NSM Consulting is a London-based advisory firm delivering internal audit, enterprise risk, compliance and assurance for regulated Financial Services, the NHS and the wider Public Sector.
Frameworks & standards we work to
Our GRCC group brings together specialists across internal audit, finance, risk, compliance and technology — deployed as integrated teams that understand both regulation and operational reality.
Outsourced, co-sourced and specialist internal audit across Financial Services, NHS and the Public Sector — risk-based plans through to board-ready reporting.
End-to-end ERM implementation — risk taxonomy, appetite, RCSA and reporting embedded into how the business actually runs and governs itself.
Regulatory compliance for FCA-regulated firms — ICARA, financial crime and AML frameworks, assurance testing and remediation.
Independent controls opinions for service organisations: AAF 01/20, ISAE 3000, ISAE 3402, SOC 1 and SOC 2 — first-year readiness through to signed report.
Design, rationalisation and transformation of control frameworks — cutting duplication, closing gaps and mapping controls to every relevant obligation.
SOX 404 scoping, control design, testing and management attestation — building sustainable, PCAOB-aligned programmes for newly-listed and mature filers.
Transformation under high-stakes conditions across the public healthcare system — programme turnaround, care integration and delivery of the NHS Long Term Plan.
Design, optimisation and assurance of trading and portfolio management systems, plus trade surveillance and monitoring across all major trading platforms.
Cyber security audit, attestation and controls-framework development, including full ISO 27001 controls design, implementation and certification support.
Controls redesign, finance transformation, financial-statement evaluation and chart-of-accounts mapping across integrations, carve-outs and separations.
Contingent, permanent and staff-augmentation hiring across GRC and healthcare — backed by deep candidate and industry knowledge, at competitive rates.
We pair sector specialists with GRC practitioners, so our teams speak the language of your regulator, your board and your operations from day one.
FCA/PRA-regulated firms turn to us for internal audit, ICARA, financial crime, service-auditor opinions, SOX and trade surveillance — from challenger banks to global capital-markets desks.
From NHS providers and integrated care systems to local authorities, central government and private healthcare — programme turnaround, transformation and assurance under pressure.
Independent controls assurance, risk frameworks and finance transformation for public bodies accountable to citizens, auditors and Parliament.
Anonymised to protect client confidentiality — but the challenges, methods and measurable outcomes are real.
Three engagements, told the way we scope them — situation, task, action, and the results that mattered to the board.
A fast-scaling payments group needed a credible control environment for its first attestation.
Following a public listing, a high-growth payments business faced its first SOX 404 cycle with a fragmented control environment, undocumented processes and an external auditor already asking hard questions.
Stand up an audit-ready control framework across the financial-reporting, ITGC and treasury processes — and give management the evidence to attest with confidence.
We ran end-to-end process walkthroughs, built a risk-and-control matrix mapped to financial-statement assertions, rationalised duplicate controls, remediated design gaps and led a full dry-run test cycle with the external auditor engaged throughout.
The firm passed its first attestation with no material weaknesses, a leaner control set and a testing programme its own team could sustain.
A critical clinical-systems programme had slipped its timeline and lost board confidence.
An NHS provider's flagship digital programme was months behind, over budget and facing regulatory scrutiny, with fractured governance between clinical, operational and technology stakeholders.
Diagnose why the programme had stalled, rebuild delivery governance and secure senior leadership buy-in for a realistic, outcomes-focused reset.
We ran a rapid delivery-confidence review, re-baselined scope and benefits, installed a single accountable governance forum, and worked shoulder-to-shoulder with clinical leaders to sequence delivery around patient outcomes rather than milestones on paper.
The programme was back on plan within two quarters, with a clear benefits case, renewed board confidence and recurring savings reinvested into frontline care.
An alerting engine drowning in false positives was masking the alerts that mattered.
A multi-strategy fund's trade-surveillance programme spanned three platforms and was generating so many false positives that genuine market-abuse risk was being lost in the noise — a growing concern for compliance and the regulator alike.
Assure the design and operating effectiveness of surveillance and portfolio-management systems, and recalibrate detection to focus analyst effort where risk actually sat.
We reviewed scenario coverage against the firm's traded products, tuned thresholds using historical data, closed data-completeness gaps across venues, and rebuilt the governance around model changes and alert disposition.
False positives fell sharply while true-risk coverage improved, giving compliance a defensible, well-governed surveillance framework and analysts time back for real investigations.
Every engagement follows a disciplined arc — but we adapt as the work evolves and stay focused on the outcome, not the process.
We start with your risk, regulatory obligations and commercial reality — engaging the board, management and the second and third lines.
Structured diagnosis of your controls, data and processes against the relevant standard — gaps quantified and prioritised by risk.
Design and remediation delivered by partner-led teams, working alongside your people so capability stays in-house.
Independent testing, opinion or attestation — with reporting your audit committee and regulator can rely on.
NSM Consulting Services Ltd is a premier London-based consulting group specialising in Internal Audit and Controls, Governance, Risk and Compliance, Healthcare Consulting and specialist recruitment.
Our dedicated GRCC group is made up of experts from across the firm, bringing together sector specialisms and deep experience in internal audit, finance, risk and technology — the range of a large firm, delivered with the focus and accountability of a specialist one.
Conflict-free opinions your regulator and board can trust.
Senior practitioners on the ground, not just on the pitch.
We measure ourselves on the result, not the day rate.
Sector experts who understand your world from day one.
"We bring the technical rigour of a Big-4 practice with the agility, candour and partner attention of a specialist firm — and we stay focused on the outcome as the work evolves."
Whether it's a looming attestation, a stalled programme or a control environment that needs rethinking — a short conversation is the fastest way to know if we can help.
Tell us a little about your challenge and we'll come back to you promptly — in confidence, and with a senior practitioner from the outset.
No forms, no gatekeepers. Reach a senior practitioner directly — whichever way suits you.