PRATIMĀNA CONSULTING — audit, assurance, and risk, measured to a standard

Controls you assume are working.
We verify they are.

Pratimāna Consulting runs internal audit, technology assurance, GRC, and digital transformation as one continuous standard — senior-led, retainer-based, and re-tested every cycle instead of rubber-stamped once a year.

PMC‑AC‑04 Partially effective Sample · redacted
ISO/IEC 27001:2022 A.5.15 · SOC 2 CC6.1

Privileged access to the finance ERP is granted without documented approval

Scope tested
Redacted — Oracle Fusion, production · 25 privileged grants sampled from a population of 118, over a 12-month period
Result
9 of the 25 grants had no approval record. 3 belonged to accounts whose holders had left the organisation — two of them still able to post journal entries.
Owner & date
IT Service Delivery lead · remediation agreed for the end of the following quarter, with the leaver accounts revoked the same week
Re-test
Scheduled — a fresh sample, drawn after the fix, at no additional cost
Evidence and why it matters
Evidence examined
  • Role assignment extract pulled directly from the application, not from a spreadsheet
  • Approval tickets in the service desk, matched grant by grant
  • Joiner–mover–leaver records reconciled against HR
Why it matters
This is the control your auditor tests to conclude on financial reporting access. As it stands, it does not support that conclusion, and the leaver accounts are a live exposure regardless of the audit.

Testing maps to the frameworks your auditors, your board and your regulators already recognise:

ISO/IEC 27001:2022 SOC 2 PCI DSS 4.0 NIST CSF 2.0 COBIT 2019 ITGC
Services

Four practice areas, one continuous baseline.

Pratimāna Consulting covers audit, technology, risk, and transformation — staffed by the same senior team from fieldwork kickoff to sign-off.

Practice areaWhat we testWhen to call us
Internal Audit
  • Risk-Based Internal Audit
  • Operational Audit
  • Process Audit
  • Procurement Audit
  • Inventory Audit
  • Payroll Audit
The audit committee wants assurance on processes nobody has reviewed in years.
Technology Assurance
  • IT General Controls
  • IT Audit
  • ERP Audit
  • Oracle Fusion
  • SAP Controls Review
  • Identity & Access Review
  • User Access Review
  • Segregation of Duties (SoD)
  • Change Management Review
Your external auditor raised IT general control exceptions, or an ERP go-live is coming.
GRC Consulting
  • Enterprise Risk Management
  • Control Design
  • Control Testing
  • GRC Tool Implementation
Risks live in spreadsheets, and nobody can say which controls cover which risk.
Digital Transformation
  • Business Process Reengineering
  • Finance Transformation
  • Shared Service Design
  • ERP Selection
  • Oracle Fusion Advisory
  • Business Analysis
  • PMO
  • Automation Roadmaps
  • AI Readiness Assessment
Finance is moving to a new ERP or a shared-service model, and the controls have to move with it.
The methodology

A baseline you can re-run, not an opinion you file away.

No exceptions, and no assumptions carried over from last cycle. Pratimāna Consulting runs the same three-step standard on everything we review — a control, a process, a system — before we call it sound.

01 — MEASURE

Baseline against the standard

Every control, process, or system we touch is first measured against a clear baseline. You can't strengthen what hasn't been measured.

02 — VERIFY

Test it, don't assume it

Controls are tested for design and operating effectiveness — not just checked off a questionnaire once a year.

03 — IMPROVE

Close the gap, not just the finding

Every gap comes with an owner, a remediation path, and a re-test — so the same issue doesn't reappear next cycle.

The re-test becomes the next cycle's baseline, so each year is measured against the last.

The deliverable

The audit committee reads it without a translator.

Each control carries its own line: the exception, the owner who agreed to fix it, and the date it is due. A CFO can read the outstanding list in a minute, and read it again next quarter against the same baseline.

  • Evidence pulled from the system, not from a questionnaire
  • The sample size and the population, stated
  • Exceptions written so your auditor can rely on them
  • A named owner and an agreed date on every item
  • A re-test once you have remediated
  • A baseline you can re-run next year and compare

A clean result stays clean

Where a control works, we say so — and we show the testing that supports it. An assurance report you can hand to a regulator is worth more than a long list of observations.

Start with the baseline.

Talk to a Pratimāna Consulting advisor about your controls environment — no generic pitch, just your baseline.

What happens next

  1. You tell us which controls, processes or systems worry you.
  2. We agree a scope and the first baseline to measure.
  3. Fieldwork starts against that baseline, and every exception reaches you with an owner and a date.