Skip to main content
Identify vulnerabilities. Strengthen controls. Support decisions.

Risk- and results-oriented internal audit

PGS’s Internal Audit assesses processes, controls and risks relevant to the organization, turning technical findings into clear, prioritized and actionable recommendations.

Service line02

PGS / Internal Audit

Overview

Our work takes into account the size, structure, industry and maturity level of each organization.

The goal is not only to point out failures, but to understand their causes, assess their possible effects and contribute to strengthening governance, information security and operational efficiency.

Essential questions

More than checking procedures

Internal Audit should help management and those charged with governance answer essential questions:

  1. 01

    Are the organization’s main risks identified and properly monitored?

  2. 02

    Are existing controls sufficient and operating effectively?

  3. 03

    Is there adequate segregation of duties, approval authorities and responsibilities?

  4. 04

    Is accounting, financial and management information reliable?

  5. 05

    Do processes protect assets and reduce the possibility of errors or fraud?

  6. 06

    Are internal policies and legal and regulatory requirements being complied with?

  7. 07

    Are recommendations and action plans followed up by management?

PGS structures its work so that the answers are supported by evidence and lead to concrete actions.

Engagement models

How PGS can work with you

01

Outsourced Internal Audit

PGS takes on the Internal Audit function, including planning, risk assessment, definition of engagements, performance of tests, issuance of reports and follow-up of action plans.

02

Co-sourcing

Working together with the organization’s internal team, adding technical experience, methodology, specialization and execution capacity.

03

Specific engagements

Independent assessment of an area, process or situation considered relevant by management, the Board of Directors, the Fiscal Council or the Audit Committee.

04

Internal controls diagnosis

Initial mapping of the main processes, risks and controls, identifying vulnerabilities and defining improvement priorities.

Scope

Areas that can be assessed

The work may cover, among others, the following areas:

  • Governance and general management controls
  • Accounting and closing of financial statements
  • Cash, banks, investments and treasury
  • Accounts receivable, credit and collection
  • Purchasing, suppliers and accounts payable
  • Inventory, costs and production
  • Property, plant and equipment and investment property
  • Payroll and human resources
  • Taxes and ancillary obligations
  • Information technology and systems security
  • Contracts, insurance and contingencies
  • Compliance, ethics and fraud prevention
  • Budget, cash flow and management information
  • Related parties and conflicts of interest
  • Business continuity and risk management
Methodology

Our methodology

  1. 01

    Understand — getting to know the organization’s structure, operations, systems, responsible parties and objectives.

  2. 02

    Identify the risks — assessing events that could compromise operations, assets, information, compliance, reputation or business continuity.

  3. 03

    Assess the controls — verifying whether controls have been properly designed, implemented and performed.

  4. 04

    Test — conducting interviews, document inspections, reconciliations, data analyses and sample testing, according to the defined scope.

  5. 05

    Communicate — presenting findings, risks and possible effects, evidence observed and applicable recommendations.

  6. 06

    Follow up — monitoring, when engaged, the action plans, responsible parties and deadlines set by management.

524internal control situations classified by area and subject
Findings Database

Experience turned into applicable knowledge

The experience PGS has accumulated in auditing, internal controls, accounting, governance and consulting has been organized into its own Findings Database, comprising 524 internal control situations classified by area and subject.

The database supports risk identification, engagement planning and the preparation of recommendations. Each situation is analyzed according to the organization’s context, size, complexity and specific risks.

Important: The Findings Database does not replace professional judgment and does not produce automatic conclusions. It is an exclusive PGS technical resource, used to support the performance of our engagements.

Deliverables

Internal Audit deliverables

Depending on the contracted scope, the work may result in:

  • Annual or specific Internal Audit plan
  • Risk and control matrix
  • Process mapping
  • Work programs and tests performed
  • Executive report for management or those charged with governance
  • Classification of findings by relevance
  • Description of findings and evidence
  • Assessment of risks and possible effects
  • Practical, prioritized recommendations
  • Management’s response
  • Assignment of responsible parties and deadlines for remediation
  • Follow-up of action plans
  • Presentation of results to the Board or Audit Committee
Who it is for

Who is this work for?

  • Family businesses going through professionalization
  • Organizations that do not yet have their own Internal Audit function
  • Business groups with decentralized operations
  • Companies that are growing, reorganizing or implementing new systems
  • Organizations subject to contractual or regulatory requirements
  • Boards of Directors, Fiscal Councils and Audit Committees
  • Investors who need greater visibility into risks and controls
  • Organizations that want to prevent losses, errors and fraud
Benefits

Expected benefits

A well-structured Internal Audit can help:

  • Strengthen governance
  • Increase the reliability of information
  • Protect assets and resources
  • Identify vulnerabilities before they turn into losses
  • Reduce the risk of errors, irregularities and non-compliance
  • Improve processes, approval authorities and responsibilities
  • Support accounting, tax and regulatory compliance
  • Improve the follow-up of action plans
  • Provide clearer information to management and those charged with governance
Next step

Are your controls keeping pace with your company’s growth?

The absence of known losses does not mean that controls are sufficient. Processes can run for years relying on informal knowledge, concentration of responsibilities or checks that leave no evidence.

PGS helps your organization identify relevant risks, assess existing controls and set realistic improvement priorities.

Request a diagnosis
Questions

Frequently asked questions

Are internal audit and independent audit the same thing?

No. The purpose of an independent audit is to express an opinion on the financial statements. Internal Audit assesses processes, risks, controls and governance, according to a plan defined to meet the organization’s needs.

Can PGS work with a company that already has an Internal Audit function?

Yes. PGS can work on a co-sourcing basis, support specific projects, provide specialized knowledge or perform independent assessments on specific topics.

Does Internal Audit detect fraud?

The procedures can identify indications, vulnerabilities and situations that increase the risk of fraud. However, Internal Audit does not guarantee that all existing fraud will be detected.

Is it necessary to assess every area of the company?

No. The scope can be defined based on risks, the relevance of processes and the priorities of management or those charged with governance.

Does the Findings Database replace the diagnosis?

No. The Findings Database supports planning and expands the ability to identify risks, but each situation must be analyzed within the organization’s context.

Contact

Talk to a specialist

Tell PGS which risks, processes or controls need greater visibility. The team will get in touch to understand the context and discuss an appropriate scope.

PGSTechnical · Clarity · Proximity
Request a quote or send us your question01 / 01

Only share the information needed for us to contact you. Do not send sensitive personal data.