Home
Services
Finance Services
Risk, Controls & Assurance
Consulting
Training & Academy
Resourcing & Outsourcing
Tools & Frameworks
ICT & Project Delivery
Internal Audit Services
More
Academy
Products
Blog
Free Resources & Diagnostics
Get in Touch

Your Centre of Excellence · UK Based

Helping Organisations
Strengthen Operations,
Governance &
Business Performance.

Whether you are facing audit findings, control gaps, operational backlogs, resource shortages, governance challenges or transformation pressures — BECAH provides the expertise, support, training and capability solutions needed to stabilise operations, strengthen performance and build resilience.

Your Centre of Excellence for Risk, Controls, Assurance, Governance, Finance Operations and Business Transformation.

8
Service Divisions
360°
Risk Coverage
All
Sectors Served
UK
Based
Finance Services
Risk, Controls & Assurance
Consulting
Training Academy
Resourcing
Tools & Frameworks
ICT & Project Delivery
Internal Audit

"Every organisation — regardless of size, sector, or stage — deserves access to expert governance, practical business support, and the capability to perform with confidence."

BECAH Ltd was founded to make high-quality expertise genuinely accessible — across risk, controls, assurance, governance, finance operations, and business transformation. Not just for the largest institutions. For every organisation that needs it.

One Partner.
Every Function
That Matters.

BECAH supports organisations of all sizes across two complementary service lines — Risk, Controls & Assurance, and Business Support & Transformation. Whether you need to strengthen governance, prepare for audit, manage risk, improve operations, clear backlogs, or access experienced professional capacity — we provide practical expertise that delivers results.

  • Organisations strengthening governance, risk, controls and assurance environments
  • Businesses preparing for audits, inspections, compliance reviews and regulatory scrutiny
  • Finance teams requiring accounts payable, payroll, bookkeeping and operational support
  • Organisations experiencing resource gaps, staff absences or capacity pressures
  • Businesses delivering transformation, process improvement and operational change
  • Teams requiring SOPs, process mapping, business analysis and governance frameworks
  • Public, private and not-for-profit organisations building stronger, more resilient operations

Across all sectors. For organisations of every size. Because Risk Is Everywhere, BECAH Works Anywhere.

Sectors
We Serve
Financial Services Energy & Utilities Healthcare Government & Public Sector Infrastructure Retail & E-commerce Technology Professional Services Non-profit Construction & Property

One Integrated
Professional Firm

Each of our eight specialist divisions is a practice in its own right — together forming one integrated Governance, Risk, Controls & Assurance firm, with specialist capability in Finance, Consulting, Training, Resourcing, Technology & Project Delivery, and Internal Audit.

01
BECAH Finance Services
Outsourced Finance & Bookkeeping

Comprehensive financial operations support — from bookkeeping to purchase-to-pay — delivered with professional rigour.

  • Bookkeeping & bank reconciliation
  • Accounts payable & receivable
  • Month-end support
  • Finance process improvement
  • Purchase-to-pay support
  • Supplier onboarding controls
View Division →
02
Risk, Controls & Assurance
Building Strong Control Environments

We help organisations design, test, and embed robust control frameworks and manage risk with confidence.

  • Risk register setup & workshops
  • Control framework design & RACM
  • Control testing & assurance reviews
  • Audit readiness & compliance
  • Policy, SOP & procedure writing
  • Control documentation & governance
View Division →
03
BECAH Consulting Services
Strategic Advisory & Organisational Design

Senior advisory for organisations designing new capabilities, navigating regulatory complexity, or reshaping how their functions are structured and governed.

  • Finance & risk function design
  • Operating model development
  • Process improvement & redesign
  • Programme governance & assurance
  • Regulatory & compliance advisory
  • Centre of Excellence design
View Division →
04
Training & Academy
Practical Professional Development

Empowering finance, risk, and assurance professionals with skills they can apply immediately.

  • Risk & control training
  • Internal audit fundamentals
  • Finance controls & AP training
  • Risk champion development
  • Compliance awareness workshops
  • Online, in-house & coaching formats
View Division →
05
Resourcing & Outsourced Services
Flexible Capacity & Embedded Expertise

Temporary or ongoing professional support that integrates seamlessly into your team.

  • Risk, controls & assurance analysts
  • Finance & accounts payable support
  • Bookkeeping outsourcing
  • Project assurance support
  • Audit support
  • Short and long-term contracts
View Division →
06
Tools, Frameworks & Capability
Ready-Made Professional Toolkits

Professionally designed templates, frameworks, and toolkit packages that equip teams to operate with structure and control.

  • Risk management toolkit packages
  • Control & assurance framework packs
  • RACM & control testing templates
  • Finance & AP template bundles
  • Policy, SOP & governance libraries
  • Centre of Excellence packages
View Division →
07
ICT & Project Delivery
Technology, Transformation & Business Analysis

Hands-on ICT, Business Analysis and Project Delivery support for organisations navigating technology change, digital transformation, and operational improvement programmes.

  • Business process analysis (AS-IS / TO-BE)
  • Requirements gathering & documentation
  • ICT project delivery & PMO support
  • Agile backlog & user story development
  • Data analysis & Power BI reporting
  • Testing support (SIT / UAT coordination)
  • SOP & process documentation
View Division →
08
Internal Audit Services
Independent Audit You Can Actually Rely On

Professional internal audit services delivered to IIA Global Standards — rigorous methodology, clear reporting, and an independent opinion that gives boards and governance bodies the confidence to make sound decisions.

  • Outsourced internal audit function
  • Co-sourced audit partnership
  • Controls assurance audits
  • Project & programme assurance
  • Advisory engagements
  • Follow-up & action tracking
View Division →

A Structured Path to
Confidence & Control

01

Understand Your Environment

We begin by listening. A thorough review of your governance, risk, controls, and assurance landscape tells us exactly where to focus and what matters most.

02

Design the Right Solution

We build a tailored approach matched to your sector, scale, and regulatory environment — not a one-size template applied universally.

03

Deliver With Precision

Our team embeds with yours, delivering practical outcomes quickly while transferring knowledge and capability throughout.

04

Sustain & Strengthen

We leave your organisation with documented processes, equipped teams, and structures to maintain strong governance, embed effective controls, and sustain independent assurance — independently and with confidence.

Our Commitment

Eight Disciplines.
One Trusted Partner.

Every organisation deserves access to the same quality of governance, risk, controls, and assurance expertise that the most sophisticated institutions rely on. BECAH brings all of that under one roof — across all sectors, for organisations of every kind — without the complexity, jargon, or overhead.

We are practitioners first. Every recommendation, framework, toolkit, and project delivery engagement is grounded in real operational, regulatory, and assurance experience across diverse sectors and organisation types.

GovernanceRisk, Controls & AssuranceAssuranceFinanceConsultingTrainingICT & ProjectsInternal AuditToolkitsAll SectorsUK Based

Start With Something Free

Two complete resource packs — practical, specific, and written from real experience. Each one gives you a working framework you can use immediately, whether you are preparing for an audit or governing AI for the first time.

Free Download · AI Governance

The AI Governance Blueprint

Your organisation is deploying AI. Your board has questions. Your regulators are paying attention. This guide gives you the framework, the templates, and the 90-day roadmap to govern AI properly — before someone asks why you haven't.

  • 25-page practical guide
  • AI Inventory & Risk Register templates
  • 90-day implementation roadmap
  • Board Paper template included

Free Download · Audit Readiness

The Audit Readiness Guide

The 8 categories where UK organisations most consistently fail internal and external audit — with the specific patterns we see most often and the exact steps to close every gap before auditors arrive. Written for leaders who are accountable for audit outcomes and want to walk in prepared, not pressured.

  • 25-page practical guide
  • Audit Readiness Checklist
  • 45 scored statements, auto-calculated
  • 90-day remediation roadmap

Know Where You Stand — Before Your Auditors Do

Three interactive diagnostics. Answer the questions, receive a personalised score and gap report instantly. No governance knowledge required.

Audit Readiness

Audit Readiness Diagnostic

20 questions across 9 control dimensions. Understand where your organisation stands across the full control ecosystem — before auditors do.

5 minutes to complete
8 category breakdown
Personalised gap analysis
Take the Diagnostic
Premium
Full Assessment

Full Audit Readiness Report

40 questions across 9 control dimensions. A comprehensive written report generated from your specific answers — findings, recommended actions, and a personalised remediation roadmap. Ready to share with your leadership team.

40 in-depth questions
Branded PDF report
12-week remediation roadmap
Start the Full Assessment
Control Awareness

Control Culture Assessment

When auditors visit they talk to the people doing the actual work. This 5-minute assessment tells anyone in any role how prepared they are for that conversation.

Any role, any level
No governance knowledge needed
Team deployment available
Take the Assessment

Want to deploy the Control Culture Assessment across your whole organisation?

Get an aggregate culture report showing which teams are governance-aware and where the gaps are. This is the conversation your next audit will have with your people. Have it first.

Talk to Us About Team Deployment

Let's Talk About
Your Organisation

Whether you need embedded support, a toolkit package, a consulting engagement, training for your team, or independent internal audit — we would love to hear from you.

CompanyBECAH Ltd
Email
Address13 Bishop Apartments, 16 Frogley Park
Barking, London, IG11 0AU
AvailabilityCurrently accepting new clients across all eight divisions

Back to Home
01
BECAH Finance Services

Outsourced Finance
& Bookkeeping

Comprehensive, professional financial operations support for organisations that need reliable, accurate, and well-controlled finance functions — without the cost and complexity of building everything in-house.

Enquire About This Division

What We Deliver

  • 01
    Bookkeeping
    Accurate day-to-day recording of financial transactions, ledger maintenance, and reconciliation.
  • 02
    Accounts Payable Processing
    End-to-end AP management including invoice processing, payment runs, and supplier query resolution.
  • 03
    Accounts Receivable Support
    Invoice raising, credit control support, and debtor reconciliation to maintain healthy cash flow.
  • 04
    Bank Reconciliation
    Regular reconciliation of bank accounts to ensure accuracy and identify discrepancies promptly.
  • 05
    Month-End Support
    Structured month-end close support including accruals, prepayments, and management pack preparation.
  • 06
    Finance Process Improvement
    Review and redesign of existing finance processes to eliminate inefficiencies and strengthen controls.
  • 07
    Purchase-to-Pay Support
    End-to-end P2P process support covering requisition, PO management, goods receipt, and payment.
  • 08
    Supplier Onboarding Controls
    Structured supplier onboarding processes with verification checks, approval workflows, and documentation.
  • 09
    Financial Records Clean-Up
    Remediation of historic bookkeeping errors, ledger tidying, and records restoration to audit-ready standard.
Who This Is For
Any organisation that needs reliable, controlled finance operations
Whether you have an existing finance team that needs capacity, a new business building its finance function, or an established organisation seeking to outsource specific processes — BECAH Finance Services provides the right level of support.
SMEsScale-upsCorporatesNon-profitPublic Sector
Delivery Model
Flexible to your needs
We work on short-term project engagements, ongoing outsourced arrangements, or as embedded support within your existing team. Day rate, monthly retainer, or project-based pricing available.
Related Divisions
Often paired with
Finance Services works best alongside Risk, Controls & Assurance (Division 02) to ensure strong financial controls, and our AP Process Pack from Division 06 for immediate template support.
Division 02 →Division 06 →
Ready to strengthen your
finance operations?
Back to Home
02
Risk, Controls & Assurance

Building Strong
Control Environments

We help organisations of all sizes and sectors design, implement, test, and embed robust control frameworks — and manage risk with the structure, evidence, and confidence that regulators, auditors, and boards expect.

