Internal Controls over Financial Reporting
ICFR implementation and readiness — aligned to ADAA requirements for government entities
- Full Implementation
- Readiness Reviews
- ADAA Aligned
- COSO 2013
Our ICFR Methodology
A disciplined six-phase methodology, mapped to the COSO 2013 framework and calibrated to ADAA’s expectations for Subject Entities.
COSO 2013 anchored:  Control Environment · Risk Assessment · Control Activities · Information & Communication · Monitoring
Built for assurance, designed to last
How we support your ICFR journey
Our review benchmarks your ICFR against a five-level maturity model and produces a clear readiness rating.
Full ICFR Implementation
For entities new to ICFR or rebuilding
We design and build your entire ICFR framework from the ground up — establishing the scope, documenting processes, creating the risk-control matrix, testing controls, and supporting the first management assertion in line with ADAA requirements.
WHEN IT FITS
- You are a new ADAA Subject Entity
- You have no formal ICFR framework in place
- Your current controls are undocumented
- You are preparing for first-time attestation
WHAT WE DELIVER
- ICFR scoping & materiality
- Process narratives & flowcharts
- Risk-control matrix (RCM)
- Control design assessment
- Operating effectiveness testing
- Deficiency & remediation log
- Management assertion support
- Auditor coordination
ICFR Readiness Reviews
For entities with ICFR already underway
We independently assess the maturity and completeness of your existing ICFR framework against ADAA requirements and COSO 2013 — identifying gaps, control weaknesses, and the actions needed to reach attestation readiness.
WHEN IT FITS
- You have ICFR but are unsure it’s complete
- Attestation is approaching and you need assurance
- You want an independent second opinion
- A prior review raised concerns to address
WHAT WE DELIVER
- ICFR maturity assessment
- Documentation completeness review
- Sample control walkthroughs
- Attestation-readiness rating
- Gap analysis vs ADAA & COSO
- Control design evaluation
- Prioritised remediation roadmap
- Board / management report
How we rate attestation readiness
Our review benchmarks your ICFR against a five-level maturity model and produces a clear readiness rating.
Initial
Ad hoc controls, little documentation
Developing
Some documentation, inconsistent testing
Defined
Framework documented, controls identified
Managed
Controls tested, deficiencies tracked
Optimised
Attestation-ready, continuously monitored
Your ICFR deliverables
Our enterprise risk practice is underpinned by deep expertise across every major risk category.
How an engagement begins
A clear path from first conversation to ICFR attestation readiness.
Discovery Call
Understand your ADAA obligations and current ICFR state
Scope & Proposal
Tailored scope, approach, timeline, and fixed fee
Mobilisation
Engagement letter, planning, stakeholder onboarding
Delivery
Implementation or readiness review with regular updates
Assert & embed
Attestation support and sustainable handover
