- Is this an audit that gets our people in trouble?
- It is not an investigation and we do not write findings against individuals. Almost everything we find is structural: a permission granted years ago for a legitimate reason and never reviewed, or a duty combined because the team was small. We report the exposure and the control, not the person. Where genuine misuse appears, that goes privately to the sponsor first, because it stops being our decision at that point.
- How is this different from our external auditor?
- A statutory auditor forms an opinion on the financial statements and looks at controls to the extent they affect that opinion. We look at the operational systems that produce the numbers before they reach the ledger: who can change a price, how a stock adjustment is approved, whether a delivery can be posted without a receipt. Our work often makes the audit cheaper, but it is not a substitute for it.
- Will you tell us we need to buy new software?
- Sometimes, and we earn nothing either way because we do not resell licences. Most findings are closed by configuration, by a permission change or by writing down a definition, none of which cost anything in software. Where a control genuinely cannot be enforced by the current system we say so and state what it would take. If we hold any commercial interest in that recommendation, it is disclosed in the report itself.
- How long does a review take, and what do we need to give you?
- For a single-entity company with two or three core systems, a few weeks of fieldwork and a similar period to write. What we need is read access to the systems, a list of current staff and leavers, and time with the people who actually do the work rather than only with their managers. The interviews are the part clients underestimate, and they are where most findings come from.
- What if the report finds something we cannot afford to fix?
- Then it is recorded as an accepted risk, in writing, signed by the person accepting it, with the exposure stated plainly. That is a legitimate outcome and it is very different from an issue nobody named. Accepted risks go into the plan with a review date, so the acceptance is revisited when circumstances change rather than becoming a permanent silence.