Controls that did not scale
What worked with eight staff and one branch does not work with sixty and four.
Assurance and control review
Assurance work is about giving an independent view — to a board, a lender, a donor or management — that the numbers and the controls behind them hold up. Some of that work is regulated and must be signed by a licensed practice; some of it is not, and is often more useful to management. We are explicit about which is which, because confusing the two wastes budget and creates a false sense of cover.
What worked with eight staff and one branch does not work with sixty and four.
The same person raising, approving and reconciling is common in growing businesses and is the single largest fraud enabler.
The same point comes back every year because nobody owns the fix.
Funders increasingly ask for procedures performed over reported expenditure.
Stock shrinkage, margin erosion or cash differences with no established cause.
Buying a business on management-prepared numbers without independent testing.
The engagements below differ in purpose and in who is permitted to sign. We confirm the responsible practice and credentials in writing before any engagement letter is issued.
Testing how key processes actually operate — authorisation, segregation of duties, cash handling, stock control, payroll, system access — and reporting findings with prioritised, practical recommendations. Output: a control review report with a remediation plan.
Specific procedures performed over specific figures or balances, reported factually without an opinion. Commonly used by donors, lenders and boards. Output: a factual findings report scoped to what you asked.
Preparing the schedules, reconciliations and documentation a statutory auditor will request, and clearing the predictable findings beforehand. Output: an audit file and a list of items resolved.
Financial and commercial due diligence on a target or on a customer, supplier or partner: quality of earnings, working capital, debt-like items, contract review and risk. Output: a due diligence report with the issues that affect price and terms.
Where there is a suspected irregularity: establishing what happened, quantifying the effect, preserving evidence and recommending recovery and control action. Output: an investigation report suitable for management, and where required, for legal advisers.
Reviewing access rights, approval workflows, audit logging and change management in your accounting or ERP system. Output: a systems control report with configuration recommendations.
A statutory audit of financial statements is a regulated engagement that must be performed and signed by a practice holding the relevant licence. Where this is required we either deliver it through the appropriately licensed practice or introduce you to one, and we say clearly which applies before you commit.
We establish who the report is for and what decision it supports. That determines the type of engagement, and it matters more than most clients expect.
Scope, procedures, responsibilities, credentials where relevant, timetable and fees in writing.
A single, prioritised information request rather than a drip of queries over weeks.
Testing, walkthroughs, interviews and analysis, with issues raised as they arise rather than saved to the end.
Findings, their effect, and recommendations that a manager can actually implement — with an owner and a date for each.
A review of remediation progress at an agreed point, which is where most assurance work either creates value or does not.
Preparation is where most engagements are won or lost. The more of this you can gather before we start, the faster the work goes and the more accurately we can scope it.
Assurance work reduces risk; it does not eliminate it. No review can guarantee that every irregularity will be detected, and we will not represent otherwise.
We do not publish a price list. The drivers below vary too much between businesses for a published figure to be honest — and a price quoted before an assessment is usually wrong in one direction or the other.
| Factor | How it affects the engagement |
|---|---|
| Type of engagement | A control review, agreed-upon procedures and a full audit are different scopes with different requirements. |
| Size and complexity | Entities, sites, transaction volume and systems all drive testing effort. |
| Condition of records | Poor documentation increases time spent establishing what happened. |
| Periods covered | One year or three. |
| Access and responsiveness | Delays in access extend timelines and, on time-based engagements, cost. |
| Reporting requirements | A funder's prescribed format and additional representations add reporting time. |
Fees are quoted per engagement against an agreed scope. We do not quote an audit or assurance fee before understanding the records and the reporting requirement.
Only if the engagement is performed and signed by a practice holding the relevant licence. We confirm the responsible practice and credentials in writing before you commit, and the engagement letter states who is signing. Everything else on this page is non-statutory assurance or advisory work.
No. Independence matters, and an auditor cannot audit work they prepared. If we hold your bookkeeping, we will introduce you to a separate practice for the statutory audit and support the process from our side.
An audit gives an opinion on financial statements. A control review examines whether processes and controls operate as intended, and reports findings and recommendations to management. Many businesses benefit from the control review more, and it is not regulated in the same way.
With an audit readiness review. We establish whether an audit is required, prepare the records and schedules, and clear the predictable issues first. Starting with the audit itself is usually the most expensive route.
Agreed-upon procedures and control reviews are commonly requested by donors and funders, and the report is scoped to their requirement. We confirm the exact scope and wording the funder needs before we start.
Carefully and quietly. We agree the scope and who is informed before starting, preserve evidence properly, and report factually. We do not make accusations in a report; we set out what the evidence shows and recommend next steps, including involving legal advisers where appropriate.
Tell us what you are dealing with. We will tell you honestly whether we can help, what it would involve and what it would cost.