UAEServicesAudit & AssuranceSpecialised Audit & CertificationInternal Control Over Financial Reporting (ICFR) Review

Audit & Assurance · Specialised Audit & Certification

Internal Control Over Financial Reporting (ICFR) Review

An independent, evidence-based assessment of the controls that stand between your financial statements and a material misstatement — designed and reduced to writing, walked through, and tested by chartered accountants who know the difference between a control that exists on paper and a control that actually operates every month, for boards, audit committees, lenders, and group finance functions across the UAE.

Speak with a specialist →Chat on WhatsApp

Chartered Accountants · Dubai · Since 1986

What Internal Control Over Financial Reporting (ICFR) Review is

An Internal Control over Financial Reporting (ICFR) review is an independent assessment of the design and operating effectiveness of the controls a business relies on to produce financial statements that are complete, accurate, and free from material misstatement — whether caused by error or fraud. It examines the control environment around each significant financial statement line (revenue, payroll, procurement-to-pay, treasury, fixed assets, journal entries, financial close) and asks two distinct questions for each: is the control designed properly to prevent or detect a misstatement, and is it actually operating as designed, consistently, by the people responsible for it. A control that exists in a policy manual but is routinely bypassed under deadline pressure is a design that works on paper and fails in substance — an ICFR review is built to catch exactly that gap.

In the UAE, demand for a standalone ICFR review comes from several directions at once. Group finance functions of multinational or India-UAE cross-border groups increasingly apply parent-company control frameworks (often modelled on COSO's Internal Control – Integrated Framework, the internationally recognised benchmark most auditors and audit committees reference) to their UAE subsidiaries, and want independent confirmation the local entity meets that bar before consolidation. Boards and audit committees preparing for a listing, a private equity investment, or a banking facility renewal commission an ICFR review to surface control weaknesses before an external party finds them first. Statutory auditors performing the annual financial statement audit under International Standards on Auditing (ISA) evaluate internal control as part of their risk assessment (principally ISA 315 and ISA 330), and a dedicated pre-audit ICFR review reduces the number of control deficiencies the statutory auditor otherwise discovers mid-fieldwork — which is invariably more disruptive and more expensive to remediate against a live audit timeline. Companies that have experienced a fraud incident, a restatement, or a near-miss commission an ICFR review to establish what broke and to rebuild the control structure with evidence, not assumption.

An ICFR review is not itself a UAE statutory requirement — there is no dedicated federal law mandating a standalone ICFR opinion for UAE mainland or free zone companies, unlike jurisdictions such as the United States where Sarbanes-Oxley Section 404 imposes a formal ICFR attestation regime on listed companies. What UAE law does require, for most mainland LLCs under Federal Decree-Law No. 32 of 2021 (the Commercial Companies Law) and for the majority of free zone entities, is an annual audited financial statement — and the reliability of that audit rests substantially on the quality of the underlying internal controls. Increasingly, UAE-listed and DIFC/ADGM-regulated entities, and companies preparing for one of those pathways, treat a documented ICFR framework as a practical necessity even where no single statute compels it, because both the Federal Tax Authority's expectations around Corporate Tax record-keeping under Federal Decree-Law No. 47 of 2022 and a bank's own credit risk assessment increasingly assume the numbers behind a facility application or a tax return were produced under a control environment that can withstand scrutiny.

The engagement combines several distinct techniques applied consistently across in-scope processes: control identification and documentation (walkthroughs, narratives, and RCMs — risk and control matrices — mapping each significant risk to the control that mitigates it); design effectiveness assessment (does the control, as designed, actually address the risk it is meant to cover, and is it positioned at the right point in the process); operating effectiveness testing (sample-based testing of whether the control actually operated as designed over the period under review, not just on the day of the walkthrough); and a gap and remediation report that ranks findings by the materiality of the risk they leave exposed, not merely by how easy they are to fix. PNPC structures every UAE ICFR review to produce a report a board, an incoming statutory auditor, or a parent-company internal audit function can act on directly — not a generic maturity-model score with no path to remediation.

What commonly goes undetected without an ICFR review is not usually a single catastrophic control failure — it is an accumulation of smaller gaps that compound. A journal entry approval workflow that exists in the ERP but where the approver role is shared with the preparer; a bank reconciliation performed monthly but never independently reviewed; segregation of duties that looked adequate at incorporation but eroded as the finance team grew informally; a month-end close checklist that nobody actually follows once deadlines slip. Each is individually survivable. Together, across a full financial statement cycle, they are exactly the pattern that produces a restatement, a qualified audit opinion, or a fraud that runs undetected for longer than it should.

The real scoping decisions on this engagement are the framework to benchmark against (COSO's five components — control environment, risk assessment, control activities, information and communication, and monitoring — is the most commonly used reference point, though a parent group's own framework or a bank's specific expectations sometimes take precedence), the processes and locations in scope (a full-entity review versus a targeted review of the highest-risk cycles such as revenue recognition or procurement), and the testing period (a point-in-time design assessment versus operating effectiveness testing over a full financial year, which requires a longer sample period and more evidence). Get these three agreed in writing at scoping, and the review runs cleanly; leave them ambiguous, and the findings get disputed as being out of scope or insufficiently evidenced.

The output is a structured ICFR review report — control environment assessment, process-level risk and control matrices, design and operating effectiveness conclusions by control, a ranked deficiency register (control deficiency, significant deficiency, or material weakness, using standard audit terminology), and a remediation roadmap with named owners and target dates. PNPC keeps every finding traceable to the specific walkthrough, test sample, or document reviewed, so the report withstands scrutiny from a statutory auditor, a parent-company internal audit team, or a bank credit committee months after issuance.

When an ICFR review makes sense

A UAE subsidiary of an international or India-UAE group needs to demonstrate its control environment meets the parent group's framework (typically COSO-based) ahead of consolidation or group audit sign-off

The board or audit committee wants an independent assessment of financial reporting controls ahead of a listing, private equity investment, or significant banking facility, before an external party finds the gaps first

Your statutory auditor flagged control deficiencies during the annual audit and management wants a structured, independent review to close them properly rather than patch them ad hoc

A recent fraud incident, restatement, or near-miss has raised the question of what control actually failed, and management wants an evidence-based answer rather than an assumption

Your finance team has grown quickly and informal controls that worked when three people ran finance have not been re-designed for a team of fifteen across multiple entities or locations

You are implementing a new ERP or finance system and want the control framework re-mapped and tested against the new process flows before go-live embeds any gaps

A bank or investor has specifically asked for evidence of internal control maturity as part of due diligence, separate from the audited financial statements themselves

You want a pre-audit control review timed to run ahead of year-end fieldwork, so control deficiencies are identified and where possible remediated before the statutory auditor's testing begins

Group finance wants a consistent, comparable ICFR maturity assessment across multiple UAE and India entities using one methodology rather than ad hoc, inconsistent local reviews

Your group operates several UAE licences across multiple free zones and the mainland, and you want one consistent control review covering all entities under common management rather than piecemeal, inconsistent local checks

You are outsourcing, offshoring, or restructuring part of the finance function and want independent assurance the incoming provider's control environment meets an acceptable standard before the handover, not after

When another engagement fits better

You need the annual statutory financial statement audit itself — an ICFR review assesses controls, it does not express an opinion on the financial statements as a whole

You are looking for a forensic investigation to identify a specific perpetrator of suspected fraud — that is a scoped forensic engagement with a different evidentiary standard, though an ICFR review can surface the indicators that justify commissioning one

Your business is very small with a handful of transactions a month and formal segregation of duties is genuinely impractical — a lighter compensating-controls review or basic bookkeeping oversight may be more proportionate than a full ICFR framework exercise

You need day-to-day process documentation or SOP (standard operating procedure) drafting with no independent testing component — that is a process design engagement, not an assurance review

You are seeking a formal Sarbanes-Oxley Section 404 attestation for a US-listed parent — that is a specific US regulatory regime with its own methodology and applies only where the group's US listing status actually requires it, though the underlying UAE-entity fieldwork overlaps substantially with a standard ICFR review

The requirement is really for general internal audit covering operational and compliance risk across the business, not specifically financial reporting controls

