OT Risk and Assurance

Independent assurance and risk assessment for organizations where technology and operations are increasingly interdependent, and where unmanaged exposure carries digital and physical consequences. This practice delivers operational and digital risk assessment, independent assurance, and integrated risk management across IT and OT environments. Engagements range from fully outsourced audit functions to targeted mandates, each one grounded in the operational context and built for results that last. Available on-site, hybrid, or remote  |  Canada & Latin America  |  English, Spanish

OT Risk and Assurance

Operational technology enables the physical work of mining and energy. Effective risk management and assurance help protect people, production, the environment, and operational continuity.

We work alongside site, technical, and leadership teams, providing added capacity and specialized experience to advance priorities and translate operational insight into practical action.

Scope

  1. Operational and security risk assessments grounded in ISO 31000 and best practices in Health and Safety

  2. IT and OT convergence gap assessments, including IT general controls and cybersecurity integration across the points where IT connects with plant operations

  3. Recommendations that enable technical teams and leadership to take action and achieve visible change

Our OT risk and assurance practice is grounded in more than 13 years of experience across large-scale mining sites, bringing operational insight and risk discipline to complex industrial environments.

ISO 31000 · IEC 62443 · NIST SP 800-82 · NIST CSF 2.0

Main

CISOs, OT Leaders & Risk Officers

Independent governance advisory and assurance across the seams where IT and OT converge, without adding permanent headcount.

CFOs & Chief Audit Executives

Senior IT and operational audit support on demand, with bilingual field mobility across Canada and Latin America.

Energy, Mining & Manufacturing

Independent assurance over field processes, OT environments, and the IT risk created by digitalization and operational connectivity.

Frameworks applied

COSO, COBIT, ISO/IEC 27001, IEC 62443, NIST CSF 2.0, NIST SP 800-82, ISO 31000