Setting the right corporate tone from the top is seen as by far and away the most effective way...
Corporate Governance and Internal Audit
A good Corporate Governance level ensures that the organization’s objectives are reaches with transparency towards shareholders, efficiency in operations, an internal control culture and, in general, an appropriate operation of Governance bodies and of the Board of Directors.
A good Corporate Governance level provides the following to the organization:
- Trust, transparency and value for shareholders.
- An increase in its operations’ efficiency.
- An appropriate regulatory compliance.
- An appropriate internal control culture conveyed to the employees’ activities.
- An adequate segregation of duties and responsibilities.
- Finally, a correct operation of governance bodies and of the Board of Directors.
In order to achieve the above, organizations must follow Corporate Governance best practices, and count with the appropriate risk management plans, efficient and effective internal control systems, and as far as possible an internal audit function (in-house or outsourced) transversal to the organization. The mission, values, code of ethics, together with the strategy and other internal policies must be conveyed at every level of the organization.
OUR SERVICE OFFERING
Good Corporate Governance
- Improvement of Good Governance bodies and elaboration of Bylaws, Manuals and Procedures.
- Advice and review of the Corporate Governance Annual Report.
- Compliance with Good Governance Codes and third parties’ reporting systems.
- Corporate Social Responsibility (ISO 26000).
- Ethics and integrity programmes, and development of codes of conduct.
- Implementation of good governance practices of Information Systems COBIT, ITIL, ISO 27000, etc.
- Whistleblowing Channel (www.canaldedenuncias.com).
Audit and Internal control
- Elaboration of Bylaws, Regulations and Audit and Internal Control procedures.
- Design and implementation of internal procedures. Audit of internal controls.
- Advice in Risks Management and Self-assessment models (www.gricontrol.com).
- Internal Audit outsourcing services. Co-sourcing.
- Audit of outsourced services and contractual clauses.
- Analysis of computer-assisted audit data and tools (CAATs): ACL, IDEA.
- Asset control and management.
- Customized internal audit and internal control training.
Internal Control in Regulated Entities
- Internal control on financial information in listed entities (SCIIF). CNMV regulations.
- Internal control of collective investment institutions and investment companies’ managing entities (SGIIC).
- Internal control audit for service providers (report ISAE 3402 / SAS 70).
- Solvency II, Basil III, and different sectoral regulations.
- Compliance with the Sarbanes-Oxley Act (SOX), JSOX and LSF.
- Advice in the implementation of the Markets in Financial Instruments Directive (MiFID).
Want to know more?
Jose Antonio Castrillo Madrid
COVID-19 SERVICES: COMPLIANCE AND TECHNOLOGY
The current situation derived from the COVID-19 (remote working, a more intensive use of connection technologies…) is causing an increase of information security-related crimes: scams, theft of credentials through phishing, malicious files… All this could have a possible impact both from the reputation and from the compliance standpoint. In order to face this situation with guarantees, the companies must have a comprehensive risk approach covering all aspects related to the integrated information security.