https://www.kleeberg.de/en/team/christina-inioutis/
https://www.kleeberg.de/en/team/patrick-reinhardt/
https://www.kleeberg.de/en/team/antonie-drexler/
https://www.kleeberg.de/en/team/laura-hertwig/
https://www.kleeberg.de/en/team/monika-buhring/
https://www.kleeberg.de/en/team/dmitriy-levitskiy/
https://www.kleeberg.de/en/team/christine-schrodl/
https://www.kleeberg.de/team/maria-andrea-wekerle/
https://www.kleeberg.de/en/team/laura-zwirner/
https://www.kleeberg.de/en/team/andreas-kuhn-2/
https://www.kleeberg.de/en/team/julian-philipp/
https://www.kleeberg.de/en/team/carina-boegner/
https://www.kleeberg.de/en/team/ann-katrin-schad/
https://www.kleeberg.de/en/team/katharina-frank/
https://www.kleeberg.de/en/team/carola-springfeld/
https://www.kleeberg.de/en/team/julian-liebmann/
https://www.kleeberg.de/en/team/nils-klaube/
https://www.kleeberg.de/en/team/alexander-weyer/
https://www.kleeberg.de/en/team/anna-guenther/
https://www.kleeberg.de/en/team/sebastian-schoffel/
https://www.kleeberg.de/en/team/alexander-gressierer/
https://www.kleeberg.de/en/team/lisa-spirkl/
https://www.kleeberg.de/en/team/arzum-esterhammer/
https://www.kleeberg.de/en/team/karolin-bihler/
https://www.kleeberg.de/en/team/tim-zumbach/
https://www.kleeberg.de/en/team/amelie-merath/
https://www.kleeberg.de/en/team/aylin-oezcan/
https://www.kleeberg.de/en/team/annika-ruettgers/
https://www.kleeberg.de/en/team/volker-blau/
https://www.kleeberg.de/en/team/kathrin-hamann/
https://www.kleeberg.de/en/team/angela-popp/
https://www.kleeberg.de/en/team/sebastian-sieber/
https://www.kleeberg.de/en/team/stefan-reutin/
https://www.kleeberg.de/en/team/jacqueline-goldberg/
https://www.kleeberg.de/en/team/stefan-latteyer/
https://www.kleeberg.de/en/team/lorenz-neu/
https://www.kleeberg.de/en/team/frank-straser/
https://www.kleeberg.de/en/team/jasmin-morz/
https://www.kleeberg.de/en/team/karl-nagengast/
https://www.kleeberg.de/en/team/katharina-monius/
https://www.kleeberg.de/en/team/joana-maria-ordinas-ordinas/
https://www.kleeberg.de/en/team/sanja-mitrovic/
https://www.kleeberg.de/en/team/karl-petersen/
https://www.kleeberg.de/en/team/katharina-julia-missio/
https://www.kleeberg.de/en/team/hermann-plankensteiner/
https://www.kleeberg.de/en/team/ronald-mayer/
https://www.kleeberg.de/en/team/stefan-prechtl/
https://www.kleeberg.de/en/team/lars-ludemann/
https://www.kleeberg.de/en/team/sabine-lentz/
https://www.kleeberg.de/en/team/katharina-lauschke/
https://www.kleeberg.de/en/team/daniel-lauschke/
https://www.kleeberg.de/en/team/philipp-rinke/
https://www.kleeberg.de/en/team/kai-peter-kunkele/
https://www.kleeberg.de/en/team/alexander-kruger/
https://www.kleeberg.de/en/team/hans-martin-sandleben/
https://www.kleeberg.de/en/team/beate-konig/
https://www.kleeberg.de/en/team/andreas-knatz/
https://www.kleeberg.de/en/team/christian-klose/
https://www.kleeberg.de/en/team/reinhard-schmid/
https://www.kleeberg.de/en/team/jurgen-schmidt/
https://www.kleeberg.de/en/team/thea-schopf/
https://www.kleeberg.de/en/team/steffen-sieber/
https://www.kleeberg.de/en/team/sandra-inioutis/
https://www.kleeberg.de/en/team/martina-strobel/
https://www.kleeberg.de/en/team/michael-h-thiel/
https://www.kleeberg.de/en/team/michael-vodermeier/
https://www.kleeberg.de/en/team/robert-hortnagl/
https://www.kleeberg.de/en/team/monika-walke/
https://www.kleeberg.de/en/team/erwin-herzing/
https://www.kleeberg.de/en/team/martina-hermes/
https://www.kleeberg.de/en/team/stephanie-gruber-jorg/
https://www.kleeberg.de/en/team/thomas-gottler/
https://www.kleeberg.de/en/team/kristin-fichter/
https://www.kleeberg.de/en/team/juliana-engesser/
https://www.kleeberg.de/en/team/tobias-ehrich/
https://www.kleeberg.de/en/team/gerhard-de-la-paix/
https://www.kleeberg.de/en/team/markus-wittmann/
https://www.kleeberg.de/en/team/julia-busch/
https://www.kleeberg.de/en/team/corinna-boecker/
https://www.kleeberg.de/en/team/christoph-bode/
https://www.kleeberg.de/en/team/christian-binder/
https://www.kleeberg.de/en/team/frank-behrenz/
https://www.kleeberg.de/en/team/hannes-zieglmaier/
https://www.kleeberg.de/en/team/christian-zwirner/
https://www.kleeberg.de/en/team/dirk-baum/

