Independent Assurance & Advisory

Confidence in your controls, clarity in your risk.

NSM Consulting is a London-based advisory firm delivering internal audit, enterprise risk, compliance and assurance for regulated Financial Services, the NHS and the wider Public Sector.

Partner-led teams · Big-4 pedigree · Independent, conflict-free opinions

Engagements at a glance

120+
Assurance & controls engagements delivered
3
Regulated sectors: FS, Healthcare & Public
40%
Avg. reduction in control testing effort
100%
First-year service-auditor opinions achieved
ISAE 3402ISAE 3000AAF 01/20SOC 1SOC 2 SOX 404ICARAISO 27001

Frameworks & standards we work to

Internal Audit · FS, NHS & Public Sector ERM · Enterprise Risk Management ICARA · Financial Crime & AML ISAE 3402 / 3000 AAF 01/20 SOC 1 & SOC 2 SOX · Readiness & Attestation ISO 27001 Trade Surveillance M&A · Integration & Decoupling
What we do

A full-spectrum GRC & assurance practice

Our GRCC group brings together specialists across internal audit, finance, risk, compliance and technology — deployed as integrated teams that understand both regulation and operational reality.

Internal Audit

Outsourced, co-sourced and specialist internal audit across Financial Services, NHS and the Public Sector — risk-based plans through to board-ready reporting.

  • Co-source & outsource
  • Risk-based planning
  • Audit committee reporting

Risk Management

End-to-end ERM implementation — risk taxonomy, appetite, RCSA and reporting embedded into how the business actually runs and governs itself.

  • ERM frameworks
  • Risk appetite
  • RCSA & KRIs

Compliance

Regulatory compliance for FCA-regulated firms — ICARA, financial crime and AML frameworks, assurance testing and remediation.

  • ICARA
  • Financial Crime
  • AML / KYC

Service Auditor Reporting

Independent controls opinions for service organisations: AAF 01/20, ISAE 3000, ISAE 3402, SOC 1 and SOC 2 — first-year readiness through to signed report.

  • ISAE 3402 / 3000
  • AAF 01/20
  • SOC 1 & SOC 2

Controls Framework Design

Design, rationalisation and transformation of control frameworks — cutting duplication, closing gaps and mapping controls to every relevant obligation.

  • Control rationalisation
  • Risk-control mapping
  • Automation

SOX Readiness & Attestation

SOX 404 scoping, control design, testing and management attestation — building sustainable, PCAOB-aligned programmes for newly-listed and mature filers.

  • Scoping & walkthroughs
  • Testing & RCM
  • Attestation support

Healthcare Consulting

Transformation under high-stakes conditions across the public healthcare system — programme turnaround, care integration and delivery of the NHS Long Term Plan.

  • Programme turnaround
  • System transformation
  • Care integration

Trading & Portfolio Systems

Design, optimisation and assurance of trading and portfolio management systems, plus trade surveillance and monitoring across all major trading platforms.

  • Systems assurance
  • Trade surveillance
  • Model & data controls

Cyber Security & ISO 27001

Cyber security audit, attestation and controls-framework development, including full ISO 27001 controls design, implementation and certification support.

  • Cyber audit
  • ISO 27001 design
  • Attestation

M&A Integration & Decoupling

Controls redesign, finance transformation, financial-statement evaluation and chart-of-accounts mapping across integrations, carve-outs and separations.

  • Finance transformation
  • CoA mapping
  • Day-1 readiness

Specialist Recruitment

Contingent, permanent and staff-augmentation hiring across GRC and healthcare — backed by deep candidate and industry knowledge, at competitive rates.

  • Contingent
  • Permanent
  • Staff aug
Where we work

Deep expertise in three regulated worlds

We pair sector specialists with GRC practitioners, so our teams speak the language of your regulator, your board and your operations from day one.

01 — Financial Services

Banks, asset & wealth managers, insurers, fintechs

FCA/PRA-regulated firms turn to us for internal audit, ICARA, financial crime, service-auditor opinions, SOX and trade surveillance — from challenger banks to global capital-markets desks.

02 — Healthcare & NHS

Providers, commissioners, regulators & private care

From NHS providers and integrated care systems to local authorities, central government and private healthcare — programme turnaround, transformation and assurance under pressure.

03 — Public Sector

Central government, local authorities & regulators

Independent controls assurance, risk frameworks and finance transformation for public bodies accountable to citizens, auditors and Parliament.

Client outcomes

Selected engagements & results

Anonymised to protect client confidentiality — but the challenges, methods and measurable outcomes are real.

Tier-1 Investment Bank
−40%
False-positive alerts after a trade-surveillance uplift across three trading platforms.
UK Challenger Bank
12wks
From gap analysis to a submission-ready ICARA and capital-adequacy framework.
NHS Provider
£6.8m
Recurring savings identified while turning around a stalled digital programme.
Global Asset Manager
Clean
First-year ISAE 3402 Type II opinion delivered with zero exceptions.
Payments Fintech
6mo
SOC 2 Type II readiness through to attestation, ahead of enterprise sales deadlines.
Global Insurer
Day-1
Carve-out ready — chart of accounts remapped and finance controls stood up for separation.
Wealth Manager
93
ISO 27001 Annex A controls designed and implemented to certification.
Listed Fintech
−55%
Reduction in key controls through SOX rationalisation — without losing coverage.

