Operational TPintercompany-control-maturity-assessment

Intercompany controls maturity model for the CFO and board

Annual compliance is only the first level of a system that should prevent deviations, assign ownership and create evidence.

Source cutoff: August 2, 2026. Review later changes before applying this material.

Executive answer

A maturity model helps the CFO and board assess whether intercompany operations depend on annual reaction or a governed system. This model uses five levels and eight domains: governance, perimeter, policy, data, execution, monitoring, evidence and controversy/technology. It is not a certification; it prioritizes investment.

The target is not always level five. A small operation may need proportionate controls; a multinational with loans, services, maquila and adjustments requires greater integration. Scores should reflect evidence, risk and capacity rather than perception.

Methodology cutoff: August 2, 2026. Adapt the model to current Mexican law, annual rules, treaties, industry, systems and audits. The assessment does not replace compliance or assurance.

Level 1: reactive

The group identifies transactions at year-end, prepares the study separately and responds when a problem occurs. Owners and data are informal.

Risk: omissions and late evidence.

Level 2: documented

Policies, agreements, calendar and owners exist, but execution remains manual and siloed. Reconciliation is annual.

Risk: documents without conduct.

Level 3: controlled

Processes have RACI, defined data, monthly review, exceptions and evidence. Adjustments are decided before close.

A practical target for many companies.

Level 4: integrated

ERP, tax, treasury, legal and operations share data and controls. Dashboards and workflows connect policy with invoicing and accounting.

Risk: technology dependency.

Level 5: adaptive

The system anticipates change, simulates scenarios, automates under governance and learns from audits. Controls adapt to risk.

It does not mean human-free autonomy.

Domain 1: governance

Assess sponsor, committee, RACI, policies, escalation, decisions and board reporting. Look for minutes and execution.

An organization chart is not governance proof.

Request an assessment to score evidence by domain, define a target level and build a proportionate intercompany-control roadmap.

Domain 2: perimeter

Measure identification of parties, entities, accounts, agreements and transactions. Inventory reconciles to the ledger and systems.

No perimeter means no control.

Domain 3: policy

Review delineation, method, range, adjustments, exceptions and updates. Compare agreements with conduct.

Generic policies score low.

Domain 4: data

Assess master data, sources, lineage, quality, segmentation, calendar and owners. Measure errors.

An uncontrolled critical spreadsheet limits maturity.

Domain 5: execution

Observe prices, orders, invoices, journals, withholding, payments and reconciliation. Test samples.

Policy should reach the transaction.

Domain 6: monitoring

Review KPIs, margins, alerts, forecast, deviations, decisions and true-ups. Confirm frequency and closure.

A dashboard without action is not a control.

Domain 7: evidence

Assess agreements, FAR, deliverables, benefit tests, benchmarks, approvals, receipts and retention. Look for traceability.

More files do not equal better evidence.

Domain 8: controversy and technology

Measure defense files, request protocols, precedents, access, automation, security and continuity.

Technology needs governance.

Scoring scale

Score design and operation separately from zero to five. Design asks whether the control exists; operation whether it works with evidence.

Do not average away a critical absence.

Evidence

Use documents, interviews, samples and walk-throughs. Every score links to proof.

Self-assessment without evidence is preliminary.

Materiality

Weight amount, volume, jurisdiction, complexity, audit and double tax. A large loan may need a higher control level than average.

Targets vary by process.

Inherent risk

Measure before controls: transaction, country, method, data and change. Then assess residual risk.

Prioritize high-residual gaps.

Heat map

Cross domains and entities. Use defined colors rather than decoration. Include exposure and action.

The board needs risk concentration.

RACI

Assign responsible, accountable, consulted and informed roles for inventory, policy, invoicing, adjustment, return and defense.

Avoid two approvers with no owner.

Calendar

Connect monthly, quarterly and annual cycles. Include legal deadlines and internal pre-close dates.

Measure completion.

Preventive controls

Approved masters, agreements before operation, configured prices, monthly evidence and access restrictions prevent error.

Validate design.

Detective controls

Reconciliation, margin analysis, exceptions, duplicates and invoice review find deviations.

Define tolerance.

Corrective controls

Remediation, adjustments, data correction, training and escalation address issues. Record root cause.

Do not repeat exceptions.

Automation

Automate after standardization. Test interfaces, access and rollback. Maintain human review.

PT-099 covers AI.

ERP

Review masters, pricing rules, currencies, centers, eliminations and reporting. Do not assume tax configuration exists.

Document ownership.

Services

Control inventory, benefit, costs, keys, markup, invoices and evidence. Monthly certification improves maturity.

Sample regularly.

Loans

Control capacity, agreement, disbursement, rate, interest, payment, limits and renewal. Alert before maturity.

Reconcile treasury.

Distribution

Monitor sales, costs, expenses, inventory, promotions and margin. Explain losses.

Do not adjust without cause.

Maquila

Control assets, costs, Safe Harbor bases and forecasts. Reconcile monthly.

Do not wait for annual close.

Adjustments

Define type, calculation, approval, invoice, accounting, tax and notice. Rehearse execution.

Avoid late true-ups.

Compliance

Connect the study, DIM appendix, Local File, ISSIF, SIPRED and returns. Use one source of truth.

Document differences.

Audits

Maintain protocol, RACI, index and version control. Rehearse responses.

Measure time.

Maturity KPIs

Track inventoried transactions, current agreements, reconciliations, exceptions, margin, evidence, timely adjustments, filings and repeat findings.

Do not reward document volume.