If you would like to arrange an appointment or receive further information about our firm, or if you have any questions, comments or suggestions for improvement, please do not hesitate to contact us. We look forward to hearing from you!

Dr. Kleeberg & Partner Gmbh
Audit & Accountancy Company
Tax Advisory Company

Augustenstraße 10
80333 Munich
Germany

Phone +49(0)89-55983-0
Fax +49(0)89-55983-280

E-Mail 

Your way to our office:
Arrival (Google Maps)

If you arrive by car, reserved parking spaces are available in our underground car park.

Technology

We guide your organization through holistic digital transformation, securing cloud environments, data, and end-to-end processes while establishing real-time transparency for iGRC (governance, risk management and compliance). Through pragmatic IT audits, cybersecurity analytics, data & AI assurance, and strategic CIO advisory and transformation consulting, we ensure your projects, core business processes, and M&A transactions are future-proof, executed reliably, and regulatorily compliant.

Advisory and audit approach

We act as both architects and auditors within an integrated one-stop-shop model. Leveraging deep industry expertise and practical experience, we secure your IT systems, business processes, and strategic transformation initiatives. Whether IT audit, cyber resilience, data & AI assurance, or project assurance – we identify risks early, strengthen governance, and ensure regulatory compliant outcomes. We also support strategic efforts, from CIO advisory and Target Operating Model (TOM) design to innovation management, M&A transactions, or IPO readiness. Our objective: maximum transparency, reliability, and efficiency, ensuring digital innovations and complex regulatory demands are successfully realized.

Quality assurance

We guarantee engagement top performance through cross-functional collaboration with our Audit, Tax, Legal, and Advisory units, ensuring strategic risks and opportunities are captured holistically. Our extensive expertise and deep industry know-how enable the pragmatic translation of your business objectives into reliable technology and AI solutions. Transparent communication and agile methodologies are key capabilities in this process. We leverage cloud technologies and GenAI tools for a future-proof design and efficient drive of your digital transformation.

Range of services

CIO Advisory

The IT strategy is pivotal in driving the core corporate objectives – especially in a constantly changing market.

  • We see ourselves as your strategic partner, offering a grounded entry point for developing a future-proof IT strategy. We translate strategic questions into a pragmatic roadmap and concrete digitalization initiatives. We help align business objectives and technology investments, establishing a clear vision for your future enterprise architecture.
  • Our service is designed to secure long-term competitiveness and increase the adaptability (resilience) of your organization. We proactively integrate regulatory risks (e.g., EU NIS2 Directive) and create the foundation for insight-driven decisions using data and analytics.
  • We support the implementation of your IT strategy – from defining major transformation paths (e.g., cloud migration, digitalization of core processes) to operational scaling. We combine strategic advice with technical expertise, industry knowledge, and operational process proficiency to ensure your strategy is implemented successfully, measurably and sustainably.

Target Operating Model (TOM) Design

An optimized Target Operating Model (TOM) is the foundation for aligning IT organization and processes to the corporate strategy in an agile, efficient, and scalable manner.

  • We support the conception and implementation of a future-proof operating and governance model that increases agility and accelerates decision-making. This includes organizational realignment, defining design principles, and measurable goals for the entire organization.
  • The development of the TOM considers the alignment of the entire value chain in product management along the customer journey and the definition of necessary technological and operational rewiring. We model end-to-end processes using a DevOps approach, harmonize handovers, identify automation and AI potential, and create the foundation for scalable deployment of organizational capabilities.
  • We define the organizational design, talent strategy, and governance model to prepare your company for continuous reinvention. This includes role/responsibility definitions, talent and change management strategies, sourcing decisions (make-or-buy), and performance management via KPIs and reporting. This ensures that the organization is not only transformed but that changes are implemented operationally and long-term scalable.

Disruption is the new normal – Innovation is the answer. We help you strategically deploy emerging technologies such as artificial intelligence (AI) and automation solutions to achieve new performance levels and structurally build out your innovation capability.

