Services / 08 — Technology & digital
ERP selection and implementation, IT audit and general controls, cybersecurity advisory, cloud enablement and ISO 27001, COBIT and NIST alignment.
We approach systems as accountants who understand technology rather than as technologists who have heard of accounting. The question we ask about any system is what it does to your financial reporting, your controls and your exposure — which is usually the question nobody asked before go-live.
The cheapest moment to review controls, access rights and reporting design is before go-live. The most expensive is during the first audit afterwards. Tell us where you are in the project.
We are choosing an ERP and every vendor says yes to everything.
Independent selection support from someone with no reseller relationship and no commission at stake.
Our implementation has stalled and the budget has gone.
Usually a scope and data problem rather than a software problem. We establish which before anyone spends more.
The system went live and the numbers do not agree.
Migration and cut-over issues — opening balances, in-flight transactions, mapping errors — traced and reconciled.
Our auditor raised IT general control findings.
Access management, segregation of duties and change control, remediated to a standard that closes the finding.
Everyone has access to everything.
Role redesign and segregation of duties analysis, in the system rather than in a policy document.
A customer or lender is asking about our security posture.
ISO 27001 or SOC 2 readiness assessment, and an honest view of the gap.
We had an incident and do not know how far it went.
Response support, scope assessment, and the control changes that stop a recurrence.
Finance spends three days a month on manual reports.
Reporting automation and dashboard build on top of the system you already own.
Led in-house by our Executive Director — IT Governance, Risk & Cybersecurity, holding ISO 27001, COBIT, NIST and SOC 2 credentials and more than fifteen industry certifications.
Independent evaluation, with no reseller relationship and nothing riding on which product you choose.
Acting for you rather than for the implementer — the role most projects lack and most need.
Where an ERP is the wrong answer, which is more often than the market suggests.
The controls your financial statement audit depends on, tested properly.
Practical exposure reduction rather than a maturity score nobody acts on.
ISO 27001, COBIT, NIST and SOC 2, applied to an organisation of your actual size.
Migration handled with the controls, cost and compliance questions answered first.
Removing the manual month-end work that consumes finance teams.
Almost none of these are defects in the software. Nearly all of them are decisions taken by people who were not asked the right question.
| What goes wrong | What it looks like in practice |
|---|---|
| The chart of accounts was migrated, not designed | The old structure is carried into the new system, including the twenty years of accumulated one-off codes. The reporting problem the ERP was bought to solve survives the implementation intact. |
| Nobody owned the data | Master data — customers, suppliers, items, opening balances — is the client's responsibility and the client's least prepared area. Projects stall here more often than anywhere else. |
| Controls were configured last | Approval limits, segregation of duties and access roles get set up in the final fortnight by whoever is available. The first audit finds it. |
| The implementer was the only adviser | The implementation partner is paid to deliver the scope, not to tell you the scope is wrong. Nobody in the room represents your interest independently. |
| Everyone was given administrator access to go live | Elevated permissions granted "temporarily" during cut-over are never revoked. Two years later this is a material control weakness. |
| Reporting was assumed rather than specified | The reports management actually uses are discovered after go-live, when the data model has already been fixed. |
| Cut-over balances were never reconciled | Opening balances are loaded and accepted without agreeing them back to the audited position. Every subsequent period inherits the difference. |
| Training happened once, before go-live | Users are trained on a system that changes during implementation, then left alone with it. Workarounds appear within weeks and become the process. |
No reseller agreements, no implementation partnerships, no commission. Our recommendation costs us the same whichever product you choose, which is the only basis on which independent selection advice means anything.
Revenue recognition, inventory valuation, foreign currency, intercompany. A configuration decision taken for operational convenience can change your reported numbers, and the person taking it usually does not know that.
Approval hierarchies, segregation of duties and access roles are specified during configuration. Retrofitting controls after go-live costs several times more and is resisted by users who have already learned the loose version.
Someone in the project has to be accountable to you rather than to the delivery scope. On most projects nobody is, which is why change requests are accepted rather than challenged.
Opening balances agreed to the audited position before the system is declared live. This single step prevents a category of problem that otherwise persists for years.
We know what an IT general controls review will test, because we perform them. Systems configured with that in view produce clean audits rather than findings.
These are the firm's controls applied to technology work specifically. The full set, applied to every engagement of any type, is published.
Held in-house rather than contracted in — which is unusual for a firm of our size and is the reason this practice exists at all.
Most Pakistani firms of our size outsource technology work or decline it. We built the capability in-house because the boundary between systems and financial reporting is where a great deal now goes wrong — and because advice given by the party that will also implement it is not advice.
The practice is led by a specialist with twelve years across infrastructure management, cloud security, IT governance and cybersecurity auditing, holding ISO 27001, COBIT, NIST and SOC 2 credentials, Microsoft Certified Trainer status, and more than fifteen industry certifications, with project experience spanning Azure and AWS and ERP evaluations across SAP, Oracle and Microsoft Dynamics.
The same person leads the information security controls protecting client data across the whole firm, which is set out on our quality page.
No. We hold no reseller agreements and take no commission from any vendor. Our fee is the same whichever product you select, which is the only arrangement under which independent selection advice is worth anything. If you want an implementation partner as well, we will help you choose one and then act for you during the project.
It depends on transaction volume, industry, reporting requirements, existing systems and — most often the deciding factor — the internal capability you have to run it. Many businesses that buy a full ERP would be better served by a properly configured mid-market system. We will tell you that if it is the case, which a reseller cannot.
Usually. Stalled projects are rarely software failures — they are scope, data or ownership failures. We establish which before recommending more spend, because adding budget to an unaddressed scope problem simply produces a larger version of the same outcome.
They are the controls over the systems that produce financial data — access management, change management, backup and recovery, and job scheduling. If those are weak, the auditor cannot rely on anything the system produces, which means substantially more substantive testing and a longer, more expensive audit.
We perform gap assessment, implementation support and readiness work. Certification itself is issued by an accredited certification body, which must be independent of the party that implemented the system — so we prepare you, and a certification body certifies you. We will tell you honestly how far the gap is before you commit to a timeline.
The immediate priority is scope — what was accessed, over what period, and whether it is ongoing. After that comes containment, then the control changes that prevent recurrence. Where the incident has financial reporting or regulatory implications, our assurance and legal teams are in the same building.
Client data is protected by role-based access control permissioned per engagement, controlled workstations with no local storage, encrypted transfer and storage, audit-logged access and data segregation between engagements — designed and overseen by the same specialist who leads this practice. The full set is published on our quality page.
Assessments, reviews and readiness work are fixed-fee against a defined scope. Implementation support is normally time-based with an agreed range and a cap, because project duration depends substantially on factors on your side — data readiness in particular.
Related
Let's work together
Choosing, implementing, stalled, or live and not working. A partner will tell you what the real problem is before recommending anything.