Finance controls and risk — FrontCFO Controls & Risk Review

Finance Controls & Risk Review

Where your control and risk exposures sit, and what to do about them.

Most finance control failures are not failures of effort or of integrity. They are failures of design: an objective no control addresses, a control that operates too late to catch what it was meant to catch, a duty pair that was never separated because the function grew without anyone revisiting who does what, or a control performed faithfully every month that leaves no trace it happened.

Two to six weeks

What it answers

The questions this review is built to settle.

  • —Where are the control and risk exposures in our finance function?
  • —Are the controls we think we have designed to do what we think they do?
  • —Could we prove any of it to an auditor, a regulator or our board?
  • —Can one person here move money, or change the reported result, without anyone seeing?
  • —What should we change, in what order, and who does it?

When CFOs buy it

Trigger and what they say.

Audit pressure

Our auditors keep raising the same points and the adjustments are getting bigger.

A new system

We implemented a new ERP and I do not know who can do what in it.

An event

We had a payment go to the wrong account.

Growth

We have six entities now and I cannot tell you how any of them control cash.

Lost people

Three experienced people left and I do not know what left with them.

A board question

My audit committee asked whether we could be defrauded and I had no answer.

How it is different

Built around design, evidence and limits.

We start from the risks, not your control list.

A review that walks the controls you already have cannot find the one that was never built. We set out what has to be true first, then ask what you do about it.

Duty conflicts are a rule set, not an opinion.

Fifteen incompatible duty pairs, the same for every client, run as code against your actual system access. Judgement enters only in deciding whether something mitigates, and that has its own five-part test.

Evidence overtakes judgement.

Where something has already gone wrong, that fact sets the severity and no judgement lowers it.

We say what we did not do.

This is a review of design and evidence. It is not an audit, not internal audit, and not a compliance opinion. The limits are what make the rest of it worth having.

You get a plan, not a verdict.

Every finding carries an action, an owner, an effort estimate and a date, with the thirty-day no-approval-needed actions separated out. We come back at ninety days.

What you receive

Inventory, ratings, a plan, and a follow-up.

  • —Control inventory: every objective, the control against it, and where there is none.
  • —Design and evidence ratings, with a maturity position for each entity.
  • —Segregation of duties schedule and access position.
  • —Deficiency register with severity, and a sequenced remediation plan with owners.
  • —A report written for your board or audit committee.
  • —A ninety-day follow-up, included.

Shape

Engagement and elapsed time.

Single module — duties and access, audit readiness, or fraud risk

2 weeks

Core review, one entity

4 weeks

Core review, two to three entities

4–5 weeks

Full review including regulatory readiness

5–6 weeks

Finance360 is our flagship diagnostic, but it is not a prerequisite. Where Finance360 finds that controls are the binding constraint, it routes here and its evidence is reused. Where you already know controls are the problem, start here.

FrontCFO designs controls for system implementations, or reviews controls afterwards. It does not do both for the same control set.

Book an Executive Reset — a 30-minute conversation.

Book an Executive Reset