Roadmap

Prioritize quick wins, foundations, integration and optimization. Every initiative has risk, benefit, owner, cost and date.

Do not attempt level five in a quarter.

First 90 days

Month one covers perimeter and governance. Month two covers policy, data and critical controls. Month three pilots monitoring and evidence.

Report progress.

Budget

Connect initiatives to exposure, hours and avoided cost. Include ongoing operation.

Do not fund a tool without a process.

Board reporting

Present five messages: risk, level, gaps, decisions and roadmap. Include events since the last review.

Avoid excessive detail.

Internal audit

It validates design and operation, samples and tracks remediation while preserving independence.

It does not replace the owner.

Reassessment

Repeat annually and after restructuring, acquisition, ERP, audit or reform. Compare evidence rather than scores alone.

Record trend.

Warning signs

Warnings include unsupported scoring, uniform targets, technology treated as maturity, unexecuted controls, unclear ownership, repeat findings or dashboards without decisions.

Correct the method.

Checklist

Confirm governance, perimeter, policy, data, execution, monitoring, evidence, controversy, technology, risk, design, operation, owner and roadmap.

Approve target levels.

Illustrative example

A group rates itself level four because it has an ERP. Sampling finds services without evidence and late manual adjustments. Technology design is high; operation and evidence are level two. The roadmap prioritizes inventory and monthly close.

The score is corrected.

Intercompany Controls Maturity Assessment product

It includes interviews, evidence, domain scores, heat map, risks, quick wins, roadmap and board report. It distinguishes design and operation.

It is not certification.

Quality assurance

A second reviewer challenges scores, checks samples and tests whether recommendations address root cause. Management accepts residual risk only with an owner and review date.

The final report preserves evidence and scoring rationale for next year’s comparison.

Interview and workshop method

Start with the sponsor and owners from tax, accounting, treasury, legal, operations, technology and internal audit. Use a common guide, but request actual examples: the latest new transaction, close, adjustment and information request. Compare answers across functions. A policy that tax considers current may be unknown to accounts payable.

Then walk a transaction from agreement to return. Select services, a loan and distribution or manufacturing. Identify inputs, decisions, systems, approvals, outputs and evidence. The objective is not a comfortable consensus score; it is to locate failures in design, execution or coordination.

Score calibration

Define observable anchors. Level one depends on individuals and reaction; level two has documents but irregular execution; level three operates evidenced controls; level four integrates processes and data; level five learns from metrics and adapts. One advanced tool cannot raise every domain.

Score design and operation separately. A well-written control can receive four for design and one for operation if no use sample exists. Use the lower score where a critical capability leaves a material entity or process uncovered. Document exceptions so averages do not hide risk.

Evidence sampling

Select entities and transactions for materiality, complexity, change and exposure rather than convenience. Include a close period, an ordinary period and an exception. For every control request owner, frequency, population, sample, result, exception and remediation. Verify the file’s date and origin.

Do not award maturity for isolated screenshots. Seek repetition across cycles and traceability from data to approval. Record limitations where no complete population exists. Internal audit may reproduce part of the sample to challenge selection and conclusion.

Target operating model

Define which decisions remain local, which the group centralizes and which require coordination. Assign owners for policy, data, transaction, monitoring, adjustment, documentation and controversy. Design forums and escalation thresholds. The target reflects size, jurisdictions, volume, ERP and risk; not every company needs level five.

Describe technology after the process. Specify master data, integrations, access controls, reconciliations and logs. Retain a manual contingency. The target model should operate with approved owners, calendar and budget.

Dependency map

Sequence initiatives by prerequisite. Do not automate monitoring without an inventory or fix returns without reconciliation. A common sequence is perimeter, policy, master data, contractual execution, monthly close, adjustments, evidence, returns and analytics. Mark dependencies on ERP, procurement, invoicing and consolidation.

The map prevents promising tool benefits before correcting source data. It also shows which enterprise program can accelerate or block the roadmap. Every dependency receives an owner, date, decision and alternative.

Remediation governance

Turn each priority gap into an action with root cause, risk, deliverable, owner, resources, date, interim control and closure criterion. The committee reviews overdue work and blockers, not just percentages. An action closes when evidence proves design and implementation; drafting a policy is insufficient.

Measure benefits through identified transactions, timely closes, fewer adjustments, passed reconciliations, complete files and rework hours. Record accepted residual risk with approver and review date. At six and twelve months, repeat samples to confirm that improvement persists.

Executive validation

Before the board receives the result, domain owners confirm facts and the sponsor challenges priorities, funding and target levels. The report states limitations, uncovered populations and disagreements. This prevents a precise-looking score from creating false assurance.

The board should approve direction and risk appetite, not every control detail. Management retains the evidence and converts decisions into funded actions with accountable owners.

Conclusion

Intercompany maturity is not measured by study length or purchased software. It is the ability to prevent, detect, correct and demonstrate.

A proportionate model helps the CFO invest where risk and evidence show the greatest need.

Request an Intercompany Controls Maturity Assessment to measure eight domains, define targets and build an executive roadmap.

Verified official sources

Verification closed on August 2, 2026. This is a technical model that should be adapted to the group.

Continue the analysis

PT-001A practical transfer pricing obligations diagnostic for MexicoFundamentals PT-004Mexico transfer pricing calendar for 2026Compliance PT-015Contemporaneous transfer pricing documentation and evidence retentionCompliance

A specific case

Turn the question into a defensible decision.

This article is general information. Continue on WhatsApp to identify the topic and review the facts.

Discuss this topic on WhatsApp