You want a report that confirms controls are adequate regardless of what testing shows — an independent review reports what the evidence supports, and findings cannot be pre-determined to satisfy a parent company or bank

The business has no financial statements or ERP data yet (pre-revenue or pre-launch) — there is no operating control environment to test until transactions are actually flowing through the business

You need IT general controls (ITGC) or cybersecurity-specific assurance as the primary deliverable — that sits with a dedicated IT/ERP controls or cybersecurity audit, though ITGC is typically referenced within a full ICFR scope where financially relevant systems are in play

Structure Comparison

ICFR review vs. related UAE assurance and controls engagements

FeatureICFR ReviewStatutory Financial AuditInternal AuditSOX 404 Attestation (US-listed parent only)Forensic / Fraud Investigation
Primary purposeAssess design and operating effectiveness of controls over financial reportingOpinion on whether financial statements as a whole are fairly presentedOngoing review of processes, risk, and controls across the whole businessFormal management assertion and (where applicable) auditor attestation on ICFR effectiveness under US securities lawEstablish facts around a specific suspected fraud or irregularity
Typical commissioning partyBoard, audit committee, group finance, or managementShareholders/board (mandatory for most mainland LLCs, many free zones)Board/audit committeeGroup CFO/audit committee of the listed parentBoard, shareholders, or legal counsel
Independence requiredRecommended — external CA firm gives more credibility to the reportYes — licensed UAE auditorPreferably independent, can be in-houseYes, plus external auditor attestation for accelerated filersYes, especially where findings may be relied on in a dispute
ScopeControls over significant financial statement processes and accountsFull financial statements; controls tested only as needed to support audit risk assessmentVaries by mandate — operational, compliance, and financial controlsEntity-level and process-level ICFR under a formal COSO-based framework, US SEC rulesSpecific transactions, individuals, or allegations under investigation
Regulatory basis in the UAENo dedicated UAE statute; governed by engagement terms, COSO or group framework, and professional standardsUAE Commercial Companies Law (Federal Decree-Law No. 32 of 2021) and free zone regulations require audited accounts for most entitiesNo specific UAE federal mandate; driven by governance policyUS Sarbanes-Oxley Act Section 404, not a UAE requirement — relevant only via a US-listed parentNo single statute; scope set by instructing party or court
OutputICFR review report: RCMs, design/operating effectiveness conclusions, ranked deficiency register, remediation roadmapAuditor's report and opinion on financial statementsInternal audit report to management/audit committeeManagement's ICFR assertion plus auditor's attestation report (where required)Findings of fact report, often with recommendations on further action
Reliance by third partiesBoards, group finance, incoming statutory auditors, and sometimes banks rely on itRegulators, banks, investors, tax authorities all rely on itGenerally internal use, occasionally shared with lendersSEC, external auditors, and public markets rely on the attestationInstructing party and, where relevant, legal counsel or a court
Typical trigger in UAE contextGroup consolidation requirement, pre-listing prep, post-incident review, pre-audit readinessAnnual licence renewal / shareholder requirementBoard/audit committee mandate for ongoing assuranceOnly where the UAE entity's parent is US-listed and in scope of SOXSuspected fraud, whistleblower report, unexplained variance
Typical frequencyAs needed — first-time baseline, periodic re-review, or event-triggeredAnnual, mandatory for most entitiesOngoing, per the approved audit plan cycleAnnual, mandatory for in-scope issuersAd hoc, triggered by a specific event or allegation
Methodology reference pointCOSO Internal Control – Integrated Framework, or the parent group's own frameworkInternational Standards on Auditing (ISA)Institute of Internal Auditors (IIA) Standards / IPPFCOSO framework plus PCAOB auditing standardsACFE and forensic accounting practice standards
Who signs off the final outputPNPC engagement partner, addressed to the board/audit committee/group financeLicensed UAE statutory auditorChief Audit Executive or internal audit headCEO/CFO certification, plus external auditor attestation where requiredInvestigating firm or appointed expert

Businesses preparing for a listing or a parent-group consolidation frequently commission an ICFR review and then use its findings to brief the statutory auditor — the two engagements are complementary, not substitutes for each other. Where a US-listed parent is in scope of SOX Section 404, the UAE subsidiary's ICFR review fieldwork typically forms the local building block for the group's formal attestation, but the review itself remains a UAE-scoped assurance engagement rather than a SOX filing.

How a PNPC Global UAE ICFR review engagement runs, start to finish

How a PNPC Global UAE ICFR review engagement runs, start to finish

#Stage & What PNPC DoesWhat Boards/Group Finance Actually Check ForTypical Timeline
1Scoping call — confirm trigger (group consolidation, pre-listing, pre-audit, post-incident), entities/processes in scope, and the framework to benchmark against (COSO, parent-group framework, or bank-specific expectations)Whether scope matches exactly what the board, group finance, or the incoming statutory auditor actually needs — mismatched scope is the most common cause of rework2-3 working days
2Engagement letter issued defining processes in scope, testing period (design-only versus operating effectiveness over a defined period), and reporting formatClear, written scope so there is no dispute later about what was and was not tested1-2 working days
3Entity-level control assessment — tone at the top, governance structure, whistleblower/reporting channels, and management's own risk assessment processWhether entity-level controls are strong enough to give comfort that process-level controls will be taken seriously and maintained, not just documented once3-5 working days
4Process walkthroughs — revenue, procurement-to-pay, payroll, treasury/cash, fixed assets, journal entries, and financial close, mapped into risk and control matrices (RCMs)Whether the walkthrough reflects how the process actually runs day-to-day, not the idealised version in the policy manual1-2 weeks depending on number of processes and locations in scope
5Design effectiveness assessment — for each control identified, confirm it is positioned to actually address the risk it is meant to mitigateWhether controls exist at the right point in the process (preventive, where possible, not purely detective after the fact)3-5 working days
6Sample selection and operating effectiveness testing — test whether controls actually operated as designed across the review period, not just on the walkthrough dateSample sizes and selection methodology defensible to a statutory auditor or group internal audit function reviewing the work1-2 weeks depending on sample sizes and evidence availability
7Segregation of duties analysis across ERP/system roles for financially significant processes, including journal entry preparer/approver conflictsWhether access rights were ever formally reviewed, or have simply accumulated as staff changed roles over time3-5 working days
8IT general controls (ITGC) review to the extent financially relevant — access management, change management, and backup/recovery for systems feeding the financial statementsWhether the underlying system environment is stable enough for process-level controls to be relied upon at all3-5 working days
9Deficiency evaluation and classification — each finding ranked as a control deficiency, significant deficiency, or material weakness based on the materiality of the risk left exposedWhether findings are risk-ranked with quantified or reasoned impact, not just listed as observations3-5 working days
10Draft ICFR review report circulated with RCMs, testing results, deficiency register, and preliminary remediation recommendationsWhether findings are evidenced and cross-referenced to specific walkthroughs, samples, or documents reviewed1 week
11Management response sought on each finding before finalisation, including proposed remediation timelinesWhether management accepts, disputes, or provides additional evidence for each finding3-5 working days
12Final report issued to the board, audit committee, group finance function, or statutory auditor, with a closing discussion if requiredWhether the report format and terminology align with what the incoming statutory auditor or group internal audit team expects to see2-3 working days
13Remediation roadmap agreed with named owners and target dates for each open finding, ranked by risk priorityWhether high-risk findings have an owner and a realistic date, not an open-ended commitment to 'look into it'At report issue
14Statutory auditor briefing — where requested, PNPC walks the incoming or existing statutory auditor through the ICFR findings to reduce duplicated control testing during the year-end auditWhether the review genuinely reduces statutory audit control-testing effort, or just adds another document to the fileAs required
15Remediation verification cycle scheduled — follow-up review of the highest-risk findings at an agreed interval to confirm remediation actually happenedWhether 'closed' findings were verified as remediated, not just marked closed on management's wordSet at handover
16Confidentiality protocol agreed — who receives draft findings before the board (CFO, audit committee chair) and any restrictions on internal circulation ahead of formal presentationWhether sensitive findings are controlled appropriately before a full board presentationAgreed at scoping, confirmed before draft issuance
17Closing presentation to the board or audit committee — findings walked through in a dedicated session distinct from the written report, where requestedWhether the board gets a direct opportunity to question findings rather than only reading the documentAs requested, typically alongside final report issue

A single-entity, moderate-complexity ICFR review covering the core financial statement cycles typically runs 4-6 weeks from scoping to final report. Multi-entity group reviews, or reviews requiring a full-year operating effectiveness testing period rather than a point-in-time design assessment, run longer. Reviews timed ahead of year-end statutory audit fieldwork should be scoped with enough lead time to allow remediation before the auditor's own testing begins.

