About
The people who do the work
IT audit is a credentials business. You are entitled to know who will be on your engagement, what they are qualified to do, and who signs the report.
Our commitment on staffing
The people named in a proposal are the people who deliver the engagement. If circumstances force a change, we tell you before it happens rather than after you notice.
You will be told at proposal stage who leads the engagement, who performs the fieldwork, and who provides the independent quality review before the report is issued.
Certifications across the practice
Our practitioners hold recognised professional certifications relevant to the work they perform, including:
- CISA — Certified Information Systems Auditor (ISACA)
- CISM — Certified Information Security Manager (ISACA)
- CRISC — Certified in Risk and Information Systems Control (ISACA)
- CISSP — Certified Information Systems Security Professional (ISC2)
- ISO/IEC 27001 Lead Auditor and Lead Implementer
- ISO 22301 Lead Auditor for business continuity engagements
- Offensive security certifications for the technical testing team
Quality review
Every report is subject to independent review by a practitioner who did not perform the fieldwork, before it is issued. The reviewer checks that conclusions are supported by evidence in the working paper file, that findings are rated consistently, and that the report says what the evidence supports rather than what would be more comfortable.
That review sits inside a wider approach set out in our methodology. The certifications behind it are listed under credentials.
Joining the team
We recruit continuously across IT audit, information security advisory and technical testing. If the work described here is what you want to be doing, see current openings.
Frequently asked questions
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal