Three services, one discipline

Establishing whether the controls a financial services firm relies on actually work — and building the ones that don’t yet exist. Sized for organizations that face institutional expectations without institutional resources.

Why one practice

Why these three belong together

Governance, controls and audit are usually sold as separate things by separate firms. In practice they’re three positions around the same question: can this organization demonstrate that the things it depends on are under control?

A technology risk framework that nobody audits becomes decoration. An audit finding with no framework behind it produces a fix that solves one instance and nothing structural. And AI governance, stripped of the hype, is the same discipline applied to a class of system that behaves less predictably than the ones we’ve governed for decades.

Firms your size rarely need all three at once. But the sequence matters — and knowing which one you actually need first is worth a conversation before it’s worth a proposal.

The services

Where we work

Technology governance, risk and compliance

Control frameworks, risk appetite and key risk indicators, issue management, and third-party risk processes that hold up when someone asks to see the evidence. Built on COBIT and COSO and sized for your organization — not a bank’s program handed to a firm of twelve.

Most relevant if a regulator or auditor has raised findings, your board wants technology risk reporting it can act on, or you’ve grown past the point where technology risk can live in the CTO’s head.

Technology governance, risk and compliance — learn more

AI governance, risk and compliance advisory

Your organization is adopting AI faster than anyone has written rules for it — and your board, your clients and eventually your regulator will ask how it’s governed. We build the layer that lets you keep moving: AI and model inventories, model risk management frameworks proportionate to your size, AI usage policies, vendor due diligence, and the oversight routines that make governance real rather than documented.

Most relevant if you’re adopting AI without a risk function, or you sell models and analytics into regulated institutions whose obligations are about to reach you.

AI governance, risk and compliance — learn more

Internal controls and IT audit review

Independent review of your IT general controls, application controls and technology processes — as specialist support to your internal audit function, or as a standalone controls review for management. Findings ranked by what actually matters, with a remediation plan your team can work through.

Most relevant if your audit plan includes technology coverage you can’t staff, or you’d rather find the problems yourself before a regulator, auditor or client does.

Internal controls and IT audit review — learn more

Self-assessment

Start from what’s actually on your desk

What’s happened, and where to start
What’s happened Where to start
A client or partner bank sent a due diligence questionnaire Technology GRC — third-party risk
Your board asked what your AI policy is AI governance
A regulatory exam or audit raised IT control findings Internal controls and IT audit review
You sell AI, models or analytics into regulated institutions AI governance — E-23 readiness
Your audit plan has technology or AI coverage you can’t staff Internal controls and IT audit review
You need a technology risk report your directors will read Technology GRC — risk appetite and reporting
Something went wrong and leadership wants to know whether it was bad luck or bad controls Internal controls and IT audit review
You’re starting from nothing and don’t know what you’re missing Any of the three — start with a conversation

Working together

How we work

Fixed scope, agreed first

Written scope, deliverables, timeline and fee before work begins.

You own what we build

Working documents in editable form, walked through with your team before we close the file.

Sized for your organization

Proportionality is a design principle, not an excuse for less.

We don’t review our own work

Where we’ve built something in an advisory capacity, we don’t then provide the independent review of it — and we’ll flag the conflict before you see it.

More about how we work

Advisory and review

On offering both advisory and review

A firm that designs control frameworks and also reviews control frameworks has an obvious question to answer. Ours is a written engagement acceptance policy: where we have built or designed something, we do not subsequently provide the independent review of it. Where a conflict is possible, we raise it before the engagement starts and, if it can’t be managed, we decline the second piece of work and point you to someone who can do it cleanly.

Audit committees and second-line functions are right to ask about this. Ours is available on request.

Fluency, not jargon

Standards and frameworks

Canadian regulatory

  • OSFI E-23 (Model Risk Management)
  • OSFI B-13 (Technology and Cyber Risk)
  • OSFI B-10 (Third-Party Risk)
  • Provincial equivalents

AI-specific

  • NIST AI Risk Management Framework
  • ISO/IEC 42001

Control and audit

  • COBIT 5
  • COSO Internal Control and ERM
  • IIA Global Internal Audit Standards
  • SOX 404 / ICFR

Privacy

  • PIPEDA
  • Quebec Law 25

Not sure which one you need?

That’s the most common starting point, and it’s what the first conversation is for. Thirty minutes, no cost — bring the questionnaire, the finding, or the board question, and you’ll leave with a straight view of what answering it takes and which piece of work it actually is.

Book a 30-minute consultation

Or email hello@hosmaksolutions.ca