Independent testing of whether your IT general controls, application and SAP controls actually operate, not just whether they exist. We test against evidence, prove where controls fail, and hand you a prioritised path to close the gaps.
An independent audit of your IT control environment: access management, change control, IT operations and the application and SAP controls your business relies on. We test design and operating effectiveness against evidence to demonstrate genuine control reliability, not just documented intent.
Findings are framed for King IV and POPIA from the outset. Work is conducted from local infrastructure to respect data-residency expectations, and every report speaks directly to the board’s technology governance duties, so your audit committee and compliance teams aren’t left translating.
A defined lifecycle, not a one-off review. Every engagement runs the same five stages so results are repeatable and defensible.
We agree the control environment, systems in scope, evidence requests and access. Objectives and rules of engagement are documented before fieldwork begins.
Design and operating-effectiveness testing by senior auditors, using data analytics to examine whole populations and traceable evidence for every conclusion.
A board-ready summary over a technical appendix. Every finding carries a risk rating, evidence, business impact and clear remediation guidance.
We walk your engineers through fixes, prioritised by risk, and stay available for questions while your team closes the gaps.
Once fixes are in, we re-test the findings and issue an issue-closure verification confirming closure, the evidence your auditors want.
A board-ready narrative with a risk-rated finding register, control ratings, evidence and step-by-step remediation.
A live register of findings with owners, priorities and status, mirrored in the assurance dashboard.
Independent confirmation that critical and high findings have been resolved, suitable for auditors and regulators.
A live walkthrough for your technical and leadership teams, with attack narratives and prioritised next steps.
This engagement directly supports the control and assurance requirements of the frameworks your regulators and partners expect.
No, the engagement is designed around your operations. We agree scope, timing and evidence requests up front, work through read-only access wherever possible, and keep a single point of contact live throughout so requests stay coordinated.
A checklist tells you whether a control exists; it can't tell you whether it actually operates. Our auditors test design and operating effectiveness against evidence, use data analytics to examine whole populations rather than samples, and rule out the false comfort that tick-box reviews create.
Yes. Once you've remediated, we re-test every high and critical finding and issue a verification confirming closure, at no extra cost within the agreed engagement window. It's the evidence auditors and the board actually ask for.
Work runs from South African infrastructure, evidence is stored encrypted and purged on an agreed schedule, and our team operates under a signed engagement and NDA. Reports are written to speak directly to POPIA and the Information Regulator's expectations.
Senior, experienced IT auditors based in South Africa, never outsourced or offshored. You'll know your engagement lead by name, and they'll be the one presenting your debrief.
Tell us about your control environment and we’ll scope an audit, with clear timing, a fixed price, and an issue-closure retest built in.