Compliance Audit

The engagement is performed where the outcome is to be submitted to a third party. The client is the organisation; the addressee of the conclusion is a regulator, a parent company, a group auditor, a lender or an international development institution.

What distinguishes this service from the others is not the depth of the examination but its form and the requirements that follow from it. The conclusion must be expressed against criteria settled in advance, supported by sufficient evidence and set out so that the addressee may rely upon it without knowledge of how the work was conducted.

Hence the sequence: the criteria are agreed before work begins and are not thereafter varied, the extent of procedures follows from the degree of assurance required, and every statement in the report has a traceable basis in the working papers.

To obtain a preliminary estimate of scope, timing and fees, please complete the questionnaire. A response is provided within several business days.

Download the questionnaire

Circumstances of engagement

Regulatory requirement
Group requirement
Lender or donor requirement

An organisation supervised by a financial regulator must procure an examination within a prescribed period and submit its results. The form of the report and the areas covered follow from the requirements of the regulator.

A parent company or group auditor sets its own expectations as to the control environment of a subsidiary. The examination is performed against those expectations and the report is ordinarily prepared in English.

A bank, investor or international development institution makes financing conditional upon confirmation of the state of information technology and information protection. The criteria follow from the terms of the agreement.

     

Areas covered

The areas covered follow from the criteria agreed. A typical scope comprises:

  • governance of information technology: allocation of authority and accountability, planning, and interaction with the governing bodies of the organisation
  • access management: granting, amendment and withdrawal of rights, segregation of privileged accounts, and periodic recertification
  • change management: initiation, approval, testing and migration of changes into production, and separation of environments
  • operations management: job scheduling, incident handling, monitoring, and maintenance of equipment and system software
  • backup and recovery, including confirmation of restorability in practice
  • business continuity: plans, allocation of roles, test results and alternate sites
  • information protection: perimeter and endpoint security, malware controls, vulnerability management and event response
  • physical security of premises where information is processed and stored, and supporting engineering systems
  • management of relationships with service providers and contractors, including oversight of performance and access by supplier personnel
  • processing and protection of restricted information, including personal data

Each control is considered in two respects: whether it is capable of achieving its stated objective by design, and whether it was in fact performed at the established frequency throughout the period under examination.

The place of technical security testing

Technical procedures — vulnerability scanning, configuration benchmarking and penetration testing — form part of the toolkit and are applied where they yield evidence bearing on the agreed criteria.

Their standalone value is limited. The result is a snapshot as at the date of testing. In an organisation where change, access and vulnerability management are not established, the state alters faster than the report can be issued, and repeat scanning after a short interval yields a different list. Technical procedures are therefore applied once it has been established how the organisation manages change and vulnerabilities, and their results are interpreted in that light.

Organisations seeking solely a list of technical vulnerabilities, without regard to the underlying processes, will wish to weigh that limitation when framing their request.

Course of the engagement

1
Agreement of criteria and scope

The requirements against which the conclusion is to be expressed, the degree of assurance required and the period under examination are settled. The controls to be examined follow from the criteria selected.

The scope is recorded in the engagement contract; any subsequent change is documented by an addendum.

2
Request for materials and planning of procedures

A structured schedule of requested documents, extracts and logs is issued. On the basis of the materials received, the procedures, sample sizes and interview timetable are determined.

3
Fieldwork

Inspection of documents, interviews, observation, analysis of configurations and extracts, reperformance of control procedures, sample testing of operating effectiveness, analytical procedures and, where required, technical testing are applied.

4
Evaluation and discussion

Findings are related to the criteria, supported by evidence and assessed for significance. Preliminary results are discussed with the responsible members of staff before inclusion in the report.

5
Report and presentation of results

A signed report is delivered. By arrangement, the results are presented to the board of directors, the audit committee or another body, and explanatory materials are prepared for the addressee of the conclusion.

Deliverables

  • a report setting out the scope, the procedures applied and the conclusion expressed against the agreed criteria
  • a schedule of findings identifying the criterion contravened, the supporting evidence and the risk assessment
  • a register of recommendations with an indication of priority and of expected remediation timescales
  • a management letter setting out observations that do not bear on the conclusion but merit attention
  • where required, materials for submission to the governing bodies and to the addressee of the conclusion

Timescales

Fieldwork on a comprehensive engagement ordinarily takes six to twelve weeks, depending on the number of systems, sites and legal entities. Preparation of the report takes a further two to three weeks after fieldwork concludes.

A scheduling lead time of four to eight weeks is additional. Where the engagement is tied to a deadline set by a regulator, please indicate this at first contact: the timetable is built backwards from the date on which the results are to be submitted.

Related services

Where an examination of a single system or a single rule is required, without covering the organisation as a whole, a different service applies: Information systems examination →.

Frequently asked questions

What distinguishes a review engagement from one expressing an independent conclusion

The extent of procedures and the form of the conclusion. A review engagement affords limited assurance and is expressed as a statement that nothing has come to attention indicating non-compliance. An engagement expressing an independent conclusion requires substantially more work and concludes with a direct statement of compliance or non-compliance.

What happens if significant divergences are identified

They are included in the report, identifying the criterion, the evidence and the risk assessment, and are accompanied by recommendations. The organisation may submit explanations and information on the measures being taken, which are reflected in the report. Suppressing matters identified is incompatible with the nature of the engagement.

May the engagement be confined to selected areas

Yes, provided the limitation is agreed with the addressee of the conclusion and reflected in the description of scope. Any limitation of scope is stated expressly in the report.

Is remediation subsequently verified

Yes, under a separate engagement. Such verification is performed against the findings previously raised and concludes with a statement on the state of their remediation.

In what language is the report prepared

In Russian or English, at the choice of the organisation. Reports prepared for a parent company or an international development institution ordinarily require English.