
Ivan Spiteri
As technology continues to develop, with this the regulatory environment evolves to meet the changing risks. For example, the GDPR brought changes in the scope of the data protected and significant increases in the sanctions available to the regulator. As regulations change, how the Board and business stakeholders stay abreast of the requirements to assess the adequacy of the controls in place will be key to the future vulnerabilities faced by each business.
BDO has developed a methodology to help businesses untangle the regulations impacting IT services, the vulnerabilities they bring to each organisation and the controls or procedures that will minimise the risk of a regulatory breach.
Where limited assurance exists, we can work with you to assess the controls in place, whether in-house or by providing an ISAE300, ISAE3402 or ISAE16 report across a third party service provider. The scope of any review is key to the robustness of the assurance provided. Typically we tailor our work to meet to your needs and could include the following:
Are senior management aware of the regulatory risks impacting IT? Is there appropriate management information to help inform management of the maturity of the controls in place? Does the assurance programme ensure controls are assessed and tested regularly?
With specific focus on user access management, change management, interface and batch processing management and data integrity management.
including Cyber security, technology resilience, data protection health checks, assessment of security configuration across key systems or data environments.
Get in touch with our experts
Ivan Spiteri