Audit & Assurance
Internal Audit & Assurance
We design and execute IT and cybersecurity audit programs aligned to IIA standards that produce actionable findings—not generic observations that collect dust.
Request an AssessmentWhat We Do
We embed with your internal audit function to build or strengthen IT and cybersecurity audit capabilities. Every engagement is risk-based, scope-appropriate, and designed to produce findings your organisation can act on.
- Design risk-based IT audit programs aligned to IIA Standards and IPPF
- Execute IT general controls (ITGC) and application controls testing
- Conduct cybersecurity-focused audits covering identity, access, endpoint, and data protection
- Assess audit readiness for SOC 2, ISO 27001, and regulatory examinations
- Deliver finding reports with root cause analysis, risk ratings, and remediation timelines
How We Do It
Audit Universe & Risk Assessment
We map your IT environment, identify high-risk domains, and prioritise audit focus areas using a risk-based methodology.
Audit Planning & Scoping
We develop audit programs with clear objectives, control matrices, and testing procedures tailored to your environment.
Fieldwork & Evidence Collection
We execute testing using walkthrough interviews, document inspection, re-performance, and system observation. Evidence is collected to IIA documentation standards.
Reporting & Remediation
We produce findings with severity ratings, root cause analysis, and practical remediation recommendations. No ambiguous observations—only defensible conclusions.
Follow-Up & Assurance
We track remediation progress and validate closure of findings to ensure sustained control effectiveness.
Frameworks & Techniques
IIA IPPF & Standards
International Professional Practices Framework for audit planning, execution, and reporting
COBIT 2019
Control objectives for IT governance and management processes
COSO Internal Control Framework
Integrated framework for evaluating control design and operating effectiveness
Three Lines Model
Governance structure ensuring clear separation of management, risk, and assurance functions
Risk-Based Audit Methodology
Quantitative and qualitative risk scoring to prioritise audit coverage
Data Analytics in Audit
Using automated analysis to identify anomalies, exceptions, and high-risk transactions
Deliverables
- Risk-based IT audit plan (annual or multi-year)
- Audit program with control matrices and testing procedures
- Fieldwork working papers with evidence documentation
- Audit findings report with severity, root cause, and remediation
- Management action plan tracker
- Executive summary for board or audit committee
Who This Is For
- Chief Audit Executives and Internal Audit Directors
- CISOs needing independent cybersecurity assurance
- CIOs preparing for regulatory or SOC 2 examinations
- Audit committee members seeking IT audit insight
- Organisations building or maturing internal audit functions
Strengthen Your Internal Audit Capability
Request an assessment to evaluate your IT audit maturity and design a risk-based program that delivers actionable assurance.
Request an Assessment