Enquire About This DivisionView Toolkit Packages

What We Deliver

  • 01
    Risk Register Setup
    Design and population of risk registers, including risk categorisation, scoring methodology, and ownership assignment.
  • 02
    Risk Workshops
    Facilitated risk identification and assessment workshops for leadership teams, project teams, and operational functions.
  • 03
    Control Framework Design
    End-to-end design of control frameworks tailored to your sector, regulatory environment, and risk appetite.
  • 04
    RACM Development
    Risk and Control Matrix development mapping risks to controls, owners, testing frequency, and evidence requirements.
  • 05
    Control Testing
    Independent testing of controls to verify design effectiveness and operational effectiveness, with findings reporting.
  • 06
    Assurance Reviews
    Structured assurance reviews of specific processes, functions, or control areas with actionable recommendations.
  • 07
    Audit Readiness
    Preparing organisations for internal or external audit — evidence gathering, gap remediation, and mock audit support.
  • 08
    Compliance Support
    Practical compliance support including regulatory mapping, obligations tracking, and compliance monitoring frameworks.
  • 09
    Policy & SOP Writing
    Professionally written policies and standard operating procedures aligned to your control environment and governance structure.
  • 10
    Governance Support
    Supporting boards, committees, and senior leaders with governance frameworks, terms of reference, and reporting structures.
Who This Is For
Organisations that need structured, evidenced risk and control capability
From regulated financial services firms and utilities to public sector bodies and large corporates — any organisation that needs to demonstrate effective risk management and strong internal controls.
Regulated IndustriesInternal Audit TeamsFinance FunctionsPublic Sector
Complementary Products
Toolkit packages to support this work
Our Division 06 toolkits include RACM templates, control testing packs, risk register templates, and assurance working papers — ideal for teams who want to continue the work independently after our engagement.
View Toolkits →
Ready to build a stronger control environment?
Back to Home
03
BECAH Consulting Services

Strategic Advisory
& Organisational Design

Senior advisory and consulting engagements for organisations building new capabilities, navigating complex regulatory landscapes, redesigning their operating models, or reshaping how their finance, risk, and assurance functions are structured, governed, and operated.

Discuss a Consulting Engagement

What We Deliver

  • 01
    Finance & Risk Function Design
    Designing or redesigning finance and risk functions — structure, roles, responsibilities, reporting lines, and operating model.
  • 02
    Operating Model Development
    Building target operating models that are fit for purpose, scalable, and aligned to organisational strategy.
  • 03
    Process Improvement & Redesign
    Identifying and eliminating process inefficiencies, redesigning workflows, and embedding improvement sustainably.
  • 04
    Programme Governance & Assurance
    Independent governance and assurance over major programmes and initiatives — covering risks, controls, progress reporting, and senior stakeholder oversight.
  • 05
    Regulatory & Compliance Advisory
    Expert guidance on navigating regulatory requirements, building compliance frameworks, and preparing for regulatory engagement.
  • 06
    Centre of Excellence Design
    Full CoE design service — structure, governance, templates, tools, SharePoint architecture, and ways of working.
Engagement Model
How consulting engagements work
Consulting engagements begin with a scoping conversation to understand your challenge and define the right approach. We work on fixed-scope projects, time-and-materials retainers, or phased delivery models depending on what works best for your organisation.
Who This Is For
Organisations facing strategic or operational change
Particularly suited to organisations that need strategic thinking and design expertise — new regulatory requirements, function redesign, operating model change, restructuring, or building new professional capabilities from the ground up.
New Functions & TeamsRegulated FirmsLarge CorporatesPublic Sector
Let's discuss your
advisory & design needs
Back to Home
04
Training & Academy

Practical Professional
Development

Empowering finance, risk, and assurance professionals with the skills, knowledge, and confidence to perform their roles effectively — delivered in practical, accessible formats that create immediate workplace impact.

Enquire About Training

What We Deliver

  • 01
    Risk & Control Training
    Practical training on risk identification, assessment, control design, and control ownership — suitable for all levels.
  • 02
    Assurance Training
    Building assurance skills for practitioners — planning, fieldwork, testing, reporting, and follow-up.
  • 03
    Internal Audit Fundamentals
    Introduction to internal audit methodology, standards awareness, and practical audit techniques for new practitioners.
  • 04
    Finance Controls Training
    Training finance teams on internal controls — what they are, why they matter, and how to operate them effectively.
  • 05
    AP / P2P Training
    Accounts payable and purchase-to-pay process training covering best practice, controls, and common failure points.
  • 06
    Risk Champion Training
    Equipping nominated risk champions with the skills to embed risk awareness and reporting in their business areas.
  • 07
    Control Owner Training
    Training designated control owners on their responsibilities, documentation requirements, and evidence expectations.
  • 08
    Compliance Awareness Workshops
    Targeted compliance awareness sessions covering relevant regulatory obligations, obligations mapping, and accountability.
Delivery Formats
Training that fits your organisation
All training programmes can be delivered in multiple formats to suit your team's needs and location.
Online / VirtualIn-HouseWorkshops1-to-1 CoachingBlended Learning
Who This Is For
Individuals and teams at all levels
From new joiners building foundational skills to experienced professionals refreshing their knowledge — BECAH training is practical, credible, and immediately applicable to real workplace challenges.
Finance TeamsRisk TeamsAssurance ProfessionalsManagers & Leaders
Ready to develop your
team's capability?
Back to Home
05
Resourcing & Outsourced Services

Flexible Capacity &
Embedded Expertise

Providing organisations with skilled, experienced finance, risk, and assurance professionals on a temporary, contract, or ongoing outsourced basis — seamlessly integrating into your team when and where you need them most.

Discuss Your Requirement

What We Provide

  • 01
    Risk Analyst Support
    Experienced risk analysts available for short or long-term placements to support risk identification, assessment, and reporting.
  • 02
    Controls Analyst Support
    Controls professionals to support control design, documentation, testing, and remediation activity.
  • 03
    Assurance Analyst Support
    Assurance professionals to support review planning, fieldwork, report writing, and action tracking.
  • 04
    Finance Analyst Support
    Finance professionals to support financial reporting, analysis, month-end processes, and finance function capacity.
  • 05
    AP / Accounts Payable Support
    Specialist AP resource to support invoice processing, payment runs, reconciliations, and supplier management.
  • 06
    Project Assurance Support
    Independent assurance resource for major projects and programmes — governance reviews, risk tracking, and reporting.
  • 07
    Audit Support
    Providing internal audit capacity to support audit planning, execution, and reporting on a co-sourced or fully outsourced basis.
  • 08
    Bookkeeping Outsourcing
    Ongoing outsourced bookkeeping service — a cost-effective alternative to permanent headcount for finance operations.
Engagement Types
Short-term, long-term, or ongoing
We provide resource on day-rate contracts, fixed-term placements, and ongoing outsourced arrangements. Minimum engagements from one week. Long-term retainer arrangements available at preferential rates.
Day RateFixed-Term ContractOngoing OutsourcedCo-sourced
Who This Is For
Any organisation needing professional capacity, fast
Maternity cover, sudden departures, project peaks, audit preparation, or simply building a function before making permanent hires — BECAH provides experienced professionals who can contribute from day one.
Need professional capacity
quickly?
Back to Home
06
Tools, Frameworks & Capability Solutions

Ready-Made
Professional Toolkits

Professionally designed templates, frameworks, and toolkit packages that give your teams the structure, documentation, and repeatable processes they need — without building everything from scratch. Available as standalone digital products or as part of a wider engagement.

View Pricing & BundlesRequest a Custom Pack

Six Categories of Products

  • 01
    Centre of Excellence Packages
    Without a CoE, teams work inconsistently and governance is weak. Our CoE packages give your function the structure, tools, and processes to operate as a professional, accountable, and high-performing unit — from day one.
  • 02
    Risk Toolkit Packages
    Organisations without proper risk tools are reactive rather than proactive. Our risk toolkits give your team everything needed to identify risks early, assign ownership, score them consistently, and report with confidence.
  • 03
    Control & Assurance Toolkits
    Many organisations have controls but cannot evidence them. Our toolkits help you document, test, and report on your control environment so you are always audit-ready and able to demonstrate genuine compliance.
  • 04
    Finance & AP Toolkit Packages
    Finance errors and fraud risk often stem from poor processes and missing controls. Our finance and AP toolkits give your team the SOPs, checklists, and control templates to process transactions accurately and compliantly.
  • 05
    Governance & Compliance Packages
    Without clear policies and compliance frameworks, organisations face regulatory risk and reputational damage. Our packages help you put the right rules in place, monitor compliance, and prepare confidently for inspections.
  • 06
    Transformation & Setup Packs
    Starting a new team or function from scratch is time-consuming and costly. Our setup packs give new and growing functions a professional head start — with operating models, SOPs, trackers, and governance frameworks ready to go.
How They Work
Contact us for pricing
All toolkit packages are delivered digitally — downloadable immediately after purchase confirmation. Products are designed for real operational use, built from professional experience, and ready to adapt to your organisation's specific context.
Instant DownloadOne-Time PurchaseFully EditableNo Subscription
Bundle Options
Starter · Professional · Enterprise
Our toolkit and template packages are available at a range of scales — from focused topic packs for individual teams to comprehensive enterprise bundles with consultation and implementation support. Contact us to discuss which package is right for your organisation.
View Bundle Pricing →
Custom Packs
Can't find exactly what you need?
We can create bespoke toolkit packages tailored to your specific sector, regulatory environment, or organisational structure. Contact us to discuss a custom solution.
Discuss Custom Pack →

Tools, Frameworks &
Capability Solutions

Six categories of ready-made professional toolkits — designed for operational, regulated, and project-driven environments. Buy as a complete bundle or choose individual packs. All delivered digitally with email support included.

Category 01
Centre of Excellence Packages

Folder architecture, template libraries, SharePoint layout, and governance design — everything to set up a structured CoE from scratch.

