AccAnalysisAccAnalysis
Audits & Advisory

Know what you're running before you decide what to build

Independent assessment of your systems, processes and controls — graded by risk, with a costed roadmap. Useful on its own, whoever you hire next.

How we approach it
  1. 1Access
  2. 2Inventory
  3. 3Grade
  4. 4Sequence
  5. 5Present

You probably need this if…

  • You're being asked to approve an ERP investment and can't validate the numbers.
  • An upgrade or replacement is proposed and you want a second opinion on the risk.
  • Your annual IT-controls audit produced findings you can't close.
  • You inherited a system and nobody can tell you what's customised.
  • A vendor is the only source of truth about your own system.
Audits & Advisory

What's in scope

System audit

Full technical inventory — versions, database size and growth, custom modules, Studio and low-code changes, custom reports, scheduled jobs, integrations, users and permissions, and infrastructure baseline. Each finding graded critical through low.

Process assessment

How the business actually runs against how the system says it does, with the gaps named and owned.

Controls and audit readiness

Access control, segregation of duties, change management, evidence retention and logging — assessed against what your auditors will ask for, with the remediation sequenced.

Technology selection

Vendor-neutral evaluation of build, configure or buy, with a scored comparison and total cost of ownership over five years.

Transformation roadmap

A sequenced plan with dependencies, effort ranges, indicative cost and the risk of doing nothing stated as plainly as the risk of doing something.

Second-opinion review

Independent review of a proposal, estimate or architecture you've been given by someone else.

Method

How we approach it

  1. 1

    Access

    Read-only access to systems, a database copy, and interviews.

  2. 2

    Inventory

    Everything you're running, documented.

  3. 3

    Grade

    Each finding assigned a severity, an impact and an owner.

  4. 4

    Sequence

    What to fix first, and what can safely wait.

  5. 5

    Present

    Findings and roadmap to leadership, in business terms.

What you keep

Yours at the end of the engagement

  • A written audit report with graded findings
  • A full system inventory
  • A controls gap analysis
  • A sequenced roadmap with effort and cost ranges

Yours to act on with any partner — the audit is deliberately useful even if you don't hire us for the delivery.

Track record

Relevant experience

Pre-migration ERP audit for an eleven-company telecoms group, covering database growth, five custom modules, Studio core changes, five live integrations and the infrastructure baseline — with each risk graded and sequenced.

Three-year IT-controls audit support for an advertising and communications group, covering access control, evidence and audit readiness.

Independent build-versus-configure evaluations for clients choosing between custom platforms and standard ERP modules.

FAQ

Common questions

Will you recommend your own services?

The roadmap says what needs doing, not who should do it. Plenty of our audits have concluded that the client's existing team can handle most of the work.

How long does an audit take?

Two to four weeks for a single system, depending on access and complexity. Multi-entity groups take longer.

What access do you need?

Read-only system access, a database copy, and time with the people who use and maintain the system. Nothing that changes anything.

Can the audit be used for our annual IT-controls review?

Yes — the controls section is written with that use in mind. It's the same evidence auditors ask for.

Keep reading

Related services

Commission an audit. You'll get a graded findings report and a costed roadmap you own outright, regardless of what you do next.