Services / 05 — Risk & forensic
Enterprise risk assessment, internal control review, fraud investigation, forensic accounting and dispute support — for boards, audit committees and management who need an independent answer.
Risk and forensic work sits apart from audit for a reason: it goes looking for what an annual audit is not designed to find, and it goes deep on a single question rather than broad across a full set of accounts. We are engaged when something specific needs answering, not when a box needs ticking.
A live concern needs different handling from a routine review — evidence preserved, exposure contained, and the right people told at the right time. Speak to us before internal messages are sent about it.
We suspect an employee is diverting funds.
A forensic investigation handled so evidence stays usable and the situation isn't tipped off before it's contained.
A whistleblower report just landed and we don't know how serious it is.
An initial assessment establishes what's credible before a full investigation is launched — and before anyone overreacts or underreacts.
Our board wants an independent view of enterprise risk.
A risk assessment that isn't filtered through the people whose performance it happens to be judging.
Internal controls have never been formally reviewed.
A control review builds the map before a gap becomes a loss, rather than after.
A dispute has ended up in litigation and the numbers need explaining.
Forensic accounting and independent quantification of loss for arbitration or court.
We are trying to put a governance, risk and compliance framework in place.
A GRC framework translated into something the business can actually run, not a binder nobody opens.
A joint venture partner's numbers don't add up.
Independent forensic review before the relationship — or the dispute — escalates any further.
A regulator or lender has asked what our risk management looks like.
A documented framework ready to show, not an ad hoc answer assembled under pressure.
Independent risk, control and investigative work, reporting to the board or audit committee rather than to the function under review.
Identifying and prioritising the risks that actually threaten the business, not a generic checklist.
Testing whether controls exist on paper and actually operate in practice.
Structured, evidence-led investigation from the point a concern is first raised.
Reconstructing and explaining financial position for a dispute or investigation.
Handling reports credibly from the first point of contact.
Governance, risk and compliance built as one coherent structure, not three separate exercises.
Independent scrutiny of relationships that are easy for insiders to overlook.
Independent financial analysis for arbitration, litigation or shareholder disputes.
"We've been audited" is often assumed to cover ground it was never designed to cover.
| Service | What it answers |
|---|---|
| Statutory audit | Do the financial statements, taken as a whole, give a true and fair view — an opinion at year end, not an ongoing control assessment. |
| Internal audit / ICFR | Are the controls over financial reporting designed and operating effectively, tested on a rolling basis through the year. |
| Risk & forensic | Did something specific happen, how did it happen, and what is the exposure — investigated to answer one question in depth, not to review everything. |
A clean audit opinion is not evidence that fraud isn't happening — an audit is not designed to find it, and says so in its own scope.
Where we are your statutory auditor, risk and forensic work for the same entity is scoped so it does not create a self-review threat under the ICAP Code of Ethics — for public interest entities, certain work is provided only to non-audit clients.
We will tell you where that boundary falls before we quote. Where we cannot act, we will say so and, where useful, help you brief whoever can.
A finding that cannot be relied on in a disciplinary hearing or in court is a suspicion, not a finding. Evidence is gathered and preserved to a standard that survives scrutiny from day one.
An investigation that leaks before it concludes changes its own outcome. Engagements are run on a need-to-know basis from the first phone call.
What happened is stated as fact, tested and evidenced. What to do about it is a separate section, clearly marked as judgement rather than blended into the finding.
Forensic work answers a specific question. We do not quietly expand scope and re-bill for a broader review nobody asked for.
Risk and control work reports to the board or audit committee, not to the function whose performance is being assessed — that reporting line is what makes it independent in fact, not just on paper.
Who gets told, when, and in what form, is agreed at the outset — not decided in the moment a difficult finding surfaces.
These are the firm's controls applied to risk and forensic work specifically. The full set, applied to every engagement of any type, is published.
Who commissions the work changes who we report to and how independent the review needs to be seen to be.
An independent oversight review commissioned directly by the board, bypassing management.
Building or strengthening a risk and control framework as part of normal governance.
A whistleblower report, suspected fraud, or a specific incident requiring urgent, contained investigation.
The commissioning route changes who we report to and how the work is scoped — we agree it explicitly before starting, not assume it.
Internal audit runs on an ongoing cycle, testing controls across the business against a plan agreed in advance. Risk and forensic work is engaged to answer a specific question — often triggered by a concern rather than a schedule — and goes deep on that one question rather than broad across everything.
An initial, quiet assessment to establish what's credible and what evidence exists, before anyone is confronted or informed. How the first days are handled often determines whether the matter can be resolved cleanly or becomes much harder to prove.
That is how we build them from the outset — evidence gathered and documented to a standard that holds up under challenge, not assembled informally and only formalised once litigation looks likely.
Engagements are run on a need-to-know basis by design. Who is told, and when, is agreed with you before work starts rather than decided in the moment.
Sometimes, but not always. Where we are the statutory auditor, work that would create a self-review threat under the ICAP Code of Ethics is provided only to non-audit clients. We tell you where that boundary falls before we quote, and say plainly where we cannot act.
That is a normal outcome of a properly scoped initial assessment, not a failure of the process. Closing a report out cleanly, with a documented basis, protects the person who raised it and the person it named.
Both. We can review what exists against a recognised model such as COSO, or build the governance, risk and compliance structure from the ground up so it is something the business can actually run, not a document that sits unused.
Ongoing risk and control work is typically a retainer or a scoped project. Investigations are quoted once the initial assessment defines what's actually involved — the scope of a fraud investigation cannot usually be known until that first look is done.
Related
Let's work together
A partner will tell you what the right first step is — an assessment, an investigation, or a routine review — before anything is scoped.