Businesses operate in an environment shaped by emerging risks, increasing regulatory requirements and a growing need for control and transparency. Anticipating these challenges requires governance, risk management and compliance to be embedded into strategy and decision-making processes.

At Risk Advisory Services, we help our clients identify and manage risk, strengthen their control frameworks and meet their regulatory obligations, helping to create a more secure, trusted and transparent business environment.

Our advice spans corporate governance, risk management, internal control, compliance and internal audit, with solutions tailored to the specific circumstances and needs of each business. We combine specialist knowledge and experience with a responsive and collaborative approach.

Our Risk Advisory Services (RAS) 

We help create an environment of security, trust and transparency by strengthening governance structures and aligning them with business strategy.

  • Assessment of governance frameworks.
  • GRC strategic planning.
  • Annual Board evaluation processes.
  • Board training on new regulatory requirements.

We support organisations with enterprise-wide risk management and the enhancement of control frameworks, from risk identification and assessment through to ongoing monitoring.

  • Design, implementation and enhancement of risk management systems (RMS/ERM).
  • Development of corporate risk maps.
  • Management of specific risks, including operational, tax, ESG and third-party risks.
  • Identification and assessment of technology and cybersecurity risks.
  • Risk dashboards and support with the implementation of GRC solutions.
  • Resilience scenario assessments..

We develop control and identification frameworks designed to strengthen processes, facilitate ongoing monitoring and enhance the reliability of information.

  • Control frameworks for financial and non-financial information and operational processes.
  • Assessment, monitoring and testing of control frameworks.
  • Assurance reports.
  • Fraud prevention and control.
  • Definition and review of IT controls.
  • Cybersecurity.

We identify and manage regulatory obligations, embedding compliance into day-to-day business activities.

  • Ethics and integrity programmes, codes of conduct and whistleblowing channels.
  • Criminal compliance and corporate crime prevention frameworks.
  • Anti-bribery and anti-corruption compliance.
  • Integrated corporate compliance frameworks.
  • Anti-money laundering (AML).
  • Data protection and privacy.
  • Monitoring and testing of compliance frameworks.
  • Support with certification processes.

We help protect business value through an Internal Audit function focused on assessing risks, controls and processes and identifying opportunities for improvement.

  • Design of the Internal Audit function and definition of its strategic plan.
  • Outsourcing and co-sourcing of Internal Audit activities.
  • Audit and review of internal and outsourced processes.
  • Assessment of the Internal Audit function.
  • Development of assurance maps.
  • Contract Risk & Compliance audits.
  • Data Analytics applied to Internal Audit.

Contact with us

Fill in this form and the person in charge of the RSM area will contact you.

Through this form we will process your data in order to manage the queries you send us.

The data controller is RSM Spain and its group companies. We process your data, in each case, to send you information that you request, to send you our newsletter, to manage our obligation to have an external information channel, to manage your applications and to invite you to events when you ask us to, as appropriate. We will only disclose your data to public authorities and organisations where we are legally obliged to do so. You have the right to access, rectify, erase, oppose, limit the processing of your data, request portability and not be subject to automated decisions, including profiling. If you have any questions, please contact our Data Protection Officer at dpo@rsm.es.