  • We guide you in identifying, prioritizing, and managing digitalization and automation initiatives and support the development of new products, services, and business models – from initial ideation to validated prototype and scalable operating model.
  • We assess suitability for public funding programs (e.g., KfW Digitalization Funding, stages 2 and 3) and provide holistic advice on investing in emerging technologies and executing complex, profound digitalization programs.
  • The objective is the transformation of critical core business functions and supporting operating processes, promoting operational excellence through insight-driven decisions. This involves establishing structured innovation processes, agile methodologies, and a robust governance framework to make innovations scalable, steerable, and sustainably wired.

The connection of data, artificial intelligence (AI), and engineering enables the transformation of business-critical processes and creates new levers for growth, efficiency, and competitive advantage.

  • We modernize your data and infrastructure landscape by establishing a robust data foundation, securing data quality, and implementing scalable AI foundries that provide the necessary infrastructure and tools for reliable, performant, and secure AI applications.
  • Our services include solution architecture, data engineering, DevOps, and cloud infrastructure, designed to accelerate, operationalize, and scale AI and Advanced Analytics initiatives company-wide – from initial pilots to productive deployment in core processes.
  • We consistently integrate AI governance, risk management, and compliance mechanisms (e.g., the EU AI Act) to ensure transparency, traceability, and trust in AI systems and provide regulatory assurance for their deployment.

The success of major IT implementations requires professional steering, planning, and monitoring throughout the entire project lifecycle – from ideation to go-live.

  • We provide comprehensive functional, methodological, and technological expertise to holistically manage your IT projects, programs, and portfolios (PPM). This encompasses both classic and agile project methodologies, helping you effectively align strategic objectives, resources, and value contribution.
  • We support all phases – from requirements analysis through design and development to implementation – ensuring projects are executed purposefully, risk-aware, and in line with time and budget requirements. We integrate modern instruments such as PMO structures (Project Management Office), agile frameworks (e.g., SAFe), and scalable PPM tooling.
  • Effective PPM and governance structures are essential for transparent and steerable project execution. They also form the basis for project assurance audits (e.g., IDW PS 850) and enable effective risk management, quality assurance, and reporting.

Successful transformations are a team effort and only succeed when people are actively engaged, enabled, and continuously supported – especially during profound changes in work structures, processes, and technologies.

  • We help you establish a culture of change and ensure the acceptance of digital solutions and new processes (e.g., within the scope of ERP implementations or new Target Operating Models).
  • Our focus is on building future skills and business capabilities to strategically develop employees and rewire the organization to ensure an optimal interplay of data, technology, and people.
  • The goal is to increase productivity, engagement, and organizational resilience by harmonizing technology and human behavior, and ensuring changes are sustainably embedded in the organization.

(Pre-Deal) IT Due Diligence (IT DD)

Technology is a central value driver, risk factor, and integration lever in M&A transactions, as IT stability, security, and scalability decisively determine the purchase price, future performance, and success of the transaction.

  • We conduct comprehensive IT Due Diligence (IT DD) to identify technological risks, cybersecurity vulnerabilities, data and applications quality, IT costs, synergy potential, and integration impediments early on. This includes evaluating IT infrastructure, application landscape, data architecture, cloud and DevOps models, as well as the technological operating model of the target company.
  • We analyze carve-out requirements, investment needs, compliance, and data protection risks, as well as PMI implications, to secure the strategic and financial rationale of the deal and optimally prepare the subsequent Post-Merger Integration.
  • We create transparency for informed investment decisions, enhance transaction security, and ensure all relevant technological, legal, tax, and audit-related aspects are considered – to minimize risks and maximize the transaction’s value contribution.

Post-Merger Integration (PMI)

Technology is a crucial lever for success after Mergers & Acquisitions (M&A), as processes and underlying IT infrastructure must be integrated quickly, securely, and with value enhancement.

  • We guide the entire Post-Merger Integration (PMI) process to efficiently transition the acquired technology and process landscapes into the existing organization.
  • This includes analyzing and integrating IT infrastructure, harmonizing data, and realigning the organization and processes to fully realize the intended synergies, as well as the strategic and financial business benefits from the transaction.
  • We ensure transaction security and guarantee that all technical, legal, tax, and audit-related aspects of the IT integration are considered, to minimize risks and ensure long-term business success.

IPO (Initial Public Offering) Readiness

A successful Initial Public Offering (IPO) requires a robust, transparent, and regulatorily compliant technology and data landscape, as IT systems, reporting processes, and governance structures are subject to stricter requirements in the capital markets environment.

