Services / 05 — Risk & forensic
Most fraud is not found by controls. It is found by someone finally asking the right question.
Enterprise risk assessment, internal control review, fraud investigation, forensic accounting and dispute support — for boards, audit committees and management who need an independent answer.
Risk and forensic work sits apart from audit for a reason: it goes looking for what an annual audit is not designed to find, and it goes deep on a single question rather than broad across a full set of accounts. We are engaged when something specific needs answering, not when a box needs ticking.
Suspect something now?
A live concern needs different handling from a routine review — evidence preserved, exposure contained, and the right people told at the right time. Speak to us before internal messages are sent about it.
We suspect an employee is diverting funds.
A forensic investigation handled so evidence stays usable and the situation isn't tipped off before it's contained.
A whistleblower report just landed and we don't know how serious it is.
An initial assessment establishes what's credible before a full investigation is launched — and before anyone overreacts or underreacts.
Our board wants an independent view of enterprise risk.
A risk assessment that isn't filtered through the people whose performance it happens to be judging.
Internal controls have never been formally reviewed.
A control review builds the map before a gap becomes a loss, rather than after.
A dispute has ended up in litigation and the numbers need explaining.
Forensic accounting and independent quantification of loss for arbitration or court.
We are trying to put a governance, risk and compliance framework in place.
A GRC framework translated into something the business can actually run, not a binder nobody opens.
A joint venture partner's numbers don't add up.
Independent forensic review before the relationship — or the dispute — escalates any further.
A regulator or lender has asked what our risk management looks like.
A documented framework ready to show, not an ad hoc answer assembled under pressure.
Scope of the risk and forensic practice
Independent risk, control and investigative work, reporting to the board or audit committee rather than to the function under review.
Enterprise risk assessment
Identifying and prioritising the risks that actually threaten the business, not a generic checklist.
- Risk identification and register development
- Risk appetite and tolerance framework design
- Heat-mapping and prioritisation
- Board and audit committee risk reporting
- Periodic risk reassessment
Internal control review
Testing whether controls exist on paper and actually operate in practice.
- Control design and operating effectiveness review
- Process walkthroughs and gap analysis
- Segregation of duties assessment
- Control remediation planning
- Follow-up testing
Fraud investigation
Structured, evidence-led investigation from the point a concern is first raised.
- Initial assessment and scoping
- Digital and financial evidence gathering
- Interview support
- Findings reporting suitable for disciplinary or legal use
- Coordination with legal counsel and, where relevant, law enforcement
Forensic accounting
Reconstructing and explaining financial position for a dispute or investigation.
- Loss quantification
- Books and records reconstruction
- Asset tracing
- Expert witness and litigation support
- Financial statement fraud analysis
Whistleblower and disclosure support
Handling reports credibly from the first point of contact.
- Whistleblowing channel design
- Report triage and initial assessment
- Confidential investigation management
- Outcome reporting to the board or audit committee
GRC framework alignment
Governance, risk and compliance built as one coherent structure, not three separate exercises.
- Governance structure and policy review
- Risk and compliance framework integration
- Regulatory compliance mapping
- Policy and procedure documentation
- Alignment to COSO and similar recognised models
Related-party and conflict-of-interest review
Independent scrutiny of relationships that are easy for insiders to overlook.
- Related-party transaction identification and testing
- Conflict-of-interest disclosure review
- Beneficial ownership verification support
- Vendor and related-entity due diligence
Dispute and litigation support
Independent financial analysis for arbitration, litigation or shareholder disputes.
- Quantum and loss calculations
- Expert reports
- Shareholder and partnership dispute analysis
- Contract and claims analysis
Audit, internal audit and forensic work answer different questions
"We've been audited" is often assumed to cover ground it was never designed to cover.
| Service | What it answers |
|---|---|
| Statutory audit | Do the financial statements, taken as a whole, give a true and fair view — an opinion at year end, not an ongoing control assessment. |
| Internal audit / ICFR | Are the controls over financial reporting designed and operating effectively, tested on a rolling basis through the year. |
| Risk & forensic | Did something specific happen, how did it happen, and what is the exposure — investigated to answer one question in depth, not to review everything. |
A clean audit opinion is not evidence that fraud isn't happening — an audit is not designed to find it, and says so in its own scope.
Where the independence boundary falls
Where we are your statutory auditor, risk and forensic work for the same entity is scoped so it does not create a self-review threat under the ICAP Code of Ethics — for public interest entities, certain work is provided only to non-audit clients.
