Assurance · Tax · Advisory · Corporate · TechnologyPakistan · Gulf · UK · US · Canada+92-51-6138902WhatsAppinfo@mac.org.pk

Services / 05 — Risk & forensic

Most fraud is not found by controls. It is found by someone finally asking the right question.

Enterprise risk assessment, internal control review, fraud investigation, forensic accounting and dispute support — for boards, audit committees and management who need an independent answer.

Risk and forensic work sits apart from audit for a reason: it goes looking for what an annual audit is not designed to find, and it goes deep on a single question rather than broad across a full set of accounts. We are engaged when something specific needs answering, not when a box needs ticking.

Suspect something now?

A live concern needs different handling from a routine review — evidence preserved, exposure contained, and the right people told at the right time. Speak to us before internal messages are sent about it.

IWhen clients call

The situations that bring people here

We suspect an employee is diverting funds.

A forensic investigation handled so evidence stays usable and the situation isn't tipped off before it's contained.

A whistleblower report just landed and we don't know how serious it is.

An initial assessment establishes what's credible before a full investigation is launched — and before anyone overreacts or underreacts.

Our board wants an independent view of enterprise risk.

A risk assessment that isn't filtered through the people whose performance it happens to be judging.

Internal controls have never been formally reviewed.

A control review builds the map before a gap becomes a loss, rather than after.

A dispute has ended up in litigation and the numbers need explaining.

Forensic accounting and independent quantification of loss for arbitration or court.

We are trying to put a governance, risk and compliance framework in place.

A GRC framework translated into something the business can actually run, not a binder nobody opens.

A joint venture partner's numbers don't add up.

Independent forensic review before the relationship — or the dispute — escalates any further.

A regulator or lender has asked what our risk management looks like.

A documented framework ready to show, not an ad hoc answer assembled under pressure.

IIWhat we do

Scope of the risk and forensic practice

Independent risk, control and investigative work, reporting to the board or audit committee rather than to the function under review.

01

Enterprise risk assessment

Identifying and prioritising the risks that actually threaten the business, not a generic checklist.

  • Risk identification and register development
  • Risk appetite and tolerance framework design
  • Heat-mapping and prioritisation
  • Board and audit committee risk reporting
  • Periodic risk reassessment
02

Internal control review

Testing whether controls exist on paper and actually operate in practice.

  • Control design and operating effectiveness review
  • Process walkthroughs and gap analysis
  • Segregation of duties assessment
  • Control remediation planning
  • Follow-up testing
03

Fraud investigation

Structured, evidence-led investigation from the point a concern is first raised.

  • Initial assessment and scoping
  • Digital and financial evidence gathering
  • Interview support
  • Findings reporting suitable for disciplinary or legal use
  • Coordination with legal counsel and, where relevant, law enforcement
04

Forensic accounting

Reconstructing and explaining financial position for a dispute or investigation.

  • Loss quantification
  • Books and records reconstruction
  • Asset tracing
  • Expert witness and litigation support
  • Financial statement fraud analysis
05

Whistleblower and disclosure support

Handling reports credibly from the first point of contact.

  • Whistleblowing channel design
  • Report triage and initial assessment
  • Confidential investigation management
  • Outcome reporting to the board or audit committee
06

GRC framework alignment

Governance, risk and compliance built as one coherent structure, not three separate exercises.

  • Governance structure and policy review
  • Risk and compliance framework integration
  • Regulatory compliance mapping
  • Policy and procedure documentation
  • Alignment to COSO and similar recognised models
07

Related-party and conflict-of-interest review

Independent scrutiny of relationships that are easy for insiders to overlook.

  • Related-party transaction identification and testing
  • Conflict-of-interest disclosure review
  • Beneficial ownership verification support
  • Vendor and related-entity due diligence
08

Dispute and litigation support

Independent financial analysis for arbitration, litigation or shareholder disputes.

  • Quantum and loss calculations
  • Expert reports
  • Shareholder and partnership dispute analysis
  • Contract and claims analysis
IIIWhich service answers what

Audit, internal audit and forensic work answer different questions

"We've been audited" is often assumed to cover ground it was never designed to cover.

ServiceWhat it answers
Statutory auditDo the financial statements, taken as a whole, give a true and fair view — an opinion at year end, not an ongoing control assessment.
Internal audit / ICFRAre the controls over financial reporting designed and operating effectively, tested on a rolling basis through the year.
Risk & forensicDid something specific happen, how did it happen, and what is the exposure — investigated to answer one question in depth, not to review everything.

A clean audit opinion is not evidence that fraud isn't happening — an audit is not designed to find it, and says so in its own scope.

