Assurance and control review

Audit & Assurance

Assurance work is about giving an independent view — to a board, a lender, a donor or management — that the numbers and the controls behind them hold up. Some of that work is regulated and must be signed by a licensed practice; some of it is not, and is often more useful to management. We are explicit about which is which, because confusing the two wastes budget and creates a false sense of cover.

Who this service is for

  • Boards and owners who want an independent check on controls rather than relying on the same team that runs the process.
  • Businesses preparing for a statutory audit and wanting the avoidable findings cleared first.
  • Organisations with donor funding that require specific assurance or agreed-upon procedures.
  • Lenders and investors requiring verification of a financial position.
  • Businesses that have grown quickly and need to know whether the controls grew with them.
  • Companies investigating an unexplained loss, a suspected irregularity or a control failure.

The problems this addresses

Controls that did not scale

What worked with eight staff and one branch does not work with sixty and four.

Segregation of duties that has eroded

The same person raising, approving and reconciling is common in growing businesses and is the single largest fraud enabler.

Audit findings that repeat

The same point comes back every year because nobody owns the fix.

Donor reporting without independent verification

Funders increasingly ask for procedures performed over reported expenditure.

Unexplained losses

Stock shrinkage, margin erosion or cash differences with no established cause.

Acquisition risk

Buying a business on management-prepared numbers without independent testing.

Scope and deliverables

The engagements below differ in purpose and in who is permitted to sign. We confirm the responsible practice and credentials in writing before any engagement letter is issued.

  1. Internal control review

    Testing how key processes actually operate — authorisation, segregation of duties, cash handling, stock control, payroll, system access — and reporting findings with prioritised, practical recommendations. Output: a control review report with a remediation plan.

  2. Agreed-upon procedures

    Specific procedures performed over specific figures or balances, reported factually without an opinion. Commonly used by donors, lenders and boards. Output: a factual findings report scoped to what you asked.

  3. Audit readiness review

    Preparing the schedules, reconciliations and documentation a statutory auditor will request, and clearing the predictable findings beforehand. Output: an audit file and a list of items resolved.

  4. Due diligence support

    Financial and commercial due diligence on a target or on a customer, supplier or partner: quality of earnings, working capital, debt-like items, contract review and risk. Output: a due diligence report with the issues that affect price and terms.

  5. Forensic and investigative work

    Where there is a suspected irregularity: establishing what happened, quantifying the effect, preserving evidence and recommending recovery and control action. Output: an investigation report suitable for management, and where required, for legal advisers.

  6. Systems and controls review

    Reviewing access rights, approval workflows, audit logging and change management in your accounting or ERP system. Output: a systems control report with configuration recommendations.

  7. Statutory audit

    A statutory audit of financial statements is a regulated engagement that must be performed and signed by a practice holding the relevant licence. Where this is required we either deliver it through the appropriately licensed practice or introduce you to one, and we say clearly which applies before you commit.

How the engagement works

  1. Scoping conversation

    We establish who the report is for and what decision it supports. That determines the type of engagement, and it matters more than most clients expect.

  2. Engagement letter

    Scope, procedures, responsibilities, credentials where relevant, timetable and fees in writing.

  3. Planning and information request

    A single, prioritised information request rather than a drip of queries over weeks.

  4. Fieldwork

    Testing, walkthroughs, interviews and analysis, with issues raised as they arise rather than saved to the end.

  5. Reporting

    Findings, their effect, and recommendations that a manager can actually implement — with an owner and a date for each.

  6. Follow-up

    A review of remediation progress at an agreed point, which is where most assurance work either creates value or does not.

What we need from you

Preparation is where most engagements are won or lost. The more of this you can gather before we start, the faster the work goes and the more accurately we can scope it.

  • The financial records for the period and the supporting documentation.
  • Access to systems and to the people who run the processes.
  • Policies, approval matrices and procedure documents, whether or not they are current.
  • Prior reports and the status of previous recommendations.
  • A named contact who can resolve access and information queries quickly.
  • For due diligence, authority to approach the target and any third parties.

What you can reasonably expect

  • An independent view of whether the controls operate as management believes.
  • Findings that are specific, prioritised and owned.
  • Earlier detection of errors and irregularities than an annual review would give.
  • Documentation that satisfies a lender, donor or board.
  • A clearer basis for acquisition or investment decisions.
  • Fewer repeated audit findings year on year.

Assurance work reduces risk; it does not eliminate it. No review can guarantee that every irregularity will be detected, and we will not represent otherwise.

What affects fees and timelines

We do not publish a price list. The drivers below vary too much between businesses for a published figure to be honest — and a price quoted before an assessment is usually wrong in one direction or the other.

Factors affecting fees and timelines
Factor How it affects the engagement
Type of engagement A control review, agreed-upon procedures and a full audit are different scopes with different requirements.
Size and complexity Entities, sites, transaction volume and systems all drive testing effort.
Condition of records Poor documentation increases time spent establishing what happened.
Periods covered One year or three.
Access and responsiveness Delays in access extend timelines and, on time-based engagements, cost.
Reporting requirements A funder's prescribed format and additional representations add reporting time.

Fees are quoted per engagement against an agreed scope. We do not quote an audit or assurance fee before understanding the records and the reporting requirement.

Software and industries this service applies to

Platforms we commonly work with for this service

Sectors we apply this service in

Frequently asked questions

Is this a statutory audit?

Only if the engagement is performed and signed by a practice holding the relevant licence. We confirm the responsible practice and credentials in writing before you commit, and the engagement letter states who is signing. Everything else on this page is non-statutory assurance or advisory work.

Can you audit accounts you also prepared?

No. Independence matters, and an auditor cannot audit work they prepared. If we hold your bookkeeping, we will introduce you to a separate practice for the statutory audit and support the process from our side.

What is the difference between an internal control review and an audit?

An audit gives an opinion on financial statements. A control review examines whether processes and controls operate as intended, and reports findings and recommendations to management. Many businesses benefit from the control review more, and it is not regulated in the same way.

We have never had our accounts audited. Where do we start?

With an audit readiness review. We establish whether an audit is required, prepare the records and schedules, and clear the predictable issues first. Starting with the audit itself is usually the most expensive route.

Do donors accept your reports?

Agreed-upon procedures and control reviews are commonly requested by donors and funders, and the report is scoped to their requirement. We confirm the exact scope and wording the funder needs before we start.

How do you handle a suspected fraud?

Carefully and quietly. We agree the scope and who is informed before starting, preserve evidence properly, and report factually. We do not make accusations in a report; we set out what the evidence shows and recommend next steps, including involving legal advisers where appropriate.

Let’s build a stronger financial foundation for your business.

Tell us what you are dealing with. We will tell you honestly whether we can help, what it would involve and what it would cost.

Chat on WhatsApp