IT & OT Risk and Assurance
Independent assurance and risk assessment for organizations where technology and operations are increasingly interdependent, and where unmanaged exposure carries digital and physical consequences. This practice delivers operational and digital risk assessment, independent assurance, and integrated risk management across IT and OT environments. Engagements range from fully outsourced audit functions to targeted mandates, each one grounded in the operational context and built for results that last. Available on-site, hybrid, or remote | Canada & Latin America | English, SpanishWhat this covers
IT Risk and Assurance
Does your organization have the independent IT audit and governance coverage it actually needs?
Independent, risk-based audit and assurance covering IT General Controls (ITGC), access controls, data center environments, cloud and on-premises infrastructure, IT third-party risk, SOC 2 Type II Readiness Review, and IT compliance reviews. Available as a fully outsourced audit function or targeted, project-based engagements.
Governance advisory is embedded in every engagement. We work with the people who own the process, building policies, defined ownership, and documented controls that hold beyond the engagement, not documents that sit on a shelf.
Every engagement is anchored to what matters most to leadership, delivered by a bilingual team with field mobility across Canada and Latin America.
COSO · COBIT · ISO/IEC 27001 · AICPA AT-C · SSAE 18 · CSAE 3416
OT Risk and Assurance
In your operational technology environment, do you have full visibility into the risks affecting your processes, people, and systems, and confidence that gaps in alignment are not quietly creating health, safety, or environmental exposure?
Operational Technology (OT) environments, including Industrial Control Systems (ICS) such as SCADA, DCS, and PLC, are the operational backbone of mining, energy, and manufacturing organizations. As IT and OT converge, the ungoverned seams between them become the risk: unmanaged exposure, systems without clear ownership, and operational decisions made without a full picture of what is at stake.
This service delivers operational and digital risk assessment, independent operational assurance, and integrated risk management across OT environments and the points where they connect with IT. The starting point is always what the organization is actually running: what is exposed, what needs to change first, and what will deliver results that last.
Effective results with long-term impact, grounded in a deep respect for the operational context.
IEC 62443 · Idaho CCE · NIST CSF 2.0 · NIST SP 800-82 · COBIT · ISO/IEC 27001 · ISO 31000
Who this is for
CISOs, OT Leaders & Risk Officers
Independent governance advisory and assurance across the seams where IT and OT converge, without adding permanent headcount.
CFOs & Chief Audit Executives
Senior IT and operational audit support on demand, with bilingual field mobility across Canada and Latin America.
Energy, Mining & Manufacturing Operations
Independent assurance over field processes, OT environments, and the IT risk created by digitalization and operational connectivity.
Technology Companies, SaaS Providers & Startups
Organizations building or maturing IT governance and risk assurance, from early-stage to enterprise.
Frameworks applied
COSO, COBIT, ISO/IEC 27001, IEC 62443, NIST CSF 2.0, NIST SP 800-82, Idaho CCE, CSAE 3416, CSAE 3000, AICPA AT-C, SSAE 18, ISO 31000