Starter PackProfessional PackEnterprise PackDesign & Setup Service
Category 02
Risk Toolkit Packages

Risk registers, scoring guides, workshop facilitation packs, reporting templates, and dashboards ready for immediate use.

Risk Register PackRisk Workshop PackRisk Reporting Pack
Category 03
Control & Assurance Toolkits

RACM templates, control testing packs, assurance working papers, and audit readiness kits for internal audit and risk teams.

RACM Template PackAssurance Working PapersAudit Readiness Kit
Category 04
Finance & AP Toolkit Packages

AP process packs, P2P control templates, supplier onboarding kits, month-end checklists, and finance SOP libraries.

AP Process PackP2P Control PackFinance SOP Library
Category 05
Governance & Compliance Packages

Policy and SOP template libraries, governance framework packs, and compliance checklists for regulated organisations.

Policy Template LibraryGovernance Framework PackCompliance Checklist Pack
Category 06
Transformation & Setup Packs

New team and function setup packs, transformation toolkits, project assurance resources, and operating model packs.

New Team Setup PackTransformation ToolkitOperating Model Pack

Toolkit & Bundle Packages

Choose individual packs for specific needs, or select a bundle for comprehensive coverage. All packages are delivered digitally. Get in touch to discuss which option is right for your organisation.

Starter
For small teams building foundational structure

  • Risk register template pack
  • Basic control framework template
  • SOP template library (10 templates)
  • Month-end checklist pack
  • CoE starter folder structure
  • Tracker & register templates
  • Email support for 30 days
Most Popular
Professional
For medium organisations and regulated businesses

  • Full risk toolkit (register, workshop, reporting)
  • RACM template & control testing pack
  • Assurance working papers pack
  • Audit readiness kit
  • Full SOP & policy template library
  • CoE professional pack
  • Governance & compliance framework pack
  • Finance & AP template bundle
  • Priority email support for 60 days
Enterprise
For large, regulated, or infrastructure organisations

  • Everything in Professional
  • CoE Enterprise pack (full framework design)
  • SharePoint structure & document design
  • Reporting & dashboard templates
  • Transformation & operating model pack
  • Project assurance toolkit
  • CoE design consultation (2 hours)
  • 30-day implementation support
  • Customisation call included

All packages are delivered digitally. Need something bespoke, or want to combine toolkits with consulting or training? Contact us to discuss a tailored solution.

Ready to equip your team
with the right tools & frameworks?
Back to Home
07
ICT & Project Delivery

Technology, Transformation
& Business Analysis

Experienced ICT, Business Analysis and Project Delivery professionals supporting organisations through technology change, digital transformation, and operational improvement — from early requirements definition through to go-live assurance and post-implementation review.

Enquire About This Division

What We Deliver

  • 01
    Business Process Analysis
    AS-IS and TO-BE process mapping to identify inefficiencies, define improvement opportunities, and document current and future state workflows.
  • 02
    Requirements Gathering & Documentation
    Structured elicitation, analysis, and documentation of functional and non-functional requirements — traceable, agreed, and implementation-ready.
  • 03
    Stakeholder Engagement & Workshop Facilitation
    Skilled facilitation of workshops, discovery sessions, and stakeholder engagement activities to align requirements and drive project momentum.
  • 04
    Agile Backlog & User Story Development
    Backlog creation, refinement, and prioritisation with well-structured user stories, acceptance criteria, and sprint-ready requirements.
  • 05
    Data Analysis & Power BI Reporting
    Data analysis, insight generation, and Power BI dashboard development to support project reporting, decision-making, and performance tracking.
  • 06
    ICT Project Delivery & PMO Support
    End-to-end project delivery support covering planning, coordination, governance, RAID log management, and stakeholder reporting throughout the project lifecycle.
  • 07
    Testing Support (SIT / UAT)
    Coordination and support for System Integration Testing and User Acceptance Testing — test planning, defect tracking, and sign-off facilitation.
  • 08
    Business Readiness & Go-Live Support
    Ensuring your organisation is operationally ready for system go-live — readiness assessments, training coordination, cutover planning, and hypercare support.
  • 09
    Change Management Support
    Supporting the people side of change — impact assessments, communications planning, training needs analysis, and stakeholder readiness tracking.
  • 10
    SOP & Process Documentation
    Development of clear, professionally written Standard Operating Procedures and process documentation to embed new ways of working and support go-live readiness and operational continuity.
  • 11
    Post-Implementation Review & Assurance
    Independent review of project outcomes against objectives — benefits tracking, lessons learned, and assurance that the solution is delivering as intended.
Who This Is For
Organisations delivering technology and transformation programmes
Whether you are implementing a new system, running a digital transformation programme, or managing operational change — BECAH provides the business analysis, project delivery, and assurance capability to keep your programme on track.
Financial Services Energy & Utilities Public Sector Technology Operations & Finance
Our Team
Experienced Project Managers & Business Analysts
Our delivery team includes experienced Project Managers and Business Analysts who have supported ICT, transformation, and change programmes across multiple sectors. We provide hands-on delivery, documentation, and assurance support throughout the project lifecycle.
Related Divisions
Often paired with
ICT & Project Delivery works naturally alongside our Consulting division for operating model design, Risk, Controls & Assurance for transformation assurance, and our Tools & Frameworks division for SOP and process documentation packages.
Division 02 → Division 03 → Division 06 →
Ready to strengthen your
project delivery capability?
Back to Home
08
Internal Audit Services

Independent Audit
You Can Rely On

We deliver professional internal audit services — rigorous methodology, clear reporting, and an independent opinion that gives the people who matter the confidence to make sound decisions. Every engagement follows our 11-phase methodology, built on the IIA Global Internal Audit Standards.

Start A Conversation How We Work
Standards We Work To
IIA Global Internal Audit Standards 2024 Public Sector Internal Audit Standards (PSIAS) Accounts & Audit Regulations 2015 CIPFA Good Governance Framework

What BECAH Delivers

Whether you need a complete outsourced audit function, specialist co-sourced capacity, or independent assurance over a specific area of risk — we deliver it to the same professional standard every time.

Core Service
Controls Assurance Audits

We test whether your controls are designed to address the risks they are supposed to prevent — and whether they are operating effectively in practice. Every engagement produces a formal, evidenced opinion with a clear action plan.

Fully Outsourced
Outsourced Internal Audit Function

For organisations without an in-house audit team, BECAH provides the complete function — from annual risk-based planning through to follow-up reporting. A professional, independent audit service without the overhead of an internal team.

Co-Sourced
Co-Sourced Partnership

We work alongside your existing audit team or the firm that holds your contract — providing specialist expertise, additional capacity, or deep-dive assurance on the high-risk areas you want to prioritise.

Full Cycle
Follow-Up & Action Tracking

We do not stop at the report. We issue management action trackers, conduct formal follow-up reviews, and report implementation status to your governance body — ensuring agreed actions are completed, not just promised.

Advisory
Advisory Engagements

Where you need professional guidance on risk management, control design, or governance arrangements — without a formal audit opinion — we offer structured, independent advisory support tailored to your needs.

Specialist
Project & Programme Assurance

Independent assurance over major projects and change programmes — assessing whether governance, risk, and controls are strong enough to protect delivery. We prefer early involvement, before problems become expensive.

A Structured Approach, Every Time

Every BECAH engagement follows an 11-phase methodology — from mandate through to closure. You know exactly what to expect, when to expect it, and what the output will look like.

1
Engagement Initiation & Mandate

Scope, reporting lines, and engagement terms confirmed in writing before any work begins.

2
Preliminary Information Request

Governance, risk, financial, and prior audit documents requested and formally logged.

3
Desk Review: Risk & Context Analysis

Risk universe mapped and prioritised. Assurance gaps identified before any stakeholder contact.

4
Pre-Engagement Stakeholder Meetings

Structured conversations with senior stakeholders to gather operational intelligence and context.

5
Engagement Planning & Programme Setup

Detailed scopes, risk and control matrix, testing framework, and kick-off materials prepared.

6
Fieldwork Preparation & Walkthroughs

End-to-end process walkthroughs conducted. Process flows validated and signed off by process owners.

7
Audit Test Planning

Sample sizes determined. Test scripts written. Evidence requests issued to named owners.

8
Fieldwork Execution: Controls Testing

Evidence received, logged, and tested. Workpapers completed to IIA evidence standards.

9
Findings & Management Response

Structured findings issued, root causes addressed, management responses rigorously assessed.

10
Reporting Chain

Final report delivered to the appropriate governance body. Opinion stated clearly and defended.

11
Closure & Follow-Up

Management action tracker issued, follow-up review conducted, implementation reported. Formally closed.

The Same Standard. Every Time.

Our methodology means no engagement is improvised and no report is assembled under time pressure.

Each phase is completed and confirmed before the next opens. The audit committee receives a report they can rely on — not one that reflects the preferences of the people being audited.

Every engagement concludes with a formal audit opinion — clearly stated, fully evidenced, and never softened in response to management pressure.

Audit Coverage Includes
Financial Controls Procurement & Contracts Information Technology Housing Governance & Compliance People & HR Social Care Specialist Reviews

How We Can Work Together

  • A
    Your Organisation, Direct
    BECAH is appointed directly by your organisation. We work with your senior leadership and governance structures, report to your commissioning officer, and present to your board or audit committee when required. Scope, fees, and deliverables are agreed upfront in writing — always.
  • B
    Specialist Partner To Your Firm
    Your firm holds the client contract. We work alongside your team as a specialist co-sourced auditor — delivering fieldwork, findings, and draft reports to your quality standard. All client-facing reporting is managed through you. A seamless extension of your capability.
  • ?
    Not Sure? Let's Talk
    Not every situation fits neatly into a category. Tell us what you are looking for — a single engagement, a full annual programme, or an initial conversation — and we will take it from there. No obligation. No pressure.
Who This Is For
Public sector bodies, local authorities, and firms seeking a specialist co-sourced partner
Any organisation that needs credible, evidence-based assurance over its governance, risk, and controls. We work directly with organisations and alongside audit firms and consultancies that need specialist capacity.
Local Authorities Public Sector Bodies Audit Firms (Co-Source) Regulated Organisations
Related Divisions
Internal Audit works alongside Risk, Controls & Assurance and Consulting
Division 02 provides control framework design and testing that complements our audit work. Division 03 provides advisory and governance support that often follows an audit engagement.
Division 02 → Division 03 →
Ready for an audit you can actually rely on?
Back to Home

BECAH Academy

The Skills Organisations
Need. The Training Practitioners Deserve.

