Approach

Evidence before opinion.

Our standard engagement architecture is structured around six stages and adapted to the written scope of each mandate. The expected stages, principal information requirements and reporting basis are agreed at the outset, with material scope changes documented if they arise.

Principles

Four commitments that shape every engagement.

These are the rules we apply to our own work. They exist because reviews that skip them tend to produce findings that cannot be defended later.

01

Scope is agreed in writing first

No review begins before the firm profile, risk areas, files in scope, stakeholders, reporting lines and deliverables are recorded and agreed. Undefined scope produces findings nobody owns and conclusions nobody can act on.

02

Evidence over assertion

A control counts as evidenced when a reviewer can locate the record, identify its owner and see when it was last reviewed. Where a control is confirmed verbally but not documented, it is reported as undocumented rather than absent.

03

Severity reflects consequence

Findings are rated by the consequence of failure, not by how many were found. One unowned control over a high-risk client relationship matters more than twenty formatting inconsistencies in a policy library.

04

Closure has to be demonstrable

A remediation action is not closed when it is agreed. It is closed when the updated control, its named owner, its effective date and its supporting evidence are recorded and can be produced on request.

Engagement

How an engagement actually runs.

Six stages provide the standard architecture. The information requested and outputs produced are adapted to the written scope, intended use and circumstances of each mandate.

  1. 01

    Scope

    Establish what is being reviewed, why, and what the output needs to support. This is where the engagement is bounded.

    What we request

    • Firm profile, services and client base
    • Current risk assessment, if one exists
    • Names of control owners and approvers

    Representative outputs may include

    • Written scope and engagement basis
    • Document request list
    • Agreed reporting format
  2. 02

    Map

    Set out the obligations that apply, who owns each one, and where the supporting evidence is meant to live.

    What we request

    • Policy and procedure library
    • Approval routes and delegated authority records
    • Registers, logs and governance calendars

    Representative outputs may include

    • Obligation and ownership map
    • Evidence source inventory
    • Initial gap observations
  3. 03

    Review

    Review the agreed documents, files and workflows against the recorded criteria, with the basis and coverage of the review documented proportionately to the mandate.

    What we request

    • Relevant client and counterparty files
    • Screening and monitoring records
    • Committee minutes and decision records

    Representative outputs may include

    • Documented review record
    • Recorded review basis and coverage note
    • Exception log
  4. 04

    Evidence

    Identify what is missing, inconsistent, outdated or unowned, and distinguish a control that does not exist from one that exists but is not documented.

    What we request

    • Clarification on unowned or undated records
    • Access to prior review or remediation history

    Representative outputs may include

    • Evidence gap schedule
    • Ownership exceptions
    • Document currency assessment
  5. 05

    Report

    Present findings with severity ratings, the evidence behind each one, and management actions written so an owner can act without further interpretation.

    What we request

    • Management response to draft findings
    • Confirmation of accepted actions and owners

    Representative outputs may include

    • Severity-rated findings report
    • Board or committee summary pack
    • Prioritised action schedule
  6. 06

    Remediate

    Support the closure trail: updated controls, named owners, effective dates and the evidence that demonstrates the action was actually completed.

    What we request

    • Updated policies, registers and control records
    • Owner confirmation of completion

    Representative outputs may include

    • Action tracker with closure evidence
    • Follow-up review note
    • Residual issue summary
Standards

What makes a file review-ready.

These are the tests we apply when assessing whether evidence would survive review by a bank, insurer, counterparty or regulated stakeholder.

  • Every record is attributable to a named owner, not a department.
  • Every document carries a version, an approval date and a next-review date.
  • Decisions are traceable to the meeting, approver or delegated authority that made them.
  • Screening and monitoring outcomes are retained, not just the fact that screening ran.
  • Exceptions and overrides are recorded with a rationale and an approver.
  • Remediation history is retained so repeat findings are visible over time.
Boundaries

What this work is not.

Being explicit about scope protects both sides. Where a matter falls outside our remit we will say so and recommend you engage an appropriately qualified and authorised adviser.

  • Legal advice or legal representation
  • Statutory audit or assurance opinions
  • Tax advice or tax structuring
  • Investment advice or regulated financial advice

Services are administrative, procedural and advisory support services unless separately agreed in writing. All engagements are subject to conflicts checks and independence considerations.

See the services this method applies to

Start with a scoping discussion.

We will help define the documents, records and control areas worth assessing before any engagement is agreed.