Business & Management Advisory
Internal Controls & Risk
Control design, testing, segregation of duties and closing audit findings for good.
Overview
Audit findings that reappear year after year are not audit problems. They are design problems: a control that nobody can actually perform as written.
We design controls around how the work is really done, test them, and close findings in a way that survives the following year's audit.
What is included
- Risk assessment and control environment review
- Control design and documentation
- Segregation of duties analysis
- Control testing and evidence standards
- Audit finding remediation planning
- Fraud risk assessment
- Policy and procedure development
- Control owner training and handover
How we run it
- 01
Scope
Assess the control environment and map findings to their real root causes.
- 02
Build
Design workable controls with named owners and evidence requirements.
- 03
Launch
Implement, test and document the evidence trail.
- 04
Measure
Retest at the next cycle and confirm findings stayed closed.
Questions
Before you enquire
- Are you auditors?
- No, and that separation matters. We design and remediate; your auditors test independently.
- Why do our findings keep recurring?
- Almost always because the control as written cannot be performed in practice, so it is quietly skipped. We design for what is actually workable.
- Do you cover IT general controls?
- Yes, jointly with our technology practice where the controls are system-based.
Often bought together
Process Improvement
Lean and Six Sigma-informed redesign of the workflows that cost you margin.
Programme & Project Delivery
PMO setup, recovery of troubled programmes and delivery governance that surfaces bad news early.
Enterprise Cyber Security
Identity, endpoint, cloud posture and audit readiness for ISO 27001 and SOC 2.
Next step
Need internal controls & risk?
Tell us what you are trying to achieve and by when. We will come back with scope, price and an honest view on fit.
