Skip to content

About

The people who do the work

IT audit is a credentials business. You are entitled to know who will be on your engagement, what they are qualified to do, and who signs the report.

Our commitment on staffing

The people named in a proposal are the people who deliver the engagement. If circumstances force a change, we tell you before it happens rather than after you notice.

You will be told at proposal stage who leads the engagement, who performs the fieldwork, and who provides the independent quality review before the report is issued.

Certifications across the practice

Our practitioners hold recognised professional certifications relevant to the work they perform, including:

  • CISA — Certified Information Systems Auditor (ISACA)
  • CISM — Certified Information Security Manager (ISACA)
  • CRISC — Certified in Risk and Information Systems Control (ISACA)
  • CISSP — Certified Information Systems Security Professional (ISC2)
  • ISO/IEC 27001 Lead Auditor and Lead Implementer
  • ISO 22301 Lead Auditor for business continuity engagements
  • Offensive security certifications for the technical testing team

Quality review

Every report is subject to independent review by a practitioner who did not perform the fieldwork, before it is issued. The reviewer checks that conclusions are supported by evidence in the working paper file, that findings are rated consistently, and that the report says what the evidence supports rather than what would be more comfortable.

That review sits inside a wider approach set out in our methodology. The certifications behind it are listed under credentials.

Joining the team

We recruit continuously across IT audit, information security advisory and technical testing. If the work described here is what you want to be doing, see current openings.

Note for the site owner (this block disappears automatically once populated): TEAM PROFILES: add named practitioners with photographs, role, certifications and a short biography in src/content/pages.js -> team.people. Named people with verifiable credentials are the single strongest trust signal on a professional services site. Leaving this section generic is a missed opportunity.

Frequently asked questions

The engagement partner named in your proposal. The report identifies who performed the work and who reviewed it, so accountability is visible rather than institutional.

Not without telling you. Where a specialist skill sits outside the core team — a particular platform or a specialised testing discipline — we say so in the proposal and name the individual. You should never discover a subcontractor by reading the report.

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top