ERM Controls & Metric Review

Evaluate risk controls for design AND operating effectiveness, map them to the risk register, review KRIs and KPIs against appetite thresholds, and produce a severity-ranked findings register - with a citation on every conclusion.

Banking / LendingCompliance Testing

A control-effectiveness and metric review that took risk and audit analysts days of manual cross-referencing across the control testing procedure, risk register, process maps, and metric dashboards - produced in minutes, with separate design and operating conclusions, metric breach flags, and a citation on every line

per control review

What it extracts

11 extraction fields

Review Scope Summary
A one-look roll-up of what is under review - the business line and products, the frameworks applied (COSO, Three Lines), the control testing procedure, risk register, process maps, and metric sources referenced, and the review period - so a reviewer can orient before the control and metric detail.
Control Inventory
The controls under review parsed into one row each, with a stable ID, objective, first-line owner, line of defense, control type (preventive/detective/corrective), nature (automated/manual/IT-dependent), frequency, products covered, system dependencies, and governing procedure.
Risk Register and Risk-to-Control Mapping
Each in-scope risk from the register mapped to the control(s) that mitigate it, with risk category, inherent and residual ratings, and a mapping-adequacy call; risks with no adequate control are flagged as gaps.
Control Design Assessment
Per control, whether it is adequately DESIGNED - the required What/Who/How/How Often elements present, its placement in the process map, and its frequency adequacy - judged from design and documentation, not test results.
Control Operating Effectiveness Assessment
Per control, whether it actually OPERATED effectively across the period - the test and its population, the results, and any bypasses, failures, overrides, or non-performance and whether they were remediated.
Control Effectiveness Rating
Design and operating conclusions combined into one effectiveness rating per control (Effective / Needs improvement / Ineffective) plus a deficiency-severity classification (deficiency / significant deficiency / material weakness).
KRI and KPI Metric and Threshold Review
The metric side of the review - each KRI/KPI/KCI compared to its appetite/tolerance threshold, placed in a Green/Amber/Red zone with a breach flag and trend, and the governance response owed on a breach.
Issues and Findings Register
The severity-ranked action list - one row per risk-coverage gap, per control rated needs-improvement or ineffective, and per metric breach, each with severity, root cause, impact, a concrete remediation, an owner, and a target date.
Overall Control Environment Rating
A single verdict on the control environment - effective, effective with minor deficiencies, significant deficiencies identified, material weakness identified, or needs manual review - weighting controls over high inherent risks most heavily.
Metric Appetite Status
A single verdict on where the business line sits against its risk appetite - within appetite, approaching tolerance, threshold breach detected, no metrics provided, or needs manual review.
Review Executive Summary
The executive conclusion a risk committee or audit lead reads first - the control-environment and metric verdicts, effective vs. deficient control counts, significant deficiencies and breaches, coverage gaps, a three-lines accountability note, priority actions, and a two-paragraph narrative with cited examples.

Where it fits

Enterprise risk management - control assurance and risk/metric monitoring

Upstream

Risk and control identification - the risk register / RCSA, control inventory, control testing procedure, business process maps, and KRI/KPI dashboards are maintained and queued for a periodic controls & metric review

This step

Controls & metric review (control design + operating effectiveness assessment and metric-vs-threshold review)

Downstream

  • Issue / finding remediation and control build-out
  • Risk committee and board risk reporting
  • Internal audit and examination readiness (control-effectiveness evidence)
  • RCSA refresh and residual-risk re-rating

What it needs

Documents

  • Control inventory / control documentation and control testing procedure (the methodology and required elements)
  • Risk register or RCSA (the risk taxonomy the controls are mapped against)
  • Business process maps (to confirm control placement)
  • Control testing results and exception / issue reports
  • KRI / KPI / KCI dashboards, scorecards, or monitoring reports with defined thresholds

Systems

  • GRC / risk-and-control platform
  • Risk register / RCSA system
  • Workflow / BPM platform and the system of record
  • Metric / KRI dashboard and reporting tools

Prerequisites

  • A control testing procedure defining the methodology and required control elements (What / Who / How / How Often)
  • A risk register / taxonomy to map controls against (controls can be inventoried without it, but risk coverage cannot be scored)
  • Defined KRI / KPI thresholds tied to the organization's risk appetite and tolerance (required to flag metric breaches)

What it produces

An ERM controls & metric review - a review-scope summary, a control inventory, a risk-to-control mapping with inherent/residual ratings, separate control design and operating-effectiveness assessments, a per-control effectiveness rating with deficiency severity, a KRI/KPI metric-vs-threshold review with breach flags, a severity-ranked issues-and-findings register, an overall control-environment verdict, a metric-appetite verdict, and a cited executive summary

Delivered to

  • GRC / control-inventory system
  • Issue / remediation tracker
  • Risk committee and board risk reporting pack
  • Internal audit and examination workpapers

Review model

A second-line risk/compliance reviewer or third-line internal auditor reviews the control inventory, the risk-to-control mapping, the design and operating conclusions, the metric breaches, and the cited findings before the review is trusted and findings are routed to owners for remediation.

Who uses it

Risk ManagerOperational Risk AnalystCompliance OfficerInternal AuditorGRC / Controls AnalystChief Risk Officer

Volume fit

Works best for

risk, compliance, and internal-audit teams reviewing many controls and metrics across a portfolio each quarter or testing cycle, and re-reviewing each time controls, risks, or thresholds change

Too small for

a one-off read of a single control with no risk register, testing procedure, or metrics to review against

Grounded in

  • COSO, Internal Control-Integrated Framework (2013)verified as of 2026-07-22
  • COSO, Enterprise Risk Management-Integrating with Strategy and Performance (2017)verified as of 2026-07-22
  • The Institute of Internal Auditors (IIA), The Three Lines Model (2020 update of the Three Lines of Defense)verified as of 2026-07-22
  • PCAOB Auditing Standard AS 2201 (An Audit of Internal Control Over Financial Reporting Integrated with an Audit of Financial Statements) - control-deficiency severity taxonomyverified as of 2026-07-22
  • Risk appetite, risk tolerance, and Key Risk Indicator (KRI) threshold practice (COSO ERM 2017; common industry / IIA practice)verified as of 2026-07-22

Changelog

  • July 2026

based on a production deployment at a consumer lending & card issuer

Related agents

Browse all agents →

See ERM Controls & Metric Review on your documents

We'll run it against a file of yours and walk through every cited field.