Document Checklist
Entity & engagement documents

Trade licence and Memorandum/Articles of Association or free zone registration certificate for each entity in scope

Group control framework document or parent-company ICFR policy, where the review is benchmarked against a group standard

Board resolution or audit committee minutes commissioning the review, or the bank/investor request specifying the requirement

Prior internal audit or ICFR review reports for the same entity, if any

Engagement letter signed by both parties setting out scope, framework, and testing period

Process documentation

Existing SOPs, process narratives, or flowcharts for revenue, procurement-to-pay, payroll, treasury, fixed assets, and financial close

Organisation chart identifying process owners, approvers, and reviewers for each significant financial cycle

Delegation of authority matrix or approval-limits policy currently in force

Chart of accounts and month-end close checklist currently used by the finance team

ERP or accounting system module list and workflow configuration for financially significant processes

Financial & transactional evidence

Trial balance, general ledger extracts, and journal entry listing for the period under review

Bank reconciliation working papers for all operating accounts over the sample period

Sample of purchase orders, invoices, and payment approvals for procurement-to-pay testing

Payroll registers and WPS (Wage Protection System) submission records for payroll control testing

Fixed asset register and capitalisation/disposal approval documentation

Systems, access & IT controls

ERP/finance system user access rights listing, including journal entry preparer and approver roles

Change management log for financially significant system configuration changes during the review period

IT policy documents covering access provisioning, de-provisioning, and periodic access review

Backup and disaster recovery documentation for systems feeding the financial statements

Governance & oversight evidence

Audit committee or board finance-committee meeting minutes for the review period

Whistleblower or ethics-hotline policy and any reports logged during the period

Management's own risk assessment or control self-assessment documentation, if performed

Statutory auditor's prior-year management letter or control-deficiency communications, if available

Authority and registry evidence

Authority, registrar, free zone, bank, or property records relevant to internal control over financial reporting review.

Current licence, certificate, permit, title, visa, or filing status evidence where applicable.

Open queries, rejected applications, expired records, or pending amendments that may affect scope.

Controls, approvals and assumptions

Management sign-off for assumptions, exceptions, and risk tolerance used in the ICFR review.

Approval trails, resolutions, meeting notes, or stakeholder instructions supporting the requested outcome.

Named client-side owner for each unresolved item after handover.

Reporting and handover requirements

Preferred recipient and use of the final ICFR review output, because a board, group finance function, statutory auditor, or bank may need different framing.

Prior reports, applications, renewals, certificates, or correspondence to preserve continuity.

Post-completion calendar for remediation verification, renewals, or authority follow-up.

Multi-entity and group-structure evidence

Full group structure chart identifying every UAE licence (mainland, free zone, and offshore) in scope, their respective fiscal year-ends, and any that report on a non-calendar cycle requiring separate testing-period planning

Intercompany guarantee, comfort letter, and contingent-liability register across group entities, since these frequently sit outside the standalone entity ledger and are missed unless specifically requested

Prior-year auditor change correspondence or resignation/appointment letters, where the statutory auditor changed recently, since this can signal an unresolved disagreement worth understanding before scoping the review

List of any UAE entities recently acquired, incorporated, or scheduled for onboarding into the group's ICFR programme, so the review can flag which entities are not yet covered by any RCM

Ongoing ICFR lifecycle for UAE businesses with recurring or evolving control requirements

Ongoing ICFR lifecycle for UAE businesses with recurring or evolving control requirements

PhaseTriggered ByPNPC GuidanceRisk If Ignored
Baseline ICFR reviewFirst-time group consolidation requirement, pre-listing preparation, or board requestEstablish a clean process-by-process risk and control matrix and a documented deficiency register from day oneThe entity enters a listing process, audit, or facility renewal with no evidence base for its own control maturity
Annual or periodic re-reviewGroup policy, board mandate, or bank covenant requiring recurring ICFR assuranceKeep RCMs and testing evidence updated between cycles so each review builds on the last rather than starting freshRecurring reviews get progressively harder and more expensive if documentation and evidence trails are not maintained
Post-incident reviewA fraud event, restatement, or near-miss reveals a control gapCommission a targeted, evidence-based review of the specific process that failed, not just a general reassurance exerciseRoot cause is never established, and the same gap resurfaces under different circumstances
Pre-audit readiness reviewYear-end statutory audit approaching and management wants to reduce audit-fieldwork surprisesTime the ICFR review to complete with enough lead time for remediation before the statutory auditor's own control testing beginsStatutory auditor finds control deficiencies mid-fieldwork, disrupting the audit timeline and often triggering additional audit procedures and cost
ERP or system migrationNew finance system go-live or major module changeRe-map RCMs against the new process flows and retest before go-live embeds untested controls into daily operationMigration carries forward undocumented workarounds that become permanent, undetected control gaps
Rapid finance team growthHeadcount in finance doubles or the team spans multiple entities/locationsFormalise segregation of duties and approval hierarchies before informal practices calcify into inconsistent, undocumented habitsControls that worked for a three-person finance team fail silently once the team and transaction volume scale
Remediation follow-upPrior ICFR review identified material control weaknessesTrack management's corrective actions and independently verify at the next review that they were actually implemented, not just marked closedUnresolved control weaknesses recur and erode the board's or group finance function's confidence in subsequent reports
Group framework changeParent company adopts a new or updated control framework, or acquires the UAE entity into an existing group structureRe-benchmark the local entity's RCMs against the new framework promptly rather than reporting against a superseded standardGroup consolidation of control assurance becomes inconsistent, and the UAE entity's report is rejected by group internal audit as non-comparable
Access rights review cyclePeriodic (commonly annual) review of ERP/system access rights falls dueIndependently verify access rights match current roles, particularly journal entry preparer/approver segregationAccess creep from staff role changes silently erodes segregation-of-duties controls between reviews
Facility renewal or capital raiseBank or investor requests updated evidence of control maturity as part of renewal or investment due diligenceProvide a current, clean ICFR review trail as part of the renewal or fundraising packageWeak or outdated control assurance evidence weakens the negotiating position with the bank or investor
New entity onboardingGroup acquires or incorporates a new UAE entityBring the new entity onto the same RCM methodology and testing cadence as existing group entities promptly, rather than treating it as a standalone exerciseThe newly onboarded entity's controls remain unassessed and become the weakest link in group consolidation
Finance leadership transitionCFO, Financial Controller, or key process-owner turnoverReconfirm process ownership and control-performance responsibility in the RCM immediately after a leadership changeInstitutional knowledge of how a control is actually performed leaves with the departing owner and the control quietly degrades

Businesses that treat ICFR as a maintained control framework rather than a one-off compliance exercise consistently get faster, cheaper subsequent reviews and stronger standing with statutory auditors, banks, and group internal audit functions.