BECAH professional programmes span Risk, Audit, Controls, Assurance, Governance, Compliance, Project, AI and Technology disciplines — designed by practitioners and built around real workplace challenges. Every programme comes with practical templates, role playbooks, and resources you can apply from day one. Programmes are available for individual enrolment, group and team delivery, and organisational licensing — and if you need something tailored, we build that too.

How Our Programmes Are Delivered

Public Cohort Programmes

Join scheduled virtual or classroom-based programmes delivered by BECAH facilitators alongside professionals from different organisations and industries.

Corporate & Team Training

Virtual, in-person, or blended delivery brought directly into your organisation, customised around your business needs and objectives.

Licensed Delivery

Licence BECAH programmes for your academy, L&D platform, or apprenticeship scheme. Train-the-trainer support included.

Bespoke Development

We adapt existing programmes or design bespoke learning solutions built around your organisation's framework, processes, and maturity level.

19+
Programmes
400+
Modules
4
Delivery Formats
All
Sectors

Choose Your Learning Pathway

AI Series

AI Governance, Risk, Controls & Assurance

Four professional bundles for practitioners working with AI systems — covering risk, audit, controls, and assurance in AI environments. Built for professionals who need to govern, audit, and assure AI responsibly.

01

AI Risk Professional Bundle

Managing and Reporting Risk in AI Environments

20 Modules
+

A comprehensive programme for risk professionals working in or alongside AI environments. Covers AI risk identification, risk register development, model risk, data risk, regulatory risk, KRI monitoring, and board-level AI risk reporting.

Module 01Introduction to AI Risk Management
Module 02AI Risk Frameworks & Standards
Module 03AI Risk Identification & Categorisation
Module 04Model Risk Management
Module 05Data Risk in AI Systems
Module 06AI Risk Assessment & Scoring
Module 07AI Risk Register Development
Module 08AI Risk Appetite & Tolerance
Module 09AI Controls & Mitigation Planning
Module 10AI Risk Monitoring & KRIs
Module 11Regulatory & Ethical AI Risk
Module 12Third-Party AI Risk
Module 13AI Incident Management
Module 14AI Risk Reporting for Management
Module 15AI Risk Governance & Oversight
Module 16AI Risk in Financial Services
Module 17Emerging AI Risk
Module 18Board-Level AI Risk Reporting
Module 19AI Risk Review & Continuous Improvement
Module 20AI Risk Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
02

AI Audit Professional Bundle

Auditing AI Systems, Models, and Governance

22 Modules
+

Designed for internal auditors and assurance professionals auditing AI systems. Covers AI audit planning, model audit techniques, data quality audits, algorithmic bias review, regulatory compliance audits, and AI audit reporting.

Module 01Introduction to AI Auditing
Module 02AI Governance Frameworks for Auditors
Module 03Planning an AI Audit
Module 04Understanding AI Models for Auditors
Module 05Data Quality & Data Governance Audits
Module 06Algorithmic Bias & Fairness Review
Module 07AI Controls Testing
Module 08Model Validation Audits
Module 09Third-Party AI Audits
Module 10Regulatory Compliance Audits for AI
Module 11AI Audit Fieldwork & Evidence
Module 12AI Audit Findings & Reporting
Module 13AI Audit Recommendations
Module 14Continuous Auditing of AI Systems
Module 15AI Risk in the Audit Universe
Module 16AI Audit Committee Reporting
Module 17Auditing AI in Financial Services
Module 18Auditing AI in Public Sector
Module 19Emerging Techniques in AI Auditing
Module 20AI Ethics & Responsible AI for Auditors
Module 21Building an AI Audit Programme
Module 22AI Audit Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
03

AI Controls Professional Bundle

Designing and Testing Controls for AI Systems

20 Modules
+

For controls professionals responsible for designing, implementing, and testing controls over AI systems. Covers AI control frameworks, model governance controls, data controls, access and change controls for AI, control testing, and remediation.

Module 01Introduction to AI Controls
Module 02AI Control Frameworks & Standards
Module 03Designing Controls for AI Systems
Module 04Model Governance Controls
Module 05Data Controls in AI Environments
Module 06Access Controls for AI Systems
Module 07Change Controls for AI Models
Module 08AI Control Testing Methodology
Module 09Control Testing — Practical Application
Module 10AI Control Failures & Remediation
Module 11Third-Party AI Controls
Module 12Regulatory Controls for AI
Module 13AI Controls Monitoring & KCIs
Module 14Control Health Reporting for AI
Module 15AI Controls in Financial Services
Module 16Segregation of Duties in AI Workflows
Module 17AI Controls Documentation
Module 18Board Reporting on AI Controls
Module 19Continuous Improvement of AI Controls
Module 20AI Controls Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
04

AI Assurance Professional Bundle

Providing Assurance over AI Systems and Governance

30 Modules · 7 Phases
+

The most comprehensive AI assurance programme in the BECAH catalogue. Seven phases covering the full AI assurance lifecycle — from planning and scoping through to opinion, reporting, and board-level communication Suitable for senior assurance professionals and those building an AI assurance capability.

Phase 1AI Assurance Foundations & Planning
Phase 2AI Governance & Oversight Assurance
Phase 3Model Risk & Model Validation Assurance
Phase 4Data Quality & Data Governance Assurance
Phase 5AI Controls & Compliance Assurance
Phase 6AI Audit Findings & Recommendations
Phase 7AI Assurance Reporting & Capstone
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
IT Series

IT Governance, Risk, Controls & Assurance

Four professional bundles for practitioners working across IT governance, IT risk, IT controls, and IT assurance. Built for professionals who bridge the gap between technology and governance.

05

IT Risk Management Professional Bundle

End-to-End IT Risk Management

19 Modules
+

A comprehensive IT risk management programme covering IT risk identification, cyber risk, third-party IT risk, IT risk frameworks, KRI monitoring, and IT risk reporting.

Module 01Introduction to IT Risk Management
Module 02IT Risk Frameworks & Standards
Module 03IT Risk Identification & Categorisation
Module 04Cyber Risk Management
Module 05IT Risk Assessment & Scoring
Module 06IT Risk Register Development
Module 07IT Risk Appetite & Tolerance
Module 08Third-Party IT Risk
Module 09IT Risk Controls & Mitigation
Module 10IT Risk Monitoring & KRIs
Module 11IT Incident & Resilience Risk
Module 12Data & Privacy Risk
Module 13Change & Project IT Risk
Module 14IT Risk Reporting for Management
Module 15IT Risk Governance & Oversight
Module 16Cloud & Infrastructure Risk
Module 17Regulatory IT Risk
Module 18Board-Level IT Risk Reporting
Module 19IT Risk Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
06

IT Audit Professional Bundle

Auditing IT Systems, Infrastructure, and Controls

22 Modules
+

A structured IT audit programme for internal auditors and assurance professionals. Covers IT general controls audits, cyber audits, change management audits, access control reviews, IT audit reporting, and audit committee communication.

Module 01Introduction to IT Auditing
Module 02IT Audit Frameworks & Standards
Module 03Planning an IT Audit
Module 04IT General Controls (ITGC) Auditing
Module 05Access Control Reviews
Module 06Change Management Audits
Module 07Cyber Security Audits
Module 08Data Management & Privacy Audits
Module 09Third-Party & Vendor Audits
Module 10Cloud Infrastructure Audits
Module 11IT Audit Fieldwork & Evidence
Module 12IT Audit Findings & Ratings
Module 13IT Audit Reporting
Module 14IT Audit Recommendations & Tracking
Module 15Continuous IT Auditing
Module 16IT Audit in Financial Services
Module 17IT Audit in Public Sector
Module 18Incident & Resilience Audits
Module 19IT Audit Committee Reporting
Module 20Emerging Technology Audits
Module 21Building an IT Audit Programme
Module 22IT Audit Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
07

IT Controls Professional Bundle

Designing, Testing and Reporting IT Controls

20 Modules
+

For IT and controls professionals designing, implementing, and testing IT controls. Covers IT general controls, application controls, ITGC testing, change controls, access controls, segregation of duties in IT, and IT controls reporting.

Module 01Introduction to IT Controls
Module 02IT Control Frameworks (COBIT, ISO 27001)
Module 03IT General Controls Design
Module 04Application Controls
Module 05Access & Identity Controls
Module 06Change Management Controls
Module 07Backup & Recovery Controls
Module 08IT Controls Testing Methodology
Module 09ITGC Testing — Practical Application
Module 10Control Failures & Remediation
Module 11Segregation of Duties in IT
Module 12Third-Party IT Controls
Module 13IT Controls Monitoring
Module 14IT Controls Health Reporting
Module 15Cloud Controls
Module 16Cyber Controls
Module 17IT Controls in Financial Services
Module 18Regulatory IT Controls
Module 19Board Reporting on IT Controls
Module 20IT Controls Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
08

IT Assurance Professional Bundle

Providing Assurance over IT Systems and Digital Infrastructure

20 Modules
+

Covers IT assurance planning, scoping, delivery, findings, and reporting. Designed for assurance professionals providing independent assurance over IT systems, digital transformation programmes, and technology governance frameworks.

Module 01Introduction to IT Assurance
Module 02IT Assurance Frameworks
Module 03IT Assurance Planning & Scoping
Module 04IT Governance Assurance
Module 05IT Controls Assurance
Module 06Cyber Assurance
Module 07Data & Privacy Assurance
Module 08Third-Party IT Assurance
Module 09IT Assurance Fieldwork
Module 10IT Assurance Findings & Opinions
Module 11IT Assurance Reporting
Module 12IT Assurance Recommendations
Module 13Combined IT Assurance
Module 14Digital Transformation Assurance
Module 15Cloud Assurance
Module 16IT Assurance in Financial Services
Module 17IT Assurance in Public Sector
Module 18IT Audit Committee Reporting
Module 19Building an IT Assurance Programme
Module 20IT Assurance Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
GRC Professional Series

Risk, Audit, Controls, Assurance & Governance

The core BECAH professional series — covering enterprise risk, internal audit, controls, assurance, and governance across all sectors. The most established programmes in the BECAH catalogue, each built around real organisations and real scenarios.

09

Enterprise Risk Management Professional Bundle

End-to-End ERM

16 Modules
+

A comprehensive ERM programme covering the full risk management lifecycle — from risk identification and assessment through to appetite, reporting, governance, and a practical capstone

Module 01Introduction to Enterprise Risk Management
Module 02ERM Frameworks & Standards
Module 03Risk Identification & Risk Universe
Module 04Risk Assessment & Scoring
Module 05Risk Register Development & Management
Module 06Risk Appetite & Risk Tolerance
Module 07Risk Controls & Mitigation Planning
Module 08Key Risk Indicators (KRIs)
Module 09Risk Monitoring & Tracking
Module 10Risk Reporting & Dashboards
Module 11Risk Governance & Three Lines Model
Module 12Running Risk Workshops
Module 13Operational Risk in Practice
Module 14Emerging Risk & Horizon Scanning
Module 15Board-Level Risk Reporting
Module 16ERM Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
10

Building a Risk Function — End-to-End Execution Programme

Setting Up and Running a Risk Management Function

21 Modules
+

A practical programme for professionals tasked with building or restructuring a risk function from the ground up. Covers operating model design, team structure, framework development, policy creation, stakeholder engagement, and function governance.

