Practice 01 · Ask before
Where the business can lose money, and what to fix first.
A structured look at where the company can lose money, data or its licence to operate, ranked, owned and dated. Risk assessment, SOPs and risk-control matrices, process redesign, fraud, AI and cyber risk.
We help management see the business the way a lender, an investor or a regulator would: where it can break, how badly, and what it would cost to fix. The output is a short, ranked list, not a catalogue.
- A new plant, a new ERP, a new lender or a planned listing.
- Approvals that have outgrown the promoter’s line of sight.
- A fraud, a near miss, or an auditor’s observation that nobody owned.
- AI tools already inside payables, payroll or HR without anyone having tested them.
Without a ranked register, every risk is equal and none is owned. Controls get written after the loss, SOPs describe what people wish happened, and the board reads about the gap in the auditor’s report.
- Week 1Risk conversations with management and the board. How the company makes money, then where that can fail.
- Weeks 2 to 3Process walk-throughs. Where a risk can be tested on full data, we test it before we rate it.
- Week 4Ranked register reviewed with the board. Each risk rated for likelihood and impact, with an owner and a date.
- Follow-onSOPs and risk-control matrices for the processes that carry the most risk, so the control exists on paper before anyone audits it.
- A ranked risk register: strategic, operational, financial and compliance.
- Standard operating procedures and risk-control matrices for key processes.
- Process redesign recommendations where the control cannot work as designed.
- A view on fraud, AI and cyber risk specific to the business, not a generic checklist.
Questions
Asked before the first call.
Is this the same as internal audit?
No. Risk advisory decides what matters and designs the control. Internal audit tests whether the control worked. Many clients start here and move to Governance & Controls Assurance or monitoring.
Do you write the SOPs or review ours?
Either. Where SOPs exist we test them against practice and rewrite the gaps. Where they do not, we write them with the process owner and attach the risk-control matrix that tests them.
How long does a risk assessment take?
Four weeks for a single-location business; longer for multi-division groups. The register is then refreshed annually.
Can the highest risks be monitored continuously?
Yes. The register is built so that the top risks become data tests that Continuous Control Monitoring runs every cycle.
Related practices