In depth

Three engagements, told the way we scope them — situation, task, action, and the results that mattered to the board.

Financial Services

Controls transformation & SOX readiness for a newly-listed fintech

A fast-scaling payments group needed a credible control environment for its first attestation.

Situation

Following a public listing, a high-growth payments business faced its first SOX 404 cycle with a fragmented control environment, undocumented processes and an external auditor already asking hard questions.

Task

Stand up an audit-ready control framework across the financial-reporting, ITGC and treasury processes — and give management the evidence to attest with confidence.

Action

We ran end-to-end process walkthroughs, built a risk-and-control matrix mapped to financial-statement assertions, rationalised duplicate controls, remediated design gaps and led a full dry-run test cycle with the external auditor engaged throughout.

Result

The firm passed its first attestation with no material weaknesses, a leaner control set and a testing programme its own team could sustain.

By the numbers
−55%
Key controls after rationalisation
0
Material weaknesses at first attestation
14wks
From kick-off to audit-ready
Healthcare / NHS

Turnaround of a stalled digital transformation programme

A critical clinical-systems programme had slipped its timeline and lost board confidence.

Situation

An NHS provider's flagship digital programme was months behind, over budget and facing regulatory scrutiny, with fractured governance between clinical, operational and technology stakeholders.

Task

Diagnose why the programme had stalled, rebuild delivery governance and secure senior leadership buy-in for a realistic, outcomes-focused reset.

Action

We ran a rapid delivery-confidence review, re-baselined scope and benefits, installed a single accountable governance forum, and worked shoulder-to-shoulder with clinical leaders to sequence delivery around patient outcomes rather than milestones on paper.

Result

The programme was back on plan within two quarters, with a clear benefits case, renewed board confidence and recurring savings reinvested into frontline care.

By the numbers
£6.8m
Recurring savings identified
2qtrs
To return to plan
1
Unified governance forum installed
Capital Markets

Trade surveillance & portfolio-systems assurance for a hedge fund

An alerting engine drowning in false positives was masking the alerts that mattered.

Situation

A multi-strategy fund's trade-surveillance programme spanned three platforms and was generating so many false positives that genuine market-abuse risk was being lost in the noise — a growing concern for compliance and the regulator alike.

Task

Assure the design and operating effectiveness of surveillance and portfolio-management systems, and recalibrate detection to focus analyst effort where risk actually sat.

Action

We reviewed scenario coverage against the firm's traded products, tuned thresholds using historical data, closed data-completeness gaps across venues, and rebuilt the governance around model changes and alert disposition.

Result

False positives fell sharply while true-risk coverage improved, giving compliance a defensible, well-governed surveillance framework and analysts time back for real investigations.

By the numbers
−40%
False-positive alert volume
3
Trading platforms brought into scope
100%
Traded-product scenario coverage
How we work

Rigorous method. No surprises.

Every engagement follows a disciplined arc — but we adapt as the work evolves and stay focused on the outcome, not the process.

1

Understand

We start with your risk, regulatory obligations and commercial reality — engaging the board, management and the second and third lines.

2

Assess

Structured diagnosis of your controls, data and processes against the relevant standard — gaps quantified and prioritised by risk.

3

Transform

Design and remediation delivered by partner-led teams, working alongside your people so capability stays in-house.

4

Assure

Independent testing, opinion or attestation — with reporting your audit committee and regulator can rely on.

About NSM

A trusted partner for governance, risk & controls

NSM Consulting Services Ltd is a premier London-based consulting group specialising in Internal Audit and Controls, Governance, Risk and Compliance, Healthcare Consulting and specialist recruitment.

Our dedicated GRCC group is made up of experts from across the firm, bringing together sector specialisms and deep experience in internal audit, finance, risk and technology — the range of a large firm, delivered with the focus and accountability of a specialist one.

Independent

Conflict-free opinions your regulator and board can trust.

Partner-led

Senior practitioners on the ground, not just on the pitch.

Outcome-focused

We measure ourselves on the result, not the day rate.

Specialist depth

Sector experts who understand your world from day one.

"We bring the technical rigour of a Big-4 practice with the agility, candour and partner attention of a specialist firm — and we stay focused on the outcome as the work evolves."

Matt Brandon
Partner, NSM Consulting Services
  • Big-4 pedigree across audit, risk & controls
  • Regulated FS, NHS & public-sector experience
  • Integrated teams: audit, finance, risk & technology

Let's talk about the risk keeping you up at night.

Whether it's a looming attestation, a stalled programme or a control environment that needs rethinking — a short conversation is the fastest way to know if we can help.

Get in touch

Speak to our team

Tell us a little about your challenge and we'll come back to you promptly — in confidence, and with a senior practitioner from the outset.

Office
1 St Katharine's Way,
London E1W 1UN

Start a conversation

No forms, no gatekeepers. Reach a senior practitioner directly — whichever way suits you.

In strict confidence · we typically respond within one business day.