Internal Audit Advisory

A strong internal audit function provides more than assurance – it offers insight, foresight, and a foundation for smarter risk management. At CNM, we take a risk-smart, insights-driven, and tech-enabled approach to internal audit, partnering with companies to build, enhance, and co-source programs that align with business objectives while addressing evolving regulatory, operational, and technology risks.

Our experienced professionals deliver practical, risk-based solutions that add value and drive continuous improvement.


Internal Audit Advisory

In today’s rapidly changing business climate, with unprecedented regulatory pressures and market expectations, many organizations face ongoing challenges to improve the effectiveness of their internal audit functions. An increasing number of these organizations find it hard to get the specialized skills needed for a high-performance, cost-effective internal audit function. Many organizations recognize the benefits of having a strategic partner that can assist with an existing internal audit function or provide a fully outsourced solution.

CNM can customize a solution depending on your specific internal audit needs. We will help you identify internal audit areas that represent key operational, compliance and strategic risks to your organization. We will work with you to find flexible, cost-effective solutions for achieving your company’s objectives.

Internal Audit Advisory Services

Internal Audit (IA) Full Outsourcing, Co-source Models

We have provided a full range of Internal Audit services to our clients including fully outsourced or co-sourced internal audit functions in various industries.

We can assist your organization in establishing a new internal audit function and developing an internal audit approach focused on high-risk areas rather than the traditional compliance-based approach. We have the resources to conduct all the agreed-upon internal audit reviews throughout the year.

Under a co-sourcing arrangement, we will work directly with your internal audit department under our tried-and-true method of team integration: one team, one goal. We can provide specialized skills and subject matter experts on ad-hoc reviews and projects.

New IA Function & IA Charter

Establishment of a new IA function for both a private or newly public entity in accordance with IIA’s new Global Internal Audit Standards. IA’s ultimate goal should be to provide any organization with value-added IA services that help identify risk, provide valuable internal control and operational improvement opportunities, and actionable recommendations and solutions.

Internal Control Framework & COSO 2013 Mapping

Integration of COSO’s 2013 internal control framework by designing and mapping your control environment to COSO’s seventeen principles, which represent the fundamental concepts of effective internal control.

Internal Audit Risk Assessment & Plan Development

Identification and assessment of enterprise-wide risks to the company including documentation of significant risks and how they threaten the achievement of strategic objectives. Based on the company’s internal audit risk assessment, development of the audit universe and proposed IA plan which consider risk, budget, timing, and resources.

Policies & Procedures

Development of corporate policies and procedures governing areas such as finance and accounting, regulatory compliance, IT and HR. CNM can further assist with implementation and training of new policies.

Business Process Improvement

CNM utilizes a structured methodology to optimize our clients’ business processes. Our approach is value-based, meaning we focus on functions experiencing significant operational inefficiencies, control gaps, inaccurate reporting, shifting market demands, or new regulatory requirements. This approach enables our team to focus on areas of highest importance to our clients when assessing gaps, providing value-add process-oriented recommendations, and implementing those recommendations in our clients’ environment. Typical deliverables of our services include the following:

  • As-is Process-level Documentation
  • Process-level Control Gap Assessment and Recommendations
  • Future State Remediation Action Plans
  • Implementation Roadmap
  • Future State Process Documentation

To learn more about our Business Transformation practice, please visit our Business Transformation Advisory page.

Ethics & Fraud

  • Fraud Risk Assessment
  • Establish & Maintain a Fraud & Ethics Hotline
  • Draft & Implement a Code of Conduct
  • Fraud Prevention Policies & Awareness Programs, including Foreign Corrupt Practices Act (FCPA), Bribery Act of 2010, Organization for Economic Cooperation & Development (OECD) Anti-Bribery Convention, and Bank Secrecy Act (BSA) / Anti-Money Laundering (AML)
Cybersecurity & Data Privacy

CNM has a full-service cybersecurity and data privacy practice. To learn more about our Cybersecurity & Privacy Advisory services, visit our our Cybersecurity page.

IT IA Advisory Areas

CNM has the IT experience to provide advisory services in a variety of specialized IT areas. To learn more about our IT IA practice, visit our IT Advisory page.

Enterprise Risk Management

Macroeconomic, strategic, operational, and compliance-based risks challenge corporate directors and senior management to effectively maneuver their companies to achieve objectives across the organization.

CNM has experienced risk advisory professionals in various industries that will work with you to define, execute, and monitor your risk management strategies and ensure they effectively mitigate risks to achieve enterprise-wide objectives.

ERM Co-source or Outsource Models

Fully outsource or co-source your ERM function with CNM’s experienced professionals to integrate seamlessly with your governance infrastructure.

Establishing an ERM Function/Framework

New implementation of a risk management framework (e.g., COSO ERM Framework) that provides foundations and organizational arrangements for designing, executing, monitoring, reviewing, and continually improving risk management throughout the organization.

Evaluation of Existing ERM Function/Framework & Policies

Assessment of the client’s existing ERM function/framework against leading frameworks (e.g., COSO, ISO 31000) in order to provide value-add enhancements including structural/procedural recommendations and augmented reporting and automation.

Evaluation of Corporate Governance Infrastructure

Assess the client’s current governance operating model and provide value-add recommendations for the board and executive management to strengthen their governance framework and policies including a reassertion/clarification of their governance roles, establish board-level risk committees, or appoint chief risk officers (CROs).

Enterprise-wide Risk Assessments

Development and execution of a methodology to identify and assess the significance of entity-wide risks to the company and management’s corresponding activities in response .

Conduct Monitoring Activities in Response to Identified Risk Areas

Based on enterprise-wide risks, execute value-add monitoring audit reviews in accordance with the established ERM governance framework.

Regulatory Compliance

The complexity and changing nature of compliance requirements have caused companies to seek the expertise and resources to stay current. CNM’s professionals have the right skillset to assist with the regulatory compliance process end to end.

Compliance Risk Management Program

Assist organizations in the alignment of firm practices with industry requirements and regulatory guidelines, such as SR 08-08

Financial Crimes Compliance (BSA/AML Sanctions)

Assist organizations with creating or enhancing an effective AML program in line with your organization’s AML risk profile, including deep experience performing independent testing requirements

FSI Federal Reg Requirements (FFIEC, OCC Standards, FRB, FDIC, FINRA)

Assist organizations with compliance with federal regulatory rules, regulations and guidelines, including FFIEC, OCC Standards, FRB, FDIC, FINRA

MRA/MRI Validation

Assist organizations with the implementation of management’s actions to remediate Matters Requiring Attention or Matters Requiring Immediate Attention

Trust & Fiduciary (12CFR9)

Assist organizations with creating or enhancing its fiduciary compliance program in line with regulatory expectations

Fraud & Investigations

Assist organizations with services to combat the risk of fraud and managing the investigation and remediation process

Federal Trade Commission Act Section 5

Assist organizations with creating an effective monitoring program to detect and prevent deceptive acts

Banking Industry Compliance

Assist organizations with creating or enhancing their overall compliance with banking specific regulations in line with regulatory expectations including:

  • Lending Compliance – Samples include the TILA-RESPA Integrated Disclosure (“TRID”), Home Mortgage Disclosure Act (“HMDA”), Equal Credit Opportunity Act (“Reg B”)
  • Fair Lending – Samples include monitoring for potential red lining and steering and prevention
  • Deposit Compliance – Samples include Truth in Savings Act (“Reg DD”), and Expedited Funds Availability (“Reg CC”)
  • Payments & Third-Party Services Including wire transfers, ACH, and SWIFT
  • Affiliate Transactions (Regulation W)
  • Corporate Treasury