Operational & Process Audits
We examine how an organisation operates in practice, including its processes, responsibilities, controls and documentation, and identify where these diverge from what is required or intended. Each audit concludes with findings ranked by significance and a plan for addressing them.
Scope of audits
Process mapping and gap analysis
We document how key processes are actually carried out, compare them with how they are intended to work, and identify gaps, duplications and points of failure.
Internal control review
We assess whether the controls an organisation relies on, such as approvals, segregation of duties, reconciliations and access rights, are designed appropriately and applied in practice.
Compliance readiness review
We assess an organisation’s preparedness for the requirements of applicable EU frameworks, such as the GDPR, CSRD, DORA and the AI Act, and identify what remains to be put in place.
Documentation and record-keeping audit
We review whether policies, procedures, contracts and records exist, are current and are consistent with one another and with actual practice.
Supplier and procurement process review
We examine how suppliers are selected, verified, contracted and monitored, and where the process exposes the organisation to avoidable risk.
Outside our scope
We do not conduct statutory audits of financial statements, which are reserved for registered auditors. We are not a certification body, and our reviews do not result in a certificate or formal attestation of compliance. Where a matter requires a legal opinion, we will say so at the scoping stage.
What you receive
- An audit report with findings ranked by significance
- Maps of the processes reviewed, as they operate in practice
- A list of gaps against the agreed requirements or intended practice
- A remediation plan stating the measures required and who is responsible for each
- A record of the evidence on which each finding rests
Related practice areas
Where an audit identifies missing or outdated documentation, policies and procedures can be prepared through Law27, our document drafting practice, including GDPR documentation, ICT risk policies under DORA and AI Act compliance documentation. Where a supplier review raises concerns about a specific counterparty, Risk Management & Due Diligence verifies it in detail. Findings that call for changes to structure or operating model can be taken forward through Strategic & Business Advisory.

Discuss the scope
If you are considering an audit of a process, a control environment or your readiness for an EU framework, describe it briefly. We will reply by email to arrange a discussion and propose a scope of work.
If your matter does not fall within the areas described above, describe it briefly. We will advise whether it is within our scope.