Businesses growing faster than their systems
SMEs without an internal audit team
An independent view of risks and controls without building a full-time team.
Family businesses
Separate owner and management roles, set approval authorities and build transparency everyone can trust.
Family business →Companies preparing to list
Install and run internal controls before filing, so the company already operates like a listed company.
IPO advisory →Companies changing ERP
Design user access, approval workflows and segregation of duties together with the new system.
ERP & controls →How MMN can help
Outsourced internal audit
A risk-based annual audit plan, audits against the plan, and reporting along the lines set in the internal-audit charter — functionally to the board / audit committee, with administrative coordination with management.
Internal control design & review
Design or review controls with reference to the COSO framework, sized to the business.
Risk assessment
Identify and rank the key business risks, with owners and responses.
Process improvement
Review core processes — purchase-to-pay, order-to-cash, inventory and payroll — to reduce risk and duplicated work.
IPO readiness
Assess internal control gaps against what a listed company is expected to have, and plan the fixes.
IPO readiness check →ERP & system controls
Review user access, segregation of duties and automated controls in the ERP.
Read more →With reference to the COSO framework
The COSO Internal Control — Integrated Framework is widely used to design and assess internal control. It is organised into five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. MMN uses it as a guide and scales it to the size of each business.
- Internal audit helps management look after risks and controls, but does not replace the annual statutory audit of the financial statements.
- If MMN is also the statutory auditor, the applicable independence prohibitions and threats/safeguards are applied first; internal-audit services that are prohibited or would create an unacceptable self-review threat will not be accepted.
Risk-based work, followed through to real fixes
Understand & assess risk
Interview management, map the processes and rank the key risks.
Plan the work
Set up the internal-audit charter and a risk-based scope and plan, for the board / audit committee to approve.
Test & report
Test the controls and report observations with ratings and practical recommendations.
Follow up
Track remediation against the agreed plan and report progress periodically.
Frequently asked questions
How is internal audit different from a statutory audit?
A statutory audit is a licensed auditor’s opinion on the annual financial statements, required by law. Internal audit assesses risks, controls and processes for the board and management — for some organisations (e.g. financial institutions, listed companies) regulators expect or require an internal-audit function; for others it is a governance choice. One does not replace the other.
How much internal control does a company preparing to list need?
Internal control and governance are key elements of listing readiness, so companies usually put the system in place and run it consistently before filing. The right level depends on the size and complexity of the business; the MMN team can help assess the gaps.
Can internal audit be outsourced?
Yes. Companies may outsource internal audit fully or co-source it with an in-house team. MMN can take on this role, with reporting lines set in the internal-audit charter — functional accountability to the board / audit committee (or highest governance body), with administrative coordination with management as appropriate. The company remains responsible for its own internal control.
Should controls be designed before or after an ERP change?
Ideally alongside the ERP implementation — user access, approval workflows and segregation of duties — because fixing them after go-live is usually harder.
Related pages
Start with a conversation about your risks
Tell us which processes worry you and we will help scope internal audit work that fits your business.
Book a meetingThis page is general information for education only — not professional advice for any specific case. Internal control can reduce risk but cannot prevent every error or fraud. Please consult MMN before making decisions or acting.