  • We guide the entire IPO process to strategically align your IT, data, process structures, and governance with the operating model of a publicly listed company. This includes an IPO readiness assessment, the modernization of capital market-ready reporting, controlling, and compliance processes, the strengthening of IT governance, cybersecurity, and data quality, as well as ensuring compliance with financial reporting standards (IFRS) and additional regulatory requirements (e.g., ESG).
  • Furthermore, we support the establishment of an internal control system (ICS), the management of capital market-relevant KPIs, the implementation of required ERP and financial consolidation systems, and the coordination of all IPO stakeholders, including auditors, banks, legal advisors, analysts and rating agencies, financial investors (institutional and retail), and internal business functions.
  • We enhance IPO transparency, strengthen compliance, reduce regulatory and reporting risks, and ensure that all technological, organizational, regulatory, and audit-related requirements are met – enabling a seamless and successful transition to operating as a publicly listed company.

Dynamic market shifts, emerging technologies, and highly complex industry-specific regulatory mandates demand tailored, cross-functional solutions that go far beyond standardized consulting approaches.

  • Specialized Regulatory & Tech: To enhance the efficiency of your transformation initiatives, we provide agile, highly specialized advisory services for targeted technological challenges, industry verticals, and regulatory focus areas. This includes the strategic conception and technological implementation of new statutory mandates such as mandatory electronic invoicing (E-Invoicing according to EU standard EN 16931), the IT-side integration of sustainability and reporting obligations – such as the EU Corporate Sustainability Reporting Directive (CSRD including ESRS data points) and the Carbon Border Adjustment Mechanism (CBAM interfaces) – as well as the compliant digital design of processes in accordance with the Supply Chain Due Diligence Act (LkSG).
  • Sector Transformation: We provide strategic support in digitalizing sector-specific core processes. This applies particularly to highly regulated environments like Financial Services (e.g., FinTechs subject to MaRisk banking requirements), Healthcare & Life Sciences (e.g., quality assurance under Good Manufacturing Practice guidelines), the Automotive industry (e.g., information security via Trusted Information Security Assessment Exchange), Energy & Utilities (e.g., secure market communication via Applicability Statement 4 protocol and further Federal Network Agency BNetzA mandates), or the Public Sector (e.g., digital government under the Online Access Act OZG 2.0). We translate functional requirements into high-performance, modular application architectures, ensuring your systems are fully audit-ready.
  • Subsidy Management (CapEx & OpEx Optimization): We provide comprehensive end-to-end guidance through the identification, application, administration, and financial verification (pre-audit, audit) of strategic public funding and government grants to optimize your IT and investment budgets. Our focus lies on achieving the ideal balance between CapEx (e.g., capitalization of in-house software development) and OpEx (e.g., cloud and SaaS infrastructures). Our expertise spans EU structural funds (e.g., ERDF, NextGenerationEU), direct EU funding programmes (e.g., Digital Europe Programme, Horizon Europe), and national innovation and digitalization initiatives (e.g., KfW Digitalization Loans, BAFA Advisory Grants, Central Innovation Programme for SMEs – ZIM), extending to the tax-based Research Allowance under the FZulG (e.g., for the in-house development of proprietary models or novel architectures) as well as regional state-level subsidies (e.g., Digitalbonus Bavaria). As an independent audit body, we handle the compilation of financial project statements as well as the auditing and issuance of regulatory Audit Certificates (CFS – Certificate on the Financial Statements) in strict accordance with the European Commission’s guidelines (MGA – Model Grant Agreement) for Continuous Reporting, Periodic Reports, and Final Reports.

We conduct comprehensive assessments to optimize and audit GRC systems within multi-layered process and system architectures – such as ERP systems (e.g., SAP) or cloud platforms –, where high degrees of automation and complexity demand intensified scrutiny.

“1st Line” (formerly 1st Line of Defense within the Three Lines of Defense (3LoD) model of the IIA (The Institute of Internal Auditors)) – Governance for Operational Integrity (ICS): We assess the design and effectiveness of your process-integrated controls.
The initial focus is on operational excellence – our analyses are based on:

  • leading frameworks such as COSO (Enterprise Risk Management and Internal Controls-Integrated Framework, issued by the Committee of Sponsoring Organizations of the Treadway Commission), COBIT (covering IT Governance, Risk Management, and Compliance, issued by ISACA (Information Systems Audit and Control Association)), ITIL 5 (for value-oriented, holistic Product and IT Service Management (ITSM) as well as high-quality, experience-centric, and AI-powered IT Support), and TOGAF (for ensuring a coherent and efficient IT architecture, issued by The Open Group) as well as
  • further industry- or company-relevant international standards (e.g., ISO 22301 Security and Resilience – BCM (Business Continuity Management) Systems) or
  • regulatory requirements (e.g., PCI DSS (Payment Card Industry Data Security Standard) for entities processing credit card data, or GMP (Good Manufacturing Practices) for organizations in highly regulated sectors such as Pharma, HealthTech, Cosmetics, or Food).