Module 01Understanding the Brief & Mandate
Module 02Risk Function Operating Model Design
Module 03Risk Team Structure & Roles
Module 04Risk Framework Development
Module 05Risk Policy & Procedure Creation
Module 06Risk Appetite Statement Design
Module 07Risk Register Design & Implementation
Module 08KRI Design & Implementation
Module 09Risk Committee Setup & Governance
Module 10Stakeholder Engagement Strategy
Module 11Risk Culture & Awareness
Module 12Risk Reporting Suite Design
Module 13Three Lines Model in Practice
Module 14Risk Technology & Tools
Module 15Risk Function Budget & Resources
Module 16Risk Function Performance Metrics
Module 17Regulatory & Compliance Considerations
Module 18Board & Audit Committee Engagement
Module 19First-Year Risk Function Roadmap
Module 20Common Pitfalls & How to Avoid Them
Module 21Risk Function Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£5,500
per person
individual enrolment
11

Internal Audit Professional Bundle

End-to-End Internal Audit Practice

15 Modules
+

A comprehensive internal audit programme covering the full audit lifecycle — planning, fieldwork, findings, reporting, and follow-up. Suitable for new and experienced auditors across all sectors.

Module 01Introduction to Internal Audit
Module 02Internal Audit Standards & Frameworks
Module 03Audit Universe & Risk-Based Planning
Module 04Engagement Planning & Scoping
Module 05Audit Fieldwork Techniques
Module 06Working Papers & Evidence Management
Module 07Audit Findings & Root Cause Analysis
Module 08Audit Ratings & Opinions
Module 09Audit Report Writing
Module 10Management Responses & Action Tracking
Module 11Audit Committee Reporting
Module 12Quality Assurance in Internal Audit
Module 13Stakeholder Relationships in Audit
Module 14Emerging Topics in Internal Audit
Module 15Internal Audit Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
12

Setting Up & Running an Internal Audit Function

Building an Internal Audit Function from Scratch

30 Modules
+

The most comprehensive internal audit function-building programme in the BECAH catalogue. Thirty modules covering everything from mandate and charter through to quality assurance, team development, and stakeholder engagement. Includes a Soft Skills Addendum

Module 01The IA Mandate & Charter
Module 02IA Operating Model Design
Module 03IA Team Structure & Roles
Module 04Audit Universe Development
Module 05Risk-Based Audit Planning
Module 06Annual Audit Plan Design
Module 07Audit Methodology & Standards
Module 08Engagement Management
Module 09Working Paper Standards
Module 10Findings & Reporting Standards
Module 11Action Tracking & Follow-Up
Module 12Audit Committee Relationships
Module 13Board Reporting for CAEs
Module 14IA Technology & Tools
Module 15Quality Assurance & Improvement
Module 16Co-sourcing & Guest Auditors
Module 17IA Budget & Resource Planning
Module 18IA Performance Metrics & KPIs
Module 19Stakeholder Engagement Strategy
Module 20IA Culture & Independence
Module 21–30Soft Skills Addendum + Capstone
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£5,500
per person
individual enrolment
13

Internal Controls & Control Framework Professional Bundle

Designing, Testing and Managing Internal Controls

15 Modules
+

A practical controls programme covering control design, the RACM, control testing, remediation, and controls reporting. Built for controls analysts, control owners, and risk and assurance professionals who work with control frameworks.

Module 01Introduction to Internal Controls
Module 02Control Frameworks (COSO, ISO 31000)
Module 03Control Design Principles
Module 04Preventive, Detective & Corrective Controls
Module 05Risk & Control Matrix (RACM)
Module 06Control Ownership & Accountability
Module 07Control Testing Methodology
Module 08Control Testing — Practical Application
Module 09Control Failures & Root Cause
Module 10Remediation Planning & Tracking
Module 11Control Monitoring & KCIs
Module 12Controls Reporting for Management
Module 13Financial Controls & SOX
Module 14Controls Governance & Three Lines
Module 15Controls Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
14

Assurance & Review Professional Bundle

End-to-End Assurance Practice

15 Modules
+

Covers the full assurance lifecycle including planning, scoping, fieldwork, opinions, findings, and reporting. Designed for assurance professionals across all sectors providing independent assurance to management and boards.

Module 01Introduction to Assurance
Module 02Assurance Frameworks & Standards
Module 03Assurance Planning & Scoping
Module 04Assurance Fieldwork Techniques
Module 05Working Papers & Evidence
Module 06Assurance Findings & Root Cause
Module 07Assurance Opinions & Ratings
Module 08Assurance Report Writing
Module 09Recommendations & Action Tracking
Module 10Combined Assurance & Three Lines
Module 11Assurance Committee Reporting
Module 12Quality in Assurance
Module 13Stakeholder Management in Assurance
Module 14Emerging Topics in Assurance
Module 15Assurance Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
15

Governance & Compliance Professional Bundle

Governance Frameworks, Compliance Management, and Board Reporting

16 Modules
+

A structured programme for governance and compliance professionals. Covers governance frameworks, regulatory compliance, policy management, compliance monitoring, horizon scanning, and board-level governance reporting.

Module 01Introduction to Governance & Compliance
Module 02Corporate Governance Frameworks
Module 03The Three Lines Model
Module 04Regulatory Compliance Management
Module 05Compliance Universe & Obligation Mapping
Module 06Policy Management & Governance
Module 07Compliance Monitoring & Testing
Module 08Compliance Risk Management
Module 09Regulatory Horizon Scanning
Module 10Consumer Duty & FCA Compliance
Module 11GDPR & Data Compliance
Module 12Board & Committee Governance
Module 13Governance Reporting for Boards
Module 14Compliance Culture & Awareness
Module 15Governance Improvement & Maturity
Module 16Governance & Compliance Capstone
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
Project Series

Project Risk, Controls & Assurance

Three professional bundles for practitioners working in project environments — covering project risk, project controls, and project assurance. Built for project professionals, PMO teams, and assurance practitioners supporting major programmes.

16

Project Risk Management Professional Bundle

Managing Risk Across Projects and Programmes

21 Modules
+

A comprehensive project risk management programme covering risk identification, Monte Carlo analysis, risk registers for projects, stakeholder risk communication, and board-level project risk reporting

Module 01Introduction to Project Risk Management
Module 02Project Risk Frameworks & Standards
Module 03Project Risk Identification
Module 04Project Risk Assessment & Scoring
Module 05Project Risk Register Management
Module 06Risk Appetite in Project Environments
Module 07Quantitative Risk Analysis
Module 08Risk Response Planning
Module 09Opportunity Management
Module 10Project Risk Monitoring & Control
Module 11Risk in Project Planning & Scheduling
Module 12Risk in Project Cost Management
Module 13Stakeholder Risk Communication
Module 14Programme & Portfolio Risk
Module 15Risk in Change Management
Module 16Procurement & Supply Chain Risk
Module 17Risk Reporting for Project Boards
Module 18Risk in Agile Environments
Module 19Lessons Learned & Risk Reviews
Module 20Risk Maturity in Projects
Module 21Project Risk Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
17

Project Controls Professional Bundle

Cost, Schedule and Performance Controls for Projects

16 Modules
+

A structured project controls programme covering earned value management, cost control, schedule control, change control, and project performance reporting

Module 01Introduction to Project Controls
Module 02Project Controls Frameworks
Module 03Scope Control & Change Management
Module 04Schedule Planning & Baseline
Module 05Schedule Control & Monitoring
Module 06Cost Planning & Budgeting
Module 07Cost Control & Forecasting
Module 08Earned Value Management (EVM)
Module 09Risk & Contingency in Controls
Module 10Project Performance Reporting
Module 11Project Controls Dashboards
Module 12Procurement Controls
Module 13Project Controls in Agile
Module 14PMO Controls & Governance
Module 15Project Board Reporting
Module 16Project Controls Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
18

Project Assurance Professional Bundle

Providing Independent Assurance over Projects and Programmes

18 Modules
+

Covers the full project assurance lifecycle — from assurance planning and gateway reviews through to findings, opinions, and reporting to project boards and sponsors. Designed for assurance professionals, PMO leads, and internal auditors providing assurance over major programmes.

Module 01Introduction to Project Assurance
Module 02Project Assurance Frameworks
Module 03Assurance Planning for Projects
Module 04Gateway Reviews
Module 05Project Assurance Fieldwork
Module 06Risk Assurance in Projects
Module 07Controls Assurance in Projects
Module 08Financial Assurance in Projects
Module 09Procurement Assurance
Module 10Assurance Findings & Opinions
Module 11Project Assurance Reporting
Module 12Reporting to Project Boards & Sponsors
Module 13Recommendations & Action Tracking
Module 14Combined Assurance on Projects
Module 15Agile Project Assurance
Module 16Benefits Realisation Assurance
Module 17Building a Project Assurance Function
Module 18Project Assurance Capstone Project
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
Career Pathways Series

Become a GRC Professional

For individuals entering or developing within GRC. One comprehensive programme — the AI Assurance Professional Bundle — that maps the complete journey from foundations to practitioner level across risk, controls, and assurance disciplines.

19

AI Assurance Professional Bundle (also listed in AI Series)

The Complete Career Pathway — Foundations to Senior Practitioner Across All GRC Disciplines

30 Modules · 7 Phases
+

The BECAH AI Assurance Professional Bundle doubles as the most comprehensive career development programme in the catalogue — mapping the full journey from GRC foundations through to board-level assurance practice. Individuals new to the profession can use this as their complete career pathway programme. Experienced practitioners use it to develop AI assurance as a specialism.

Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£3,000
per person
individual enrolment
GRC Intelligence Series

Power BI for GRC Professionals

A dedicated programme for GRC professionals who want to transform how their function reports to management and boards — building professional intelligence dashboards using Power BI, without needing a technical or data background.

20

Become a GRC Intelligence Analyst Coming Soon

Build professional Risk, Audit, Controls, Assurance and Governance dashboards using Power BI — no technical background required

Core + Role Tracks
+

GRC professionals produce enormous amounts of data — risk registers, audit findings, control testing results, compliance obligations, board reports. Most of it sits in spreadsheets, presented in static slides, and read by nobody. This programme changes that. You will learn to build complete, professional intelligence dashboards using Power BI that turn your GRC data into management information that actually gets used. No prior Power BI or data experience required. Designed specifically for GRC practitioners — every exercise, dataset, and dashboard is built around real governance, risk, audit, and assurance scenarios.