Where the independence boundary falls

Where we are your statutory auditor, risk and forensic work for the same entity is scoped so it does not create a self-review threat under the ICAP Code of Ethics — for public interest entities, certain work is provided only to non-audit clients.

We will tell you where that boundary falls before we quote. Where we cannot act, we will say so and, where useful, help you brief whoever can.

Our independence framework →

IVHow we work on risk and forensic engagements

Six things that make findings hold up

01

Evidence handled so it stays usable

A finding that cannot be relied on in a disciplinary hearing or in court is a suspicion, not a finding. Evidence is gathered and preserved to a standard that survives scrutiny from day one.

02

Confidentiality by default

An investigation that leaks before it concludes changes its own outcome. Engagements are run on a need-to-know basis from the first phone call.

03

Findings separated from recommendations

What happened is stated as fact, tested and evidenced. What to do about it is a separate section, clearly marked as judgement rather than blended into the finding.

04

Scoped to the question actually asked

Forensic work answers a specific question. We do not quietly expand scope and re-bill for a broader review nobody asked for.

05

Independent of the people being reviewed

Risk and control work reports to the board or audit committee, not to the function whose performance is being assessed — that reporting line is what makes it independent in fact, not just on paper.

06

Escalation path agreed before work starts

Who gets told, when, and in what form, is agreed at the outset — not decided in the moment a difficult finding surfaces.

These are the firm's controls applied to risk and forensic work specifically. The full set, applied to every engagement of any type, is published.

The seven controls on every engagement →

VWho we report to

Three ways this work gets commissioned

Who commissions the work changes who we report to and how independent the review needs to be seen to be.

Route 01

Board or audit-committee mandated

An independent oversight review commissioned directly by the board, bypassing management.

Typically used for
Independent assurance over an area management itself is being assessed on
Reporting line
Directly to the board or audit committee, with management informed at the same time or after
Watch for
Genuine independence requires the scope and findings to bypass the function being reviewed, not just the fieldwork
Route 02

Management-commissioned

Building or strengthening a risk and control framework as part of normal governance.

Typically used for
Enterprise risk assessment, control review and GRC framework work as ongoing governance
Reporting line
To management, with periodic summary reporting to the board
Watch for
Where findings touch senior management itself, an escalation route to the board needs to exist from the outset
Route 03

Trigger-event investigation

A whistleblower report, suspected fraud, or a specific incident requiring urgent, contained investigation.

Typically used for
Fraud investigation and forensic accounting once a specific concern has been raised
Reporting line
Agreed before work starts — often directly to the board or a designated committee
Watch for
Speed and confidentiality matter more than usual; evidence handling from day one determines whether findings can later be acted on

The commissioning route changes who we report to and how the work is scoped — we agree it explicitly before starting, not assume it.

Our independence framework →

VICommon questions

Questions we are asked

How is this different from an internal audit?

Internal audit runs on an ongoing cycle, testing controls across the business against a plan agreed in advance. Risk and forensic work is engaged to answer a specific question — often triggered by a concern rather than a schedule — and goes deep on that one question rather than broad across everything.

We suspect a specific employee — what happens first?

An initial, quiet assessment to establish what's credible and what evidence exists, before anyone is confronted or informed. How the first days are handled often determines whether the matter can be resolved cleanly or becomes much harder to prove.

Can your findings be used in a disciplinary process or in court?

That is how we build them from the outset — evidence gathered and documented to a standard that holds up under challenge, not assembled informally and only formalised once litigation looks likely.

Will an investigation stay confidential?

Engagements are run on a need-to-know basis by design. Who is told, and when, is agreed with you before work starts rather than decided in the moment.

Can you review our risk and controls if you are also our auditor?

Sometimes, but not always. Where we are the statutory auditor, work that would create a self-review threat under the ICAP Code of Ethics is provided only to non-audit clients. We tell you where that boundary falls before we quote, and say plainly where we cannot act.

What if the whistleblower report turns out to be unfounded?

That is a normal outcome of a properly scoped initial assessment, not a failure of the process. Closing a report out cleanly, with a documented basis, protects the person who raised it and the person it named.

Do you help implement a GRC framework, or only assess one?

Both. We can review what exists against a recognised model such as COSO, or build the governance, risk and compliance structure from the ground up so it is something the business can actually run, not a document that sits unused.

How is risk and forensic work priced?

Ongoing risk and control work is typically a retainer or a scoped project. Investigations are quoted once the initial assessment defines what's actually involved — the scope of a fraud investigation cannot usually be known until that first look is done.

Let's work together

Tell us what's happened, or what you're worried might have.

A partner will tell you what the right first step is — an assessment, an investigation, or a routine review — before anything is scoped.