Secondly, the IDW AS 982 (Auditing Standard issued by the Institute of Public Auditors in Germany – Principles for the Proper Audit of the Internal Control System for Internal and External Reporting) serves as the minimum benchmark.

“2nd Line” – Steering through a robust Risk Management System (RMS): We implement and review monitoring systems according to current standards, such as IDW AS 981 (Principles for the Proper Audit of Risk Management Systems), IDW AS 340 Rev. (The Audit of the Early Risk Detection System), and IDW S 16 (Design of Crisis Early Warning and Crisis Management Systems according to § 1 StaRUG (German Act on the Stabilization and Restructuring Framework for Businesses)), as well as ISO 31000 (Risk Management). In doing so, we integrate regulatory frameworks such as the KonTraG (Act on Control and Transparency in Business, which mandates boards to establish early risk detection systems) and administrative directives from supervisory authorities, e.g., the MaRisk (Minimum Requirements for Risk Management) of the BaFin (Federal Financial Supervisory Authority) for the financial sector, incl. modern FinTechs.

Legal certainty through a value-adding Compliance Management System (CMS): To address increasing regulatory complexity and the heightened burden of proof with resilient structures, we transform your compliance requirements into an audit-proof foundation. We support you in the design and audit of compliance systems, a. o. in accordance with IDW AS 980 Rev. (Principles for the Proper Audit of Compliance Management Systems), ISO 37301 (Compliance Management Systems), and ISO 37001 (Anti-bribery Management Systems). In doing so, we secure your license to operate in global marketplaces (e.g., EU, following the fulfillment of parallel requirements and deadlines from EU regulations and transposed national EU directives) and turn regulatory pressure into a testament of trust for customers, business partners (supply chains), and investors.

“3rd Line” – Validation through Internal Audit System (IAS) and Whistleblowing System (WBS): As an objective, external body, we audit the resilience of your governance and monitoring structures in accordance with IDW AS 983 Rev. (Principles for the Proper Audit of Internal Audit Systems). We evaluate the installed whistleblowing system according to the strict requirements of the HinSchG (German Whistleblower Protection Act, the national transposition of the EU Whistleblower Directive into German law) and utilize confidentially submitted reports specifically as a basis for independent investigations. This allows us to identify vulnerabilities in the 1st and 2nd lines at an early stage and establish corresponding measures within the PDCA Cycle (Plan-Do-Check-Act) as a Continuous Improvement Process (CIP).

Given rising cyber risks and new regulations, ensuring information security has become a critical survival factor for organizations.

  • We perform information security audits as well as comprehensive maturity and gap analyses to strengthen your organization’s cyber resilience.
  • Our consulting services include the implementation of standards such as ISO/IEC 27001 ff. for ISMS (Information Security Management System) requirements, the implementation of the EU NIS2 Directive (Network and Information Security Directive) and the German NIS2UmsuCG (NIS2 Implementation and Cybersecurity Strengthening Act), as well as the requirements of DORA (Digital Operational Resilience Act) for the financial sector – evolving from and replacing specific IT supervisory requirements for banking (BAIT), insurance (VAIT), and asset management (KAIT). This includes providing proof of compliance to the BSI (Federal Office for Information Security) according to IDW PH 9.860.2 n.F. – the audit guidance for auditing measures to be implemented by operators of Critical Infrastructures (KRITIS) pursuant to Section 8a of the BSI Act (BSIG) within the framework of the IT-SiG 2.0 (IT Security Act).
  • Beyond the preparatory NIS-2 Readiness Assessment to identify implementation gaps, we support you through the preparation of an Independent Auditor’s Opinion on NIS-2 compliance. This formal expert opinion, prepared in accordance with professional auditing standards, aligns with the rigorous requirements of regulatory authorities. It serves the executive management as an independent, point-in-time documentation of the fulfillment of their own due diligence obligations (providing an essential argumentative basis for personal liability minimization) regarding the establishment of legally required cybersecurity measures. Furthermore, it offers a standardized proof for submission to supervisory authorities, cyber insurance providers, or supply chain partners, supporting international interoperability and strengthening your position in negotiations.
  • Our approach provides practically proven recommendations for your cybersecurity strategy and risk management. Additional services: phishing tests (social engineering), security awareness trainings, Identity & Access Management (IAM), fraud prevention, technical pentests.

Data, analytics, and AI models, alongside resilient reporting, are critical to global competitiveness. They require the highest levels of transparency, reliability, and regulatory assurance to preserve long-term success and market trust.

