What Is Internal Control and Risk Management?
Internal control and risk management is the system of policies, procedures, and practices that an organisation implements to safeguard assets, ensure reliable financial reporting, promote operational efficiency, and encourage compliance with laws and regulations. CityLinkers designs and implements robust internal control frameworks tailored to the specific needs of each client, drawing on globally recognised standards such as the COSO Internal Control — Integrated Framework. Our services help companies build resilient governance structures that satisfy regulators, investors, and other key stakeholders.
How Does CityLinkers Design an Internal Control Framework?
Our internal control framework design begins with a thorough understanding of the client's business model, organisational structure, and risk profile. We apply the COSO framework's five components — control environment, risk assessment, control activities, information and communication, and monitoring — to build a comprehensive control architecture. We map existing controls against business processes, identify gaps, and design remediation procedures. The resulting framework includes detailed process documentation, flowcharts, risk and control matrices (RACM), and control activity descriptions that form the foundation for ongoing control monitoring and improvement.
What Is a Risk Assessment Matrix and How Is It Used?
A risk assessment matrix is a structured tool that identifies, categorises, and evaluates risks across the organisation based on likelihood and impact. CityLinkers develops tailored risk assessment matrices that align with the client's strategic objectives and regulatory environment. Each risk is assigned an inherent risk rating, residual risk rating after controls, and a risk owner responsible for mitigation. The matrix drives prioritisation of risk management efforts and provides a clear audit trail for board and audit committee oversight. We regularly update the matrix to reflect emerging risks and changes in the business environment.
How Does CityLinkers Address HKEX Corporate Governance Code Compliance?
Listed companies on the HKEX must comply with the Corporate Governance Code, which includes specific provisions on internal controls under Code Provision C.2. CityLinkers assists listed and pre-listing companies in meeting these requirements by conducting annual reviews of the effectiveness of internal controls, as required by the Listing Rules. We evaluate the design and operational effectiveness of controls over financial reporting, operations, and compliance. Our reviews produce management reports with identified deficiencies, risk ratings, and actionable remediation recommendations that satisfy HKEX disclosure expectations.
What Role Does Internal Audit Play in the Control Framework?
Internal audit is the third line of defence in the corporate governance structure, providing independent assurance that the internal control system is functioning as designed. CityLinkers assists in establishing internal audit functions, developing risk-based audit plans, and executing internal audit engagements. Our approach includes control testing — verifying that controls operate effectively through sample testing, walkthrough procedures, and substantive testing where appropriate. We provide detailed audit reports with findings, ratings, and management action plans, enabling the audit committee to exercise effective oversight of the control environment.
How Does CityLinkers Approach Process Documentation and Segregation of Duties?
Process documentation is the foundation of a sustainable internal control system. We create comprehensive documentation including process narratives, flowcharts, and procedure manuals that clearly define how each business process operates. A critical element of this documentation is segregation of duties — ensuring that no single individual has control over all phases of a transaction (authorisation, recording, custody, and reconciliation). We identify segregation of duties conflicts, assess compensating controls where separation is not feasible, and recommend restructuring of responsibilities to minimise fraud risk and operational errors.
How Does CityLinkers Support Fraud Prevention?
Fraud prevention requires a multi-layered approach combining preventive controls, detective controls, and a strong ethical culture. CityLinkers designs anti-fraud programmes that include whistleblower policies, fraud risk assessments, and monitoring controls such as exception reporting and data analytics. We evaluate the adequacy of existing fraud prevention measures against common fraud schemes — including asset misappropriation, financial statement fraud, and corruption. Our recommendations strengthen the control environment and reduce the organisation's exposure to fraud-related losses and reputational damage.
What Are IT General Controls (ITGC) and Why Do They Matter?
IT General Controls (ITGC) are the foundational controls that ensure the integrity, confidentiality, and availability of information systems supporting business processes. CityLinkers assesses ITGC across four key domains: access management, change management, computer operations, and programme development. We evaluate logical access controls, password policies, user access reviews, system change procedures, backup and recovery processes, and data security measures. Strong ITGCs are essential for reliable automated controls and financial reporting, particularly as companies increasingly rely on enterprise resource planning (ERP) systems and cloud-based platforms.
