Skip to content

Business & Management Advisory

Internal Controls & Risk

Control design, testing, segregation of duties and closing audit findings for good.

Overview

Audit findings that reappear year after year are not audit problems. They are design problems: a control that nobody can actually perform as written.

We design controls around how the work is really done, test them, and close findings in a way that survives the following year's audit.

What is included

  • Risk assessment and control environment review
  • Control design and documentation
  • Segregation of duties analysis
  • Control testing and evidence standards
  • Audit finding remediation planning
  • Fraud risk assessment
  • Policy and procedure development
  • Control owner training and handover

How we run it

  1. 01

    Scope

    Assess the control environment and map findings to their real root causes.

  2. 02

    Build

    Design workable controls with named owners and evidence requirements.

  3. 03

    Launch

    Implement, test and document the evidence trail.

  4. 04

    Measure

    Retest at the next cycle and confirm findings stayed closed.

Questions

Before you enquire

Are you auditors?
No, and that separation matters. We design and remediate; your auditors test independently.
Why do our findings keep recurring?
Almost always because the control as written cannot be performed in practice, so it is quietly skipped. We design for what is actually workable.
Do you cover IT general controls?
Yes, jointly with our technology practice where the controls are system-based.

Often bought together

Next step

Need internal controls & risk?

Tell us what you are trying to achieve and by when. We will come back with scope, price and an honest view on fit.