Common mistakes to avoid
Scoping and Framework Mistakes

Agreeing to benchmark against COSO without confirming whether the parent group actually applies a modified or stricter internal variant, producing two reports that group internal audit treats as inconsistent

Leaving the testing period ambiguous at scoping — a point-in-time design assessment versus a full financial year of operating effectiveness testing are very different pieces of work, and disputes about what was agreed surface only at draft-report stage

Excluding IT general controls from scope early on, then discovering mid-fieldwork that journal entry preparer/approver segregation cannot actually be assessed without it

Starting fieldwork before the engagement letter specifies who receives draft findings, creating avoidable disputes later about circulation to the board versus management

Fieldwork and Evidence Mistakes

Accepting a process owner's verbal description of a control as sufficient evidence instead of a dated, retained document trail that would satisfy a statutory auditor reviewing the same file

Testing only the transaction visible on the walkthrough date instead of a proper sample spread across the full review period, which understates how often a control was actually skipped under deadline pressure

Relying on a stale ERP access-rights listing instead of cross-checking it against current organisational roles, so segregation-of-duties findings are based on who used to hold a role rather than who holds it now

Scheduling the review too close to year-end statutory audit fieldwork, leaving no realistic lead time to remediate high-priority findings before the auditor's own control testing begins

Remediation and Follow-Through Mistakes

Marking a finding 'closed' on management's word alone without independently verifying the remediating action, so the same gap resurfaces at the next review cycle

Fixing the easiest findings first because they are quick wins, rather than sequencing remediation by the materiality of the risk left exposed

Not re-benchmarking risk and control matrices after a parent company adopts a new or updated control framework, so the UAE entity's next report is rejected by group internal audit as non-comparable

Letting a new ERP or finance system go live without re-testing the redesigned control flows first, carrying forward untested manual workarounds into permanent daily operation

Frequently asked
What exactly is an ICFR review in the UAE context?

It is an independent assessment of the controls a business relies on to produce accurate, complete financial statements — examining both whether each control is properly designed to address a specific risk and whether it actually operated as designed over the review period. It is commonly commissioned by boards, group finance functions, or ahead of a listing, investment, or major banking facility.

Practitioner noteClients sometimes assume an ICFR review is a statutory filing requirement. It is not — there is no dedicated UAE law mandating a standalone ICFR opinion. It exists because a board, group parent, or counterparty wants independent comfort on control quality, and the terms of that request define the scope.
Is an ICFR review legally required in the UAE?

No single UAE statute mandates a stand-alone ICFR review for mainland or free zone companies. It becomes necessary contractually or operationally — most commonly because a parent group's consolidation framework requires it, a board or audit committee wants pre-listing assurance, or a bank or investor specifically asks for evidence of control maturity.

Practitioner noteAlways check whether the requirement originates from a group policy, a bank covenant, or an internal board decision — the source of the requirement usually dictates the framework and reporting format expected.
How is an ICFR review different from the annual statutory audit?

The statutory audit gives an opinion on the financial statements as a whole, and evaluates internal control only to the extent needed to plan and perform that audit efficiently under ISA 315 and ISA 330. An ICFR review is a dedicated, deeper examination of the control environment itself — walkthroughs, risk and control matrices, design assessment, and operating effectiveness testing across each significant financial reporting process.

Practitioner noteAn ICFR review does not replace the statutory audit, and the statutory audit's incidental control observations do not substitute for a dedicated ICFR review — they serve different purposes, though a well-timed ICFR review can materially reduce statutory audit control-testing effort.
What framework does PNPC benchmark against for a UAE ICFR review?

Most commonly the COSO Internal Control – Integrated Framework (control environment, risk assessment, control activities, information and communication, and monitoring activities), which is the internationally recognised reference point most auditors and audit committees use. Where a parent group has its own control framework, or a bank has specific expectations, we benchmark against that instead, agreed explicitly at scoping.

Practitioner noteWe confirm the exact framework in writing before fieldwork starts — reviewing against the wrong framework produces a report that group internal audit or the parent company will not accept as comparable to its own standard.
What is the difference between design effectiveness and operating effectiveness?

Design effectiveness asks whether a control, as designed, would actually prevent or detect the risk it is meant to address if it operated as intended. Operating effectiveness asks whether the control actually did operate that way, consistently, over the period under review — tested through a sample of transactions or instances, not just a single walkthrough observation.

Practitioner noteA control can be well designed and still fail operating effectiveness testing because it was skipped under deadline pressure — this distinction is exactly why a walkthrough alone is not sufficient assurance and sample-based testing matters.
What is a risk and control matrix (RCM) and why does it matter?

An RCM maps each significant financial reporting risk in a process (for example, revenue being recorded in the wrong period) to the specific control that mitigates it, who performs the control, how often, and what evidence demonstrates it happened. It is the structural backbone of the entire review — every finding traces back to a specific cell in the RCM.

Practitioner noteWe build the RCM collaboratively with process owners during the walkthrough stage rather than presenting a pre-built generic template — a matrix that does not reflect how the process actually runs produces findings nobody trusts.
How long does an ICFR review take in the UAE?

For a single-entity, moderate-complexity business covering the core financial statement cycles, a typical engagement runs four to six weeks from scoping to final report. Multi-entity group reviews, or reviews requiring a full financial year of operating effectiveness testing rather than a point-in-time design assessment, take longer.

Practitioner noteIf the review is timed ahead of year-end statutory audit fieldwork, build in enough lead time for remediation of high-priority findings before the auditor's own testing begins — running the review too close to year-end defeats its purpose.
How does a UAE subsidiary's ICFR review relate to a US-listed parent's SOX Section 404 requirements?

SOX Section 404 is a US securities law requirement applying to the listed parent, not a UAE obligation in its own right. Where the UAE entity is material to the group's consolidated financial statements, its ICFR fieldwork typically forms a local building block feeding the group's overall SOX attestation, but the UAE-scoped review itself remains a standard ICFR engagement rather than a SOX filing.

Practitioner noteWe are explicit with clients that PNPC's UAE-scoped ICFR review supports the group's SOX process but is not itself the formal SOX attestation — that determination and filing responsibility sits with the parent's US-facing auditors and management.
What is the difference between a control deficiency, a significant deficiency, and a material weakness?

A control deficiency is a gap in design or operation that could allow a misstatement, however small the likely impact. A significant deficiency is a deficiency (or combination) important enough to merit attention from those charged with governance. A material weakness is a deficiency (or combination) creating a reasonable possibility that a material misstatement of the financial statements would not be prevented or detected in a timely manner. Findings are classified using this hierarchy so the board understands relative severity.

Practitioner noteWe resist the temptation to soften classification language for a client who wants every finding called a 'minor observation' — the classification has to reflect the actual materiality of the risk left exposed, since that is what a statutory auditor or group internal audit will independently assess against.
Does an ICFR review cover IT controls?

To the extent financially relevant — access management, change management, and backup/recovery for systems that feed the financial statements are reviewed as IT general controls (ITGC) within the overall ICFR scope, since a strong process-level control loses its value if the underlying system environment is not itself controlled. A dedicated, deeper IT or cybersecurity audit is a separate, broader engagement if that is the primary need.

Practitioner noteJournal entry preparer/approver role conflicts inside the ERP are one of the most common ITGC-adjacent findings we identify — access rights accumulate as staff change roles and are rarely reviewed unless someone specifically asks for the listing.
Can an ICFR review be limited to specific processes rather than the whole entity?

Yes. A targeted review of the highest-risk cycles — commonly revenue recognition, procurement-to-pay, payroll, or financial close — is a legitimate and common scope, particularly for a first review or where budget and timeline are constrained. We agree the in-scope processes explicitly at the scoping call so there is no ambiguity later about what was and was not covered.

Practitioner noteWe recommend starting with revenue and procurement-to-pay for most first-time reviews, since these two cycles typically carry the highest financial statement risk and the most transaction volume.
What evidence does PNPC need to test operating effectiveness, not just design?

A sample of actual transactions or control instances over the review period — approved purchase orders, reviewed bank reconciliations, signed-off journal entries — evidenced with dates, approver identities, and supporting documentation, not a verbal confirmation that the control 'is usually followed'.

Practitioner noteThe single biggest cause of an inconclusive operating effectiveness test is missing or undated evidence — we flag this risk at scoping so clients understand why 'we do this control' is not sufficient without a retained evidence trail.
How does PNPC handle findings management disagrees with?

We seek management's response on every finding before finalising the report and document their explanation alongside our own conclusion. Where management provides credible supporting evidence, findings are revised; where they do not, the finding stands with both perspectives recorded in the final report.

Practitioner noteA defensible report needs to show the disagreement was considered, not ignored — this protects both the client and PNPC if the report is later reviewed by a statutory auditor, group internal audit, or a bank.
Does the ICFR review result feed into the statutory audit?

Where the client authorises it, PNPC can brief the incoming or existing statutory auditor on the ICFR review's findings, which typically reduces the extent of the auditor's own control testing during year-end fieldwork, since much of the risk assessment groundwork has already been independently performed.

