Assurance · Tax · Advisory · Corporate · TechnologyPakistan · Gulf · UK · US · Canada+92-51-6138902WhatsAppinfo@mac.org.pk

Services / 08 — Technology & digital

Most ERP failures are not technology failures.

ERP selection and implementation, IT audit and general controls, cybersecurity advisory, cloud enablement and ISO 27001, COBIT and NIST alignment.

We approach systems as accountants who understand technology rather than as technologists who have heard of accounting. The question we ask about any system is what it does to your financial reporting, your controls and your exposure — which is usually the question nobody asked before go-live.

ERP going live soon?

The cheapest moment to review controls, access rights and reporting design is before go-live. The most expensive is during the first audit afterwards. Tell us where you are in the project.

IWhen clients call

The situations that bring people here

We are choosing an ERP and every vendor says yes to everything.

Independent selection support from someone with no reseller relationship and no commission at stake.

Our implementation has stalled and the budget has gone.

Usually a scope and data problem rather than a software problem. We establish which before anyone spends more.

The system went live and the numbers do not agree.

Migration and cut-over issues — opening balances, in-flight transactions, mapping errors — traced and reconciled.

Our auditor raised IT general control findings.

Access management, segregation of duties and change control, remediated to a standard that closes the finding.

Everyone has access to everything.

Role redesign and segregation of duties analysis, in the system rather than in a policy document.

A customer or lender is asking about our security posture.

ISO 27001 or SOC 2 readiness assessment, and an honest view of the gap.

We had an incident and do not know how far it went.

Response support, scope assessment, and the control changes that stop a recurrence.

Finance spends three days a month on manual reports.

Reporting automation and dashboard build on top of the system you already own.

IIWhat we do

Scope of the technology practice

Led in-house by our Executive Director — IT Governance, Risk & Cybersecurity, holding ISO 27001, COBIT, NIST and SOC 2 credentials and more than fifteen industry certifications.

01

ERP selection

Independent evaluation, with no reseller relationship and nothing riding on which product you choose.

  • Requirements definition and process mapping
  • Vendor evaluation and scoring
  • SAP, Oracle, Microsoft Dynamics assessment
  • Odoo, ERPNext and mid-market alternatives
  • Total cost of ownership modelling
  • Build-versus-buy analysis
02

ERP implementation support

Acting for you rather than for the implementer — the role most projects lack and most need.

  • Chart of accounts and master data design
  • Business process configuration review
  • Data migration and reconciliation
  • Controls and approval workflow design
  • User acceptance testing
  • Cut-over and opening balance verification
  • Post-implementation review
03

SME accounting systems

Where an ERP is the wrong answer, which is more often than the market suggests.

  • TallyPrime and Tally ERP 9 setup and migration
  • QuickBooks and Xero implementation
  • Sage and Zoho Books configuration
  • Chart of accounts design
  • Bank feed and integration setup
  • User training and documentation
04

IT audit and general controls

The controls your financial statement audit depends on, tested properly.

  • IT general controls review
  • Access management and user provisioning
  • Segregation of duties in the ERP
  • Change management controls
  • Backup, recovery and job scheduling
  • Automated control and interface testing
  • Application control review
05

Cybersecurity advisory

Practical exposure reduction rather than a maturity score nobody acts on.

  • Security posture assessment
  • Vulnerability and configuration review
  • Incident response planning
  • Business continuity and disaster recovery
  • Third-party and vendor risk
  • Security awareness training
06

Framework alignment

ISO 27001, COBIT, NIST and SOC 2, applied to an organisation of your actual size.

  • Gap assessment against the chosen framework
  • Policy and procedure development
  • Control implementation support
  • Internal audit against the framework
  • Certification and audit readiness
  • SOC 1 and SOC 2 readiness
07

Cloud enablement

Migration handled with the controls, cost and compliance questions answered first.

  • Azure and AWS migration planning
  • Cloud security configuration review
  • Identity and access management
  • Data residency and compliance assessment
  • Cost optimisation review
  • Hybrid environment design
08

Automation and reporting

Removing the manual month-end work that consumes finance teams.

  • Management reporting automation
  • Power BI dashboard development
  • Custom accounting software for SMEs
  • System integration and interfaces
  • Workflow automation
  • ERP and MS Office training programmes
IIIWhere implementations go wrong

Eight reasons ERP projects disappoint

Almost none of these are defects in the software. Nearly all of them are decisions taken by people who were not asked the right question.

