We advise organisations on governance, risk management, internal control, compliance and internal audit, helping them anticipate risks, strengthen their management and control systems and make better decisions.

In an environment characterised by emerging risks, increasing regulatory requirements and growing demands for control and transparency, organisations need to integrate governance, risk and compliance into their strategy and decision-making processes, while maintaining an objective and independent view of the effectiveness of their management and control systems.

Through our Risk Advisory Services, we help clients identify and manage their key risks, strengthen their control systems and meet their regulatory obligations. We combine specialist knowledge and experience with a practical, collaborative approach tailored to the specific circumstances of each organisation.

 Our servies  

We help strengthen governance structures and mechanisms, fostering an environment of trust, transparency and effective decision-making, aligned with strategy, regulatory requirements and stakeholder expectations.

  • Assessment and enhancement of corporate governance frameworks and development of strategic GRC plans.
  • Annual Board and Board Committee evaluation processes.
  • Support and advice to Audit, Risk and Compliance Committees.
  • Training for Boards and Committees on new regulations, emerging risks and trends in governance, risk and compliance.

We support organisations in managing risk holistically and enhancing their control systems, from risk identification and assessment through to monitoring.

  • Design, implementation and enhancement of risk management systems (RMS/ERM).
  • Development and updating of corporate risk maps and assurance maps.
  • Definition of risk appetite and tolerance frameworks, indicators and monitoring systems.
  • Management of specific risks, including operational, tax, ESG, counterparty and third-party risks.
  • Technology and cybersecurity risk management.
  • Risk dashboards and advice on the implementation of GRC solutions.
  • Assessment of emerging risks and support with their integration into decision-making and strategic planning processes.

We design and assess internal control systems aimed at strengthening processes, facilitating oversight and enhancing the reliability of financial, non-financial and operational information.

  • Design, implementation and enhancement of control frameworks for financial and non-financial information and operational processes.
  • Assessment, monitoring and testing of internal control frameworks and systems.
  • Assurance reports and engagements.
  • Fraud prevention, detection and control frameworks.
  • Review and enhancement of processes, policies and procedures.
  • Definition and review of IT General Controls (ITGCs) and technology controls.
  • Automation and enhancement of controls through technology and data analytics.

We help organisations identify and manage their regulatory obligations, embedding compliance into their processes, culture and management framework.

  • Ethics and integrity programmes, codes of conduct, internal reporting systems and whistleblowing channels.
  • Criminal compliance and crime prevention frameworks, both domestic and international (FCPA, UK Bribery Act, etc.).
  • Comprehensive corporate compliance frameworks.
  • Competition law compliance: design and review of competition compliance programmes, risk assessments, policies and procedures, training, and monitoring and control mechanisms.
  • Monitoring and testing of compliance frameworks.
  • Anti-money laundering and counter-terrorist financing (AML/CTF): design and review of AML/CTF frameworks, support in the performance of compliance functions, Technical Office services and External Expert Reports.
  • Data protection and privacy: design and review of data protection frameworks, support in the performance of related functions (records of processing activities, impact assessments, DPO, etc.), and legal and technical review of implemented measures.
  • Monitoring and testing of compliance frameworks.
  • Advice and support in certification processes.
  • Independent Assessment of Microsoft’s Supplier Security and Privacy Assurance (SSPA) Programme

We help protect and create value through an Internal Audit function focused on independently assessing risks, controls, processes and governance systems and identifying opportunities for improvement.

  • Design and transformation of the Internal Audit function and definition of its strategic plan and risk-based annual audit plan.
  • Outsourcing and co-sourcing of the Internal Audit function and individual Internal Audit engagements.
  • Process and operational, regulatory and compliance, financial and technology audits.
  • Audit and review of internal and outsourced processes.
  • Assessment of the quality and effectiveness of the Internal Audit function.
  • Audits of contracts and third-party relationships.
  • Follow-up of recommendations and action plans arising from audits.

Contact with us

Fill in this form and the person in charge of the RSM area will contact you.

Through this form we will process your data in order to manage the queries you send us.

The data controller is RSM Spain and its group companies. We process your data, in each case, to send you information that you request, to send you our newsletter, to manage our obligation to have an external information channel, to manage your applications and to invite you to events when you ask us to, as appropriate. We will only disclose your data to public authorities and organisations where we are legally obliged to do so. You have the right to access, rectify, erase, oppose, limit the processing of your data, request portability and not be subject to automated decisions, including profiling. If you have any questions, please contact our Data Protection Officer at dpo@rsm.es.