Home / Services / Risk management and compliance at HQ and investor standard

4.0 Risk

Risk management and compliance at HQ and investor standard

Internal audit, controls, governance and information security, the control environment that turns your company into a trustworthy asset for HQ, the board and investors.

Languages: Portuguese and English · Standards: SOX · CPC/IFRS · Anti-Corruption Law · Last updated: July 2026

Corporate risk management is the set of practices that identifies, assesses and treats risks that threaten a company’s objectives, from fraud and accounting error to cyber incidents. At PFM, the service includes internal audit, internal-control design, corporate governance, SOX and Anti-Corruption Law compliance, CPC/IFRS assessment, and information security.

Scope

What's included in PFM's risk management?

The service covers three integrated fronts: audit and controls, internal audit, internal controls, consolidation and CPC/IFRS, governance and compliance, corporate governance, Anti-Corruption Law and SOX, and technology and security, with IT assessment, penetration testing, incident response and business continuity.

4.1

Audit and controls

4.2

Governance and compliance

4.3

Technology and security

Who it's for

Who is PFM's risk management for?

The service serves subsidiaries of foreign groups, who need to answer to SOX, global anti-corruption policies and HQ audits, and mid-sized Brazilian companies going through professionalization: investor readiness, family-business governance, and protection against cyber incidents.

Subsidiaries of foreign groups

HQ is listed, audited and held accountable, and expects the same control environment from the Brazilian operation.

Brazilian companies professionalizing

Growth, succession or investor entry, moments when informal controls stop being acceptable.

Comparison

What's the difference between informal controls and a structured environment?

Informal controls depend on people and their memory: they work until the day they fail, and no one notices in time. A structured control environment documents processes, segregates duties, tests periodically and produces evidence, reducing fraud and error and sustaining the trust of HQ, the board and investors.

Comparison of control environments, PFM Associados, 2026
CriteriaInformal controlsStructured environment by PFM
Fraud and errorDetected late, through the lossPrevented by duty segregation and testing
HQ requirementsImprovised responses to each auditContinuous evidence at SOX standard
Investor decisionsDue diligence finds surprisesOrganized data room, known risks
Cyber incidentsImprovised response, wider damageTested response and continuity plan
Dependence on peopleKnowledge in a few people's headsDocumented, auditable processes
Method

How does PFM's risk and controls setup work?

The work follows four steps: diagnosis of the current control environment, a risk matrix prioritized by impact and likelihood, design and implementation of controls and policies, and a testing and monitoring cycle, turning compliance into an auditable routine, not a report on a shelf.

01

Environment diagnosis

Assessment of existing controls, processes, systems and policies, including the IT and information-security environment.

02

Risk matrix

Risks mapped and prioritized by impact and likelihood, with risk appetite validated with management and HQ.

03

Design and implementation

Controls, policies and duty segregation designed to measure, at the rigor required, without over-bureaucratizing the operation.

04

Testing and monitoring

Periodic testing cycles, compliance indicators, and evidence organized for internal and external audits.

Frequently asked questions

Common questions about risk management and compliance

Corporate risk management is the structured process of identifying, assessing and treating events that could compromise a company’s objectives, from fraud and accounting error to IT failures and cyber incidents. It involves internal controls, internal audit, governance policies and response plans, tested and monitored continuously.

It does, at the right scale. In the middle market, internal audit doesn’t require its own department: it can be performed by an outside partner, with scope focused on the highest-risk processes. It’s often the first thing HQs and investors check.

The Sarbanes-Oxley Act (SOX) is the US legislation requiring internal controls over financial reporting for companies listed in the US. Brazilian subsidiaries of listed groups need to maintain and evidence these controls locally, and PFM structures and tests that environment to the standard HQ’s audit expects.

IT environment assessment, review of internal technology controls, penetration testing, IT due diligence, an incident handling and response plan, and a security and business-continuity policy, an organized defense against one of the fastest-growing risks for companies of any size.

Yes. Brazil’s Anti-Corruption Law holds the company objectively liable for its representatives’ acts, regardless of size. For subsidiaries, that’s compounded by the group’s global policy requirements. A program proportional to risk protects the company and its officers.

It depends on the starting point and scope, but designing and implementing priority controls typically happens in cycles of months, not years, starting with the highest-risk processes. The initial diagnosis sets a realistic timeline for your operation.

Related services

Natural complements to this service

2.0

Tax Advisory

Tax compliance integrated into the control environment.

6.0

Corporate Finance

Governance and controls that sustain valuation in transactions.

7.0

Technology & Management

Systems and processes designed with control from the start.

The control environment your HQ and investors expect to find

Schedule a diagnostic conversation. In one meeting, we assess your control environment and prioritize the risks that matter.