We will tell you where that boundary falls before we quote. Where we cannot act, we will say so and, where useful, help you brief whoever can.
Six things that make findings hold up
Evidence handled so it stays usable
A finding that cannot be relied on in a disciplinary hearing or in court is a suspicion, not a finding. Evidence is gathered and preserved to a standard that survives scrutiny from day one.
Confidentiality by default
An investigation that leaks before it concludes changes its own outcome. Engagements are run on a need-to-know basis from the first phone call.
Findings separated from recommendations
What happened is stated as fact, tested and evidenced. What to do about it is a separate section, clearly marked as judgement rather than blended into the finding.
Scoped to the question actually asked
Forensic work answers a specific question. We do not quietly expand scope and re-bill for a broader review nobody asked for.
Independent of the people being reviewed
Risk and control work reports to the board or audit committee, not to the function whose performance is being assessed — that reporting line is what makes it independent in fact, not just on paper.
Escalation path agreed before work starts
Who gets told, when, and in what form, is agreed at the outset — not decided in the moment a difficult finding surfaces.
These are the firm's controls applied to risk and forensic work specifically. The full set, applied to every engagement of any type, is published.
Three ways this work gets commissioned
Who commissions the work changes who we report to and how independent the review needs to be seen to be.
Board or audit-committee mandated
An independent oversight review commissioned directly by the board, bypassing management.
- Typically used for
- Independent assurance over an area management itself is being assessed on
- Reporting line
- Directly to the board or audit committee, with management informed at the same time or after
- Watch for
- Genuine independence requires the scope and findings to bypass the function being reviewed, not just the fieldwork
Management-commissioned
Building or strengthening a risk and control framework as part of normal governance.
- Typically used for
- Enterprise risk assessment, control review and GRC framework work as ongoing governance
- Reporting line
- To management, with periodic summary reporting to the board
- Watch for
- Where findings touch senior management itself, an escalation route to the board needs to exist from the outset
Trigger-event investigation
A whistleblower report, suspected fraud, or a specific incident requiring urgent, contained investigation.
- Typically used for
- Fraud investigation and forensic accounting once a specific concern has been raised
- Reporting line
- Agreed before work starts — often directly to the board or a designated committee
- Watch for
- Speed and confidentiality matter more than usual; evidence handling from day one determines whether findings can later be acted on
The commissioning route changes who we report to and how the work is scoped — we agree it explicitly before starting, not assume it.
Questions we are asked
How is this different from an internal audit?
Internal audit runs on an ongoing cycle, testing controls across the business against a plan agreed in advance. Risk and forensic work is engaged to answer a specific question — often triggered by a concern rather than a schedule — and goes deep on that one question rather than broad across everything.
We suspect a specific employee — what happens first?
An initial, quiet assessment to establish what's credible and what evidence exists, before anyone is confronted or informed. How the first days are handled often determines whether the matter can be resolved cleanly or becomes much harder to prove.
Can your findings be used in a disciplinary process or in court?
That is how we build them from the outset — evidence gathered and documented to a standard that holds up under challenge, not assembled informally and only formalised once litigation looks likely.
Will an investigation stay confidential?
Engagements are run on a need-to-know basis by design. Who is told, and when, is agreed with you before work starts rather than decided in the moment.
Can you review our risk and controls if you are also our auditor?
Sometimes, but not always. Where we are the statutory auditor, work that would create a self-review threat under the ICAP Code of Ethics is provided only to non-audit clients. We tell you where that boundary falls before we quote, and say plainly where we cannot act.
What if the whistleblower report turns out to be unfounded?
That is a normal outcome of a properly scoped initial assessment, not a failure of the process. Closing a report out cleanly, with a documented basis, protects the person who raised it and the person it named.
Do you help implement a GRC framework, or only assess one?
Both. We can review what exists against a recognised model such as COSO, or build the governance, risk and compliance structure from the ground up so it is something the business can actually run, not a document that sits unused.
How is risk and forensic work priced?
Ongoing risk and control work is typically a retainer or a scoped project. Investigations are quoted once the initial assessment defines what's actually involved — the scope of a fraud investigation cannot usually be known until that first look is done.
Related
Where risk and forensic work connects
Let's work together
Tell us what's happened, or what you're worried might have.
A partner will tell you what the right first step is — an assessment, an investigation, or a routine review — before anything is scoped.
