Risk-based internal audit assurance.
Independent assurance over financial, governance, operational, compliance, information/cyber and fraud risk, planned against your risk register, evidenced, and clearly reported to your board or audit committee. For companies, charities and public-sector bodies, delivered in conformance with the Global Internal Audit Standards (GIAS) and, for public sector clients, the Public Sector Internal Audit Standards (PSIAS).
The engagement
What's included
We scope each engagement to your organisation and its risk profile, rather than a fixed template. Work is planned with management, evidenced against agreed control objectives, and closed off with a report and practical recommendations.
- Engagement letter signed before any fieldwork begins
- Risk-based audit plan agreed with management and the audit committee
- Fieldwork scheduled around your reporting cycle
- Testing evidenced against agreed control objectives
- Independence maintained throughout the engagement
- Working papers retained for the full six-year period
- Clear report with prioritised, practical recommendations
- Follow-up on the status of previously agreed actions
Coverage
Every material control area, tested with evidence.
A risk-based plan concentrates effort where it matters most. These are the areas we most often cover; the final scope is agreed with you before any work begins.
- Financial controls and the integrity of the accounting records
- Governance and the decision-making framework
- Risk management and the risk register
- Budgetary control, reserves and financial planning
- Income, expenditure and banking controls
- Payroll, PAYE and expenses
- Asset and investment registers
- Procurement, contracts and supplier controls
- Data protection and information security
- Follow-up on previously agreed actions
How we engage
From enquiry to signed report.
- 01
Initial call (20 minutes)
A short discovery call to understand your organisation, its size, its structure and any specific concerns from management or the audit committee.
- 02
Written proposal
Within 5 working days: a written proposal, scope statement, and a draft engagement letter for you to review.
- 03
Engagement letter & plan
Engagement letter signed by both parties. Risk-based audit plan agreed with management, scheduled to fit your reporting cycle.
- 04
Fieldwork
Evidence gathered and tested against each agreed control objective. Working papers retained for the full six-year period.
- 05
Report & recommendations
A clear report with prioritised, practical recommendations, delivered to management and the audit committee, with follow-up on agreed actions.
Considering an internal audit function?
Whether you need a one-off review or an ongoing programme, send us an enquiry and we'll respond with a no-obligation proposal and a draft engagement letter for you to review.