Practitioner noteThis coordination works best when the ICFR review completes with enough lead time before year-end fieldwork starts — briefing the auditor after fieldwork is already underway captures less of the potential efficiency.
What happens if the review finds a material weakness close to a listing or major transaction deadline?

We communicate material findings to the board or audit committee immediately, rather than holding them for the final polished report, since a material weakness close to a listing, investment, or facility deadline needs to be addressed — or at minimum disclosed and understood by the relevant stakeholders — before that deadline, not discovered afterward.

Practitioner noteDelaying bad news to a final report format serves no one in a time-sensitive scenario — urgent, material findings go to the client as soon as they are confirmed, with a candid assessment of what remediation is realistically achievable before the deadline.
Is an ICFR review relevant to UAE Corporate Tax compliance?

An ICFR review is not itself a Corporate Tax filing requirement, but the control environment around revenue recognition, expense recording, and journal entries directly affects the reliability of the taxable income figure reported to the Federal Tax Authority under Federal Decree-Law No. 47 of 2022 (9% on taxable income above AED 375,000, effective for financial years starting on or after 1 June 2023), and record-keeping quality supports the record-retention obligations that regime imposes.

Practitioner noteWe flag any control weaknesses around journal entries or revenue cut-off to the client's tax team specifically, since these are exactly the areas an FTA audit or Corporate Tax review would also scrutinise.
Does an ICFR review touch VAT controls?

Where VAT-relevant processes (sales invoicing, input VAT recovery, and the accuracy of VAT return preparation under Federal Decree-Law No. 8 of 2017) sit within the financial reporting cycles being reviewed, the controls around them are assessed as part of the relevant process — for example, revenue or procurement-to-pay — though a dedicated VAT process review is a narrower, VAT-specific engagement if that is the primary concern.

Practitioner noteWe note any VAT-relevant control gap identified during the review — for example, inconsistent invoice sequencing or unreconciled output VAT — so the client's VAT advisor can assess it separately against current FTA guidance.
What if our finance function is too small for full segregation of duties?

This is common in smaller UAE entities, and the review does not simply mark it as a failure — instead we assess what compensating controls exist (independent management review, dual sign-off on high-risk transactions, periodic reconciliation by someone outside the process) and whether they realistically offset the segregation gap given the entity's size and risk profile.

Practitioner noteWe are explicit in the report about where a compensating control is genuinely adequate versus where it is a stopgap that will not scale — a growing business needs to know which gaps to plan around now, not just which ones currently pass.
Can PNPC run the ICFR review alongside the statutory audit to avoid duplicated work?

Yes, and where both are needed we coordinate timing and, with the client's consent, share relevant control-testing workpapers between the two engagements to avoid duplicating walkthrough and evidence-gathering effort, while keeping the two reports' conclusions consistent.

Practitioner noteRunning both engagements through the same firm, with shared underlying control evidence, avoids the situation where two independent reviews reach different conclusions about the same control for the same period.
How does PNPC prioritise which findings to remediate first?

Findings are ranked by the materiality of the financial reporting risk left exposed — a material weakness in revenue recognition controls is prioritised well ahead of a minor documentation gap in a low-value process — and each ranked finding is paired with a named owner and a realistic target remediation date in the roadmap.

Practitioner noteWe push back on the instinct to fix the easiest findings first just because they are quick wins — the remediation roadmap is sequenced by risk reduction, not by ease of closure, though we flag genuine quick wins separately so they can be closed in parallel.
Does PNPC verify that remediation actually happened, or just record management's commitment?

We schedule a follow-up verification cycle for the highest-risk findings, independently confirming the remediating action was actually implemented — not simply accepting management's assertion that an item is closed — and report residual weaknesses if remediation fell short.

Practitioner noteUnverified 'closed' findings are one of the most common reasons a board or group internal audit loses confidence in a control framework — we build verification into the engagement from the outset rather than treating it as an optional add-on.
What deliverables do we receive at the end of the engagement?

A final ICFR review report covering the entity-level control assessment, process-level risk and control matrices, design and operating effectiveness testing results, a ranked deficiency register, and a remediation roadmap with named owners and target dates — formatted to the board's, group finance function's, or statutory auditor's requirements where specified.

Practitioner noteWe also retain the underlying walkthrough notes, RCMs, and test samples so that, if a question arises months later from a statutory auditor or group internal audit, the basis for every conclusion can be traced.
Why choose PNPC Global for a UAE ICFR review over a smaller local firm or a large international firm?

PNPC Global has run internal control, risk advisory, and audit-adjacent engagements since 1986 across India and the UAE, combining rigorous evidence-based testing methodology with practical, hands-on process experience across the trading, distribution, manufacturing, and services sectors common in the UAE market — at a cost and turnaround suited to UAE SME and mid-market businesses rather than large-firm minimum fee structures.

Practitioner noteClients with cross-border India-UAE group structures particularly value having one firm run a consistent ICFR methodology across both jurisdictions, rather than reconciling two separately commissioned, differently scoped reviews.
How much does an ICFR review cost in the UAE?

Cost depends primarily on the number of entities and processes in scope, whether operating effectiveness testing covers a full financial year or a shorter period, and the condition of existing process documentation. Single-entity, core-cycle reviews are priced modestly; multi-entity group reviews or full-year operating effectiveness testing are priced as a more substantial, structured engagement.

Practitioner noteWe give a firm, scoped quote after the initial scoping call rather than a generic price list — ICFR review cost genuinely varies too much by entity complexity and process count to quote blind.
Can the review be combined with a due diligence engagement for an investment or acquisition?

Yes. Where an ICFR review is commissioned as part of buy-side or sell-side due diligence, we scope the walkthroughs and testing to align with the transaction's specific due diligence timetable and the investor's or acquirer's particular control-quality questions.

Practitioner noteTransaction timelines are usually tighter than a routine board-mandated review — flag the deal timetable early so we can resource the fieldwork and reporting accordingly.
What happens to the engagement file and workpapers after the final report is issued?

PNPC retains walkthrough notes, RCMs, testing evidence, and correspondence underlying the report so that, if a question arises later — from group internal audit, the statutory auditor, or a subsequent transaction — the basis for every finding can be traced and re-verified. Because control evidence often underpins figures that feed the Corporate Tax return, the underlying records also fall within the UAE Corporate Tax record-retention regime, which requires Taxable Persons to keep relevant records for at least seven years after the end of the relevant tax period.

Practitioner noteWe keep engagement workpapers indexed to the final report's sections, so a query raised months later can be answered by reference to a specific RCM cell or test sample, not a general search through old correspondence.
Does the ICFR review scope differ for a DIFC or ADGM regulated entity compared to a standard mainland or free zone company?

DIFC and ADGM entities operate under their own regulator (the DFSA and FSRA respectively) with sector-specific governance and reporting expectations layered on top of standard financial reporting controls, so the entity-level assessment explicitly maps to the applicable regulator's governance requirements in addition to the underlying risk and control matrix work, rather than treating a DIFC/ADGM entity identically to a standard free zone company.

Practitioner noteWe confirm at scoping whether the client needs the DFSA/FSRA-specific governance lens layered in, since a generic COSO-only review misses expectations a regulated entity's own supervisor will specifically look for.
How does the review treat related-party transactions?

Related-party transactions are assessed as a distinct risk within the relevant process walkthroughs, most commonly revenue, procurement, and treasury — testing whether related-party transactions are identified, approved at the appropriate authority level, and disclosed consistently, since inadequate related-party controls are a recurring source of audit and Corporate Tax scrutiny in UAE group structures.

Practitioner noteWe specifically request the related-party listing and intercompany agreement register early in scoping, because this evidence is frequently scattered across legal, finance, and group functions rather than held in one place.
Can the ICFR review be conducted remotely, or does it require on-site fieldwork?

A hybrid approach is standard — entity-level interviews, document review, and evidence gathering can run remotely, but walkthroughs of physical processes (inventory counts feeding into fixed assets, cash handling, physical approval trails) and sensitive interviews are generally more reliable conducted on-site, so we agree the mix at scoping based on the processes in scope and the client's own preference.

