, control operated as designed, exceptions explained.

Gap. Logged with the control, the finding, an owner, a remediation, and a target date; re-tested after the fix.

Reporting. Control health and open gaps roll up to the process owner and to audit on a cadence.

The result

When the process changes, the matrix changes with it, and the evidence is already there when the auditor arrives, because it was designed in, not reconstructed after.

  • Process modeling
  • Risk assessment
  • Controls design
  • SOX / audit-readiness
  • Evidence & testing

A generic procure-to-pay scenario. The step-by-step risk and control design, the evidence mapping, and the gap-log discipline are how I actually do this work.

Available now Looking for my next role.

Open to a senior full-time role. Hiring brief →