• Home   /
  • Internal Control over Financial Reporting (ICFR)

Internal Control over Financial Reporting (ICFR)

CAPABILITY STATEMENT

Internal Controls over Financial Reporting

ICFR implementation and readiness — aligned to ADAA requirements for government entities

  • Full Implementation
  • Readiness Reviews
  • ADAA Aligned
  • COSO 2013

Our ICFR Methodology

A disciplined six-phase methodology, mapped to the COSO 2013 framework and calibrated to ADAA’s expectations for Subject Entities.

0

Scoping

Materiality, in-scope accounts & processes
0

Documentation

Process narratives & flowcharts

0

Risk & Controls

RCM, assertions, key controls

0

Design Assessment

Control design effectiveness

0

Operating Testing

Test controls over the period

0

Reporting

Deficiencies, remediation, assertion

COSO 2013 anchored:   Control Environment · Risk Assessment · Control Activities · Information & Communication · Monitoring

RIGOUR & COORDINATION

Built for assurance, designed to last

Risk-based scoping
Effort focused on material accounts and significant processes — proportionate, not exhaustive.
Assertion-level controls
Every key control mapped to financial statement assertions and COSO principles.
No surprises governance
Deficiencies surfaced and discussed with management and auditors as they arise.
Sustainable embedding
Frameworks designed for the entity to operate independently after handover.

Standards we hold ourselves to

ADAA Law No. 1 of 2017
COSO 2013 Internal Control
ADAA audit standards (ICOFR)
IIA IPPF & ISA 315 principles

OUR TWO CORE SERVICES

How we support your ICFR journey

Our review benchmarks your ICFR against a five-level maturity model and produces a clear readiness rating.

SERVICE 1

Full ICFR Implementation

For entities new to ICFR or rebuilding

We design and build your entire ICFR framework from the ground up — establishing the scope, documenting processes, creating the risk-control matrix, testing controls, and supporting the first management assertion in line with ADAA requirements.

WHEN IT FITS

  • You are a new ADAA Subject Entity
  • You have no formal ICFR framework in place
  • Your current controls are undocumented
  • You are preparing for first-time attestation

WHAT WE DELIVER

  • ICFR scoping & materiality
  • Process narratives & flowcharts
  • Risk-control matrix (RCM)
  • Control design assessment
  • Operating effectiveness testing
  • Deficiency & remediation log
  • Management assertion support
  • Auditor coordination

SERVICE 2

ICFR Readiness Reviews

For entities with ICFR already underway

We independently assess the maturity and completeness of your existing ICFR framework against ADAA requirements and COSO 2013 — identifying gaps, control weaknesses, and the actions needed to reach attestation readiness.

WHEN IT FITS

  • You have ICFR but are unsure it’s complete
  • Attestation is approaching and you need assurance
  • You want an independent second opinion
  • A prior review raised concerns to address

WHAT WE DELIVER

  • ICFR maturity assessment
  • Documentation completeness review
  • Sample control walkthroughs
  • Attestation-readiness rating
  • Gap analysis vs ADAA & COSO
  • Control design evaluation
  • Prioritised remediation roadmap
  • Board / management report
READINESS REVIEWS

How we rate attestation readiness

Our review benchmarks your ICFR against a five-level maturity model and produces a clear readiness rating.

0

Initial

Ad hoc controls, little documentation

0

Developing

Some documentation, inconsistent testing

0

Defined

Framework documented, controls identified

0

Managed

Controls tested, deficiencies tracked

0

Optimised

Attestation-ready, continuously monitored

WHAT YOU RECEIVE

Your ICFR deliverables

Our enterprise risk practice is underpinned by deep expertise across every major risk category.

ICFR framework & policy
The governing document defining your ICFR approach and governance
Process & risk-control matrices
Documented processes mapped to risks, controls, and assertions
Testing results & working papers
Evidence of design and operating effectiveness testing
Deficiency & remediation tracker
Identified gaps with owners, actions, and target dates
Management assertion pack
Board-ready documentation supporting the ICFR assertion
GETTING STARTED

How an engagement begins

A clear path from first conversation to ICFR attestation readiness.

0

Discovery Call

Understand your ADAA obligations and current ICFR state

0

Scope & Proposal

Tailored scope, approach, timeline, and fixed fee

0

Mobilisation

Engagement letter, planning, stakeholder onboarding

0

Delivery

Implementation or readiness review with regular updates

0

Assert & embed

Attestation support and sustainable handover

x

x

MNA Risk & Technology Advisory provides independent technology audit and assurance to regulated and high-growth organisations. We combine deep IT and cyber expertise with audit discipline — giving boards confidence that technology risk is understood and controlled. learn more…

Contact us

Unit RT-208, Level 1 Gate Avenue – South Zone, Dubai International Financial Centre, UAE.

Call us: +971 55618 4721

Mon – Sat: 8.00am – 18.00pm