Governance, Risk & Compliance
We assist domestic companies and international groups engaged in different industries with Governance, Risk & Compliance issues, offering a structured approach in complementary areas: GRC and IT Risk. With our support, clients are able to strengthen business safeguards, manage the complexities of processes and risks, and create sustainable value, inter alia in constantly evolving regulatory and technological scenarios.
Structured approach in complementary areas: GRC & IT Risk
The GRC Practice includes regulatory monitoring and business risk management activities. We assist domestic companies and international groups with the construction of structured and simplicity-oriented governance models, from Compliance 231 to Enterprise Risk Management.
Our approach is advice-based: not just technological tools but interpretation of context, oriented toward the greatest maximum operational simplicity, with a focus on eliminating the multiple process duplications and overlaps that increasingly characterize the growing regulatory requirements of Integrated Compliance.
We monitor accounting processes and cooperate with management at all stages of the Compliance and internal audit systems lifecycle.
Business areas
01 - Governance
Support to the Board of Directors in self-assessment processes and to Boards of Statutory Auditors (collegi sindacali) in their supervisory activities pursuant to article 2403-bis of the Italian civil code, strengthening governance and enhancing transparency and quality of decisions.
Definition and strengthening of Corporate Governance by laying down procedures and assessing the organizational, accounting and bookkeeping structures in line with the Italian Business Insolvency Code (legislative decree 14/2019) and the provisions of article 2086 of the Italian civil code, to ensure the company’s soundness, consistency and continued operation.
Checking the efficacy of the Organization, Management and Control Model and enhancing the monitoring of risks and regulatory compliance.
02 - Risk & Controls
Adoption and development of Enterprise Risk Management systems, in line with well-recognized frameworks such as COSO ERM. Risk mapping and risk assessment to identify, assess and govern risks in a structured manner consistently with business goals.
Assessing management control system processes and identifying inefficiencies, information gaps and room for improvement.
Optimization of business processes to strengthen the Internal Audit System, and of information flows, ensuring consistency and integration with all main control frameworks.
Identification, assessment and management of the risk of fraud by means of internal audits and checks on suppliers, clients and independent contractors, to protect business and ensure transparency.
Support services or outsourcing of the third-tier function to assess the adequacy of the internal audit system. Identification of priority action areas and laying down of practical and sustainable remediation plans.
03 - Compliance
Assistance to listed companies with the implementation and review of accounting and bookkeeping control models, in line with the requirements of law 262/2005 and the Sarbanes-Oxley Act (SOX), ensuring regulatory compliance and the soundness of the safeguards for the reliability of financial reporting.
Design, implementation and update of Management Systems compliant with ISO standards such as ISO 9001, ISO 14001 and ISO 37001, to improve business efficiency, quality and security.
Assistance to the person in charge of the digital storage of documents (Responsabile della Conservazione Digitale) and specialist support with all aspects of digital storage in compliance with the law. Preparation and review of the digital storage handbook in accordance with the AgID (Agenzia per l’Italia Digitale) guidelines and conduct of audits on e-invoicing and digital storage processes.
Support services or outsourcing of the second-tier function to assess compliance with laws and regulations. Identification of priority action areas and laying down of practical and sustainable remediation plans.