Audit and controls expertise for regulated UK businesses.
Three practice areas, one senior team. Every engagement is led by people who have spent their careers in this discipline.
01
Internal Audit Co-sourcing
Co-sourced internal audit capacity, led by people who've sat where you sit. We slot into your existing internal audit function to deliver specific engagements, cover skill or resourcing gaps, or provide surge capacity during peak periods, without the lead time or cost of a full outsourcing arrangement.
Internal audit functions are increasingly asked to do more (expanded risk universes, new regulatory expectations, third-party risk, ESG, technology and cyber controls) with headcount that hasn't kept pace. Co-sourcing lets you keep ownership of the audit plan and stakeholder relationships while bringing in specialist or additional capacity exactly where it's needed.
What we deliver
Audit execution support: planning, fieldwork, testing, and reporting for specific engagements on your annual audit plan
Specialist skill injection: subject-matter expertise in areas like financial controls, reserving and actuarial processes, regulatory compliance, and SOX-adjacent controls, where your in-house team may not have deep bench strength
Surge capacity: additional resource during peak periods (year-end, regulatory deadlines, post-merger integration) without a permanent headcount commitment
Co-delivery with your team: we work alongside your auditors rather than in a silo, so knowledge and relationships stay in-house
Quality and methodology support: audit programme design, working paper standards, and reporting templates aligned to IIA standards
How we work
Scoping conversation
We understand your audit plan, existing team structure, and where the gap actually sits.
Engagement design
Agree scope, deliverables, timeline, and whether we lead, support, or embed.
Delivery
Fieldwork and reporting to your standards (or ours, if you're building them).
Handover
Findings, working papers, and where useful, capability transfer back to your permanent team.
Who this is for
Internal audit functions with a lean permanent headcount facing a full-scope annual plan
Functions needing specialist coverage for a specific audit area (financial reporting controls, regulatory compliance, third-party risk)
Organisations between Head of Internal Audit hires who need continuity
Businesses in a growth phase where the audit universe has outpaced the team
02
SOX Advisory
SOX compliance that holds up under audit scrutiny, not just on paper. From first-time SOX readiness to mature programme optimisation, we help finance and controls teams build, test, and defend a control environment that satisfies management, the audit committee, and the external auditor.
SOX programmes often accumulate documentation debt: controls that were designed once and never revisited, evidence that doesn't clearly demonstrate completeness and accuracy, and control owners who can perform the control but can't articulate why it works. External auditors are increasingly focused on the rigour of evidence (not just whether a control exists, but whether it can be shown to operate consistently). We help close that gap before it becomes an audit finding.
What we deliver
Programme design & scoping
Risk and control matrix (RCM) development and maintenance
Scoping of in-scope entities, processes, and significant accounts
SOX 302/404 readiness assessments for first-time compliance (e.g., IPO, post-acquisition)
Control design & documentation
Control narrative and process flow documentation
Control design effectiveness reviews
Remediation of control gaps identified by internal or external audit
Guidance on evidencing completeness and accuracy (C&A) of reports used in controls, a recurring area of external audit challenge
Testing & assurance
Design and operating effectiveness testing (Management Testing / 1st line, or independent 2nd line support)
Deficiency evaluation and severity assessment (deficiency vs. significant deficiency vs. material weakness)
Testing methodology and sampling approach design
Change management & sustainability
Control change management for system, process, or organisational change (including model and reserving change in regulated environments)
Control owner training and communication, including translating technical compliance requirements into practical guidance for control performers
ITGC and IT-dependent control coordination with technology teams
Remediation support
Root cause analysis for control deficiencies
Remediation plan design and project management through to retest
Liaison support with external auditors on control matters
How we work
Diagnostic
Review your current RCM, testing results, and prior-year audit findings to find where the real risk sits.
Prioritised plan
A focused set of workstreams, not a generic SOX checklist.
Delivery
Hands-on documentation, testing, or remediation work, done to a standard that anticipates audit scrutiny.
Sustainability
Control owner enablement so improvements don't regress next cycle.
Who this is for
Finance and controls teams preparing for first-time SOX compliance
Organisations with recurring external audit findings on control documentation or evidence quality
Businesses undergoing system change, reserving/model change, or M&A that need control impact assessed
SOX PMOs needing surge testing or remediation capacity ahead of year-end
03
AI & Algorithmic Controls Automation Advisory
AI & Algorithmic Controls Automation Advisory provides organisations with the confidence to innovate with AI, while ensuring automated decisions remain governed, transparent, compliant, and resilient.
We help organisations move from manual control execution and periodic testing to automated controls and continuous assurance models that improve both efficiency and risk management.
Our work covers three things: tools that automate control testing, tools that automate the performance of controls, and AI governance.
What we deliver
Controls automation
Controls Automation Strategy: identify opportunities to automate manual and spreadsheet-based controls across finance, risk, compliance and operational processes.
Automated Control Design: design preventative, detective and monitoring controls embedded directly within business processes, applications and workflows.
Continuous Controls Monitoring (CCM): implement automated monitoring solutions that identify exceptions, anomalies and control failures in near real-time.
Controls Testing Automation: reduce manual testing effort through automated evidence collection, testing scripts, data analytics and workflow-driven assessments.
Third-Party and Vendor Control Monitoring: automate oversight activities and performance monitoring for outsourced service providers and critical vendors.
AI governance
AI Governance Framework: define the policies, roles and accountabilities for how AI, machine learning and algorithmic models are approved, used and overseen across the organisation.
AI and Algorithm Inventory: build and maintain a register of the models, algorithms and automated decisions in use, with clear owners, purpose and a risk rating for each.
Independent Assurance over AI and Models: assess the design and operation of controls over critical algorithms and models, including those behind customer decisions, financial reporting, operational processes and risk management.
Model Risk and Control Design: embed controls over data quality, model validation, change management and human oversight, so automated decisions stay transparent, explainable and reliable.
Regulatory Readiness: prepare for emerging AI regulation and external assurance requirements, with the evidence and reporting to stand up to regulatory scrutiny.
How we work
Opportunity Assessment
Review your current control environment, testing approach and technology landscape to identify automation opportunities and quick wins.
Process & Controls Mapping
Document key processes, risks and controls to determine where automation can improve efficiency, consistency and coverage.
Solution Design
Develop a target-state controls automation and testing framework, including automated controls, monitoring rules, workflows and reporting requirements.
Technology Enablement
Leverage existing ERP, GRC, workflow, analytics and AI platforms to embed automation with minimal disruption to operations.
Pilot & Validation
Deploy automation within selected processes, validate results and refine control logic to ensure accuracy and effectiveness.
Implementation & Scaling
Roll out automated controls and testing capabilities across the wider control environment using a risk-based approach.
Continuous Monitoring & Optimisation
Establish ongoing monitoring, exception management and performance reporting to continuously improve control effectiveness.
Knowledge Transfer & Sustainability
Equip control owners, risk teams and internal audit functions with the skills, documentation and operating model needed to sustain and enhance the solution.
Who this is for
Organisations implementing or expanding AI, machine learning and intelligent automation capabilities
Internal Audit, Risk and Compliance functions seeking independent assessment of AI governance and controls
Businesses looking to automate manual control activities and enhance assurance through data-driven monitoring
Organisations preparing for emerging AI regulations, external assurance requirements or regulatory scrutiny
Companies relying on critical algorithms or models for customer decisions, financial reporting, operational processes or risk management
Ready to discuss your requirements?
Every engagement begins with a straightforward conversation. Tell us about your organisation and we will outline how we can help.