IT governance & risk
Assess strategy, decision rights, risk methodology, policies and management reporting.
- Risk appetite and register
- Committees and RACI
- KPI/KRI and exceptions

We map regulatory requirements to processes, systems, risks, controls, ownership and evidence, then assess actual operation through an auditor’s lens.
A policy statement is not a control unless its process and system operation are clear. Ownership, frequency, inputs, tolerance, outputs and retained evidence should be defined; design and operating effectiveness should be tested separately.
Assess strategy, decision rights, risk methodology, policies and management reporting.
Test user lifecycle, privileged access, segregation and periodic recertification.
Review requirements, development, testing, approval, release, emergency change and code security.
Assess asset, configuration, vulnerability, patching, logging, incident, backup and capacity controls.
Test input, processing, output, interface/API, reconciliation, maker-checker and data quality controls.
Map shared responsibility, cloud configuration, supplier risk, continuity and exit capability.
We build control matrices at working-paper depth: basis, risk, control description, owner, frequency, system, evidence, test step, sample and conclusion.
We use frameworks as control design and testing criteria, not as badges. Scope is tailored to the institution type, competent authority, service model, technology architecture and assurance need.
Decision rights, policy, roles, resources, risk, performance and management oversight.
Information security governance, control coverage, risk treatment and technical safeguards.
Service organisation controls, control design, operating effectiveness and evidence expectations.
Continuity and recovery management together with cardholder data environment requirements.
Applicable legal and supervisory requirements for data, outsourcing, technology and accountability.
Shared responsibility, configuration, application security, data controls and extended technical testing.
We do not assess cybersecurity through technical vulnerabilities alone. We examine the design and operation of governance, risk management, identity and access, secure software development, cloud, third-party, incident response and resilience controls, together with the evidence that supports them.

Before the audit begins, we define the scope and audit universe, walk through systems with process owners, challenge design and operating evidence, and carry findings through root cause, retest and closure opinion.