  • Validation of AI Systems: We support you in the selection and prioritization of use cases as well as the proper Introduction of Generative Artificial Intelligence (GenAI), taking into account the Advisory Note IDW AdvN 6.003. In doing so, we address both strategic aspects (a. o. opportunity-risk profiles) and operational topics such as fine-tuning, Retrieval-Augmented Generation (RAG), and multi-agent systems. To provide independent assurance of reliability and compliance, we also conduct specialized Audit of AI Systems in accordance with IDW AS 861. This includes the validation of your AI applications into which AI algorithms/models are integrated, the data governance (training, validation, testing, and output data), the underlying IT infrastructure (e.g., scalable cloud solutions), and AI monitoring. The assessment is performed based on specific criteria such as model transparency, robust safeguards, and a comprehensive risk analysis (e.g., data privacy, model behavior, and security vulnerabilities), considering the risk classifications of the EU AI Act and further industry-specific requirements (e.g., BSI Test Criteria Catalogue for AI Systems in Finance). By ensuring the auditability of AI systems, we build lasting trust in your data-driven decisions.
  • Assurance of Business Model KPIs & ESG Data: We ensure the quality of your reporting processes by auditing mission-critical metrics and sustainability data. This is conducted based on the global ISSA 5000 standard (General Requirements for Sustainability Assurance Engagements) as well as in consideration of the EU CSRD (Corporate Sustainability Reporting Directive), which mandates who must report and that the information must be externally audited, and the specific technical ESRS (European Sustainability Reporting Standards), which define exactly what (content) and in what form (metrics, data points) must be reported under the CSRD. A key element is the design and audit of your ICS in accordance with IDW AS 982 (Principles for the Proper Audit of the Internal Control System for Internal and External Reporting) and IDW Practice Note 4/2023 (Design and Audit of the Internal Control System for the Preparation of a Sustainability Report). As the technology-based implementation of ESG reporting (IDW AdvN 6.002) – depending on the audit approach chosen by the respective ESG reporting auditor – may trigger additional downstream requirements, we support you in the selection of certified reporting tools pursuant to IDW AS 880 (Audit of Software Products). To minimize risk and ensure audit-readiness, we also provide early-stage Project-related Audits of the implementation process in accordance with IDW DAS 850 Rev..

Outsourcing IT operations up to moving complete IT to the cloud requires compliance with specific regulatory and contractual obligations.

The outsourcing of business-critical processes – ranging from the cloud (e.g., hyperscalers such as Google Cloud, Microsoft Azure, or AWS) and SaaS platforms whose product portfolios are continuously expanding to include new AI-driven solutions (e.g., ServiceNow, Salesforce, Workday), to innovative XTech (e.g., FinTech, RegTech, MarTech, InsurTech, PropTech) – offers immense opportunities, but requires strict adherence to regulatory obligations. As the ultimate responsibility for the internal control system (ICS) always remains with your organization, our Third-Party Provider (TPP) Assesments ensure that your compliance requirements are seamlessly met, even within highly dynamic outsourcing structures.

For Service Providers: An independent assurance report (e.g., SOC 2 or BSI C5) serves as a “master key.” Instead of responding to individual questionnaires or hosting on-site audits for every client, you can efficiently demonstrate your compliance-ready posture through a standardized report.

  • Focus on Financial Reporting (SOC 1 / ISAE 3402 / IDW PS 951): If your services could have an impact on your customers’ accounting or financial statements (e.g., payroll accounting, data center operations for ERP systems, asset management / custody), an audit of the service-related ICS (Internal Control System) regarding the reliability of finance-related processes is required. The audit report enables the customer’s auditor to rely on the controls at the service provider (User Auditor Reliance), without having to perform their own audit procedures. We conduct audits of your ICS and issue independent (Type 1 and 2) assurance reports such as SOC 1 (Report on Monthly Controls at a Service Organization Relevant to User Entities’ Internal Control over Financial Reporting (ICFR)) / ISAE 3402 (Assurance Reports on Controls at a Service Organization) / IDW AS 951 Rev. (The Audit of the Internal Control System at Service Organizations).
  • Focus on non-financial criteria (e.g., IT Security) (SOC 2 & 3 / ISAE 3000 / IDW PS 860): If the security of your systems is the primary focus of your services (e.g., for cloud providers or SaaS solutions), proof of compliance based on the TSC (Trust Services Criteria) is required. We perform audits of your ICS and issue independent (Type 1 and 2) assurance reports, such as SOC 2 (Report on Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy), SOC 3 (requires a SOC 2 Type 2) (Trust Services Report for Service Organizations), ISAE 3000 Rev. (Assurance Engagements Other than Audits or Reviews of Historical Financial Information), or IDW AS 860 (IT Audit outside of the Financial Statement Audit).
  • In accordance with IDW PS 860 (analogous to ISAE 3000), we differentiate between two types of engagements: while the Direct Engagement assesses the system directly and reduces your operational burden (ideal for initial audits), the Assertion-based Engagement focuses on your management’s own description of the ICS, representing a highly efficient and cost-effective alternative for organizations with a high level of documentation maturity.
    The scope of these IT audits ranges from security in the software development process and compliance with regulatory requirements – such as IDW PH 9.860.1 (Audit of the Principles, Procedures and Measures according to the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG)) and IDW PH 9.860.4 (The Audit of Compliance with the Principles for the Proper Keeping and Storage of Books, Records and Documents in Electronic Form and for Data Access (GoBD Compliance)) – to conformity assessments based on industry standards (e.g., PCI DSS or GMP), tax regulations (§ 14 UStG, §§ 146-147 AO), instructions from regulatory authorities (e.g., MaRisk), as well as recognized frameworks (such as COSO, COBIT, ITIL, and PRINCE2 or the PMBOK Guide) or ISO/DIN standards.
  • We also provide advisory support through Readiness Assessments to ensue your internal controls meet all requirements for a successful third-party certification.

