Internal audit
Risk-based annual audit plans, process audits across the transaction cycle, follow-up on prior findings, and reporting to the audit committee at the altitude the committee needs.
Internal audit, controls and risk frameworks that report on what is actually happening, not on what the policy says should happen.
Discuss your requirementsOUR APPROACH
Most control failures are not sophisticated. They are ordinary: an approval that everyone routes around, a reconciliation that has not been performed since a staff change, a vendor master nobody owns. The failure is visible for months before it becomes a loss.
We build the audit universe from where value and risk actually sit — cash, procurement, revenue, inventory, payroll, IT access — rather than auditing to a generic checklist that treats every process as equally important.
We report the root cause, not only the instance. Three exceptions in a payment process may be three errors, or they may be one broken approval workflow. The distinction determines whether the remediation will hold.
We write findings that a process owner can act on: what was tested, what was found, why it matters in rupees or in regulatory terms, and specifically who must do what by when.
WHAT WE DO
Internal audit, controls and risk frameworks that report on what is actually happening, not on what the policy says should happen.
Risk-based annual audit plans, process audits across the transaction cycle, follow-up on prior findings, and reporting to the audit committee at the altitude the committee needs.
Risk and control matrices, design assessment, operating effectiveness testing, deficiency evaluation and remediation support, and documentation supporting management’s and the auditor’s reporting obligations.
Risk identification and assessment, risk appetite articulation, register design and maintenance, key risk indicators, and integration of risk reporting into board and management reviews.
Investigation of suspected irregularities, transaction and data analysis, fraud risk assessment, whistleblower complaint examination, and support for consequential regulatory and legal action.
Process mapping, control rationalisation to remove duplicated effort, delegation of authority design, and SOPs written to be followed rather than filed.
Access and change management review, segregation of duties in the ERP, interface and data integrity testing, and IT general controls assessment supporting financial reporting.
WHO WE HELP
QUESTIONS WE ARE ASKED
DELIVERED THROUGH OUR NETWORK
Your engagement is contracted with, and signed by, a single member firm. Member firms in these locations lead on this practice.
Each member firm is a separate and independent legal entity practising in its own name under ICAI regulations.
CONNECTED EXPERTISE
LET’S START WITH YOUR QUESTION
Describe the risk advisory matter you are facing. A partner from the relevant member firm will respond directly.