IT Audit
We gather and evaluate evidence to determine whether the information systems and associated controls enable you to achieve your business objectives and prevent or, at least, identify and correct undesirable events.
IT Governance
We assess whether IT governance adequately supports and is aligned with the company's strategies and objectives by reviewing the effectiveness of IT resources and performance management.
Continuous and remote auditing
- Continuous and remote auditing represents a radical change in the way internal audit departments work. Appropriate use of this method provides a much higher degree of coverage of the auditable universe than traditional approaches.
- However, its implementation is an arduous and complex process that requires the involvement of top management, the collaboration of other areas such as Technology and an adequate medium/long-term approach to prevent it from becoming a limited tool that is difficult to adapt to the continuous evolution of the business.
- PKF Attest can help you identify the most appropriate solution for your needs and facilitate its development / acquisition, implementation and deployment, as well as guide you on how to adapt the management of your Internal Audit department to this new approach.
Business processes
- We analyze and evaluate the risks associated with a business process, both from a technical and operational point of view, as well as the controls implemented to mitigate them and the existing residual risk.
Application auditing
- The level of control existing in the applications that support the business processes is evaluated.
Data quality
- Incidents caused by deficiencies in the integrity and quality of information can generate very significant financial, legal and reputational errors. These incidents can be caused by various factors such as the migration of computer systems, implementation of new applications, platform changes, gradual deterioration of data due to the age of the systems, the absence of controls in the collection, maintenance and updating of information, etc.
- Based on the existing governance model, we evaluate aspects such as completeness, coherence, integrity, consistency or traceability of data throughout its life cycle, including customer information, management information, reports and dashboards, etc.
Audit of technical measures of the RGPD and the LOPDDGDD
- Following the principle of proactive responsibility set out in the General Data Protection Regulation (GDPR), the objective is to issue an audit opinion on the adequacy of the existing technical measures to the regulations governing the processing of personal data.
IT Outsourcing / SLA's / Cloud Services Contracts
- The outsourcing of technological services is common nowadays and its purpose is to take advantage of the supplier's economies of scale and to access profiles, resources and knowledge that are out of reach due to their cost or degree of specialization.
- At PKF Attest we evaluate the inherent risks and controls established in relation to the outsourcing (including services contracted in the cloud) of an IT activity and verify the correct implementation of appropriate assessment and monitoring procedures.
Segregation of duties / Identity and Access Management (IAM)
- Information systems management processes must have the necessary mechanisms to prevent each of the roles involved in the business processes from performing incompatible or unauthorized functions. Adequate segregation of duties is key if we want to avoid internal fraud and operational errors.
- To assess the degree of existing segregation, we analyze the possible differences between the functions required by the business and the authorizations implemented in the systems, environments and significant applications.
Mobile devices
- The use of mobile devices (smartphones, tablets, laptops...) has grown considerably in organizations, far exceeding the use of desktop computers.
- They present additional risks such as theft outside the company's physical locations, greater tendency to install software for personal use or a diversity of operating systems, each with its own vulnerabilities. Moreover, especially in the case of smartphones and tablets, they are usually assigned to personnel with an important position within the organization and access to relevant and confidential information.
- At PKF Attest we identify the main risks associated with this type of devices and evaluate their management and security.
Business Continuity / ISO 22301 (Business Continuity Management System)
- The objective of continuity plans is that - in the event of a serious contingency - the company returns to normal operations in the shortest possible time so that the business is not affected.
- These plans include the Disaster Recovery Plan, which covers the recovery of the company's technological platform (servers, applications, data, etc.).
- We review the continuity strategy adopted by the company, verifying the existence, reasonableness and degree of updating of contingency and disaster recovery plans.
ISO 27001 (Information Security Management System)
- Audit of the information security management system according to ISO/IEC 27001.
News
PKF Attest the only firm to climb in the ranking
Contact with us
Send us your inquiry and our team of experts will assist you as soon as possible.

