Productivity
Build a risk and control matrix
Process risks mapped to controls, with the gaps named.
Fill it in
Walk it end to end, in your words.
Risks with no control, and controls testing nothing.
How an auditor would check each control.
Your prompt
Build a risk and control matrix for this process. [the process] Walk the process and name what could go wrong at each step, in business terms: an order shipped without being billed, a credit note issued with no approval, cash applied to the wrong account. Risks written as control-framework language cannot be checked against reality. For each control say whether it is preventive or detective, manual or automated, and who performs it. A detective control found once a quarter is not the same protection as a system that refuses the transaction. Name the gaps in both directions: risks with no control, and controls that test nothing anyone was worried about. The second kind is more common and nobody removes them. Suggest a test per control, with a sample size and what a failure looks like.
Use Build a risk and control matrixOpens with everything above already filled in.
Why this works
Risks written in framework language cannot be checked against reality. This names what could go wrong in business terms at each step, and calls out controls that test nothing anyone was worried about, which is the more common failure and the one nobody removes.