Practitioner noteEntities with distributed operations across multiple Emirates or free zones often ask for a hybrid model — we flag upfront which specific walkthroughs we consider need an on-site visit rather than defaulting the whole engagement to remote.
What if the business still runs primarily on spreadsheets rather than an ERP?

The methodology does not require an ERP — controls over spreadsheet-based processes (version control, formula integrity, access restriction, and independent review before figures are used) are assessed using the same design-and-operating-effectiveness lens, though spreadsheet environments typically surface more findings around version control and unauthorised changes than a properly configured ERP with role-based access.

Practitioner noteWe flag spreadsheet-dependent processes as a standing risk area in the report even where no single finding rises to a significant deficiency, since spreadsheet control weaknesses compound quietly as transaction volume grows.
How does the review handle multi-currency treasury and cash management controls?

Treasury walkthroughs cover bank reconciliation controls, payment authorisation limits, and — where the entity holds multi-currency balances or intercompany funding arrangements — the process for recording and reconciling foreign-currency transactions and revaluation, tested with the same design and operating effectiveness approach applied to other financial statement cycles.

Practitioner noteIntercompany funding flows in cross-border India-UAE or multi-jurisdiction group structures are a common area where treasury controls look adequate on paper but the reconciliation between group entities is not actually performed on a defined cycle — we test for that specifically.
Should an ICFR review happen before or after implementing a new ERP system?

Both, ideally: a pre-implementation review of the current control environment establishes what needs to be re-designed into the new system's workflow configuration, and a post-go-live review confirms the new system's control configuration — approval workflows, segregation of roles, audit trails — actually operates as designed once live, rather than assuming the vendor's default configuration meets the entity's control requirements.

Practitioner noteWe see the most value from being engaged during the ERP requirements and configuration stage, not just after go-live — retrofitting a control gap into a live system is far more disruptive than designing it in before configuration is finalised.
Does the review cover controls at outsourced or offshored accounting functions?

Yes — where bookkeeping, payroll processing, or parts of the finance function are outsourced or offshored, the review assesses the controls governing that arrangement specifically: the service-level agreement, the client's own oversight and review controls over the outsourced provider's output, and evidence that the outsourced function's work is independently reviewed before being relied upon in the financial statements.

Practitioner noteA common gap we find is a client assuming an outsourced provider's own assurance report, where one exists, substitutes for the client's own oversight control — it does not; the client still needs a documented review control over what the provider delivers.
What happens if fieldwork uncovers evidence suggesting actual fraud, not just a control weakness?

We pause and escalate immediately to the board or audit committee, bypassing the standard reporting cycle, rather than continuing routine fieldwork and folding it into the scheduled draft report, since a live fraud indicator needs a decision from those charged with governance on next steps — including whether to commission a dedicated forensic investigation — before further testing proceeds in that area.

Practitioner noteThis distinction matters operationally: an ICFR review is designed to test control effectiveness, not to investigate a specific suspected fraud, so if fieldwork surfaces something beyond a control gap we recommend scoping a separate forensic engagement rather than stretching the ICFR review's methodology to cover it.
Is the ICFR review report confidential, or can it be shared with a bank or investor?

The report belongs to the commissioning entity, and PNPC shares it with third parties — a bank, an investor, a prospective acquirer — only on the client's written authorisation. The engagement letter specifies who the report is addressed to, and any wider circulation is a decision for the client, not something PNPC does unilaterally.

Practitioner noteWe ask early in scoping whether the client already anticipates sharing the report externally, since that affects how findings are framed and whether a summary version alongside the full report makes sense for external circulation.
Does the review specifically assess revenue recognition controls under IFRS 15?

Where revenue recognition is in scope, the walkthrough and testing examine the controls around identifying performance obligations, timing of recognition, and variable consideration estimates consistent with IFRS 15 (Revenue from Contracts with Customers) principles, since revenue is typically the single highest-risk financial statement line and misapplied recognition timing is a recurring source of restatement.

Practitioner noteBusinesses with long-term contracts, milestone billing, or bundled services — common in UAE construction, real estate, and services sectors — tend to carry the most IFRS 15 judgement risk; we flag these specifically for deeper testing rather than treating revenue as a single homogenous control area.
How does the review apply to a dormant or pre-revenue UAE entity?

There is limited value in operating effectiveness testing where no meaningful transaction volume exists, but a lighter entity-level and design assessment can still be useful — confirming governance structure, bank account controls, and the framework that will apply once the entity becomes active — so the control environment is ready rather than retrofitted once transactions begin.

Practitioner noteWe are candid with dormant-entity clients that a full ICFR review is usually premature; a governance and readiness assessment is normally the more proportionate and cost-effective starting point.
Can the ICFR review run in parallel with UAE Corporate Tax registration or a Corporate Tax health check?

Yes, and there is a natural overlap — the same journal entry, revenue recognition, and expense-recording controls examined in the ICFR review directly support the reliability of the taxable income figure a Corporate Tax health check assesses, so running both on a coordinated timeline avoids duplicating document requests and walkthrough time with the client's finance team.

Practitioner noteWe flag any control finding with direct Corporate Tax relevance — for example, inconsistent expense cut-off — to the client's tax advisor in real time rather than waiting for both reports to separately surface the same issue months apart.
What is the client's own role and time commitment during the review?

Process owners need to be available for walkthrough interviews, finance needs to compile the evidence requested against the document checklist, and a single internal coordinator — typically the CFO, Financial Controller, or Head of Internal Audit — is needed to manage document flow and scheduling. The time commitment scales with the number of processes and entities in scope, and we agree a realistic client-side resourcing expectation at the scoping call.

Practitioner noteReviews slip most often not because of PNPC's fieldwork capacity but because client-side document requests sit unanswered — we build a named internal coordinator into the engagement letter specifically to keep this moving.
How does PNPC keep the review proportionate for a mid-market UAE business rather than over-engineering it like a listed-company exercise?

Scope, sample sizes, and testing depth are calibrated to the entity's actual size, transaction volume, and risk profile agreed at scoping — a mid-market trading or services business does not need the same testing intensity as a listed group's consolidated ICFR programme, and we are explicit about where we have deliberately scoped down testing depth versus where materiality genuinely requires full testing.

Practitioner noteWe push back on scope creep in both directions — resisting pressure to under-test a genuinely high-risk process to save cost, and equally resisting the instinct to apply listed-company-grade testing depth to a process where the transaction volume and risk simply do not justify it.
How does an ICFR review relate to an Indian parent company's Companies Act 2013 internal financial controls requirement?

Where the UAE entity is a subsidiary of an Indian-listed or large unlisted parent, the parent's own statutory auditor typically has to report on the adequacy and operating effectiveness of internal financial controls over financial reporting for the group under Section 143(3)(i) of India's Companies Act, 2013 — and that reporting obligation extends, in substance, to material subsidiaries even though the UAE entity itself has no equivalent standalone Indian filing obligation. A UAE-scoped ICFR review conducted to a comparable methodology gives the Indian parent's auditor independent local evidence to rely on for the subsidiary's contribution to that group-level conclusion.

Practitioner noteWe ask explicitly at scoping whether the Indian parent's auditor has specific documentation or testing-period expectations under Section 143(3)(i), since aligning to those expectations upfront avoids a second round of supplementary testing requested by the Indian audit team after our report is already issued.
Does an ICFR review still add value if the statutory auditor already issued an unqualified opinion?

Yes — an unqualified audit opinion confirms the financial statements as a whole were not materially misstated, but the statutory auditor's control evaluation under ISA 315/330 is scoped only to what is necessary for audit risk assessment, not to giving the board an independent, process-by-process view of control maturity. A clean opinion is compatible with real control weaknesses that happened not to produce a misstatement in that particular period, or that the audit's substantive testing approach was not designed to surface.

Practitioner noteWe are candid that a clean audit opinion is reassuring but not the same evidence as an ICFR review — boards sometimes assume the two are interchangeable, and that assumption is exactly the gap that later surfaces as an unpleasant finding during a listing or acquisition process.
What are the main cost drivers behind an ICFR review fee, beyond just entity count?

