Attestware

Internal audit · Beyond management systems

Outsourced internal audit: risk, controls and governance assurance without the headcount.

Internal audit is the independent assurance function that tells a board whether risk is managed, controls work and governance holds. Most small and mid-sized organisations cannot justify an in-house team. We provide the function as a service, led by practitioners with a financial statement audit background, so the discipline of financial auditing carries into everything we examine.

Risk-based plans Board reporting Finance controls home ground Not statutory audit

The service

Assurance the board can rely on

Internal audit exists to give directors an independent answer to three questions: are our risks actually managed, do our controls actually operate, and does our governance actually hold when tested? Management can assert all three; internal audit verifies them. Our practice is led by financial statement audit experience, where materiality, evidence and professional scepticism are drilled in daily, and that discipline shapes how we audit everything: finance processes, operational controls, and the management systems the rest of our services cover.

One boundary, stated plainly: we do not perform statutory financial statement audits, which are a separately regulated activity. What we provide is the internal audit function, which is management's and the board's own assurance.

Deliverables

What an engagement includes

  • D1A risk-based annual audit planBuilt from your actual risk register and agreed with the board or audit committee, so audit effort lands on what threatens the business, not on a template calendar.
  • D2Internal control testingDesign and operating effectiveness testing of the controls that matter: finance processes, payments and approvals, access management, change management, vendor management.
  • D3Governance and compliance reviewsIndependent review of how decisions are made, recorded and followed, and whether the organisation actually complies with the policies it has signed.
  • D4Findings with root causesEvery finding ranked by risk, its root cause named rather than its symptom, and a corrective action agreed with an owner and a date.
  • D5Board-level reporting and follow-upReports written for the board or audit committee, and findings tracked to verified closure rather than annual rediscovery.

Who this is for

Three situations we see most

Growing companies

You have appointed a board or audit committee for the first time and it needs an assurance function behind it, without a full-time hire.

Regulated and investor-backed

Regulators, lenders and investors increasingly expect internal audit coverage. An outsourced function meets the expectation credibly and proportionately.

After an incident

A fraud, a control failure or a near miss has shown the gap. We establish what happened, why the controls did not catch it, and what must change.

One programme, every obligation: if you also hold ISO certifications, your Clause 9.2 internal audits can run inside the same annual plan, one auditor relationship, one reporting line, no duplicated effort.

FAQ

Fair questions, straight answers

How is internal audit different from our statutory audit?

Your statutory auditor reports to shareholders on whether the financial statements give a true and fair view, once a year, within a regulated framework. Internal audit works for the board year-round, across any risk, control or governance topic the plan covers, and its job is improvement, not opinion on the accounts. The two complement each other, and a working internal audit function typically makes the statutory audit smoother.

Who do you report to?

The board or audit committee, not the managers whose areas we audit. That reporting line is what makes the function independent, and we decline engagements structured any other way.

Can this combine with our ISO internal audits?

Yes, and it should. ISO Clause 9.2 audits are internal audits with a specific scope, so they belong inside the same risk-based annual plan. You get one auditor relationship, one findings register and one board report covering both.

Discuss your needs

Give your board its own eyes.

Tell us about your risk register, your board calendar and what keeps the audit committee awake. We will come back with a proposed annual plan and a fixed price.

Contact Attestware