What goes wrongWhat it looks like in practice
The chart of accounts was migrated, not designedThe old structure is carried into the new system, including the twenty years of accumulated one-off codes. The reporting problem the ERP was bought to solve survives the implementation intact.
Nobody owned the dataMaster data — customers, suppliers, items, opening balances — is the client's responsibility and the client's least prepared area. Projects stall here more often than anywhere else.
Controls were configured lastApproval limits, segregation of duties and access roles get set up in the final fortnight by whoever is available. The first audit finds it.
The implementer was the only adviserThe implementation partner is paid to deliver the scope, not to tell you the scope is wrong. Nobody in the room represents your interest independently.
Everyone was given administrator access to go liveElevated permissions granted "temporarily" during cut-over are never revoked. Two years later this is a material control weakness.
Reporting was assumed rather than specifiedThe reports management actually uses are discovered after go-live, when the data model has already been fixed.
Cut-over balances were never reconciledOpening balances are loaded and accepted without agreeing them back to the audited position. Every subsequent period inherits the difference.
Training happened once, before go-liveUsers are trained on a system that changes during implementation, then left alone with it. Workarounds appear within weeks and become the process.
IVHow we work on technology

Six things that make us different from an IT vendor

01

We do not sell software

No reseller agreements, no implementation partnerships, no commission. Our recommendation costs us the same whichever product you choose, which is the only basis on which independent selection advice means anything.

02

We ask what it does to the financial statements

Revenue recognition, inventory valuation, foreign currency, intercompany. A configuration decision taken for operational convenience can change your reported numbers, and the person taking it usually does not know that.

03

Controls are designed in, not added later

Approval hierarchies, segregation of duties and access roles are specified during configuration. Retrofitting controls after go-live costs several times more and is resisted by users who have already learned the loose version.

04

We represent you, not the implementer

Someone in the project has to be accountable to you rather than to the delivery scope. On most projects nobody is, which is why change requests are accepted rather than challenged.

05

Cut-over is reconciled, not assumed

Opening balances agreed to the audited position before the system is declared live. This single step prevents a category of problem that otherwise persists for years.

06

The auditor's questions are anticipated

We know what an IT general controls review will test, because we perform them. Systems configured with that in view produce clean audits rather than findings.

These are the firm's controls applied to technology work specifically. The full set, applied to every engagement of any type, is published.

The seven controls on every engagement →

VFrameworks and credentials

The standards we work to

Held in-house rather than contracted in — which is unusual for a firm of our size and is the reason this practice exists at all.

ISO 27001Information security management systems — gap assessment, implementation and certification readiness
COBITIT governance and management, aligning technology decisions with business objectives
NISTCybersecurity framework — identify, protect, detect, respond and recover
SOC 1 & SOC 2Service organisation controls, for businesses their customers depend on

Why this sits inside an accountancy firm

Most Pakistani firms of our size outsource technology work or decline it. We built the capability in-house because the boundary between systems and financial reporting is where a great deal now goes wrong — and because advice given by the party that will also implement it is not advice.

The practice is led by a specialist with twelve years across infrastructure management, cloud security, IT governance and cybersecurity auditing, holding ISO 27001, COBIT, NIST and SOC 2 credentials, Microsoft Certified Trainer status, and more than fifteen industry certifications, with project experience spanning Azure and AWS and ERP evaluations across SAP, Oracle and Microsoft Dynamics.

The same person leads the information security controls protecting client data across the whole firm, which is set out on our quality page.

Our confidentiality and information security controls →

VICommon questions

Questions we are asked

Do you sell or resell ERP software?

No. We hold no reseller agreements and take no commission from any vendor. Our fee is the same whichever product you select, which is the only arrangement under which independent selection advice is worth anything. If you want an implementation partner as well, we will help you choose one and then act for you during the project.

Which ERP should we choose?

It depends on transaction volume, industry, reporting requirements, existing systems and — most often the deciding factor — the internal capability you have to run it. Many businesses that buy a full ERP would be better served by a properly configured mid-market system. We will tell you that if it is the case, which a reseller cannot.

Our implementation has stalled. Can it be recovered?

Usually. Stalled projects are rarely software failures — they are scope, data or ownership failures. We establish which before recommending more spend, because adding budget to an unaddressed scope problem simply produces a larger version of the same outcome.

What are IT general controls and why does our auditor care?

They are the controls over the systems that produce financial data — access management, change management, backup and recovery, and job scheduling. If those are weak, the auditor cannot rely on anything the system produces, which means substantially more substantive testing and a longer, more expensive audit.

Can you do ISO 27001 certification for us?

We perform gap assessment, implementation support and readiness work. Certification itself is issued by an accredited certification body, which must be independent of the party that implemented the system — so we prepare you, and a certification body certifies you. We will tell you honestly how far the gap is before you commit to a timeline.

We have had a security incident. What now?

The immediate priority is scope — what was accessed, over what period, and whether it is ongoing. After that comes containment, then the control changes that prevent recurrence. Where the incident has financial reporting or regulatory implications, our assurance and legal teams are in the same building.

Is our data safe if we outsource accounting to you?

Client data is protected by role-based access control permissioned per engagement, controlled workstations with no local storage, encrypted transfer and storage, audit-logged access and data segregation between engagements — designed and overseen by the same specialist who leads this practice. The full set is published on our quality page.

How is technology work priced?

Assessments, reviews and readiness work are fixed-fee against a defined scope. Implementation support is normally time-based with an agreed range and a cap, because project duration depends substantially on factors on your side — data readiness in particular.

Let's work together

Tell us where the project is.

Choosing, implementing, stalled, or live and not working. A partner will tell you what the real problem is before recommending anything.