Beyond the number of entities and processes in scope, the principal cost drivers are: whether testing covers design only or a full financial year of operating effectiveness; the condition of existing process documentation (a business with current SOPs and RCMs from a prior review costs meaningfully less to re-test than one starting from a blank page); headcount and location count, since segregation-of-duties and access-rights testing scale with organisational complexity; and whether ITGC and DIFC/ADGM-specific governance layers are in scope alongside the core financial process review.

Practitioner noteWe walk clients through these specific drivers at the scoping call rather than a single lump-sum estimate, so they understand which cost lever they can pull — for example, narrowing to a targeted process review — if budget is a genuine constraint.
What is different about a repeat or periodic ICFR review compared to a first-time baseline review?

A first-time baseline review builds the entity's RCMs and process documentation essentially from scratch through full walkthroughs with every process owner. A repeat review starts from the prior cycle's RCMs, updates them for any process or personnel changes since the last review, and can generally run a leaner, faster fieldwork phase focused on confirming what changed and re-testing operating effectiveness for the new period, provided documentation from the prior cycle was properly maintained.

Practitioner noteThe efficiency gain on a repeat review depends entirely on whether the client kept the RCMs and evidence trail current between cycles — a repeat review after a well-maintained first review is genuinely faster and cheaper; one where nothing was kept up to date is barely different from starting over.
Is a whistleblower or ethics-hotline policy a mandatory prerequisite for an ICFR review?

No — it is not a legal prerequisite under UAE law, but its presence and actual use (or absence) is assessed as part of the entity-level control environment, since a functioning whistleblower channel is one of the recognised ways a business detects a control failure or fraud indicator before it compounds into a larger problem. Its absence is noted as an entity-level gap, not treated as disqualifying the review from proceeding.

Practitioner noteMany UAE SMEs have no formal whistleblower channel at all — we flag this as a low-cost, high-value entity-level improvement in nearly every first-time review for a smaller business, since it is one of the more straightforward gaps to close.
How does PNPC handle a group review where entities have different financial year-ends?

Each entity's testing period is aligned to its own financial year-end for operating effectiveness sampling, while entity-level and cross-entity findings (such as group-wide segregation-of-duties policy or a shared ERP configuration) are assessed and reported on a consistent basis across the group regardless of individual fiscal calendars, so the consolidated group report remains internally comparable even where the underlying testing windows differ by entity.

Practitioner noteWe map out each entity's fiscal year-end explicitly at scoping for any multi-entity engagement — assuming a single group-wide testing period when entities actually close on different dates is a common source of confusion in the fieldwork schedule.
Does an ICFR review matter for a UAE entity being wound down or exited, rather than one continuing to operate?

Its relevance narrows considerably. Operating-effectiveness testing over an extended future period has limited value for an entity winding down, but a targeted review of controls over the final financial statements, asset realisation, and liability settlement process can still matter — particularly where the liquidator, remaining shareholders, or a parent group need independent comfort that the final reported position is reliable before deregistration.

Practitioner noteWe scope wind-down engagements narrowly around the specific final-position assurance need rather than running the full standing ICFR methodology, since most of the forward-looking remediation and monitoring elements of a normal review have no practical application to an entity that will shortly cease to exist.
How much shorter or different is the report for a small single-entity business compared to a large multi-entity group?

The underlying methodology — walkthroughs, RCMs, design and operating effectiveness testing, deficiency classification — is the same, but the report for a small single-entity business covers fewer processes, a shorter RCM set, and a shorter deficiency register, and is typically delivered as a single consolidated document rather than the entity-by-entity structure a multi-entity group report requires, with a cross-entity executive summary layered on top for group-level readers.

Practitioner noteWe deliberately size the report format to the audience — a five-person finance team does not need the same document architecture as a group CFO managing consolidated reporting across a dozen entities, even where the underlying rigour is identical.
How does Ministerial Decision No. 114 of 2023 on accounting standards relate to the control design ICFR reviews assess?

Ministerial Decision No. 114 of 2023 sets the accounting standards and methods a Taxable Person must apply for UAE Corporate Tax purposes under Federal Decree-Law No. 47 of 2022. Where a target's chart of accounts, management accounts, depreciation policy, or closing procedures need to produce financial statements defensible for Corporate Tax purposes and not just for internal management reporting, the ICFR review's process-level controls over the close and journal entry cycle are assessed with that accounting-standard framing specifically in view, rather than assuming any internally consistent set of numbers is automatically adequate.

Practitioner noteWe flag to clients specifically where a chart-of-accounts or closing-procedure gap could affect the Corporate Tax-relevant accounting treatment under Ministerial Decision No. 114 of 2023, since this is a distinct and sometimes overlooked angle from the general 'are our books accurate' question most finance teams ask themselves.
Who actually signs the engagement letter for an ICFR review — the board, the CFO, or someone else?

The engagement letter is typically signed by whoever has authority to commission the review on the entity's behalf — commonly the CFO or Financial Controller acting under board or audit committee authorisation, or directly by a board member or audit committee chair where the review was commissioned at that level. PNPC confirms the signing authority explicitly at scoping so the engagement letter, and any subsequent findings, are addressed to the party with genuine decision-making responsibility.

Practitioner noteWe ask early who the ultimate decision-maker is on findings, not just who signs the paperwork — a CFO-commissioned review that surfaces a finding implicating the CFO's own team needs an escalation path to the audit committee built in from the outset, not improvised later.
Can the engagement be phased to manage budget, rather than committing to the full scope upfront?

Yes. A common phasing approach runs the entity-level control assessment and design effectiveness review as Phase 1, giving the board or management an initial view of control maturity and priority risk areas at a lower cost, with Phase 2 — full sample-based operating effectiveness testing across the agreed processes — commissioned separately once Phase 1 findings confirm where deeper testing is genuinely warranted.

Practitioner noteWe recommend phasing for first-time reviews at cost-sensitive SMEs specifically, since Phase 1 findings often redirect Phase 2 testing toward the two or three processes that actually carry the most risk, rather than spreading full operating-effectiveness testing evenly and less efficiently across every process from day one.
In what language is the ICFR review report delivered?

The full report is delivered in English as standard, since this is the working language of virtually all UAE corporate finance, audit, and group-reporting functions we engage with. Where a board, government-linked stakeholder, or specific reader requires it, PNPC can prepare an Arabic executive summary alongside the full English report.

Practitioner noteWe confirm language requirements at scoping rather than assuming — this comes up more often for entities with a government-linked shareholder or a board that includes an Arabic-first reader who wants the executive summary in their working language.
Does the risk and control matrix need to be rebuilt from scratch at every renewal cycle?

No, provided it was properly maintained between cycles — the RCM is updated for any process, personnel, or system changes since the last review rather than rebuilt from a blank template, which is precisely why keeping RCMs and evidence trails current between engagements (rather than only during an active review) meaningfully reduces the cost and duration of every subsequent cycle.

Practitioner noteWe explicitly hand over a maintenance checklist at the end of every engagement so the client's finance team knows what to keep updating between reviews — clients who follow it get a noticeably faster and cheaper next cycle; clients who file the report away and forget about it effectively restart from scratch.
Does the ICFR review approach differ for a trading company versus a professional services business?

The core methodology is the same, but the weighting of process risk differs — a trading company's highest-risk cycles are typically inventory, procurement-to-pay, and revenue/receivables, with physical stock-count controls a material addition to the walkthrough scope, while a services business carries relatively less inventory risk but proportionately more risk around time/project-based revenue recognition, work-in-progress valuation, and utilisation-linked billing accuracy.

Practitioner noteWe adjust the RCM's process weighting at scoping based on the client's actual business model rather than applying a single generic template across sectors — a services business does not need the same inventory-count testing depth as a distribution business, and vice versa for revenue recognition judgement testing.
If the company recently changed its statutory auditor, does that affect how the ICFR review is scoped?

It can — a recent auditor change is not automatically a red flag, but where it followed a disagreement over accounting treatment, a qualified opinion, or an unresolved management letter point, we specifically request the prior auditor's final management letter and any resignation or non-reappointment correspondence, since those documents often identify exactly the control area most worth prioritising in the ICFR review's scope.