GRC Core TrackCompleted by every learner — Power BI foundations, data quality & governance, DAX & the GRC KPI library, data storytelling for executives, stakeholder & consulting skills
C01Welcome to Power BI — connecting to data, navigating the interface, building your first dashboard
C02Connecting and Shaping GRC Data — Power Query, cleaning messy risk and audit data, combining sources
C03Building Your First GRC Dashboard — visuals, slicers, filters, multi-page reports, formatting
C04Understanding GRC Data & Data Models — star schema, fact and dimension tables, relationships
C05Data Quality & Data Governance — profiling, validation rules, completeness scoring, the data quality dashboard
C06DAX Foundations & the GRC KPI Library — measures, calculated columns, 25+ pre-built GRC measures
C07Visuals That Tell a Story — choosing the right visual, RAG logic, conditional formatting, heat maps
C08Data Storytelling for Executive Audiences — board pack design, dynamic commentary, drill-through, tooltips
C09Stakeholder & Consulting Skills — requirements gathering, design workshops, managing scope, presenting dashboards
C10Core Track Capstone — build a complete GRC foundation suite from scratch
Role TracksLearner selects their discipline — Risk Analyst, Audit Analyst, Controls Analyst, Assurance Analyst, or Governance & Compliance Analyst
Risk Analyst TrackRisk register dashboard · KRI monitoring dashboard · ERM specialist dashboards · Board risk pack
Audit Analyst TrackAudit plan tracker · Findings dashboard · Action tracking dashboard · Audit committee pack
Controls Analyst TrackControl testing tracker · Control health dashboard · Remediation tracker · Financial controls suite
Assurance Analyst TrackAssurance plan tracker · Opinion dashboard · Recommendation monitor · Combined assurance view
Governance & Compliance TrackCompliance universe tracker · Policy monitoring dashboard · Regulatory horizon scanner · Board compliance pack
Advanced TrackAdvanced DAX · Power BI Service administration · SharePoint & Power Automate integration · AI for Power BI · Portfolio building · GRC Intelligence Capstone
Included with this programme: Role Playbooks, practical templates, toolkits, and resources relevant to this discipline — everything you need to apply your learning from day one.
£4,500
per person
individual enrolment

Group, Corporate & Licensing

Pricing for Teams,
Organisations & Providers

The prices shown on this page are for individual enrolment on public cohort programmes. If you are looking to train a team, bring a programme in-house, license our curriculum for your academy or apprenticeship scheme, or discuss a bespoke or customised programme — pricing is agreed separately based on your specific requirements.

Corporate & Team Training
Virtual, in-person or blended delivery for your team. Customised to your sector, objectives, and schedule.
Licensed Curriculum
Licence BECAH programmes for your academy, L&D platform, or apprenticeship scheme. Train-the-trainer support included.
Bespoke & Customised Programmes
Adapted to your organisation's framework, processes, and maturity level. Built around your context.

Not sure which bundle is right for you?

Get in touch and we will help you choose the right pathway based on your role, experience, sector, and learning goals. We also offer group and team delivery and organisational licensing. For group, corporate, and licensing enquiries, get in touch to discuss a package suited to your needs.

Back to Home

BECAH Products

Intelligence Suites, Playbooks
& Professional Toolkits

Ready-made professional products you can purchase standalone — whether or not you are enrolled on a BECAH programme. GRC Intelligence Suites give your team the dashboards they need from day one. Role Playbooks guide your practice step by step. Toolkits and frameworks give you the templates to operate professionally. All priced on enquiry.

Step-by-Step Practice Guides for GRC Professionals

BECAH Role Playbooks are practical, step-by-step guides to executing the work in each GRC role — what to do, in what order, and how to do it. Available as standalone purchases for any professional who wants structured guidance without enrolling on a full programme.

Risk
Risk Analyst Playbook
End-to-end execution guide for risk analysts — risk identification, RACM, risk register management, KRI monitoring, risk reporting, and board pack production.
Controls
Controls Analyst Playbook
Step-by-step guide to controls analysis — control design, RACM development, control testing, remediation tracking, and controls reporting for management.
Internal Controls
Internal Controls Analyst Playbook
Practical execution guide focused on internal controls — control framework design, SOX-style testing, financial controls, remediation management, and committee reporting.
Assurance
Assurance Analyst Playbook
Complete execution guide for assurance analysts — assurance planning, fieldwork, opinions, findings, recommendations, and stakeholder reporting.
Internal Audit
Internal Audit Analyst Playbook
Practical guide for internal audit analysts — audit planning, fieldwork execution, working papers, findings documentation, report writing, and action tracking.
Governance & Compliance
Governance & Compliance Analyst Playbook
Step-by-step guide to governance and compliance practice — compliance universe management, policy governance, horizon scanning, and board compliance reporting.
Project Assurance
Project Assurance Analyst Playbook
Execution guide for project assurance — assurance planning for projects, gateway reviews, project board reporting, combined assurance, and benefits realisation assurance.

Professional Templates & Working Documents

Professionally designed toolkit packs, template libraries, and working document sets — ready to use from day one. Organised by discipline so you can buy exactly what your function needs without purchasing a full bundle.

Risk Management
Risk Management Toolkit

A complete set of professional risk management templates covering the full risk lifecycle — from identification through to reporting and governance.

  • Risk register template (Excel — inherent, residual, treatment tracking)
  • Risk appetite statement template
  • Risk heat map and scoring matrix
  • KRI monitoring tracker with RAG logic
  • Risk treatment and action log
  • Risk report template (management and board versions)
  • Risk workshop facilitation guide and templates
  • Three Lines Model mapping template
Controls
Controls & RACM Toolkit

Everything a controls team needs to design, test, and report on internal controls — from the risk and control matrix through to remediation tracking and committee reporting.

  • Risk and Control Matrix (RACM) template
  • Control design and description template
  • Control testing workpaper templates
  • Test result and evidence log
  • Control failure and root cause log
  • Remediation tracker and management action plan
  • Control health summary reporting template
  • Segregation of duties matrix template
Internal Audit
Internal Audit Toolkit

A comprehensive internal audit document set covering the full audit lifecycle — from annual planning through to findings, reporting, and action tracking.

  • Audit universe template
  • Annual audit plan template
  • Engagement planning and scoping document
  • Audit programme template
  • Working paper templates (interview, walkthrough, testing)
  • Evidence request list template
  • Findings log and grading criteria
  • Audit report template (management and committee versions)
  • Management action plan and tracking template
  • Audit readiness assessment and checklist
Assurance
Assurance Working Papers & Reporting Toolkit

Professional assurance documents covering the end-to-end assurance engagement lifecycle — from planning and fieldwork through to opinions, reports, and recommendations.

  • Assurance plan and scope template
  • Assurance programme template
  • Working paper templates (planning, fieldwork, conclusion)
  • Evidence cross-reference log
  • Finding log and grading criteria
  • Assurance opinion template
  • Assurance report template
  • Recommendation tracker and follow-up log
  • Combined assurance mapping template
  • Stakeholder communication templates
Governance & Compliance
Governance & Compliance Toolkit

A complete governance and compliance document set — compliance universe management, policy governance, regulatory horizon scanning, and board reporting templates.

  • Compliance universe and obligation register template
  • Compliance monitoring and testing log
  • Regulatory horizon scanning tracker
  • Policy register and review schedule template
  • Policy template (standard format, 5 versions)
  • Board compliance report template
  • Governance terms of reference template
  • Committee meeting pack template
Finance & Accounts Payable
Finance Controls & AP Toolkit

Professional finance controls and accounts payable templates for teams that need properly documented processes, controls, and month-end procedures.

  • Accounts payable SOP and process flowchart
  • Invoice processing and approval matrix
  • Three-way match checklist
  • Supplier onboarding and due diligence template
  • Month-end close checklist and schedule
  • Bank reconciliation template
  • Finance controls register template
  • Exception and escalation log
  • Finance risk and control matrix (RACM)
Centre of Excellence
CoE Starter Kit

Everything a new or restructuring GRC team needs to establish a well-governed Centre of Excellence — structure, governance documents, operating procedures, and a core template library.

  • CoE folder and filing structure
  • Terms of reference template
  • CoE operating procedures document
  • Roles and responsibilities matrix
  • Core tracker templates (risk, actions, findings)
  • Onboarding and induction guide template
  • CoE performance metrics and KPI template
Governance
Policy & SOP Template Library

A library of 20+ professionally structured policy and SOP templates covering the most commonly required governance, risk, financial controls, and compliance documents.

  • Risk management policy template
  • Internal audit charter template
  • Anti-fraud and whistleblowing policy
  • Financial controls and delegated authority policy
  • Procurement and expenses policy
  • Data protection and information security policy
  • Conflict of interest policy
  • SOP template (standard format, adaptable)
  • 10+ further policy templates across GRC disciplines

Ready-Made Professional Dashboards — by Role

Each GRC Intelligence Suite is a professionally built Power BI dashboard pack for a specific analyst role. Buy the suite for your team, connect it to your data, and have professional management reporting running immediately. No course enrolment required — these are standalone products. Each suite includes all the dashboards a professional in that role needs to report to management and boards.

Coming Soon
Audit Analyst
Audit Intelligence Suite
  • Audit plan tracker — Gantt view, resource analysis, completion trend
  • Findings dashboard — by rating, area, and team, repeat findings, trend
  • Action tracking dashboard — status, ageing, escalation view, closure rate
  • Audit committee pack — one-page format, dynamic commentary
Coming Soon
Controls Analyst
Controls Intelligence Suite
  • Control testing tracker — plan vs actual, results by domain, drill-through
  • Control health dashboard — health score, repeat failures, year-on-year trend
  • Remediation status tracker — ageing analysis, management action plan table
  • Financial controls suite — SOX-style dashboard, segregation of duties view
Coming Soon
Assurance Analyst
Assurance Intelligence Suite
  • Assurance plan tracker — timeline, coverage map, engagement status
  • Opinion & findings dashboard — opinion breakdown, trend, thematic analysis
  • Recommendation monitor — priority view, closure rate trend, area performance
  • Combined assurance view — three lines coverage matrix, gaps and overlaps
  • Stakeholder reporting pack — one-page committee format
Coming Soon
Governance & Compliance Analyst
Governance & Compliance Intelligence Suite
  • Compliance universe tracker — status by regulator, obligation table, trend
  • Policy monitoring dashboard — review calendar, health score, overdue policies
  • Regulatory horizon scanner — change pipeline, implementation tracker
  • Board compliance pack — one-page format, dynamic commentary
Back to Home

Governance, Risk, Controls & Assurance

Governance, Risk, Controls
& Assurance Insights

Expert perspectives on Governance, Risk, Controls, and Assurance — written by practitioners for practitioners across all sectors. Practical, relevant, and free to read.

