You probably need this if…
- You're being asked to approve an ERP investment and can't validate the numbers.
- An upgrade or replacement is proposed and you want a second opinion on the risk.
- Your annual IT-controls audit produced findings you can't close.
- You inherited a system and nobody can tell you what's customised.
- A vendor is the only source of truth about your own system.
What's in scope
System audit
Full technical inventory — versions, database size and growth, custom modules, Studio and low-code changes, custom reports, scheduled jobs, integrations, users and permissions, and infrastructure baseline. Each finding graded critical through low.
Process assessment
How the business actually runs against how the system says it does, with the gaps named and owned.
Controls and audit readiness
Access control, segregation of duties, change management, evidence retention and logging — assessed against what your auditors will ask for, with the remediation sequenced.
Technology selection
Vendor-neutral evaluation of build, configure or buy, with a scored comparison and total cost of ownership over five years.
Transformation roadmap
A sequenced plan with dependencies, effort ranges, indicative cost and the risk of doing nothing stated as plainly as the risk of doing something.
Second-opinion review
Independent review of a proposal, estimate or architecture you've been given by someone else.
How we approach it
- 1
Access
Read-only access to systems, a database copy, and interviews.
- 2
Inventory
Everything you're running, documented.
- 3
Grade
Each finding assigned a severity, an impact and an owner.
- 4
Sequence
What to fix first, and what can safely wait.
- 5
Present
Findings and roadmap to leadership, in business terms.
Yours at the end of the engagement
- A written audit report with graded findings
- A full system inventory
- A controls gap analysis
- A sequenced roadmap with effort and cost ranges
Yours to act on with any partner — the audit is deliberately useful even if you don't hire us for the delivery.
Relevant experience
Pre-migration ERP audit for an eleven-company telecoms group, covering database growth, five custom modules, Studio core changes, five live integrations and the infrastructure baseline — with each risk graded and sequenced.
Three-year IT-controls audit support for an advertising and communications group, covering access control, evidence and audit readiness.
Independent build-versus-configure evaluations for clients choosing between custom platforms and standard ERP modules.
Common questions
Will you recommend your own services?
The roadmap says what needs doing, not who should do it. Plenty of our audits have concluded that the client's existing team can handle most of the work.
How long does an audit take?
Two to four weeks for a single system, depending on access and complexity. Multi-entity groups take longer.
What access do you need?
Read-only system access, a database copy, and time with the people who use and maintain the system. Nothing that changes anything.
Can the audit be used for our annual IT-controls review?
Yes — the controls section is written with that use in mind. It's the same evidence auditors ask for.