This paper presents a control measurement methodology applied in the processes performed by any entity. The methodology is derived from the analysis of the mitigation capabilities of the controls currently in use by the entity. The method enables risk managers to identify which risks require urgent actions to improve the control levels, which risks are already adequately controlled and which ones are in a situation of excessive control. This kind of information can play an important role to improve the application of available internal risk and control management resources in companies. The methodology was applied to a case study and revealed to be a satisfactory tool to assess and identify control levels.
Internal Controls; Risk Management; Risk Matrix; Importance-Performance Matrix