Risk audit and
internal controls assessment

Comprehensive assessment of risks,
business processes, and control procedures

Effective risk management and a properly designed internal control system help companies achieve strategic objectives, ensure business continuity, safeguard assets, and improve the reliability of management and financial information.

Changes in the business model, business expansion, implementation of new information systems, and increasingly stringent regulatory requirements may create new risks and reduce the effectiveness of existing control procedures.

Kreston Ukraine professionals provide risk audits and internal control system assessments, helping companies identify gaps, evaluate the effectiveness of the control environment, and determine practical areas for improvement.

The approach and scope of work are tailored to the company’s risk assessment results, organisational structure, industry specifics, business processes, and regulatory requirements.

Аудит ризиків, оцінка системи внутрішнього контролю - business people working laptop

AN INTERNAL CONTROL SYSTEM ASSESSMENT MAY BE REQUIRED IF YOUR COMPANY:

enters new markets or launches new products;

is preparing for an audit of financial statements;

has a complex organisational structure;

is attracting an investor or external financing;

is growing, scaling or changing its business model;

is undergoing organisational or digital transformation;

faces recurring errors, losses, violations or cases of fraud;

needs to assess compliance with regulatory or corporate requirements.

Following the assessment, the company receives an independent analysis of the current state of its governance
and control systems, along with practical recommendations for improvement.

Internal Control and Corporate Governance Assessment for Public Sector Entities

Public sector entities are subject to increased requirements regarding governance transparency, control effectiveness, risk management and corporate governance.

Kreston Ukraine provides independent assessments of governance, risk management and internal control systems for large companies and organisations, including public sector entities.

As part of such engagements, we assess:

What Risk Audit and Internal Control System Assessment Include

identification and assessment of corporate risks, including strategic, operational, financial, compliance and IT risks;

analysis of the risk management system and allocation of responsibilities among its participants;

assessment of controls related to the preparation of financial and management reporting;

assessment of preventive controls designed to reduce the risk of errors, violations and fraud;

preparation of recommendations and an action plan for improving the internal control system;

assessment of the control environment and corporate policies;

analysis of key business processes and associated risks;

analysis of the allocation of authority and compliance with the segregation of duties principle;

development of a risk and control matrix;

identification of gaps, duplication or excessive control procedures;

assessment of the design and implementation of control procedures.

The assessment may cover the company’s internal control system as a whole or individual processes, departments, functions or areas of activity.

How Risk Audit and Internal Control System Assessment Are Conducted

1. Defining the Objectives and Scope of Work

We agree on the project objectives, the processes and departments to be covered, assessment criteria and the expected format of the deliverables.

2. Risk Identification and Assessment

Our professionals analyse business processes, internal documents, information flows and the allocation of responsibilities to identify risks that may prevent the company from achieving its objectives.

3. Analysis of Control Procedures

We assess whether control procedures are appropriately designed and implemented and, where necessary, test the operating effectiveness of key controls.

4. Identification of Deficiencies

Based on our analysis, we identify missing, ineffective, excessive or duplicative controls and assess the potential impact of the identified deficiencies.

5. Development of Recommendations

We develop practical recommendations and a prioritised action plan, taking into account the level of risk, the company’s resources and the specifics of its operations.

Following the Internal Control System Assessment, the Company Receives:

The format and scope of the deliverables are determined in accordance with the agreed scope of work.

Why Kreston Ukraine

Kreston Ukraine professionals combine an understanding of the Ukrainian business environment with the international expertise of the Kreston Global network in risk management, internal audit, corporate governance and compliance, including experience working with large corporate structures and public sector entities.

We apply internationally recognised approaches to risk management and internal control, including COSO and IIA practices, as well as corporate governance approaches used by international companies.

When delivering projects, we:

take into account the company’s industry specifics and business model;

focus on the risks that are most significant to the business.

ensure the confidentiality of information received;

provide realistic recommendations that take into account the company’s resources and priorities;

assess not only the existence of documentation but also the practical effectiveness of control procedures.

Frequently Asked Questions

What Is a Risk Audit?

A risk audit is a systematic analysis of risks that may affect the achievement of a company’s strategic and operational objectives. It involves identifying risks, assessing their likelihood and potential impact, and analysing the measures the company uses to manage them.

What Does an Internal Control System Assessment Include?

The assessment covers the control environment, business processes, allocation of authority, information flows and control procedures. Depending on the agreed scope of work, it may also include testing the actual operating effectiveness of key controls.

How Does an Internal Control Assessment Differ from Internal Audit?

An internal control system assessment may be conducted as a standalone engagement focused on specific processes, risks or control procedures. Internal audit is a broader ongoing or periodic function that evaluates corporate governance, risk management and control processes. If a company requires external support for this function, Kreston Ukraine provides internal audit outsourcing and co-sourcing services.

Can You Assess Only a Specific Business Process?

Yes. The assessment may cover an individual process, such as procurement, sales, inventory management, treasury, financial reporting, human resources or information technology.

Does Kreston Ukraine Assess Governance Systems for Public Sector Entities?

Yes. Kreston Ukraine has experience delivering corporate governance, internal control, risk management and compliance projects for large companies and organisations. Where required, we engage professionals with international expertise in corporate governance, internal control and risk management to perform a comprehensive assessment of governance systems.

Does Kreston Ukraine Help Implement the Recommendations?

Yes. Subject to a separate agreement, Kreston Ukraine professionals can provide methodological support in developing control procedures, internal policies, risk and control matrices, as well as an implementation plan for the recommended changes.

Assess Risks and Improve the Effectiveness of Your Internal Control System

Kreston Ukraine will help identify key risks, assess the effectiveness of control procedures and develop practical recommendations to improve the reliability and transparency of business processes.

TRUST YOUR PROJECT TO PROFESSIONALS

JOIN KRESTON