Outsourced Internal Audit
PGS takes on the Internal Audit function, including planning, risk assessment, definition of engagements, performance of tests, issuance of reports and follow-up of action plans.
PGS’s Internal Audit assesses processes, controls and risks relevant to the organization, turning technical findings into clear, prioritized and actionable recommendations.
PGS / Internal Audit
The goal is not only to point out failures, but to understand their causes, assess their possible effects and contribute to strengthening governance, information security and operational efficiency.
Internal Audit should help management and those charged with governance answer essential questions:
Are the organization’s main risks identified and properly monitored?
Are existing controls sufficient and operating effectively?
Is there adequate segregation of duties, approval authorities and responsibilities?
Is accounting, financial and management information reliable?
Do processes protect assets and reduce the possibility of errors or fraud?
Are internal policies and legal and regulatory requirements being complied with?
Are recommendations and action plans followed up by management?
PGS structures its work so that the answers are supported by evidence and lead to concrete actions.
PGS takes on the Internal Audit function, including planning, risk assessment, definition of engagements, performance of tests, issuance of reports and follow-up of action plans.
Working together with the organization’s internal team, adding technical experience, methodology, specialization and execution capacity.
Independent assessment of an area, process or situation considered relevant by management, the Board of Directors, the Fiscal Council or the Audit Committee.
Initial mapping of the main processes, risks and controls, identifying vulnerabilities and defining improvement priorities.
The work may cover, among others, the following areas:
Understand — getting to know the organization’s structure, operations, systems, responsible parties and objectives.
Identify the risks — assessing events that could compromise operations, assets, information, compliance, reputation or business continuity.
Assess the controls — verifying whether controls have been properly designed, implemented and performed.
Test — conducting interviews, document inspections, reconciliations, data analyses and sample testing, according to the defined scope.
Communicate — presenting findings, risks and possible effects, evidence observed and applicable recommendations.
Follow up — monitoring, when engaged, the action plans, responsible parties and deadlines set by management.
The experience PGS has accumulated in auditing, internal controls, accounting, governance and consulting has been organized into its own Findings Database, comprising 524 internal control situations classified by area and subject.
The database supports risk identification, engagement planning and the preparation of recommendations. Each situation is analyzed according to the organization’s context, size, complexity and specific risks.
Important: The Findings Database does not replace professional judgment and does not produce automatic conclusions. It is an exclusive PGS technical resource, used to support the performance of our engagements.
Depending on the contracted scope, the work may result in:
A well-structured Internal Audit can help:
The absence of known losses does not mean that controls are sufficient. Processes can run for years relying on informal knowledge, concentration of responsibilities or checks that leave no evidence.
PGS helps your organization identify relevant risks, assess existing controls and set realistic improvement priorities.
No. The purpose of an independent audit is to express an opinion on the financial statements. Internal Audit assesses processes, risks, controls and governance, according to a plan defined to meet the organization’s needs.
Yes. PGS can work on a co-sourcing basis, support specific projects, provide specialized knowledge or perform independent assessments on specific topics.
The procedures can identify indications, vulnerabilities and situations that increase the risk of fraud. However, Internal Audit does not guarantee that all existing fraud will be detected.
No. The scope can be defined based on risks, the relevance of processes and the priorities of management or those charged with governance.
No. The Findings Database supports planning and expands the ability to identify risks, but each situation must be analyzed within the organization’s context.
Tell PGS which risks, processes or controls need greater visibility. The team will get in touch to understand the context and discuss an appropriate scope.