Laurelle Nob ConsultingLN ConsultingManagement · Organisation · Internal control

HomeServicesInternal control and risk management

Internal control and risk management

Secure flows, assets and financial information, without weighing operations down.

Internal control is not a layer of bureaucracy: it is what lets management delegate without losing oversight. The engagement identifies the organisation's real risks (fraud, error, non-compliance) and puts in place proportionate, documented, verifiable controls.

What the engagement covers

  • Process diagnosis

    Description of key processes (purchasing, sales, cash, payroll, fixed assets) as they actually operate, strengths and weaknesses included.

  • Risk mapping

    Identification and rating of risks by process, a criticality matrix, and prioritisation of treatment.

  • Segregation of duties

    Analysis of incompatible role combinations and reorganisation of access rights, including in IT tools.

  • Remediation plans

    For each retained weakness: a control, an owner, a deadline, an expected item of evidence. Implementation follow-up.

Risk map A likelihood and impact matrix with graded criticality shading, plotted risks and a critical zone at top right. CRITICAL ZONE Impact Low High Likelihood Low High R5R4R3 R6R2R1 rated and monitored risk high criticality: priority remediation plan, designated owner
The criticality matrix: every risk is rated, plotted, then given a control and an owner.

Approach

The same sequence on every engagement, from scoping to delivery.

1 · Scoping
Engagement letter, confidentiality agreement, scope of processes covered and timeline.
2 · Fieldwork
Interviews, observation of operations, walkthrough tests on real documents: the diagnosis describes what happens, not what should happen.
3 · Reporting
Risk map, findings ranked by criticality and a remediation plan discussed with management: no fictitious controls, no unassigned responsibilities.
4 · Follow-up
Progress reviews on remediation, at the frequency agreed in the proposal.

Typical deliverables

Dated, sourced documents, ready to use: for management, the board or the auditor.

  • Risk map

    The criticality matrix and its rating method, reusable from one year to the next.

  • Diagnostic report

    Documented, ranked findings, each tied to its evidence and its concrete impact.

  • Segregation-of-duties matrix

    Incompatible functions, observed accumulations and proposed reassignments.

  • Remediation plan

    Controls, owners, deadlines and expected evidence: a follow-up document, not a list of intentions.

Every engagement is framed by an engagement letter and a confidentiality agreement. Scope, timeline and deliverables are set before work starts; duration depends on the agreed scope and is stated in the proposal. This work is organisational and internal-control consulting; it does not include auditing, certification of accounts or statutory audit.

A first conversation, with no obligation.

In English or in French. Acknowledgement of receipt within 24 business hours.

Get in touch
You are offline. Pages already visited remain readable.