Recent Insights

Your Organisation Is Using AI. Does Anyone Actually Govern It?

Artificial intelligence has quietly become part of how most organisations work. It filters applications, assists customer queries, supports credit decisions, drafts documents, and surfaces insights from data that would otherwise sit untouched. For the most part, this has happened organically — teams found tools that helped them work better, adopted them, and moved forward. That instinct for progress is a healthy one.

But as AI becomes more embedded in how decisions are made and how services are delivered, a natural and important question begins to surface: how do we make sure we remain in control of what these systems are doing on our behalf? That question — about oversight, accountability, and confidence — is what AI governance is really about. And it is one that more and more organisations are beginning to take seriously, often for the first time.

This article is not a technical guide. It is a reflection on where most organisations find themselves today, what AI governance looks like in practice, and how to begin building it in a way that is proportionate, practical, and genuinely useful — rather than something that simply sits in a policy library.

How AI tends to enter organisations

AI tools rarely arrive through a single strategic decision. More often, they come in through many smaller ones. A customer service team adopts a chatbot to handle routine queries. A finance team uses an AI-powered tool to automate reconciliations. A hiring manager subscribes to a screening platform that surfaces the most relevant CVs. A data analyst starts using generative AI to speed up report writing. Each of these decisions makes sense on its own terms. Taken together, across a whole organisation, they can create a landscape of AI use that nobody has fully mapped — and that nobody is centrally responsible for.

This is not a failure of leadership or judgement. It is a natural consequence of how innovation tends to work. The tools arrive faster than the frameworks to govern them. And when individual decisions are small and local, it is easy to miss the cumulative picture they create. The challenge, as AI becomes more consequential, is to step back and ask: what do we actually know about the AI we are relying on, and what confidence do we have that it is working as we intend?

What AI governance actually looks like

AI governance is not a compliance checkbox or an ethics statement on a website. At its most practical, it is the answer to a set of straightforward questions about each AI system an organisation uses: what does it do, who is responsible for it, how was it approved, how do we know it is performing correctly, and what would we do if it did not?

A working AI governance framework tends to have four components. The first is an AI inventory — a living register of the AI tools in use across the organisation, capturing what each one does, where it sits in a process or decision, and who owns it. The second is an approval process — a structured way of evaluating new AI tools before they are adopted, covering the risks they introduce, the controls needed to manage those risks, and the accountabilities attached to them. The third is ongoing monitoring — a mechanism for checking that AI systems continue to behave as expected over time, which matters because AI tools can drift in performance, especially as the data they process changes. And the fourth is a clear escalation path — an agreed set of steps for what happens when a concern is raised, including who is informed, what decisions need to be made, and how the outcome is recorded.

Most organisations already have elements of this — a partial register here, an informal approval conversation there. The opportunity is in connecting those elements into something coherent and consistent, so that the governance of AI is as reliable as the governance of any other operational risk.

The regulatory context

AI governance is also increasingly important from a regulatory perspective, which makes it relevant not just as an internal discipline but as a form of external accountability. The EU AI Act has introduced a risk-based framework that creates specific obligations for organisations deploying AI in higher-risk contexts — financial services, healthcare, employment decisions, and public sector applications among them. The FCA has signalled clearly that it expects firms to be able to explain and take responsibility for AI-influenced decisions that affect customers. The ICO has ongoing guidance on automated decision-making under UK GDPR that remains directly relevant to how many organisations use AI today.

What regulators are looking for is essentially what good internal governance already provides: evidence that an organisation understands the AI it uses, can demonstrate that appropriate oversight exists, and can show what happens when something needs to be reviewed or corrected. Organisations that have invested in building this capability will find they are well positioned — not just for regulatory examinations but for the broader confidence it gives to customers, employees, and boards.

A practical place to start

For many organisations, the most useful starting point is simply to build an honest picture of where they are. Before governance can be strengthened, there needs to be a clear view of what AI is in use, where it sits, and what decisions it touches. This discovery process — mapping the AI landscape across functions and platforms — tends to surface both more than expected and less structure than assumed. That is not a cause for alarm; it is useful information, and it is exactly the kind of insight that makes governance efforts targeted rather than generic.

From that foundation, the natural next step is to prioritise. Not every AI tool carries the same level of risk. The ones that influence material decisions — about customers, about employees, about financial outcomes — deserve deeper oversight first. Starting there, and building the approval process, monitoring, and accountability structures around those higher-risk areas, is a proportionate and sustainable approach.

A conversation worth having

AI governance is ultimately a leadership conversation — about what the organisation values, what risks it is comfortable carrying, and how it wants to be seen by the people it serves. Boards and senior leaders who are engaging with these questions early are giving themselves and their organisations something genuinely valuable: the time and space to build oversight thoughtfully, rather than reactively. If this is a conversation your organisation has not yet had in a structured way, there is real value in starting it — not because something has gone wrong, but because the organisations that govern AI well tend to be the ones that use it most confidently and most effectively.

BECAH has developed a free AI Governance Blueprint for organisations looking to understand and begin structuring their AI governance approach. It is available to download from the Free Resources section at becah.co.uk. If your organisation needs support building an AI governance framework, assessing its current AI risk landscape, or preparing for regulatory scrutiny — get in touch.

Audit Readiness Is Not a Sprint — It Is a Discipline

Every year, without fail, I see the same pattern. An audit notification arrives. A flurry of activity begins. Evidence is hunted down from inboxes and personal drives. People are briefed hurriedly on what auditors will ask. A week later, fieldwork starts — and the organisation is hoping it has done enough.

This is not audit readiness. This is audit panic dressed up as preparation. And the organisations that operate this way — however experienced they are — consistently receive more findings, spend more time on remediation, and have more uncomfortable conversations with their boards than they need to. The pre-audit sprint is expensive, stressful, and almost entirely avoidable.

Audit readiness is not something you achieve in the two weeks before fieldwork. It is something you build, maintain, and improve throughout the year. And once it is genuinely embedded, audits stop being events that disrupt your team — and start being structured confirmations of what everyone already knows. The question is what that building actually looks like in practice — and it starts well before any audit notification arrives.

Start with design — because everything else rests on it

The foundation of audit readiness is a documented control framework — a structured map that connects your key risks to the controls designed to manage them. Without this, everything else is being built on uncertain ground. You cannot evidence what has not been defined. You cannot own what has not been specified. You cannot test what exists only in someone's head.

Most organisations have some version of this — a Risk and Control Matrix, a process document, a control register. The more common problem is that it was built once and never maintained. It describes how the organisation operated two years ago, before the restructuring, before the new system, before three people changed roles. When auditors trace transactions through documentation that no longer reflects reality, the gap they find is immediate and telling.

So before anything else, review your control framework against how your organisation actually operates today. Work through your five highest-risk processes and confirm that every key control is documented with enough specificity to be tested — who performs it, how often, what it produces, and what evidence confirms it ran. A control named "management review of reports" is not specified. A control that names the reviewer, the report, the frequency, and the sign-off location is. That level of specificity is what makes everything that follows possible.

Once it is designed, someone has to own it

A well-designed control framework tells you what should happen. Ownership is what determines whether it actually does. Every key control needs a single named individual who is accountable for its execution — not a team, not a function, a person. That person is responsible for performing the control consistently, producing the required evidence, and escalating any issues that arise. Without that named individual, a control that exists on paper has no one watching whether it runs in practice.

The most common ownership failure I see is not the absence of names — it is names that were assigned and never revisited. Someone left the organisation. Someone moved roles. Someone was listed as owner of a control they have never heard of. Go through your framework and ask, for each key control: is the named owner still in the right position, and do they know what ownership requires of them? If you cannot answer both questions confidently, that is where to start. A brief conversation with each control owner — covering what evidence they must produce, how to escalate, and what to do if the control cannot run — takes very little time and makes the accountability real rather than nominal.

Ownership without evidence is just an assertion

When a control owner performs their control consistently and correctly, what do they leave behind? That is the evidence question — and it is where audit readiness most visibly succeeds or fails. A control that operated but left no retrievable evidence did not operate as far as an auditor is concerned. The auditor can only conclude what the evidence tells them. If it is absent, incomplete, or stored somewhere only one person can find, the conclusion will not be favourable.

This is directly connected to ownership. When control owners understand what evidence their control must produce, where to store it, and to what standard, evidence gaps stop being a documentation problem and start being a managed process. The practical steps are: define the evidence requirement for every key control — what record is produced, what it must contain, and where it is filed. Centralise storage so that any authorised colleague can retrieve it without asking. Then test it — pick two controls at random and try to retrieve last month's evidence without help. If you cannot do it in five minutes, you have found a gap that needs closing before your next audit.

With design, ownership, and evidence in place — now you can test

Pre-audit testing is only meaningful once the foundations above are in place. There is little value in testing a control that is poorly designed, has no clear owner, or cannot produce evidence. But once your controls are specified, owned, and evidenced, testing becomes the most powerful tool you have for staying ahead of findings.

For each of your highest-risk controls, work through two questions before any audit arrives. First — is this control designed to actually prevent or detect the risk it addresses? Second — did it operate as designed across the full period under review, consistently, by the right person, with evidence to prove it? Both questions are necessary. A well-designed control that ran inconsistently fails the operating effectiveness test. A consistently operated control with a design flaw fails regardless of how diligently it was performed.

The critical point is timing. Testing completed the week before fieldwork is not preparation — it is documented exposure with no time to act. Schedule your control self-assessment at least six weeks before planned fieldwork, put it in the governance calendar at the start of the year, and treat it as non-negotiable. Six weeks gives you time to investigate what you find, implement fixes, and confirm those fixes are operating before auditors arrive.

And none of this is sustained without governance oversight

Design, ownership, evidence, and testing — done well, these four things produce a strong audit outcome. But they only become a discipline rather than a one-off effort when leadership is actively invested in maintaining them. The organisations that consistently produce strong audit outcomes are the ones where the board and audit committee receive regular structured reporting on control effectiveness throughout the year — not just after fieldwork concludes — and where significant weaknesses are escalated before auditors find them. This means building audit readiness into the governance calendar as a year-round programme: framework review at the start of the year, pre-audit testing six weeks before every planned audit, quarterly reporting to the audit committee on control performance, and a standing process for tracking findings to properly validated closure. When leadership is seeing this picture regularly, the pre-audit sprint becomes unnecessary — because the discipline has already done the work.

If your organisation is preparing for an upcoming audit and wants support strengthening its control environment, closing evidence gaps, or conducting pre-audit testing — BECAH works with finance, risk, and assurance teams across all sectors to build audit readiness that holds up under scrutiny. Get in touch at hello@becah.co.uk or visit our contact page to start a conversation.

