GDPR Services
We offer comprehensive solutions, services and expertise to help you meet your GDPR compliance objectives.
TRAINING COURSES
- EU General Data Protection Regulation (GDPR)
- Data Protection Officer (DPO)
- Data Protection Impact Assessment (DPIA)
- Professional Training for Individuals that would like to obtain the GDPR Practitioner status from prominent certification bodies in UK
COMPLIANCE TOOLS
✓ EU GDPR Compliance Gap Assessment Tool
✓ Identify quickly your GDPR compliance gaps
✓ Plan and prioritise your GDPR project
EU GENERAL DATA PROTECTION REGULATION (GDPR) DOCUMENTATION
The introduction of the accountability principle under the GDPR means that not only do organisations have to comply with the GDPR but they also have to be able to demonstrate compliance. This includes keeping up-to-date records of processing activities, and sharing these records with data protection authorities upon request.
We will provide all the templates, worksheets and policies required to comply with documented aspects of the Regulation including:
✓ Data protection policy
✓ Training policy
✓ Information security policy
✓ Data protection impact assessment procedure.
✓ Retention of records procedure
✓ Subject access request form and procedure
✓ Privacy procedure
✓ International data transfer procedure
✓ Data portability procedure
✓ Data protection officer (DPO) job description
✓ Complaints procedure
✓ Audit checklist for compliance
✓ Privacy notice
With the above, you can:
- Get professional guidance on GDPR compliance obligations and personal information best practices;
- Make sure that you have adequately identified risks to personal data and are able to put in place the necessary controls to protect your data; and
- Embed the documentation into your organisation quickly and easily.
ISQC1 Services
In accordance with International Standard on Quality Control 1 (ISQC1), it is the objective of the firm to establish and maintain a system of Quality Control to provide it with reasonable assurance that:
-
The firm and its personnel comply with professional standards and applicable legal and regulatory requirements; and
-
Reports issued by the firm or engagement partners are appropriate in the circumstances.
Through our experience, knowledge and practical application of ISQC 1 over the years, we can offer to Auditing and Accounting Practices the following services in order to ensure that they comply with the requirements of ISQC 1.
ANNUAL COMPLIANCE REVIEW OF ISQC1
The scope of annual compliance monitoring of ISQC 1 includes the following:
Review of existing policies and procedures and ISQC 1 Manual in relation to the following areas:
-
Leadership Responsibilities for Quality within the Practice.
-
Relevant Ethical Requirements.
-
Acceptance and Continuance of Client Relationships and Specific Engagements.
-
Human Resources.
-
Engagement Performance.
-
Monitoring.
-
Documentation.
Review of a sample of audit files.
Through our review we will provide you with a report with our evaluation of the following areas:
-
Level of compliance with professional standards and legal/regulatory requirements.
-
Evaluation as to the effectiveness of the design of the Practice’s System of Quality Control.
-
The effectiveness of the Practice’s Quality Control policies and procedures.
-
Deficiencies identified and their classification (significant, repetitive or systemic).
-
Recommendations for improvement.
Training for the partners, directors and staff in relation to:
ASSISTANCE WITH THE IMPLEMENTATION OF ISQC1
We can assist our clients with the implementation of ISQC1 and ensure full compliance through the following services:
-
Preparation of ISQC 1 Manual (policies, procedures, templates) based on the size and other operating characteristics of the Practice.
-
Training for partners, directors and staff.
FILE REVIEWS AND OTHER SERVICES
Through our experience and expertise in the audit of Practices within a wide spectrum of industries and characteristics, including PIEs (Public Interest Entities), and subject to our independence requirements, we can provide the following services:
Audit File Cold Review
A cold file review takes place when the Auditor’s report is signed-off. The purpose of this review is to detect weaknesses in the quality control policies and procedures of the Practice and to take corrective actions. Through our expertise in this area we can assist our clients to comply with relevant auditing standards through the identification of the weaknesses in the way the whole audit work is conducted and how it can be improved through our recommendations for other similar assignments. External Cold File Reviews are compulsory for sole practitioners in order to comply with ISQC 1.
Audit File Hot Review
A hot file review takes place during the audit but before the Auditor’s report is issued and is one of the most significant safeguards against the threats of Auditor’s objectivity and independence. The purpose of this detailed review is to identify any weaknesses in the application of audit procedures, to evaluate the judgements made and conclusions reached by the engagement team and to ensure that the Auditor’s opinion is appropriate.
Engagement Quality Control Review
An Engagement Quality Control Review (EQCR) is a process designed to provide an objective evaluation, on or before the date of the audit report, of the significant judgments the engagement team made and the conclusions it reached in formulating the report. The EQCR process is compulsory for audits of financial statements of PIEs (Public Interest Entities) and for other engagements, for which the Practice has determined that an Engagement Quality Control Review is required.