Audit & Assurance
Targeted Reviews
One area, examined properly, finished in a fortnight. For when you know exactly what the question is and do not need a full audit to answer it.
When a targeted review is the right instrument
- An external auditor raised a specific deficiency and you need it independently validated as closed.
- A regulator asked a pointed question about one control area.
- An incident exposed a weakness and the board wants to know how far it extends.
- You are about to make a significant investment decision and need an evidenced baseline first.
- A full audit is not affordable this cycle, but leaving the highest-risk area untouched is not acceptable either.
Common scopes
- Privileged access review — who holds administrative rights across the estate, how they were granted, whether they are still needed, and whether their use is logged and reviewed.
- User access recertification review — whether the periodic review actually happens, whether reviewers read what they approve, and whether removals get actioned.
- Change management review — the standard path usually works; this examines the emergency path, which is where control failures concentrate.
- Backup and recovery review — not whether backups complete, but whether a restore has been proven, and whether it meets the recovery objectives you have published.
- Vendor and third-party risk review — whether contractual security requirements are monitored in operation, or only signed.
- Segregation of duties review — conflicting access combinations in a specific application.
Pick one area and finish it
Scope discipline
The value of a targeted review is entirely in its boundary. Adjacent problems always surface during fieldwork — that is the nature of the work. We record them, we tell you about them, and we do not quietly absorb them into the scope.
If something we find genuinely changes the risk picture, we raise it immediately and you decide whether to extend. What we will not do is deliver a review that took three times the agreed effort because it kept growing.
What you get, and what you do not
You get a properly evidenced conclusion on one area, at the same testing and documentation standard as a full audit. You do not get an opinion on anything outside that boundary, and the report says so explicitly — an unbounded conclusion drawn from a narrow scope is exactly the kind of thing that fails an external quality review.
How the engagement runs
-
1
Define the boundary
Agree in writing the single area, the systems, the period and — critically — what is excluded.
-
2
Programme design
A small number of control objectives, tested properly, rather than broad shallow coverage.
-
3
Evidence request
Issued up front, with population completeness agreed before any sampling.
-
4
Fieldwork
Typically five to ten days depending on the area and estate size.
-
5
Validation
Every exception discussed with the control owner before it becomes a finding.
-
6
Report
Short, specific, and explicit about the scope boundary.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal