ICAEW Registered Auditors  ·  90+ UK-Based Experts

Internal Risk

One partner-led team for your board's assurance needs: internal audit, risk management, governance, IT risk, anti-fraud, health and safety, and business improvement — delivered with pace and budget certainty.

Boards, CFOs and Finance Directors face the same underlying challenge in a dozen different forms: how do you know your risks are controlled, your systems are resilient and your governance would stand up to scrutiny? Regulation keeps raising the stakes — board declarations on material internal controls under the UK Corporate Governance Code, the failure-to-prevent-fraud offence in force since September 2025, and growing cyber expectations from insurers, customers and regulators alike.

Our Risk & Tech Assurance practice brings the answers together in one place. Every service is led by a partner who is a Chartered Member of the Institute of Internal Auditors (CMIIA) with more than 20 years' experience, and every engagement is time-bound with budget certainty — fully outsourced, co-sourced with your team, or a focused one-off review, often completed within one to two weeks.

Assurance: Internal Audit, Risk and Governance

Internal Audit and Risk Assurance provides independent, risk-based assurance over your controls and governance, with clear audit committee reporting — as a fully outsourced function, co-sourced support for your in-house team, or one-off reviews.

Risk Management Audit and Advisory builds and tests the framework itself: risk identification and appetite, mitigation strategies, monitoring and board reporting.

Corporate Governance Audit and Consultancy reviews board effectiveness, committee structures and delegation, and prepares boards for the internal controls declaration now expected under Provision 29 of the UK Corporate Governance Code.

Protection: IT Risk, Anti-Fraud and Health & Safety

IT Risk Audit and Assurance independently assesses cyber security controls, data protection and UK GDPR compliance, access management, business continuity and third-party IT risk.

Anti-Fraud Services covers fraud risk assessment, prevention and detection controls, whistleblowing frameworks and investigations — including readiness for the ECCTA failure-to-prevent-fraud offence.

Health and Safety Audit and Assurance independently tests whether your safety policies, risk assessments, incident management and contractor controls work in practice, not just on paper.

Improvement: Health Checks, Transformation and Benchmarking

The Business Health Check is a fast whole-business diagnostic across finance, operations, governance, IT and strategy — typically completed within one to two weeks and often the best first step.

Business Transformation consultancy diagnoses root causes of underperformance, redesigns operating models and embeds change that lasts.

Benchmarking and Thematic Reviews show how your performance, controls and governance compare with peers, with data-driven reports and prioritised actions.

How We Deliver

Three engagement models run across every service: fully outsourced, where we take responsibility for the function or programme; co-sourced, where we work alongside your team adding capacity, specialist skills or independence; and ad-hoc reviews, mobilised rapidly and typically completed within one to two weeks. All engagements are time-bound with budget certainty and senior-led throughout.

Sector experience spans banking, financial services, insurance, retail, fintech, listed companies, utilities and energy; local and central government, emergency services, non-departmental public bodies, academy trusts, and further and higher education; and charities and NGOs across the third sector.

Where to Start

If you know the risk you need addressed, go straight to the relevant service — each is described in detail on its own page, linked from this one. If you want an objective view of where to focus first, start with the Business Health Check: it maps your risk and performance position across the whole organisation and tells you which deeper reviews will pay back fastest.

What You Get With Acumon

  • Internal audit and risk assurance with audit committee reporting
  • Risk management frameworks, risk appetite and board reporting
  • Corporate governance reviews and Provision 29 readiness
  • IT risk, cyber security and UK GDPR assurance
  • Anti-fraud frameworks, investigations and ECCTA readiness
  • Health and safety audit and assurance
  • Business health checks, transformation and benchmarking
  • Outsourced, co-sourced or ad-hoc delivery — time-bound with budget certainty

Why Acumon for Internal Risk?

  • Partner-led services with Chartered Member of the Institute of Internal Auditors (CMIIA) qualification
  • 20+ years of governance, risk management and internal audit experience at national and mid-tier company level
  • Sector expertise spans corporate/commercial, public sector (including NDPBs, academy trusts, FE and HE) and not-for-profit/charity organisations

Get a Fixed-Fee Quote

Tell us what you need and we'll come back within one business day with a clear scope and a fixed price — no hourly-rate surprises. Call 020 8567 3451 or use the form and we'll be in touch.

Common Questions

Frequently Asked Questions

Which service should we start with?
If a specific risk is already keeping the board awake — cyber, fraud, governance, safety — start with that service directly. If you want an objective view of where to focus, start with the Business Health Check: a one-to-two-week diagnostic across finance, operations, governance, IT and strategy that identifies which deeper reviews will deliver the most value.
What is the difference between outsourced, co-sourced and ad-hoc engagements?
Outsourced means we take full responsibility for the function — for example, acting as your internal audit function with audit committee reporting. Co-sourced means we work alongside your in-house team, adding capacity, specialist skills or independence. Ad-hoc means a single focused review, mobilised rapidly and typically completed within one to two weeks. Every service on this page is available in all three models.
Who leads the work?
A partner who is a Chartered Member of the Institute of Internal Auditors (CMIIA) with more than 20 years of governance, risk and internal audit experience at national and mid-tier company level. Engagements are senior-led throughout rather than delegated to junior teams.
What sectors do you cover?
Corporate and commercial: banking, financial services, insurance, retail, fintech, listed companies, utilities and energy. Public sector: local and central government, emergency services, non-departmental public bodies, academy trusts, and further and higher education. Not-for-profit: charities, third sector organisations and NGOs.
How do these services relate to recent regulatory changes?
Directly. Provision 29 of the UK Corporate Governance Code 2024 asks boards to declare on the effectiveness of material internal controls for financial years beginning on or after 1 January 2026 — our governance, risk and internal audit services build the evidence behind that declaration. The ECCTA failure-to-prevent-fraud offence, in force since September 2025, makes documented fraud prevention procedures a legal necessity for large organisations — our anti-fraud services deliver exactly that.
Get in Touch

Ready to Sort Your Internal Risk?

Tell us what you need. Within one business day, a qualified accountant will be in touch to talk it through and give you a clear, fixed-fee quote — no obligation.

Visit us1-2 Craven Road, Ealing, London, W5 2UA

Speak to a Specialist

Fill this in and we'll come back to you within one business day.

No obligation. Your details stay private.
Call Now Get in Touch