Internal control system

Reliable processes, transparent decision-making, and early risk identification define well-governed organizations. Yet many companies struggle with unclear responsibilities, inconsistent controls, and hidden process weaknesses. An effective Internal Control System (ICS) addresses these issues at their source by embedding accountability, increasing transparency, and establishing a strong foundation for sound corporate governance.
Martin Mannes
Associate Partner
Certified Information Systems Auditor (CISA)
Cassandra Rieff
Senior Associate
Certified Internal Auditor (CIA)

Creating transparency, accountability, and operational resilience

An effective ICS does more than simply fulfill regulatory or audit requirements. It creates clarity in day‑to‑day operations, identifies risks before they materialize, and enables management to act with confidence and precision.

We design ICS frameworks tailored to the complexity, size, and regulatory environment of your organization: practical, scalable systems that perform reliably in both operational and audit contexts.

Our services cover the full ICS lifecycle, from risk identification and control design to documentation, optimization, and digital integration. The result is a resilient and scalable control environment that reduces operational risk and strengthens long‑term organizational stability.

Our services

Readiness assessment


Our Readiness Assessment provides a clear overview of the maturity of your Internal Control System within a short timeframe. Based on best practice, the COSO framework, and standardised checklists, we assess how your existing ICS is structured and where improvement potential exists.

  • Standardised questionnaire on the ICS structure
  • Analysis of existing policies and documentation
  • Workshop to support the joint assessment of processes
  • AI‑supported document analysis and structured evaluation
  • Summary of findings with clear, actionable recommendations

Audit and certification of existing control systems


As an independent auditor, we assess your Internal Control System with regard to the adequacy of its design and the effectiveness of its controls. Based on this, we issue a certificate confirming the quality of your ICS and building trust with customers, business partners, and auditors.

  • IDW PS 951 and ISAE 3402 for outsourced services
  • IDW PS 982 for internal control systems

Risk analysis and control identification


Every effective ICS begins with a clear understanding of where risks exist within business processes. We conduct structured risk assessments in close collaboration with process owners, define appropriate controls, and establish minimum control standards that are proportionate, practical, and audit‑ready.

  • Analysis of key business processes and risk areas
  • Identification and assessment of relevant risks
  • Definition of appropriate controls and minimum control standards
  • Documentation within risk-control matrices and GRC tools

Policy framework and process documentation


Clear policies and consistently documented procedures form the structural foundation of an effective ICS. We develop, revise, and structure documentation frameworks that ensure requirements are transparent, practical, and consistently applied across the organization.

  • Process descriptions and work instructions
  • ICS policies and control documentation
  • Responsibility and approval frameworks
  • Creation and enhancement of GoBD‑compliant procedural documentation

Further development and optimization


Many organizations operate individual controls without a consistent, enterprise-wide control approach. We assess existing structures, eliminate redundancies, and evolve your ICS into a coherent, scalable framework aligned with growth, transformation, and organizational change

  • Identification and elimination of inefficient or redundant controls
  • Automation and digitalization of control activities
  • Application of established methodologies and industry standards
  • Rollout of control requirements across subsidiaries
  • Standardization of control frameworks and reporting structures
  • Scalable adaptation during growth phases and restructuring initiatives

Control execution and monitoring


An ICS creates value when controls are embedded seamlessly into day‑to‑day operations and monitored with discipline. We design monitoring structures that are efficient, transparent, and actionable, transforming oversight from a compliance obligation into a meaningful management instrument.

  • Definition of control cycles and responsibilities
  • Support in the execution of key controls
  • Establishment of reporting and escalation mechanisms
  • Assessment of the effectiveness of existing controls

Structural and authorization analysis


Modern, technology‑enabled controls are essential for an efficient and resilient ICS. We analyze workflows and authorization structures to identify automation potential, close control gaps, and embed sustainable safeguards within system environments.

  • Authorization and role concepts
  • Segregation of duties across processes
  • System‑supported controls such as limits, tolerances, and plausibility checks
  • Mandatory fields and validation logic within IT systems

Digitalization of the ICS


A digitally integrated ICS reduces administrative effort, increases transparency, and strengthens audit readiness. We support organizations in selecting, implementing, and optimizing suitable ICS solutions, enabling a control environment that scales efficiently with the business.

  • Selection of appropriate ICS software solutions
  • Implementation and configuration within the system environment
  • Support in documenting and maintaining risks and controls
  • Visualization of processes and control workflows in BPMN‑compliant models

“An ICS is more than a control mechanism; it is a foundation for stability. It strengthens process quality and provides a basis for reliable, forward‑looking corporate governance.”

Martin Mannes
Associate Partner