The initial phase of audit fieldwork focuses on gathering a detailed understanding of the process architecture, mapping workflows, and evaluating control designs using a Risk and Control Matrix (RCM).
[Perform Process Walkthrough] ---> [Document Workflow Flowcharts] ---> [Build Risk & Control Matrix]

The auditor documents the process through several consecutive steps:
  • The Process Walkthrough: The auditor selects a single transaction and traces it from initial system entry to final ledger settlement. The auditor observes the operational steps as they occur, reviews system configurations, and collects samples of processing evidence at each stage to confirm their understanding of the workflow.
  • Process Mapping Flowcharts: The auditor creates process flowcharts using standard notation to map the sequence of actions, decision points, manual hand-offs, and system interfaces. This visualization helps highlight single points of failure, manual processing risks, and areas lacking verification loops.
  • Building the Risk and Control Matrix (RCM): The auditor logs process data into the RCM, creating a structured record that maps identified process risks directly to their corresponding internal controls:

Process Risk Reference Risk Description Key Control Reference Control Description Design Evaluation (Pass/Fail)
R-1: Purchase Fraud Purchase orders could be issued to unapproved or fraudulent vendors. C-1: Vendor Access The vendor master database can only be modified by the Procurement Control Unit, and changes require dual authorization. Pass: The control is designed effectively to prevent the risk.
R-2: Duplicate Spend Duplicate invoice entries could result in double payments to suppliers. C-2: Manual Review Department managers review a manual spreadsheet check sheet monthly to spot duplicate payments. Fail: The control design is weak because it relies on manual human review and is prone to oversight.

Â