For User Entities: We provide the necessary guidance and assurance during the selection of outsourcing partners. This enables consumers to demonstrate that they have fulfilled their due diligence in the selection, monitoring, and management of critical suppliers (e.g., in accordance with NIS 2, Art. 21).

In an increasingly digitalized accounting environment, proper bookkeeping no longer starts with the figures, but with the software in use: only when business software solutions comply with statutory requirements can the proper preparation of the annual financial statements be ensured.

  • We conduct Audits of Software Products in accordance with the IDW PS 880 Rev. to certify software manufacturers’ compliance with the German principles for proper bookkeeping (GoBD) as well as other statutory and regulatory requirements. The certification process includes validating the development environment, assessing software development and maintenance processes, and performing comprehensive tests of the design and operating effectiveness of the technical implementation. As a result, manufacturers receive a recognized certificate (and audit report) that serves as a key quality indicator and competitive advantage, while significantly reducing the audit effort required during annual financial statement audits for software users.

IT General Controls (ITGC)

The compliance of IT systems and their control environment is critical to the reliability of digital business processes and ensures the representational faithfulness of the resulting financial reporting.

  • Risk-Based Audit Approach: In accordance with ISA [DE] 315 (Identifying and Assessing the Risks of Material Misstatement), we first assess the complexity of your IT environment. Based on this, we derive targeted audit procedures to sustainably protect the integrity of your financial reporting against IT-specific risks at the financial statement level.
  • Audit Methodology: Our audit is aligned with ISA [DE] 330 (The Auditor’s Responses to Assessed Risks) and the updated requirements of ISA [DE] 315 (Revised 2019), which succeeds the former IDW AS 330 (Financial Statement Audit when using Information Technology). We perform a two-stage assessment: first, we test the Design and Implementation (D&I), followed by the Operating Effectiveness (OE) of your accounting-relevant IT systems. The objective is to validate compliance with German GAAP requirements for electronic record-keeping GoBD (Principles for the proper keeping and retention of books, records and documents in electronic form as well as for data access), ensuring completeness, accuracy, timeliness, order, traceability, and immutability.
    By validating IT General Controls (ITGCs) across the entire audit period, we establish the necessary foundation for testing (semi-)automated Application Controls (ACs) and IT-dependent Business Process Controls (BPCs). The ITGC validation covers four core domains: Computer Operations, Program Changes, Program Development, and Access to Programs/Data. This ensures that Information Processing Objectives (IPOs) – specifically Completeness, Accuracy, Validity, and Restricted Access (CAVR) – are met.
  • Scalability for SMEs (Small and Medium-sized Enterprises): Where applicable, we align our methodology with standards for less complex entities, such as IDW AS LCE 4 (Risk Identification and Assessment) and IDW AS LCE 5 (Responses to Relevant Risks). This scaled approach allows us to efficiently tailor the intensity of IT audit procedures to your company’s specific risk profile and complexity without compromising regulatory assurance.

Application Controls (ACs)

Application controls (ACs) are essential to ensure the correct processing of financial reporting-relevant transactions within specific enterprise applications.

  • We focus on auditing system-side controls, particularly in complex ERP Systems (enterprise resource planning) – such as SAP (S/4HANA, Business One), Microsoft Dynamics 365, Sage, DATEV, or NetSuite –  to attest to the regularity of processing and compliance with legal requirements.
  • These audits are a necessary component of the IT audits within the scope of the Annual Financial Statements (AFS) audit and form the basis for assessing the internal control system (ICS) in place.
  • We ensure that your IT-supported business processes function reliably and meet business requirements, for example, for GoBD-compliant (German principles for the proper management and storage of books, records, and documents in electronic form, as well as for data access) electronic invoicing (e-invoices) or when using tax CMS (compliance management systems).

Business Processes Controls (BPCs)

IT-supported Business Process Controls (BPCs) serve as the vital link between purely technical IT controls and your company’s operational workflows.

