Case study one: Supporting digital transformation for one large charity
A leading charitable organisation and its associated financial services arm were undergoing a major digital transformation, replacing legacy systems with modern, cloud-native technologies to enhance resilience and operational efficiency.
As their outsourced internal audit partner, we played a critical role in supporting this transformation. We conducted targeted assessments of both current and future-state technologies, focusing on key risks around data confidentiality, integrity, and availability. Our work also evaluated the governance and implementation frameworks underpinning the transformation programme.
To further strengthen internal controls, we now provide continuous assurance throughout the programme’s lifecycle. This includes active participation in governance forums, such as steering committees and go-live decision-making, as an independent and objective voice. We also conduct regular health checks, deep dives, and readiness assessments.
Impact: Our involvement has helped embed robust controls from day one, reducing the risk of implementation failure and ensuring the organisation is well-positioned to realise the full benefits of its digital investments.
Case study two: Enhancing technology assurance for a consumer-focused not-for-profit
A prominent consumer advocacy organisation with a complex IT landscape - including cloud-based customer platforms and enterprise systems like ERP, CRM, and HCM - engaged us as a co-sourced internal audit partner.
Our work has focused on delivering assurance aligned to the organisation’s principal risks. We conducted in-depth reviews of high-risk areas such as the software development lifecycle, cloud configuration, and security management. Our approach goes beyond control effectiveness, also evaluating the scalability and efficiency of systems and processes.
Impact: We’ve provided assurance over key strategic decisions related to security and product development, while also delivering actionable recommendations to reduce risk across both product and corporate IT environments.