
Previous experienceBusinesses subject to Value Added Tax
Tax Agency registration No. 30001887 — registered to act and correspond on your behalf before the FTA.
Verify on the FTA registerOpens the FTA's official register filtered to this entry (20043873).
Internal audit that strengthens how the business actually runs
An independent, risk-based review of your controls, processes and exposures — producing ranked findings your management team can act on, not a report that sits in a drawer.
Growth exposes the gaps informal controls used to hide
As a business grows, the informal controls that worked when the owner saw every transaction stop being enough. Approval limits blur, segregation of duties slips, and errors or losses go unnoticed until they become expensive.
Internal audit gives you an independent, structured view of where the real exposures are — and what to do about them. It is for you, not for an external reader: it examines how the business runs and hands management a ranked list of what to fix first.
See what we doWhen an outside view is worth more than another meeting
- The business has grown faster than its procedures.
- You suspect leakage in purchasing, stock or cash but cannot evidence it.
- An investor, lender or board has asked for independent assurance.
- You are formalising governance ahead of a funding round or expansion.
- A specific incident has raised questions about how controls are working.
Each of these is a scoping conversation, not a commitment. Tell us which one is yours
The matrix behind an internal audit
Hover or focus a cell to read what was tested and what was found.
Six things an internal audit engagement delivers
Every engagement is scoped from the risk assessment down — so the effort goes where the exposure is, and every finding arrives with a practical fix.
Risk assessment
IncludedWe identify where the business is genuinely exposed — by cycle, by location and by person — and rank those exposures so the review starts where it matters most.
Annual internal-audit plan
Agent-reviewedA written plan that turns the risk ranking into a calendar: which areas are reviewed, in what depth, when — agreed with owners or the board before fieldwork begins.
Process and controls audits
IncludedWe walk through procure-to-pay, order-to-cash, payroll, inventory and cash handling as they actually operate, and test whether the controls you rely on are well designed and working.
Fraud-risk reviews
IncludedA focused look at the points where cash, stock or approvals can leak — segregation of duties, vendor and payroll master data, manual journals — with evidence, not suspicion.
Follow-up and remediation tracking
IncludedEvery finding gets an owner and a date. We re-test the agreed actions at the follow-up review and report what is closed, what is open and what has slipped.
Board and owner reporting
IncludedFindings pitched for the reader: a ranked summary for owners, a board or an audit committee, and the detailed working papers for the managers who have to fix things.
You receive the schedules, the findings and the owners of each action — in writing, before the auditor arrives.

Fieldwork you can see
Walkthroughs happen at your premises and on your records. Findings are discussed with the people who own the process before they are written into a report.
The internal-audit cycle, in five steps
The same cycle whether we run the whole function for you or work alongside an internal team. Nothing starts before the scope is agreed in writing.
Scope
We agree the areas, the risks and the depth of review with you, then issue a written scope and quote. The cost is defined before the first interview.
Risk assessment and plan
Interviews with owners and key managers, a review of the organisation, systems and past incidents, and a ranked risk map that becomes the audit plan.
Review and test
We examine processes as they operate — not as they are documented — and test the controls in practice, with short, focused conversations with the people who do the work.
Report
Ranked findings, the practical implication of each, and a recommended action with a suggested owner and timeline. Discussed with management first, then presented to owners or the board.
Follow up
We re-test the agreed actions and confirm the improvements hold. Open items roll into the next cycle so nothing quietly disappears.
Timing is set in the scope for each engagement; a single-cycle review is short, a multi-cycle plan runs across the year.Outsourced, co-sourced or a one-off review
Three ways to bring internal audit into the business. The scope decides which one fits; the standards are the same in all three.
| Included | Outsourced | Co-sourced | One-off review |
|---|---|---|---|
| Risk assessment and annual planRanked exposures, agreed calendar | Included | Included | On request |
| Fieldwork by AL TAMAYUZProcess walkthroughs and controls testing | Included | Shared with your team | Included |
| Works alongside your internal audit teamMethodology, review and specialist areas | Not applicable | Included | Not applicable |
| Fraud-risk reviewLeakage points, master data, manual journals | Included | On request | On request |
| Board and owner reportingRanked summary plus detailed working papers | Included | Included | Included |
| Follow-up re-testingConfirming the improvements hold | Included | Included | On request |
| Best suited toA starting point, refined in scoping | Owner-managed businesses and groups without an internal audit function | Companies with an internal team that needs capacity, method or specialist coverage | A single cycle, an incident, or an investor or lender request |
| Scope first, then a written quote. The same scope always gets the same standards, whichever model you choose. | |||
Amber = available on request within the engagement. Nothing here is a price list.
Businesses that need independent assurance over controls
Owner-managed businesses, groups, and companies with boards or investors — including businesses formalising governance for the first time.
- Owner-managed businesses that have outgrown informal controlsThe owner no longer sees every transaction, and wants to know what changed
- Groups with several entities or branches across the EmiratesOne method applied consistently, with reporting that compares like with like
- Companies with a board or investors asking for independent assuranceReporting pitched for a board or an audit committee, with management responses
- Businesses formalising governance ahead of funding or expansionApproval matrices, segregation of duties and policies that actually get used
- Operations with cash, stock or many suppliers where leakage hidesTrading, retail, hospitality, construction and manufacturing in particular
- Companies with an internal auditor who needs capacity or specialist supportCo-sourced: your team keeps ownership, we add method and hands
Read before you scope
Two short guides that answer the questions most owners ask before their first internal audit.
Internal audit vs. statutory audit — what each one is for
One gives an opinion on your financial statements for external readers; the other examines how the business runs, for you. Why they are usually done separately, and what each one can and cannot tell you.
Segregation of duties in a small finance team
When three people run the whole finance function, perfect separation is impossible. The compensating controls that work in practice — approval limits, bank mandates, review of manual journals and vendor master data.
Questions owners ask before the first engagement
The statutory audit gives an opinion on your financial statements for external users. Internal audit is for you: it examines controls, processes and risks and gives management ranked recommendations. The two are normally done separately; if you already have an external auditor we coordinate so nothing is asked for twice.
It depends entirely on scope. A focused review of a single cycle, such as purchasing, is a short engagement; a broader review or an annual plan runs across the year. We scope it with you first and issue a written quote for that defined scope, so the cost is never open-ended.
We plan fieldwork around your operations — avoiding month-end, peak trading and payroll runs — and keep interviews short. Most of what we need is documentation and system reports, plus brief conversations with the people who do the work. Findings are discussed with managers before they reach the report.
A written report with ranked findings, the practical implication of each, and a recommended action with a suggested owner and timeline — written to be acted on, not filed. Owners or the board receive a summary; managers receive the detail. At the agreed follow-up date we re-test the actions and report what remains open.
Nothing is a finding until it is tested and documented.
Get an independent view of your controls
Tell us which situation is yours and roughly how the business is organised. A specialist responds promptly with the questions we need answered, then a short scoping conversation — online or at our Business Bay office — and a written scope and quote before any work.
- Independent of your finance teamFindings go to owners or the board, discussed with management first
- Scoped and quoted in writingThe cost is defined before the first interview
- Planned around your operationsShort interviews, documentation first, no surprises in the report

Discuss an internal audit
A specialist responds promptly.
We use your details only to respond to your request.
We reply
A prompt reply, with the questions we need answered.
First stepScoping conversation
Areas, risks and depth of review — agreed with you, online or in Business Bay.
NextScope and quote
A written scope and quote before any fieldwork begins.
Before any workGet an independent view of your controls
Book a consultation and receive a written scope and quote before any work begins.


