Services / 02 — Internal audit & ICFR / SOX
Outsourced and co-sourced internal audit, ICFR design and testing, SOX 404 readiness, COSO implementation and audit committee reporting.
Most control frameworks look adequate on paper. What decides whether they hold is evidence — that the control operated, every time, and that somebody can demonstrate it afterwards. Our team has tested controls to a standard a PCAOB-registered auditor subsequently relied upon.
Group requirements usually arrive with a deadline and a template. Send us what the parent has asked for and we will tell you what it actually requires, and what it will take here.
Our US-listed parent needs ICFR testing done here.
Testing performed to a standard the group's external auditor will rely on, coordinated with the parent's timetable.
The audit committee wants an internal audit function.
Outsourced or co-sourced, with a risk-based annual plan approved by the committee rather than assembled by management.
The same audit findings appear every year.
Recurring findings mean remediation was documented rather than implemented. That is a different problem from the finding itself.
We have grown and nobody redesigned the controls.
Controls that worked at thirty people fail at two hundred, usually at the approval and segregation points.
Something went wrong and we do not know how it got through.
Control gap analysis after an incident — what should have caught it, and why it did not.
We are preparing for a transaction and expect scrutiny.
Buyers and lenders test the control environment. Weaknesses found by them cost more than weaknesses found by you.
Our ERP went live and controls were an afterthought.
Access rights, segregation of duties and automated controls reviewed alongside the configuration.
A regulator or donor requires assurance over our processes.
Independent testing of specified processes, reported in the format the requesting party expects.
Delivered by the assurance team, with IT general controls handled jointly with our technology practice.
A complete internal audit function for organisations that need one but should not build one.
Specialist capacity alongside an existing function, for the areas it cannot cover.
Establishing what the controls are before anyone can test whether they work.
Design and operating effectiveness testing, evidenced to a standard an external auditor can rely on.
The framework most groups require, applied to an organisation of your actual size.
The part that decides whether next year's testing produces the same findings.
Where financial reporting depends on systems — which is now everywhere.
Reporting written for the people who have to act on it, not for the file.
Almost none of them are the control being absent. Nearly all of them are the control existing and not working.
| Failure mode | What it looks like in practice |
|---|---|
| The control operates without evidence | Someone genuinely reviews it — and nothing records that they did. Untestable is indistinguishable from absent, and it is the single most common finding we raise. |
| Approval is a signature, not a review | The approver has no practical means of knowing whether the item is right, and signs because the workflow requires it. The control is theatre. |
| One person holds the whole process | Segregation broke informally — through a resignation, an illness, a system change — and was never restored. Usually the person is entirely trustworthy, which is why nobody looks. |
| System access outlives the role | People change jobs and keep permissions. Over a few years, senior staff accumulate access nobody would grant them today. |
| The control was designed for a smaller company | Manual review of every transaction worked at thirty a month. At three thousand, the control becomes a sample nobody defined. |
| Exceptions have become the process | The workaround built for an urgent case is now the normal route, and the designed control is bypassed as a matter of routine. |
| Remediation was documented, not implemented | The plan exists, the owner is named, the date has passed. This is why the same finding appears three years running. |
| Nobody owns the control | It sits between two departments. Both assume the other performs it, and it has not been performed for some time. |
Risks, controls, key control designation and testing attributes agreed with management up front. Testing against a matrix nobody signed off produces findings nobody accepts.
Population, frequency and risk determine the sample. We document the basis, because an external auditor relying on our work will ask for it.
The document tested is on the file, not a note saying it was seen. This is the difference between work that can be relied upon and work that has to be repeated.
A finding without a cause produces a remediation plan that treats the symptom. A finding without a named owner produces the same finding next year.
If everything is high risk, nothing is. We rate findings so an audit committee can act on the top of the list rather than reading all of it.
Workpapers are prepared assuming the external auditor will review and rely on them. That standard costs nothing extra during fieldwork and saves the entire engagement being redone.
These are the firm's controls applied to internal audit work specifically. The full set, applied to every engagement of any type, is published.
Confusion about this is common, and it is expensive — because work performed by the wrong party cannot be relied on by anyone.
Owns the controls and the assessment. Under SOX 404(a), management asserts on the effectiveness of internal control over financial reporting. The assertion is theirs and cannot be delegated.
Provides independent assurance to the audit committee, and frequently performs or supports the testing underpinning management's assessment.
Where required, attests separately on ICFR under SOX 404(b). Independent of management, and may place reliance on internal audit work that meets the standard.
We support management's assessment and the internal audit function — testing, documenting and remediating. We are not the external auditor on those engagements, and that separation is what makes our work usable.
Our team has performed ICFR testing for an NYSE-listed company, working alongside the client's internal audit function to test the operating effectiveness of implemented controls in advance of external audit fieldwork.
That is a useful benchmark for two reasons. It means the documentation standard our team works to has already been accepted by a US-listed issuer's auditor. And it means the coordination — group templates, deadlines, evidence expectations — is familiar rather than theoretical.
One boundary we apply without exception: where we act as your statutory auditor, we will not perform controls work that creates a self-review threat under the ICAP Code of Ethics. We tell you which side of that line your engagement falls on before we quote.
External audit gives an opinion to third parties on whether the financial statements are fairly presented, and is required by statute or by stakeholders. Internal audit provides assurance to the board and audit committee on whether controls and processes work, covers operational and compliance areas as well as financial ones, and is directed by the organisation rather than by law.
Internal control over financial reporting is the set of controls providing reasonable assurance that financial statements are reliable. Formal ICFR assessment obligations arise most often from a listed parent — particularly a US-listed one — or from lender and investor requirements. Many private groups implement it voluntarily because it is the fastest route to a control environment that survives diligence.
404(a) is management's own assessment and assertion on the effectiveness of internal control over financial reporting. 404(b) is the external auditor's separate attestation on it, required for certain categories of issuer. Work supporting management's assessment and the auditor's attestation are different exercises performed by different parties — which is why who does the testing matters.
Not where doing so would create a self-review threat — we would be testing controls and then auditing the financial statements those controls produce. For public interest entities the restriction is strict. Where we act as your auditor, controls work generally goes to another firm, and we will say so at the outset rather than after you have engaged us.
Outsourcing the function entirely is the usual answer, and it is often better than building one — you get an independent team, a risk-based plan and reporting directly to the audit committee, without a permanent headcount. Co-sourcing works where you have someone internal but need specialist coverage in areas like IT or treasury.
Almost always because remediation was documented rather than implemented — a plan exists, an owner is named, the date has passed. The second most common reason is that the root cause was never established, so the fix addressed the symptom. We test remediation before closing a finding, which is why our findings tend not to reappear.
Yes. IT general controls — access management, segregation of duties in the ERP, change management, backup and recovery — are handled jointly with our technology practice, which is led in-house by a specialist holding ISO 27001, COBIT, NIST and SOC 2 credentials. Financial reporting now depends on systems, so testing process controls without testing the systems beneath them is incomplete.
Outsourced internal audit is normally an annual retainer covering an agreed plan. Discrete engagements — an ICFR implementation, a specific cycle audit, a remediation project — are scoped and fixed-fee. Testing volumes are agreed before fieldwork so the fee does not move once work starts.
Related
Let's work together
Or tell us which finding keeps coming back. A partner will tell you what testing is actually required and what it will take.