Practice 01 · Ask before

Where the business can lose money, and what to fix first.

A structured look at where the company can lose money, data or its licence to operate, ranked, owned and dated. Risk assessment, SOPs and risk-control matrices, process redesign, fraud, AI and cyber risk.

Risk AdvisoryPage reviewed October 2026
Who it is for
Promoter-led companies, growing manufacturers and traders, boards preparing to scale or list.
Cycle
Set per engagement; the register is refreshed every year.
You receive
A ranked risk register, SOPs and RCMs for key processes, redesign recommendations, an owner for every risk.
01 · DefinitionWhat it is

We help management see the business the way a lender, an investor or a regulator would: where it can break, how badly, and what it would cost to fix. The output is a short, ranked list, not a catalogue.

02 · TriggerWhen to consider it
  • A new plant, a new ERP, a new lender or a planned listing.
  • Approvals that have outgrown the promoter’s line of sight.
  • A fraud, a near miss, or an auditor’s observation that nobody owned.
  • AI tools already inside payables, payroll or HR without anyone having tested them.
03 · RiskWhat goes wrong without it

Without a ranked register, every risk is equal and none is owned. Controls get written after the loss, SOPs describe what people wish happened, and the board reads about the gap in the auditor’s report.

04 · MethodHow we do it
  1. Week 1Risk conversations with management and the board. How the company makes money, then where that can fail.
  2. Weeks 2 to 3Process walk-throughs. Where a risk can be tested on full data, we test it before we rate it.
  3. Week 4Ranked register reviewed with the board. Each risk rated for likelihood and impact, with an owner and a date.
  4. Follow-onSOPs and risk-control matrices for the processes that carry the most risk, so the control exists on paper before anyone audits it.
05 · OutputWhat you receive
  • A ranked risk register: strategic, operational, financial and compliance.
  • Standard operating procedures and risk-control matrices for key processes.
  • Process redesign recommendations where the control cannot work as designed.
  • A view on fraud, AI and cyber risk specific to the business, not a generic checklist.
Book a conversationStart with a conversation.

Questions

Asked before the first call.

Is this the same as internal audit?

No. Risk advisory decides what matters and designs the control. Internal audit tests whether the control worked. Many clients start here and move to Governance & Controls Assurance or monitoring.

Do you write the SOPs or review ours?

Either. Where SOPs exist we test them against practice and rewrite the gaps. Where they do not, we write them with the process owner and attach the risk-control matrix that tests them.

How long does a risk assessment take?

Four weeks for a single-location business; longer for multi-division groups. The register is then refreshed annually.

Can the highest risks be monitored continuously?

Yes. The register is built so that the top risks become data tests that Continuous Control Monitoring runs every cycle.

Related practices