  • Integrated Audit Approach: We validate the operating effectiveness (OE) of controls within your core business processes (e.g., O2C/Order-to-Cash, P2P/Purchase-to-Pay, or H2R/Hire-to-Retire). Our focus lies on the interplay between manual control steps and system-based dependencies (IT-dependent Manual Controls) to minimize media breaks and risks of manual intervention. This includes activities such as automated tolerance checks, system-driven workflows to ensure, for instance, the Segregation of Duties (SoD), and verifying the completeness of interface transfers between legacy systems and the general ledger. By auditing BPCs, we ensure that business transactions are not only processed technically correctly, but are also aligned with internal policies and regulatory requirements.
  • Differentiation from Formalized ICS: We distinguish between operationally executed controls (BPCs) and the seamless documentation of the Internal Control System – for instance, in a Risk Control Matrix (RCM). To ensure that executed controls can be considered risk-mitigating within audit planning, they must meet the requirements of national and international standards (see GRC Assessments above).
  • Process Mining: As a valuable byproduct of our audit, we use modern technologies to provide transparency regarding process deviations and inefficiencies (e.g., bottlenecks or manual workarounds). In doing so, we transform regulatory requirements into strategic insights, helping you enhance the performance of your processes and integrate existing BPCs into a robust and audit-ready ICS framework.

Internal Audit

A high-performing Internal Audit function enables companies to identify risks at an early stage, strengthen governance structures, and continuously improve the effectiveness of processes and controls. With our Managed Services, we provide the flexibility to efficiently expand and scale your Internal Audit – for instance, through demand-oriented extensions such as fraud analytics and software audits – ensuring its long-term performance.

  • Co-/Outsourcing: We execute individual audit engagements or entire audit plans, ensuring risk-oriented and methodologically sound performance in accordance with ISA [DE] 610 (Using the Work of Internal Auditors) and IDW AS 321 (Internal Audit and Financial Statement Audit).
  • Transformation: Our experts support the further development of your Internal Audit function – from strategic planning and operative execution to reporting and quality assurance – in compliance with the new GIAS (Global Internal Audit Standards) issued by the IIA (Institute of Internal Auditors) as well as the national standards of the DIIR (German Institute of Internal Auditing).
  • Digital Audit: By leveraging modern technologies (e.g., AI-based Data Analytics) and scalable, data-driven audit methodologies, we sustainably increase the effectiveness, transparency, and strategic value of your Internal Audit function.

Project-Related Audits

In complex transformations – whether through the introduction of new systems (e.g., ERP, cloud), products, or profound changes to organizational structures and processes – early-stage confidence in the compliance readiness and security is critical.

  • Transformation & Project Audit: We conduct separate IT and process audits, prior to the statutory Annual Financial Statements (AFS) audit in accordance with IDW DAS 850 Rev. (Project-related Audits). This proactive approach enables the validation of compliance and transactional security for your systems, as well as the related organizational structures and business processes, already during the implementation phase. As an independent third party, we support you throughout all project phases – from conception to go-live – including the integration of classic due diligence, as well as in-depth analysis of IT infrastructure, security requirements, and change management. Through our early involvement, we identify deviations in a timely manner and can intervene with risk-oriented recommendations to minimize project risks before they jeopardize the subsequent year-end audit or live operations. This leads to a significant reduction in the AFS audit effort and builds trust among all internal and external stakeholders.
  • Case-in-Point ERP Transformation: Taking into account IDW AdvN 6.001 (Implementation of SAP® S/4HANA), we support you in the time-critical migration (addressing the end of ECC 6.0 maintenance by 2027/2030). We ensure that your new system landscape – or comparable ERP solutions – is not only future-proof, but also fulfills all regulatory requirements and strategic business objectives “by design.

Your contact for Technology

Filter by

Technology News

Technology

NIS-2-Registrierung: BSI gewährt Nachfrist bis 31. Juli 2026

Unternehmen, die ihrer NIS-2-Registrierungspflicht bislang noch nicht nachgekommen sind, erhalten vom Bundesamt für Sicherheit in der Informationstechnik (BSI) mehr...
to the news
Audit Advisory Legal Technology

NIS-2 und KRITIS-Dachgesetz: Der neue Standard für Resilienz im deutschen Mittelstand

Mit dem NIS-2-Umsetzungsgesetz und dem KRITIS-Dachgesetz verschärfen sich die Anforderungen an die digitale und physische Resilienz für den deutschen...
to the news
Technology

NIS-2-Richtlinie in Deutschland umgesetzt

Laut einer jüngst durchgeführten TÜV-BSI-Studie zur Cybersicherheit der deutschen Wirtschaft sind eine Zunahme der Cyberangriffe, die mangelnde Kenntnis der...
to the news