Internal audit · Forensic audit · Business intelligence

Audit is not the cost of control.
It is an investment in what you cannot yet see.

Processes show how the organisation works. Operations show how much it does. Audit shows what is actually happening — and what the things nobody raises at board level are costing you.

Book a free consultation See the POP methodology →

20+years in internal control and audit
AIartificial intelligence in everyday audit work
EN / PLaudits and reports delivered in both languages
Proprietary methodology

POP — three questions every audit must answer

Most audits answer one question: is this compliant with the procedure? That is the question which changes least. POP organises the audit around the three questions that actually translate into board decisions.

P

Potential

What could the organisation achieve if what holds it back were removed?

An audit does not end with a list of shortcomings. We show where the unused capacity sits — processes that can be shortened, controls that can be automated, competencies present in the organisation but not where they are needed.

O

One-off and recurring savings

What is the current state costing — and how much of it can be recovered?

Every finding is quantified. Overpaid invoices, duplicated contracts, losses from fraud, the cost of controls that catch nothing. The report shows an amount, not just a risk — which makes acting on it a business decision.

P

Perspective

What does audit see that processes and operations cannot?

A process owner sees their own stretch. Operations see today. Audit is the only function that looks across the organisation and back in time at once — which is why it catches patterns invisible from any single position.

The deliverable: a report ready for the audit committee or the board — three POP ratings, a financial valuation of findings, a priority map and an implementation schedule. No wall of text nobody will read.

Scope of services

What we do

Pillar 01

Internal audit and outsourcing of the function

Running the internal audit function in full, or supporting an existing team. Risk-based annual plan, audit engagements, reporting to the board and audit committee, follow-up on recommendations.

See details

Pillar 02

Forensic audit and fraud prevention

Investigating specific events: fraud, conflict of interest, manipulation in procurement, data leaks. Building an anti-fraud system, a whistleblowing channel, red-flag analysis on transaction data.

See details

Pillar 03

Audit training — including the use of AI

Workshops for audit and internal control teams: the auditor’s craft, data analytics, fraud detection, and the practical use of artificial intelligence in audit work — from sampling to drafting findings.

See details

Pillar 04

Business intelligence, counterparty checks and OSINT

Verifying a counterparty before signing and during the relationship: ownership structure, ultimate beneficial owner, personal connections, financial standing, litigation history, sanctions. Open-source analysis with a documented source behind every finding.

See details

How we work

The audit, step by step

A transparent process from the first conversation to confirming that the recommendations actually worked. A typical engagement runs four to eight weeks.

  1. Initial conversation and context

    We establish what concerns you and where that concern came from — an employee’s signal, the outcome of an external inspection, a discrepancy in the numbers, or simply an area nobody has looked at for years. The first conversation is free and without obligation.

  2. Risk analysis and scoping

    We map the processes in the area under review, identify the critical points and agree the scope. You receive an audit programme with specific research questions, a schedule and a list of required access — before any work begins.

  3. Data collection and analysis

    We pull transaction data, documentation and registers. Analysis runs on the full population rather than a random sample — continuous testing, duplicate detection, value-distribution and timing-pattern analysis. Where it shortens the work we use AI tools, but every finding is verified by an auditor.

  4. Interviews and fieldwork

    We talk to process owners and to the people who actually perform the tasks. We compare what the documentation says with how the process really runs, and observe the work on site where it matters.

  5. Preliminary findings and factual verification

    Before the report is written, findings go back for confirmation of the facts. Nobody is ambushed at a board meeting — the audited party has the right to correct the record before it reaches the document.

  6. POP report and presentation

    The final report follows the Potential — Savings — Perspective structure, with findings quantified, recommendations ranked by effect against effort, and proposed deadlines. We present the results to the board or the audit committee.

  7. Follow-up

    After an agreed period we check whether the recommendations were implemented and whether they produced the expected effect. Without this step, an audit ends up as a binder on a shelf.

The Lykta group

We also operate under separate brands

Part of our work runs under its own name, because the nature of the services and the legal requirements differ. All of it is delivered by the same team.

lykta.pl

Security officer for classified information

Implementation and supervision of a classified information protection system, facility security clearance, ABW/SKW accreditation of IT systems, registry office, vetting procedures and training.

Go to lykta.pl →

lyktawywiad.pl

Business intelligence and counterparty screening

In-depth verification of business partners, analysis of capital and personal connections, payment reliability assessment, counterparty risk monitoring and pre-transaction due diligence reports.

lyktawywiad.pl — coming soon

lyktadetektyw.pl

Detective services

Licensed detective work under the Polish Detective Services Act — enquiries in commercial and employment matters, asset tracing, and securing evidence for use in proceedings.

lyktadetektyw.pl — coming soon

Who we work with

Our clients

  • Boards and owners — who want to know what is really happening in the company before an external inspection tells them
  • Audit committees and supervisory boards — needing an independent assessment without committing their own resources
  • Public sector entities — required by law to maintain an internal audit function
  • Companies without an audit department — for whom a full-time auditor is not economically justified
  • Existing audit teams — needing support on an engagement that calls for specialist knowledge or extra capacity

Not sure whether you need an audit?

If any of these sound familiar, it is worth a conversation:

  • costs in some area keep rising and nobody can explain why
  • one supplier has been winning every tender for years
  • you received a signal from an employee and do not know how to verify it
  • an external inspection is coming and you want to know what it will find

Let’s talk

Let’s start with a conversation

Describe the situation briefly — we will tell you whether an audit is the right instrument here, what scope makes sense and how long it will take. The first consultation is free and without obligation.

Get in touch
Zgoda na pliki cookie z Real Cookie Banner