Service
Audit, Risk Advisory & Assurance
This is the specialism Sarmad Maqsood Paracha leads, and it is a different discipline from year-end compliance work. It covers how a business proves its controls work — to a board, an audit committee, or a regulator — rather than what it reports to HMRC.
What the fee covers
Included as standard
Internal audit, planned around actual risk
A risk-based plan rather than a fixed checklist repeated each year, so effort goes where the exposure is. Delivered in line with the Global Internal Audit Standards (GIAS 2024).
Enterprise risk management
Building or reviewing a risk framework that the board can actually use — registers that get updated, appetite that means something, and reporting that surfaces change rather than restating the same heat map.
Internal controls and IT general controls
Reviewing the controls the rest of the business depends on: access and change management, segregation of duties, and the reconciliations that catch things before they become restatements.
Governance and regulatory compliance
Advising boards and audit committees on governance structures and compliance obligations, drawing on experience across banking, asset management and other regulated industries.
Reporting people will read
Findings written so a non-specialist director can see what the issue is, what it risks, and what to do about it.
Common questions
Questions we get asked about this
Is this the same as a statutory audit?
No. This is internal audit and assurance work carried out for the business itself. Statutory audit is a separate regulated activity with its own registration requirements. If you need a statutory audit, tell us and we will be straight with you about scope.
We are small. Do we need internal audit?
Often not as a standing function. Smaller businesses more usually need a one-off controls review, or help responding to something a lender, insurer or client has asked for. That is a proportionate piece of work, not a permanent overhead.
What does 'aligned to GIAS 2024' actually mean?
The Global Internal Audit Standards set out how internal audit should be planned, performed and reported to be credible to a board. Working to them means the output stands up to outside scrutiny rather than being an internal opinion.
Can you review controls in our systems as well as our processes?
Yes — IT general controls are part of the work, including access management, change control and the interfaces between systems where reconciliation breaks most often.
Next step
Talk to us about audit & risk advisory
A short call, an honest view of what is involved, and a fixed price. No obligation and no sales script.