ERM Controls & Metric Review
Evaluate risk controls for design AND operating effectiveness, map them to the risk register, review KRIs and KPIs against appetite thresholds, and produce a severity-ranked findings register - with a citation on every conclusion.
A control-effectiveness and metric review that took risk and audit analysts days of manual cross-referencing across the control testing procedure, risk register, process maps, and metric dashboards - produced in minutes, with separate design and operating conclusions, metric breach flags, and a citation on every line
per control review
What it extracts
11 extraction fields
- Review Scope Summary
- A one-look roll-up of what is under review - the business line and products, the frameworks applied (COSO, Three Lines), the control testing procedure, risk register, process maps, and metric sources referenced, and the review period - so a reviewer can orient before the control and metric detail.
- Control Inventory
- The controls under review parsed into one row each, with a stable ID, objective, first-line owner, line of defense, control type (preventive/detective/corrective), nature (automated/manual/IT-dependent), frequency, products covered, system dependencies, and governing procedure.
- Risk Register and Risk-to-Control Mapping
- Each in-scope risk from the register mapped to the control(s) that mitigate it, with risk category, inherent and residual ratings, and a mapping-adequacy call; risks with no adequate control are flagged as gaps.
- Control Design Assessment
- Per control, whether it is adequately DESIGNED - the required What/Who/How/How Often elements present, its placement in the process map, and its frequency adequacy - judged from design and documentation, not test results.
- Control Operating Effectiveness Assessment
- Per control, whether it actually OPERATED effectively across the period - the test and its population, the results, and any bypasses, failures, overrides, or non-performance and whether they were remediated.
- Control Effectiveness Rating
- Design and operating conclusions combined into one effectiveness rating per control (Effective / Needs improvement / Ineffective) plus a deficiency-severity classification (deficiency / significant deficiency / material weakness).
- KRI and KPI Metric and Threshold Review
- The metric side of the review - each KRI/KPI/KCI compared to its appetite/tolerance threshold, placed in a Green/Amber/Red zone with a breach flag and trend, and the governance response owed on a breach.
- Issues and Findings Register
- The severity-ranked action list - one row per risk-coverage gap, per control rated needs-improvement or ineffective, and per metric breach, each with severity, root cause, impact, a concrete remediation, an owner, and a target date.
- Overall Control Environment Rating
- A single verdict on the control environment - effective, effective with minor deficiencies, significant deficiencies identified, material weakness identified, or needs manual review - weighting controls over high inherent risks most heavily.
- Metric Appetite Status
- A single verdict on where the business line sits against its risk appetite - within appetite, approaching tolerance, threshold breach detected, no metrics provided, or needs manual review.
- Review Executive Summary
- The executive conclusion a risk committee or audit lead reads first - the control-environment and metric verdicts, effective vs. deficient control counts, significant deficiencies and breaches, coverage gaps, a three-lines accountability note, priority actions, and a two-paragraph narrative with cited examples.
Where it fits
Enterprise risk management - control assurance and risk/metric monitoring
Upstream
Risk and control identification - the risk register / RCSA, control inventory, control testing procedure, business process maps, and KRI/KPI dashboards are maintained and queued for a periodic controls & metric review
This step
Controls & metric review (control design + operating effectiveness assessment and metric-vs-threshold review)
Downstream
- Issue / finding remediation and control build-out
- Risk committee and board risk reporting
- Internal audit and examination readiness (control-effectiveness evidence)
- RCSA refresh and residual-risk re-rating
What it needs
Documents
- Control inventory / control documentation and control testing procedure (the methodology and required elements)
- Risk register or RCSA (the risk taxonomy the controls are mapped against)
- Business process maps (to confirm control placement)
- Control testing results and exception / issue reports
- KRI / KPI / KCI dashboards, scorecards, or monitoring reports with defined thresholds
Systems
- GRC / risk-and-control platform
- Risk register / RCSA system
- Workflow / BPM platform and the system of record
- Metric / KRI dashboard and reporting tools
Prerequisites
- A control testing procedure defining the methodology and required control elements (What / Who / How / How Often)
- A risk register / taxonomy to map controls against (controls can be inventoried without it, but risk coverage cannot be scored)
- Defined KRI / KPI thresholds tied to the organization's risk appetite and tolerance (required to flag metric breaches)
What it produces
An ERM controls & metric review - a review-scope summary, a control inventory, a risk-to-control mapping with inherent/residual ratings, separate control design and operating-effectiveness assessments, a per-control effectiveness rating with deficiency severity, a KRI/KPI metric-vs-threshold review with breach flags, a severity-ranked issues-and-findings register, an overall control-environment verdict, a metric-appetite verdict, and a cited executive summary
Delivered to
- GRC / control-inventory system
- Issue / remediation tracker
- Risk committee and board risk reporting pack
- Internal audit and examination workpapers
Review model
A second-line risk/compliance reviewer or third-line internal auditor reviews the control inventory, the risk-to-control mapping, the design and operating conclusions, the metric breaches, and the cited findings before the review is trusted and findings are routed to owners for remediation.
Who uses it
Volume fit
Works best for
risk, compliance, and internal-audit teams reviewing many controls and metrics across a portfolio each quarter or testing cycle, and re-reviewing each time controls, risks, or thresholds change
Too small for
a one-off read of a single control with no risk register, testing procedure, or metrics to review against
Grounded in
- COSO, Internal Control-Integrated Framework (2013)verified as of 2026-07-22
- COSO, Enterprise Risk Management-Integrating with Strategy and Performance (2017)verified as of 2026-07-22
- The Institute of Internal Auditors (IIA), The Three Lines Model (2020 update of the Three Lines of Defense)verified as of 2026-07-22
- PCAOB Auditing Standard AS 2201 (An Audit of Internal Control Over Financial Reporting Integrated with an Audit of Financial Statements) - control-deficiency severity taxonomyverified as of 2026-07-22
- Risk appetite, risk tolerance, and Key Risk Indicator (KRI) threshold practice (COSO ERM 2017; common industry / IIA practice)verified as of 2026-07-22
Changelog
- July 2026
based on a production deployment at a consumer lending & card issuer
Related agents
Browse all agents →Regulatory Obligation-to-Control Mapping
Parse a regulation, exam manual, or guidance into discrete obligations and map each to an owned internal control - with control type, coverage status, gaps, UDAAP flags, and a citation on every line.
Change-in-Terms & Cardholder-Agreement Review
Test a credit card change-in-terms notice against Regulation Z: every changed term summarized, the 45-day advance-notice window and right-to-reject verified, penalty rate increases justified and reevaluation-eligible, and every required disclosure present and cited.
Compliance Testing — Periodic Statement Disclosure
Test a credit card periodic statement against Regulation Z (12 CFR 1026.7): every required disclosure present, and the balance, interest, and minimum-payment math footed and cited.
See ERM Controls & Metric Review on your documents
We'll run it against a file of yours and walk through every cited field.