Skip to content
faceela

Find out what your systems are actually doing

Every department reports a different number for the same month, and each one can defend theirs.

What you get

  • One written diagnosis of every system in use, including the shadow ones
  • Where two systems disagree, and which one the business should trust
  • Licence and subscription spend against actual usage
  • A fix list ordered by cost of inaction, not by vendor preference

Two departments, one month, two numbers, and both can defend theirs

Sales reports the month at one figure and finance at another. Both are right inside their own system: one counts an order when it is confirmed, the other when it is invoiced, and nobody ever wrote down which one the business runs on. The board meeting turns into a reconciliation exercise and the decision it was called to make gets deferred to the next one.

Underneath that there is a second layer that never appears on the IT inventory. A desktop database from a decade ago that produces the commission report. A pricing model on one laptop. A messaging group that is, in practice, the approval trail for purchases. These are load-bearing systems. They are also unbacked-up, unowned, and invisible to whoever signs the IT budget.

Then the spend. Subscriptions billed for every named user ever created while only a fraction sign in during a month. Two products bought separately by two departments to do the same job. A leaver whose account still holds administrator rights on the ERP, discovered during an audit rather than during an offboarding.

What an IT audit and system audit across the GCC actually covers

Every system in genuine use, including the shadow ones, with what each holds and who depends on it. Where two systems disagree, why they disagree, and which one the business should treat as authoritative. Data quality where it decides money: customer and item masters, opening balances, stock, unbilled work.

Access rights and segregation of duties — who can create a supplier and pay it, who can change a price after approval, whose account should have been closed. Licence and subscription spend against actual usage. The integrations between systems, and what stops when one of them is down. Backups, and specifically whether a restore has ever been tested rather than merely scheduled. Vendor contracts, lock-in and what leaving would cost.

Every finding is written the same way: what it is, what it costs in a month if nothing changes, and what fixing it involves. A finding without a cost attached is an opinion, and opinions get filed.

Independent means we are not quoting for the fix while we write the report

An audit run by the firm that implemented your system, or by a reseller who would like to replace it, is a proposal wearing an audit's clothes. The findings point at their product. Everyone in this market knows it, which is why so many audit reports are quietly ignored by the people who paid for them.

We sell the diagnosis as its own piece of work. The report is yours. You can hand it to your incumbent partner, to your external auditor, to your board, or to a competitor of ours, and it remains usable. We would rather be the firm whose report was actioned by somebody else than the firm whose report was never believed.

Where a fix is work we could do, we say so and price it separately, after the report is delivered. Never inside it.

Who needs an audit, and who is being sold one

Groups with more than one entity and more than one system. Companies about to commit to a new ERP — an audit before that decision is the cheapest money in the whole programme, because it changes what you buy. Businesses after an acquisition, where two operating models are now supposed to produce one set of numbers. Owners and boards who have stopped believing the pack they are shown each month.

It also fits companies running a UAE-headquartered system across Saudi Arabia, Qatar and Oman, where the real question is which entity's data is authoritative and who is allowed to change it.

Who does not need it: a single-entity company on one system with one person in finance. That is a bookkeeping problem, not a governance one, and an audit will tell you what you already know at a price you did not need to pay. Nor is this for a company that knows exactly what is wrong and simply has not done it. Buying a report to confirm a decision you have already made is procrastination with an invoice attached.

What determines the cost and the duration

The number of entities, the number of systems in genuine use, the number of sites, and how much documentation already exists. An audit of one company on two systems is a different piece of work from a group with entities in four Gulf markets running a different system in each.

Duration is set by access more than by effort. If the people who actually do the work are available and your administrator can grant read access early, the fieldwork is short. If every extract has to be requested through a vendor who is not enthusiastic about being audited, it is not.

The price is fixed for a defined scope before the work starts, and nothing in the recommendation is contingent on our doing it. If the honest conclusion is that your systems are adequate and the problem is that two managers have never agreed a definition, the report will say that and it will be a short one.

How the engagement runs

  1. 01

    Diagnose

    Two weeks inside your operation. We map how the work is actually done, where two systems disagree, and what each gap costs you in a month.

  2. 02

    Architect

    A target design tied to operating decisions: which system holds which truth, who owns it, and what has to be true before go-live.

  3. 03

    Implement

    Delivery in phases you can stop after. We train your team to run it, because a system that only we can operate is a system you do not own.

  4. 04

    Govern

    The part everyone skips. Ownership, review cadence and metrics, so the system does not quietly decay back into chaos.

Questions

What people ask before they start this work

What does a system audit cost?

It is priced as a fixed scope agreed before the work starts. The drivers are the number of legal entities, the number of systems in genuine use, the number of sites, and how much is already documented. Because the audit is sold separately from any fix, the price does not move depending on what we find, which is the point of buying it from a firm that is not also the implementer.

How long does an audit take?

Fieldwork is usually a matter of weeks, and the variable is access rather than effort. If the people doing the work are available for interview and read access to the systems is granted early, it moves quickly. If extracts have to be requested through a vendor, it stretches. The written report follows the fieldwork, and we would rather deliver it late than deliver findings we have not verified.

Who owns the report, and can we show it to other firms?

You own it outright and you can show it to anyone — your incumbent implementation partner, your external auditor, your board, or another consultancy quoting for the remediation. It is written to be usable by someone who has never spoken to us. A diagnosis that only works if the firm that wrote it does the delivery is not a diagnosis.

What if the audit finds our systems are fine?

Then that is what it says, and the report will be shorter than you expected. It happens: sometimes the software is adequate and the actual problem is that two departments never agreed a definition, or that one process was never written down. You will have paid for a document that tells you not to spend more, which is a better outcome than an ERP replacement you did not need.

Is this an audit of our IT staff?

No. We audit systems, data and spend, not people's performance. Findings are written against processes and controls rather than names, and in most cases the internal team already knows about half of what we report and has not been able to get it prioritised. A written independent diagnosis is often the thing that finally gets them the budget they have been asking for.

Do you cover cybersecurity and penetration testing?

We cover access rights, segregation of duties, administrator accounts, backup and restore, and the governance around them, because those are where system audit findings usually sit. We do not run penetration tests or offensive security work. That is a specialist discipline and you should buy it from a specialist. Where the audit finds you need one, the report says so and we do not pretend to be it.

Will you implement the fixes?

Sometimes, and never as a condition. The fix list is ordered by cost of inaction, and a good part of it is usually work your own team can do, or work for the vendor you already pay. Where something is genuinely ours to do, it is quoted separately after the report is delivered, so the findings cannot be read as a sales document.

IT Governance & Audit

Start with a diagnosis

Tell us the symptom in one line. We will come back with what we would look at first and what it would take.

Monday to Friday, 9:00 AM – 6:00 PM (GST)

Prefer we call you?

Leave your WhatsApp number and we will reach out.

We reply on WhatsApp first. Include your country code.

No newsletter, no reselling your number. We use it to reply to you — see our privacy policy.

WhatsApp us