4.0 Risk
Risk management and compliance at HQ and investor standard
Internal audit, controls, governance and information security, the control environment that turns your company into a trustworthy asset for HQ, the board and investors.
Languages: Portuguese and English · Standards: SOX · CPC/IFRS · Anti-Corruption Law · Last updated: July 2026
Corporate risk management is the set of practices that identifies, assesses and treats risks that threaten a company’s objectives, from fraud and accounting error to cyber incidents. At PFM, the service includes internal audit, internal-control design, corporate governance, SOX and Anti-Corruption Law compliance, CPC/IFRS assessment, and information security.
Scope
What's included in PFM's risk management?
The service covers three integrated fronts: audit and controls, internal audit, internal controls, consolidation and CPC/IFRS, governance and compliance, corporate governance, Anti-Corruption Law and SOX, and technology and security, with IT assessment, penetration testing, incident response and business continuity.
4.1
Audit and controls
- Internal audit
- Internal-control design and assessment
- Financial-accounting consolidation
- CPC and IFRS implementation assessment
- Strategic budget planning
- Cost-system review and development
4.2
Governance and compliance
- Corporate governance and compliance
- Anti-Corruption Law
- Sarbanes-Oxley Act (SOX)
- Preparation for HQ and investor requirements
4.3
Technology and security
- IT environment assessment
- Review of internal IT controls
- Information security and penetration testing
- IT due diligence
- Incident handling and response
- Security policy and business continuity
Who it's for
Who is PFM's risk management for?
The service serves subsidiaries of foreign groups, who need to answer to SOX, global anti-corruption policies and HQ audits, and mid-sized Brazilian companies going through professionalization: investor readiness, family-business governance, and protection against cyber incidents.
Subsidiaries of foreign groups
HQ is listed, audited and held accountable, and expects the same control environment from the Brazilian operation.
- SOX compliance in the local operation
- Global anti-corruption policies applied to Brazil
- CPC/IFRS reporting and consolidation
- Evidence ready for HQ's audit
Brazilian companies professionalizing
Growth, succession or investor entry, moments when informal controls stop being acceptable.
- Internal controls that survive key people
- Governance for family businesses
- Preparation for investor due diligence
- Defense against cyber incidents
Comparison
What's the difference between informal controls and a structured environment?
Informal controls depend on people and their memory: they work until the day they fail, and no one notices in time. A structured control environment documents processes, segregates duties, tests periodically and produces evidence, reducing fraud and error and sustaining the trust of HQ, the board and investors.
| Criteria | Informal controls | Structured environment by PFM |
|---|---|---|
| Fraud and error | Detected late, through the loss | Prevented by duty segregation and testing |
| HQ requirements | Improvised responses to each audit | Continuous evidence at SOX standard |
| Investor decisions | Due diligence finds surprises | Organized data room, known risks |
| Cyber incidents | Improvised response, wider damage | Tested response and continuity plan |
| Dependence on people | Knowledge in a few people's heads | Documented, auditable processes |
Method
How does PFM's risk and controls setup work?
The work follows four steps: diagnosis of the current control environment, a risk matrix prioritized by impact and likelihood, design and implementation of controls and policies, and a testing and monitoring cycle, turning compliance into an auditable routine, not a report on a shelf.
01
Environment diagnosis
Assessment of existing controls, processes, systems and policies, including the IT and information-security environment.
02
Risk matrix
Risks mapped and prioritized by impact and likelihood, with risk appetite validated with management and HQ.
03
Design and implementation
Controls, policies and duty segregation designed to measure, at the rigor required, without over-bureaucratizing the operation.
04
Testing and monitoring
Periodic testing cycles, compliance indicators, and evidence organized for internal and external audits.
Frequently asked questions
Common questions about risk management and compliance
Corporate risk management is the structured process of identifying, assessing and treating events that could compromise a company’s objectives, from fraud and accounting error to IT failures and cyber incidents. It involves internal controls, internal audit, governance policies and response plans, tested and monitored continuously.
It does, at the right scale. In the middle market, internal audit doesn’t require its own department: it can be performed by an outside partner, with scope focused on the highest-risk processes. It’s often the first thing HQs and investors check.
The Sarbanes-Oxley Act (SOX) is the US legislation requiring internal controls over financial reporting for companies listed in the US. Brazilian subsidiaries of listed groups need to maintain and evidence these controls locally, and PFM structures and tests that environment to the standard HQ’s audit expects.
IT environment assessment, review of internal technology controls, penetration testing, IT due diligence, an incident handling and response plan, and a security and business-continuity policy, an organized defense against one of the fastest-growing risks for companies of any size.
Yes. Brazil’s Anti-Corruption Law holds the company objectively liable for its representatives’ acts, regardless of size. For subsidiaries, that’s compounded by the group’s global policy requirements. A program proportional to risk protects the company and its officers.
It depends on the starting point and scope, but designing and implementing priority controls typically happens in cycles of months, not years, starting with the highest-risk processes. The initial diagnosis sets a realistic timeline for your operation.
Related services
Natural complements to this service
The control environment your HQ and investors expect to find
Schedule a diagnostic conversation. In one meeting, we assess your control environment and prioritize the risks that matter.