How Does CityLinkers Support Business Continuity Planning?
Business continuity planning (BCP) ensures that an organisation can maintain critical operations during and after a disruption. CityLinkers develops business continuity plans that include business impact analyses, recovery time objectives, and recovery point objectives for key processes. We design incident response procedures, crisis communication protocols, and disaster recovery strategies for IT systems. Our BCP services include tabletop exercise facilitation and plan testing to ensure readiness. A robust BCP is increasingly expected by regulators, investors, and business partners as part of enterprise risk management.
Why Choose CityLinkers for Internal Control and Risk Management?
CityLinkers combines deep technical expertise with practical implementation experience. Our team includes professionals with Big Four backgrounds, certified internal auditors (CIA), and risk management specialists. We tailor every engagement to the client's industry, size, and regulatory context, ensuring that controls are both effective and proportionate. Our deliverables are designed to be usable by management and defensible to regulators, auditors, and audit committees.
Robust internal controls and proactive risk management are essential to long-term business resilience and sustainable growth. At CityLinkers, we partner with organisations to design, implement, and continuously enhance governance frameworks that not only meet today’s regulatory expectations but also support tomorrow’s strategic goals.
Whether you're strengthening internal control functions, addressing specific risk exposures, or preparing for future challenges, our team is here to guide you with expertise and clarity. Contact CityLinkers today to explore how we can support your organisation in building a more secure and future-ready enterprise.
What is the COSO framework and why is it important?
The COSO Internal Control — Integrated Framework is a globally recognised model for designing, implementing, and evaluating internal controls. It comprises five interrelated components: control environment, risk assessment, control activities, information and communication, and monitoring. COSO provides a structured approach that is widely accepted by regulators, auditors, and standard-setters, making it the preferred framework for listed companies.
How often should internal control reviews be conducted?
HKEX-listed companies are required to conduct an annual review of the effectiveness of their internal controls. Beyond regulatory requirements, CityLinkers recommends that significant changes in business operations, organisational structure, or IT systems should trigger ad hoc control reviews. Regular monitoring through continuous control testing ensures that controls remain effective as the business evolves and new risks emerge.
What is the difference between SOX-style controls and HKEX requirements?
SOX-style controls, mandated by the US Sarbanes-Oxley Act, require management to formally assess and attest to the effectiveness of internal controls over financial reporting (ICFR). HKEX requirements, under the Corporate Governance Code, also require annual internal control reviews but are generally less prescriptive than SOX. CityLinkers designs control frameworks that meet both standards, which is particularly valuable for dual-listed companies.
What is segregation of duties and why does it matter?
Segregation of duties is the principle that no single individual should control all stages of a transaction — authorisation, execution, recording, and reconciliation. This separation reduces the risk of fraud, error, and manipulation. CityLinkers identifies segregation of duties conflicts and recommends compensating controls or role restructuring where complete separation is not operationally feasible, ensuring that risks are properly mitigated.
What are IT General Controls (ITGC) and what do they cover?
ITGC are foundational controls over information technology systems, covering four domains: access management (user access, passwords, privileged access), change management (system modifications and approvals), computer operations (backups, job scheduling, incident management), and programme development (system development lifecycle). CityLinkers assesses ITGC to ensure that automated controls and financial reporting systems are reliable and secure.
How does CityLinkers conduct control testing?
Control testing involves evaluating whether controls are properly designed and operating effectively. We use a combination of walkthrough procedures to confirm design effectiveness and sample-based testing to verify operational effectiveness. Testing methods include reperformance, observation, inspection of documentation, and inquiry. Results are documented with identified deficiencies, severity ratings, and remediation recommendations in a format suitable for audit committee reporting.
Does CityLinkers provide ongoing internal audit support?
Yes. CityLinkers offers co-sourced and fully outsourced internal audit solutions. We develop risk-based annual audit plans, execute audit engagements, and provide continuous monitoring support. Our internal audit services are aligned with the Global Internal Audit Standards issued by the IIA and are tailored to each client's risk profile, regulatory requirements, and organisational objectives.