Skip to content

Security & Quality

Controls Designed Into the Delivery Process.

Finance and accounting operations involve sensitive information, financial data and defined professional responsibilities.

VnV Global approaches information security and quality as part of the operating model rather than as activities added after delivery begins.

Controls across the operating model

  1. 01Access
  2. 02Process
  3. 03Review
  4. 04Evidence
  5. 05Oversight
Access, process, review, evidence and oversight form the control sequence in delivery.

Control Philosophy

Security and Quality Begin With Process Design.

Effective controls depend on knowing who can access information, who performs the activity, who reviews it and how exceptions are recorded and resolved.

Least necessary access

Access is aligned to what the role actually requires.

Defined responsibility

Each activity has a named owner and a defined reviewer.

Evidence of review

Review should leave a record, not only an assurance.

Traceable exceptions

Exceptions are recorded, tracked and resolved visibly.

Information Access

Control Access to the Work

Role-Based Access

Access aligned to responsibilities.

User Permissions

Permissions designed around the systems and process requirements.

Access Review

Periodic review of required access based on the engagement model.

Controlled Environments

Client information handled within agreed technology and operating environments.

Joiner / Mover / Leaver Controls

Access changes aligned with role changes and departures where applicable.

Process Controls

Controls Within Day-to-Day Delivery

  • Defined SOPs

  • Checklists

  • Maker-checker workflows

  • Approval requirements

  • Reconciliations

  • Exception tracking

  • Escalation procedures

  • Completion evidence

Quality Review

Review Is Part of the Workflow

The appropriate review structure depends on the service.

For professional services such as tax preparation support and audit support, professional judgement, regulated review and sign-off remain with the appropriate licensed professional or client firm.

  1. 01

    Preparation

  2. 02

    Internal Review

  3. 03

    Client / Professional Review

  4. 04

    Resolution

  5. 05

    Completion

Data Handling Principles

Handle Information According to the Engagement

  • Access only where required

  • Controlled sharing

  • Defined storage locations

  • Document handling procedures

  • Retention requirements

  • Secure disposal processes

  • Client-specific restrictions

  • Confidentiality responsibilities

Technology Controls

Technology Should Strengthen Traceability

The controls available depend on the platform and the client environment. Where applicable, technology is configured to make activity, approval and exception history traceable.

  • Authentication

  • Role-based permissions

  • Approval workflows

  • Validation controls

  • Audit trails

  • Exception logs

  • Change control

  • User acceptance testing

  • Backup considerations

  • Monitoring where applicable

Quality Management Framework

Quality Requires More Than Final Review

  1. 01

    Process Definition

    Document what should happen.

  2. 02

    Training

    Ensure the delivery team understands the process.

  3. 03

    Execution Controls

    Use checklists, reconciliations and validations.

  4. 04

    Review

    Review work according to defined responsibility.

  5. 05

    Improvement

    Analyse recurring errors, exceptions and process weaknesses.

Business Continuity

Plan for Delivery Continuity

Continuity planning is engagement-specific. Depending on the service and systems involved, it may address the following areas.

  • People availability

  • Technology access

  • Process documentation

  • Backup responsibilities

  • Communication

  • Escalation

  • Recovery priorities

Client-Specific Controls

The Control Environment Should Reflect the Engagement

Different clients have different systems, information-security requirements, approval structures and professional responsibilities.

During transition, engagement-specific controls can be incorporated into the operating model.

  • Access restrictions

  • Approval levels

  • Review requirements

  • Data-location requirements

  • Documentation standards

  • Escalation procedures

  • Client security policies

Professional Responsibility

Clear Boundaries of Responsibility

Where services support regulated accounting, tax or audit activities, VnV Global operates within the agreed support scope.

Licensed professionals and client firms retain responsibilities that legally or professionally require their judgement, approval, signature, filing authority or attest responsibility.

FAQ

Common Questions About Security and Quality

Discuss Your Security and Control Requirements.

If your organisation has specific access, review, information-security or process-control requirements, they can be considered during engagement design.

Contact

Start a Conversation

Tell us what you are looking to build or improve. Our team will get back to you to understand your requirements.

Fields marked with an asterisk are required.