Internal Audit

CAPABILITY STATEMENT

Internal Audit

IA Outsourcing

End-to-end internal audit solutions tailored to your business, governance.

Risk Assessment

Identify, assess, and prioritise key risks to strengthen decision.

Co-Sourcing

Enhance your internal audit capability with experienced professionals.

Secondments

Flexible audit specialists to support projects, resource gaps.

Quality Assurance

Independent quality assessments aligned with the (GIAS).

IT Internal Audit

Evaluate IT controls, cybersecurity, and digital risk.

CAPABILITY STATEMENT

Internal Audit

Independent assurance, delivered with rigour and insight

  • IA Outsourcing
  • Risk Assessment
  • Co-Sourcing
  • Secondments
  • Quality Assurance
  • IT Internal Audit
0 +
Years combined IA leadership
1
Regulatory regimes covered
1 +
Senior-led engagements
1 A
IPPF 2024 aligned

Our Internal Audit Methodology

Every engagement follows a disciplined five-phase approach, aligned to the Global Internal Audit Standards (GIAS) and calibrated to your risk profile.

0

Planning & Risk Assessment

Scoping workshops, regulatory context, audit plan sign-off

0

Fieldwork

Walkthroughs, control testing, sampling, interviews

0

Findings & Analysis

5C findings, root cause, risk rating, quality review

0

Reporting

Draft to management, responses, final report to Board

0

Follow-Up

Action tracking, remediation validation, AC reporting

5C finding model:   Criteria   ·   Condition   ·   Cause   ·   Consequence   ·   Corrective Action

METHODOLOGY

Built for rigour, designed for insight

Risk-based scoping
We focus effort where it matters — material risks and regulatory priorities, not a generic checklist.
Evidence-led testing
Design and operating effectiveness tested against clear criteria, with documented working papers.
Root-cause analysis
Findings go beyond symptoms to the underlying cause, so remediation actually sticks.
Closed-loop follow-up
Agreed actions tracked to closure with validation — assurance that issues are genuinely resolved.

Standards we hold ourselves to

Global Internal Audit Standards (GIAS)
COSO Internal Control Framework
ISO 31000 Risk Management
Sector-specific regulatory codes

Internal Audit Services

Five flexible delivery models, scaled to your needs — from fully outsourced functions to targeted specialist support.

IA Outsourcing

We assume full responsibility for your internal audit function as a managed service — from risk-based annual planning through delivery…

IA Co-Sourcing

We complement your existing internal audit team — providing technical specialists, surge capacity for peak periods, and methodology support.

IA Secondments

We place experienced internal auditors directly within your organisation for a defined period — covering leadership gaps, leading specific projects,…

Quality Assurance Reviews

We provide independent External Quality Assessments (EQA) of your internal audit function against the IIA Standards — the assessment the…

IT Internal Audit

Assurance over the technology controls and cyber resilience your business depends on.
BEYOND THE CORE

Complementary capability areas

Our internal audit practice is supported by deep specialist capabilities that we bring into engagements as needed.

IT & Cyber Audit
ITGC, cyber resilience, cloud, and data protection reviews
Financial Controls / ICFR
Controls design, testing, and SOX-style attestation support
Regulatory Compliance
Compliance framework reviews and regulatory readiness
Risk Management
ERM framework design, risk appetite, and assurance mapping
Internal Controls
Controls rationalisation, optimisation, and remediation
Data Analytics
Full-population testing and continuous auditing techniques
GETTING STARTED

How an engagement begins

A straightforward path from first conversation to assurance delivered.

0

Discovery Call

Understand your needs, risks, and the assurance gap

0

Scope & Proposal

Tailored scope, approach, timeline, and fixed fee

0

Mobilisation

Engagement letter, planning, and stakeholder onboarding

0

Delivery

Risk-based execution with regular progress updates

0

Reporting & follow-up

Board-ready reporting and tracked remediation

Sector Expertise

We bring deep sector knowledge and an understanding of the regulatory environment specific to each industry we serve.

Banking & Capital Markets

FSRA • PRA • Basel

Asset & Wealth Management

FSRA • DFSA • CIR

Insurance

PRA • Solvency II

Energy & Utilities

Sector regulators

Healthcare & Life Sciences

Sector compliance

Retail & Consumer

Trading standards

Aviation & Transport

CAA • safety regimes

x

x

MNA Risk & Technology Advisory provides independent technology audit and assurance to regulated and high-growth organisations. We combine deep IT and cyber expertise with audit discipline — giving boards confidence that technology risk is understood and controlled. learn more…

Contact us

Unit RT-208, Level 1 Gate Avenue – South Zone, Dubai International Financial Centre, UAE.

Call us: +971 55618 4721

Mon – Sat: 8.00am – 18.00pm