G R A M PNETWORKSpeak to the network
OUR EXPERTISE

Risk Advisory

Internal audit, controls and risk frameworks that report on what is actually happening, not on what the policy says should happen.

Discuss your requirements

OUR APPROACH

Clear thinking.
Considered advice.

Most control failures are not sophisticated. They are ordinary: an approval that everyone routes around, a reconciliation that has not been performed since a staff change, a vendor master nobody owns. The failure is visible for months before it becomes a loss.

We build the audit universe from where value and risk actually sit — cash, procurement, revenue, inventory, payroll, IT access — rather than auditing to a generic checklist that treats every process as equally important.

We report the root cause, not only the instance. Three exceptions in a payment process may be three errors, or they may be one broken approval workflow. The distinction determines whether the remediation will hold.

We write findings that a process owner can act on: what was tested, what was found, why it matters in rupees or in regulatory terms, and specifically who must do what by when.

WHAT WE DO

The substance
of the work.

Internal audit, controls and risk frameworks that report on what is actually happening, not on what the policy says should happen.

Internal audit

Risk-based annual audit plans, process audits across the transaction cycle, follow-up on prior findings, and reporting to the audit committee at the altitude the committee needs.

Internal financial controls (IFC/ICFR)

Risk and control matrices, design assessment, operating effectiveness testing, deficiency evaluation and remediation support, and documentation supporting management’s and the auditor’s reporting obligations.

Enterprise risk management

Risk identification and assessment, risk appetite articulation, register design and maintenance, key risk indicators, and integration of risk reporting into board and management reviews.

Forensic reviews and fraud risk

Investigation of suspected irregularities, transaction and data analysis, fraud risk assessment, whistleblower complaint examination, and support for consequential regulatory and legal action.

Process improvement and standard operating procedures

Process mapping, control rationalisation to remove duplicated effort, delegation of authority design, and SOPs written to be followed rather than filed.

IT and information systems risk

Access and change management review, segregation of duties in the ERP, interface and data integrity testing, and IT general controls assessment supporting financial reporting.

WHO WE HELP

Is this the right
support for you?

  • Boards and audit committees seeking assurance that is independent and specific
  • Companies with statutory internal audit or IFC reporting obligations
  • Groups that have grown by acquisition and now operate inconsistent processes
  • Organisations responding to a loss, a whistleblower complaint or a regulatory finding

QUESTIONS WE ARE ASKED

Start with the decision
in front of you.

  • Do our documented controls reflect what our people actually do?
  • Where is our largest unmitigated exposure, and how would we know if it materialised?
  • Are the findings from last year’s internal audit genuinely closed?
  • Would we detect a material fraud in procurement, and how quickly?
Talk it through with us

DELIVERED THROUGH OUR NETWORK

Local expertise.
Clear responsibility.

Your engagement is contracted with, and signed by, a single member firm. Member firms in these locations lead on this practice.

Each member firm is a separate and independent legal entity practising in its own name under ICAI regulations.

CONNECTED EXPERTISE

Explore related practices.

All services

LET’S START WITH YOUR QUESTION

Bring clarity to
your next decision.

Describe the risk advisory matter you are facing. A partner from the relevant member firm will respond directly.