Audit & Attestation
Independent assurance you can show to others.
Independent verification, delivered externally. We give leadership and boards the objective evidence they need through structured attestation across four assurance lenses.
Who it's for
- Boards and audit committees that want independent assurance
- Internal audit teams needing specialist capacity
- Organisations responding to customer or regulator audit requests
Problems we solve
- Findings that are vague or impossible to act on
- Limited in-house audit expertise
- No independent view of technology risk
- Controls that have never been tested
What is included
Everything under Audit & Attestation
Systems certification audits
Readiness and surveillance audits against ISO/IEC 27001, 22301, 20000, 9001, 45001, 27701 and more.
Technology and infrastructure audits
Evaluation of IT infrastructure, applications, databases, cloud and endpoint security controls.
Regulatory compliance assurance
Independent attestation against PCI DSS v4.0, SWIFT CSP, SOC 2, CBN Cybersecurity, AML, NDPA and GDPR.
Governance and controls assurance
Assessing IT governance, enterprise risk, systems operations and change management effectiveness.
Four assurance lenses at a glance
| Assurance lens | What we examine | Typical result |
|---|---|---|
| Systems certification audits | Readiness and surveillance audits against ISO/IEC 27001, 22301, 20000, 9001, 45001, 27701 and more | Conformity findings and improvement opportunities |
| Technology and infrastructure audits | IT infrastructure, applications, databases, cloud and endpoint security controls | Technical risk findings and hardening advice |
| Regulatory compliance assurance | PCI DSS v4.0, SWIFT CSP, SOC 2, CBN Cybersecurity, AML, NDPA and GDPR | Independent attestation and compliance gap report |
| Governance and controls assurance | IT governance, enterprise risk, systems operations and change management | Control effectiveness rating |
Our approach
How we deliver Audit & Attestation
-
1
Analyse
Understand the scope, risks and criteria the audit will use.
Typical deliverable: Scope statement
-
2
Plan
Build an audit programme, sample plan and schedule.
Typical deliverable: Audit plan
-
3
Execute
Interview, inspect and test controls against the criteria.
Typical deliverable: Working papers
-
4
Report
Issue findings with risk ratings and practical recommendations.
Typical deliverable: Audit report
-
5
Monitor
Follow up to confirm that actions were completed and effective.
Typical deliverable: Follow-up review
Benefits
- Objective findings ranked by risk
- Recommendations your team can implement
- Confidence for boards, customers and regulators
- Audit evidence that is easy to follow
Typical deliverables
- Audit plan and scope statement
- Findings register with risk ratings
- Management report
- Follow-up review
Outcomes
- A clear, ranked list of what to fix first
- Stronger controls with each audit cycle
- Audit results stakeholders trust
FAQ
Frequently asked questions
What is the difference between an audit and an attestation?
Can you support our internal audit team?
GRC Advisory & Certification
Design, implement and certify management systems that turn compliance obligations into operating discipline.
- Gap assessment report
- Risk assessment and treatment plan
- Policy and procedure set
Cyber Offense Services
Vulnerability assessment and penetration testing, plus quarterly ASV scanning for PCI DSS.
- Rules-of-engagement document
- Technical report with evidence
- Executive summary
Outsourced Assurance Roles
Embedded DPO, ISO lead implementer and lead auditor services: senior compliance leadership, fractional commitment.
- Role charter and responsibilities
- Monthly activity and risk report
- Registers and records maintained on your behalf
Enquire about Audit & Attestation
Tell us what you need
Share a few details and a specialist will reply within one working day.
Let us assure your next move
Tell us about your organisation and we will recommend the right path to compliance, within one working day.