Practitioner noteWe ask about auditor continuity as a standard scoping question, not just when something seems unusual — an entirely routine, cost-driven auditor change needs no special handling, but we want to rule that out explicitly rather than assume it.
Does the review specifically test controls over cash and near-cash assets, separately from general treasury controls?

Yes, where cash handling is material to the business — retail, hospitality, and similar cash-intensive sectors in particular — the review tests physical cash-handling controls (till reconciliation, cash-in-transit procedures, dual custody for cash counts) as a distinct control area from the broader bank reconciliation and payment-authorisation controls covered under treasury, since cash-handling risk and bank-account risk require different evidence and testing approaches.

Practitioner noteWe scope in dedicated cash-handling testing specifically for retail, F&B, and similar cash-heavy operating models — applying only bank-account-level treasury testing to a cash-intensive business would miss where the real control risk actually sits.
Does the review assess controls over contingent liabilities and guarantee disclosures, not just recorded balance-sheet items?

Yes — the review examines whether the entity has a control process for identifying, tracking, and disclosing contingent liabilities such as guarantees given on behalf of related entities, pending litigation with an uncertain outcome, and other off-balance-sheet commitments, since these items are easy to omit from financial statements if there is no defined process requiring finance to capture them, distinct from the more visible recorded transaction cycles.

Practitioner noteIntercompany guarantees are a recurring gap we find in UAE group structures — a guarantee given years earlier by an entity to support a related company's bank facility is sometimes not tracked anywhere formally once the original transaction is forgotten, and only surfaces when we specifically ask for the group's guarantee register.
Is there a realistic minimum entity size below which a full ICFR review stops making commercial sense?

There is no fixed threshold, but a very small entity with minimal transaction volume, a single-person finance function, and no near-term listing, group-consolidation, or facility-renewal driver typically gets more value from a lighter compensating-controls or governance-readiness assessment than a full multi-process ICFR review, since the cost of full-scope testing can outweigh the risk being managed at that scale.

Practitioner noteWe tell smaller prospective clients directly when we think a full ICFR review is disproportionate to their current size and risk profile, and recommend the lighter-touch alternative instead — a review scoped beyond what an entity's risk actually warrants serves neither the client's budget nor the credibility of the report.
How does PNPC run an ICFR review across a group that mixes mainland, free zone, and offshore entities in the same engagement?

Each entity type is assessed against its own regulatory and operating context — a mainland entity's controls are tested against its actual trading operations, a free zone entity's controls include the Qualifying Free Zone Person substance and income-segregation dimension where relevant to Corporate Tax, and an offshore holding entity is typically assessed at a lighter, governance-and-custody level appropriate to a non-trading vehicle — while all three feed into a single consolidated group RCM structure and deficiency register so the board sees one coherent group-wide picture rather than three disconnected reports.

Practitioner noteWe are explicit with group clients that an offshore holding entity in the structure does not need — and should not receive — the same operating-effectiveness testing depth as the mainland trading entity beneath it; matching testing depth to what each entity actually does keeps the group engagement proportionate and credible.
Does an ICFR review consider whether the entity's insurance coverage is adequate, given the risks its controls are meant to mitigate?

Only tangentially — the review is not an insurance adequacy assessment, but where a control gap (for example, weak physical asset custody or unreconciled inventory) is identified, we note where the entity's exposure appears under-insured relative to that specific risk as a supplementary observation, since a board evaluating overall risk exposure benefits from seeing the control finding and the related insurance gap together rather than as two disconnected data points from separate advisors.

Practitioner noteWe flag this only where it is directly relevant to a control finding already identified — we do not turn the ICFR review into a general insurance audit, since that is a distinct specialism outside the review's core scope.
Why PNPC Global

PNPC Global vs. typical UAE ICFR review providers

FactorPNPC GlobalTypical Small Local FirmBig-4/Large International Firm
Depth of engagement scopingScoping call to precisely match group framework, board requirement, or bank expectation before quotingOften a generic maturity-model checklist with limited scoping discussionThorough but with high minimum fees regardless of entity size
Framework flexibilityBenchmarks against COSO, a parent-group framework, or bank-specific expectations as agreed at scopingFrequently applies a single fixed template regardless of client contextRigorous COSO-based methodology but less adaptable to a smaller entity's actual process maturity
Evidence disciplineTraces every finding to a specific RCM cell, walkthrough note, or test sampleOften accepts management assertion at face value without sample testingRigorous, but with high minimum fees regardless of engagement size
Cross-border India-UAE capabilitySingle firm applies one consistent ICFR methodology across both jurisdictions for group companiesRarely availableAvailable but typically at a much higher fee structure
Deficiency classification rigourFindings ranked control deficiency / significant deficiency / material weakness using standard audit terminologyOften presented as an unranked list of observationsRigorous classification, generally with slower internal sign-off cycles
Statutory auditor coordinationDirect briefing to the incoming or existing statutory auditor on request, reducing duplicated control testingRarely proactively coordinatedAvailable but coordination often slower for lower-fee engagements
Remediation verificationScheduled follow-up cycle independently verifying remediation, not just recording management's commitmentRarely built into the standard engagementAvailable, typically as a separate paid engagement
Cost structure for SME/mid-market clientsScoped, transparent pricing suited to UAE SME and mid-market entity complexityCan be inconsistent or ad hocOften cost-prohibitive for SME-scale entities
Responsiveness to urgent findingsImmediate communication of material weaknesses, not held back for the final reportVaries by firm disciplineGenerally rigorous but slower due to internal escalation protocols
ContinuityCreates a remediation roadmap and follow-up verification calendar after handoverStops once the document or report is deliveredAvailable, but continuity support is typically a separate paid engagement

PNPC Global positions itself between the informality of very small local providers and the process-heavy overhead of the largest international firms — rigorous, evidence-based ICFR methodology at a cost and turnaround suited to UAE SME and mid-market businesses and cross-border India-UAE groups.

What the PNPC package includes

  1. 01

    Initial scoping call fixing the benchmark framework (COSO, parent-group standard, or bank-specific expectation), entities/processes in scope, and testing period

  2. 02

    Entity-level control assessment covering governance, tone at the top, and whistleblower/reporting channels

  3. 03

    Process walkthroughs across revenue, procurement-to-pay, payroll, treasury, fixed assets, journal entries, and financial close

  4. 04

    Risk and control matrices (RCMs) mapping each significant risk to the control that mitigates it

  5. 05

    Design effectiveness assessment for every identified control

  6. 06

    Sample-based operating effectiveness testing over the agreed review period

  7. 07

    Segregation of duties analysis across ERP/system roles, including journal entry preparer/approver conflicts

  8. 08

    IT general controls (ITGC) review to the extent financially relevant — access, change management, and backup/recovery

  9. 09

    Ranked deficiency register classifying each finding as a control deficiency, significant deficiency, or material weakness

  10. 10

    Remediation roadmap with named owners and realistic target dates, sequenced by risk priority

  11. 11

    Management response meeting on material findings before the report is finalised

  12. 12

    Statutory auditor briefing on request, to reduce duplicated control testing during year-end fieldwork

  13. 13

    Report formatted to your board's, group finance function's, or bank's specific requirements

  14. 14

    Follow-up remediation verification cycle for the highest-risk findings

  15. 15

    Cross-border coordination for India-UAE group companies applying one consistent methodology

  16. 16

    Seven-year-compliant retention of RCMs, walkthrough notes, and test evidence where findings feed the Corporate Tax return

  17. 17

    Phased engagement option — entity-level and design assessment as Phase 1, full operating effectiveness testing as Phase 2 — for budget-conscious first-time reviews

  18. 18

    Bilingual delivery option, with an Arabic executive summary alongside the full English report where a board or government-linked stakeholder requires it

  19. 19

    Proportional scope calibration across mixed mainland, free zone, and offshore group structures, matching testing depth to what each entity actually does

Talk to PNPC Global before your next group consolidation, listing readiness milestone, or year-end audit — we scope the ICFR review to what your board, parent company, or bank actually needs to see, so the findings hold up under scrutiny the first time.

Jurisdiction

🇦🇪
United Arab Emirates

Free zone, mainland & offshore

Ready to get started?

Tell us about your requirement — a UAE specialist responds within 24 hours.

← Back to Specialised Audit & Certification