Skip to main content

Services / Internal Audit & Controls

Controls embedded, not added later

We deliver the full IPPF audit lifecycle, continuous control monitoring, and immutable audit trails, all on Frappe/ERPNext. Designed by a CPA-K-led team that treats the general ledger as sacred.

The IPPF lifecycle, five stages

Audit universe & annual plan

Plan

A risk-scored audit universe, inherent and residual risk, drives a prioritised, budgeted annual audit plan. Audit effort goes where the risk actually is, not where the calendar says.

Engagement & working papers

Execute

Engagements run through a role-gated Planning, Fieldwork, Reporting, Issued workflow. Working papers carry prepared-by and reviewed-by sign-off with full version history.

Findings & AI review

Find

Findings capture condition, criteria, cause, and consequence with a severity and risk score. An opt-in AI reviewer enriches and stress-tests each finding; the auditor keeps sign-off.

CAP & follow-up

Remediate

Every finding drives a Corrective Action Plan with an owner, milestones, and verification. A follow-up tracker reopens regressions automatically until the fix is confirmed closed.

Board & committee reporting

Report

Standardised board reports and quarterly audit-committee briefings close the loop from finding to fixed, on a schedule the committee can rely on.

Between audits

What watches the business while you are not looking

The lifecycle above runs on a schedule. These controls run all the time.

Immutable audit trails

Every insert, update, and trash on 20+ core ERP doctypes, GL Entry, Journal Entry, Payment Entry, Sales and Purchase Invoice, Salary Slip, Stock Entry, User and Role changes, writes an immutable audit trail entry automatically.

Continuous control monitoring

Rule-based control tests run hourly against live ERP data, raising monitoring exceptions and anomaly alerts between formal audits, not just at period end.

Segregation of duties

Nine role-gated permissions, Chief Audit Executive, Audit Manager, Auditor, Reviewer, Risk Manager, Compliance Officer, Committee Member, Management, enforce explicit permission checks in code rather than blanket overrides.

Whistleblower intake

A public web-form intake with an investigation log gives your organisation a documented ethics channel, not an informal one routed through someone's inbox.

Ready to harden your controls?

We will map your control environment, wire continuous monitoring, and turn audit findings into a tracked, closable workflow.

Book an Audit Review