What Assurance Actually Means — and Why Most Organisations Are Not Getting Enough of It

The word "assurance" is used freely in governance and risk circles — but in my experience, there is a significant gap between how often the word is used and how well the concept is actually understood. And that gap has real consequences for the organisations that rely on assurance to know whether things are working as they should.

So let me offer a plain, practical view of what assurance is, what it is not, and why most organisations are not getting as much of it as they think they are.

What assurance actually is

Assurance is the independent, evidence-based comfort that something is working as intended. It is not a feeling, an assumption, or a verbal confirmation from the person responsible for the thing being reviewed. It is a structured, objective assessment — carried out by someone independent of the activity — that examines whether controls are designed properly and operating effectively, whether processes are being followed, and whether the outcomes being reported are accurate.

Assurance answers the question: "How do we know?" Not "we think so" or "we were told so" — but how do we actually know, based on evidence, that what we believe is true?

What assurance is not

Assurance is not the same as management reporting. When a manager tells the board that controls are operating effectively, that is a management assertion — not an assurance opinion. The manager is telling you what they believe. Assurance tells you what can be independently evidenced.

Assurance is also not a one-time exercise. An annual internal audit that reviews the same three processes every year is not a comprehensive assurance programme. Proper assurance is planned, risk-based, and covers the full range of significant risks and controls across the organisation — not just the areas that are easiest to review.

And assurance is not the same as compliance monitoring. Compliance tells you whether a rule has been followed. Assurance goes deeper — it looks at whether the control environment is designed to prevent non-compliance in the first place, whether it is consistently applied, and whether the evidence exists to demonstrate it.

The three lines model — and where it often falls down

The Three Lines Model is the most widely used framework for thinking about assurance. The first line is management — the people doing the work, who own the controls and are responsible for managing risk day to day. The second line is oversight functions — risk, compliance, and finance — who monitor, challenge, and support the first line. The third line is internal audit — who provide independent assurance to the board and senior leadership that the control environment is working.

In theory, this creates a layered, comprehensive assurance structure. In practice, many organisations have a first line that does not formally monitor its own controls, a second line that is under-resourced or too close to the business to be genuinely independent, and an internal audit function that is small, underfunded, or not empowered to follow its findings through to resolution. The result is that the board receives assurance that is more fragmented and thinner than anyone would be comfortable acknowledging.

What good assurance looks like

Good assurance starts with a clear assurance map — a structured document that sets out what risks and controls exist across the organisation, who provides assurance over each of them, at what frequency, and how that assurance is reported. Without this, it is almost impossible to know where your assurance gaps are.

Good assurance is also risk-based. Resources are focused on the areas that matter most — the highest-risk processes, the controls that would have the greatest impact if they failed, and the areas where management confidence is highest but independent evidence is thinnest.

The organisations that get assurance right are not necessarily the ones with the largest internal audit teams. They are the ones where assurance is genuinely valued — where findings are taken seriously, where the board asks hard questions about the quality of its assurance coverage, and where "how do we know?" is treated as a legitimate and important question rather than a challenge to be deflected.

If your organisation wants support designing or strengthening its assurance framework — BECAH works with assurance teams and boards across sectors to make assurance more structured, credible, and genuinely useful. Get in touch at hello@becah.co.uk or visit our contact page.

Why Every Organisation Needs a Risk Register — and How to Build One That Actually Works

A risk register is one of the most fundamental governance tools an organisation can have. Yet in my experience working across finance, risk, and assurance functions, it is one of the most misunderstood — and most misused — documents in any organisation.

I have seen risk registers that are updated once a year and filed away. I have seen registers with 200 risks that nobody owns. And I have seen organisations that have no register at all — and genuinely believe they are managing risk effectively because nothing has gone wrong yet.

What a risk register actually is

A risk register is a living document that records the risks facing your organisation — what they are, how likely they are to occur, what impact they would have, who owns them, and what is being done to manage them. It is not a box-ticking exercise. Done well, it is one of the most powerful management tools you have.

The three most common mistakes

The first mistake is treating the register as a one-off task. Risk is not static. Your risk register should be reviewed regularly — at least quarterly — and updated whenever something significant changes in your organisation or operating environment.

The second mistake is listing risks that are so vague they are useless. "Operational risk" is not a risk. "Key finance staff member leaves and month-end close process fails" is a risk. Be specific. The more precise your risk statements, the more useful your register becomes.

The third mistake is assigning ownership to a team rather than a named individual. Shared ownership is no ownership. Every risk in your register should have one named person who is accountable for managing it.

How to build one that actually works

Start with a risk identification workshop. Bring together key people from across your organisation — not just senior leaders — and ask a simple question: what could go wrong, and what would the impact be? Capture everything. You can prioritise later.

Score each risk by likelihood and impact. Use a simple matrix — high, medium, and low — rather than trying to build a complex quantitative model you will never maintain. The goal is a clear sense of your most significant risks so you can focus your effort appropriately.

Assign a named owner to each risk. Make it clear that ownership means actively monitoring the risk, maintaining the controls around it, and escalating when things change.

Finally, schedule regular reviews. A risk register that is reviewed regularly and acted upon is worth a hundred registers that sit on a shared drive untouched. Build the review into your governance calendar and treat it as non-negotiable.

If your organisation needs support designing a risk register, facilitating a risk identification workshop, or building a risk framework that works in practice rather than just on paper — BECAH can help. Get in touch at hello@becah.co.uk or visit our contact page to start a conversation.

What is a Business Analyst — and Why Every Project Needs One

In my experience delivering ICT and transformation projects across multiple sectors, one of the most common reasons projects fail — or at least struggle — is not the technology. It is the gap between what the business needs and what gets built. That gap exists when there is no Business Analyst in the room.

Yet Business Analysis remains one of the most misunderstood roles in a project team. I have seen organisations cut the BA from the project plan to save money — and then spend far more fixing the problems that followed. I have seen projects go live with a system that technically works but does not do what the business actually needs. In almost every case, the root cause was the same: nobody properly defined the requirements before the build began.

What a Business Analyst actually does

A Business Analyst is the bridge between the business and the technology or solution being delivered. Their job is to understand what the business needs — deeply, not just at surface level — and translate that into clear, structured requirements that developers, system implementers, and project teams can actually work from.

A good BA does not just write documents. They map current processes, identify inefficiencies, design future state workflows, facilitate workshops, manage the requirements backlog, support testing, and stay involved through to go-live to ensure what gets delivered matches what was agreed.

When should you bring in a BA?

As early as possible — ideally at the very start of the project, during the discovery and scoping phase. This is when the BA adds the most value and when the cost of getting things wrong is lowest. Bringing in a BA after the build has started is possible, but it is always harder and more expensive to course correct than to get it right from the beginning.

Whether you are implementing a new finance system, upgrading your CRM, delivering a digital transformation programme, or running any project that involves people, processes, and technology — a Business Analyst is not optional. They are the difference between delivering what was asked for and delivering what was actually needed.

If your organisation is planning or currently running a technology or transformation project and needs experienced Business Analysis support — BECAH provides skilled, deployable BA professionals who can work with your team from discovery through to go-live. Get in touch at hello@becah.co.uk.

The Difference Between a Control and a Process — and Why It Matters for Audit Readiness

One of the most common sources of confusion I encounter when working with finance and operations teams is the difference between a process and a control. The two are related — but they are not the same thing. And confusing them is one of the fastest ways to end up underprepared for an audit.

A process describes how work gets done

A process is a sequence of steps that produces an outcome. In accounts payable, for example, the process might be: receive invoice, match to purchase order, obtain approval, post to ledger, schedule for payment. The process tells you what happens and in what order.

A control reduces the risk within that process

A control is an action — built into or applied to a process — that reduces the likelihood or impact of something going wrong. In the same accounts payable example, the three-way match between the invoice, purchase order, and goods receipt note is a control. It exists to prevent incorrect or fraudulent invoices from being paid.

The distinction matters because during an audit, your auditors are not just looking at whether your processes exist. They are looking at whether your controls are designed properly and operating effectively. You can have a beautifully documented process with no meaningful controls embedded in it — and that is a significant audit finding waiting to happen.

What auditors are actually looking for

Auditors want to see three things. First, that you have identified the key risks within your processes. Second, that you have controls designed to address those risks. Third, that those controls are actually being operated — consistently, by the right people, with evidence to prove it.

The practical takeaway — Go through your key processes and ask: where are the risks, and what controls do we have in place to manage them? If you cannot answer that question clearly, you have work to do before your next audit. The good news is that it is entirely fixable — and the organisations that do this work proactively are always better positioned than those who wait to be told.

If your organisation is preparing for an internal or external audit and wants support mapping key processes, identifying control gaps, or strengthening your control environment — BECAH works with finance and assurance teams to get audit-ready in a structured, practical way. Get in touch at hello@becah.co.uk to find out how we can help.

Setting Up a Centre of Excellence — What It Is, Why It Matters, and Where to Start

The term "Centre of Excellence" gets used a lot — but in my experience, many organisations are not entirely sure what it means in practice, or why it is worth building. Let me share a straightforward view of what a CoE actually is, what it does for a team, and how to start building one without it becoming an overwhelming project.

What a Centre of Excellence actually is

A Centre of Excellence is a structured operational home for a professional function — whether that is finance, risk, internal audit, or assurance. It is the combination of the tools, templates, processes, governance, and ways of working that allow a team to operate consistently, efficiently, and to a high standard.

Think of it as the infrastructure of a function. Without it, teams often reinvent the wheel on every engagement, store documents inconsistently, operate without clear standards, and struggle to demonstrate the quality of their work. With it, everything has a place, a standard, and an owner.

Why it matters more than people think

A well-structured CoE does several important things. It ensures consistency — everyone on the team is working to the same standards and using the same tools. It supports quality — because when processes and templates are well designed, the work product is better. It enables scalability — when the function grows, new team members can be onboarded quickly because everything is documented and accessible. And it supports accountability — because ownership of processes, documents, and activities is clear.

Where to start

The most important thing is not to try to build everything at once. Start with three things: a clear folder structure for your team's documents, a small library of core templates (risk register, control template, meeting minutes, action log), and a simple governance document that sets out how your function operates.

From that foundation you can build — adding more templates, documenting processes, setting up dashboards, and establishing review cycles. The key is to start simple, make it practical, and build incrementally. A CoE that is used every day by a team of three is worth far more than an elaborate structure that sits untouched on a SharePoint site.

BECAH supports organisations in designing and building Risk and Assurance Centres of Excellence — from folder structure and template libraries through to SharePoint implementation and governance frameworks. If you are ready to build yours, or just want to explore what is possible, we would be glad to talk. Reach us at hello@becah.co.uk or explore our CoE products.