IT Advisory & Assurance · Bahrain & GCC
IT controls that stand up when the auditor relies on them.
SRR reviews IT general controls, ERP and application controls, and cyber risk for regulated and institutional clients across Bahrain, referenced to recognised frameworks such as COBIT and ISO 27001, so the systems behind your numbers hold up under audit and examination.
The short answer
What does IT advisory and assurance cover?
It covers IT general controls reviews (access, change, and operations), IS audit support, cybersecurity risk assessment, and ERP and application control reviews, including user access and segregation of duties. The work is referenced to recognised frameworks such as COBIT for IT governance and ISO 27001 for information security, so the assessment is comprehensive and the gaps it names are ones a board or regulator will recognise.
Where a financial audit relies on system-generated data, the auditor tests the IT general controls behind it, so weak ITGC undermines audit reliance. SRR is a management and business advisory consultancy and is not a licensed audit firm: we provide IT control reviews and IS audit support as advisory work and coordinate with the financial audit, while any formal audit opinion sits with a separately registered auditor.
- Control layers
- ITGC + app
- IT general controls (access, change, operations) sit under application and ERP controls. Both have to work for the numbers to be reliable.
- Reference frameworks
- COBIT, ISO 27001
- IT governance and security work is referenced to recognised frameworks such as COBIT and ISO 27001, rather than to ad hoc checklists.
- Why it matters
- Audit reliance
- Where a financial audit relies on system-generated data, the auditor tests the IT general controls behind it. Weak ITGC undermines that reliance.
What We Handle
From access rights to the audit trail.
One team reviews the general controls, the application controls, and the cyber posture, and reports them by the risk they carry rather than as a flat list.
- IT general controls (ITGC) reviews: access, change, and operations
- IS audit support and coordination with financial audit
- Cybersecurity risk assessments against recognised frameworks
- ERP and application control reviews
- IT governance and policy design, referenced to COBIT and ISO 27001
- User access and segregation of duties reviews
- Third-party and cloud risk assessment
Who It Is For
Where clients come to us on IT.
Your auditor is relying on system data
The financial audit depends on reports out of your ERP, so the auditor needs the IT general controls behind those reports to be tested and to hold.
You are implementing or have just changed ERP
A new or reconfigured system where the application controls, access rights, and segregation of duties have not yet been designed or reviewed.
A board or regulator has asked about cyber risk
You need a cybersecurity risk assessment framed against a recognised framework, not a vendor pitch, so the board can see where the real exposure sits.
Access and segregation of duties have drifted
Users who have accumulated rights they no longer need, and conflicting duties held by the same person, so a single user can both create and approve.
How It Works
From environment to remediation.
-
Scope the environment
We map the systems, the data that matters, and where the financial statements or the regulator rely on system output, so the review targets what actually matters.
-
Assess the controls
We review IT general controls, application and ERP controls, access and segregation of duties, and cyber risk against recognised frameworks such as COBIT and ISO 27001.
-
Report and prioritise
We report the gaps by risk, separating what threatens audit reliance or regulatory compliance from what is housekeeping, so remediation is sequenced sensibly.
-
Support remediation
We help design the fixes, re-test where needed, and coordinate with the financial audit so the IT position supports it rather than undermining it.
What Goes Wrong
The IT control gaps that surface under audit.
Treating IT controls as an IT problem
ITGC and application controls sit under the reliability of the financial numbers. Left entirely to the IT team, they are designed for uptime rather than for the control objectives an auditor tests.
Access rights that only ever grow
Users accumulate access as they change roles, and it is never removed. Over time a large share of users hold rights they should not, which is both a control weakness and a security exposure.
Segregation of duties in name only
When the same person can create, approve, and pay, the control does not exist regardless of what the policy says. This is one of the first things an ERP review surfaces.
Cyber risk with no framework
A security posture assessed against a vendor’s product rather than a recognised framework leaves gaps that the framework would have named, and gives the board a false sense of coverage.
Common Questions
IT advisory and assurance, answered.
What are IT general controls, and why does the auditor care?
IT general controls (ITGC) are the controls over access, change management, and IT operations that sit beneath your applications. Where a financial audit relies on system-generated reports, the auditor tests these controls, because if they are weak, the reports cannot be relied upon. Strong ITGC is what lets an auditor place reliance on system data rather than testing everything manually.
What is the difference between ITGC and application controls?
IT general controls govern the environment: who can access systems, how changes are made, and how operations run. Application controls are built into a specific system or ERP, such as validation rules, approval workflows, and segregation of duties. Both layers have to work. Strong application controls sitting on weak general controls do not give the assurance they appear to.
Which frameworks do you use for IT and cyber work?
IT governance and security work is referenced to recognised frameworks such as COBIT for IT governance and ISO 27001 for information security, rather than to ad hoc checklists. Using a recognised framework means the assessment is comprehensive and comparable, and the gaps it names are ones a board or regulator will recognise.
Can you review our ERP access and segregation of duties?
Yes. We review user access rights and segregation of duties within the ERP, identifying accumulated access that should have been removed and conflicting duties held by the same user. Where one person can create, approve, and pay, the control effectively does not exist, and that is one of the first things a review surfaces.
Do you perform the IT audit itself?
We provide IS audit support and IT control reviews as advisory work, and coordinate with the financial audit. SRR Consultants is a management and business advisory consultancy and is not a licensed audit firm, so where a formal audit opinion is required, that sits with a separately registered auditor.
How does this connect to your risk and assurance work?
IT advisory sits within our wider advisory and assurance practice. IT and cyber risk feed the enterprise risk framework, and IT general controls feed the reliability of the financial reporting, so the IT work connects directly to risk advisory, internal audit, and reporting.
Part of our advisory and assurance practice. See also risk advisory, internal audit and controls testing, and audit support.
Make the systems behind your numbers defensible.
A short call with a senior practitioner is the quickest way to scope an ITGC review, an ERP control review, or a cyber risk assessment.