IT Controls Audit and SOX Readiness

Our IT audit consulting services give organizations complete visibility into their technology environment, identifying control gaps, evaluating IT general controls (ITGCs), and assessing application controls aligned with SOX, ICFR, and global audit requirements. Whether you are preparing for your first IT audit or strengthening a mature controls programme, our technology risk consultants design and execute testing that satisfies both internal and external audit expectations.

Capabilities

IT Controls Audit and SOX
Readiness Offerings

01

IT Controls audit program considering global compliances such as SOX

Design or enhance your IT General and Application controls / Risk and Controls Matrix (RACMs) aligned to global compliances such as SOX.
02

Concurrent IT Audits

Real-time audits conducted alongside ongoing business and technology operations.
03

Gap Assessment of IT Controls Environment

We evaluate your current controls framework against best practices and compliance requirements to identify redundancies or gaps. Our tailored recommendations help streamline your controls and enhance their effectiveness.
04

Support for IT Internal Audit Execution

Leverage our experience to augment your IT Audit Teams to execute their audit program and drafting comprehensive workpapers and test sheets.
Our Insights

Real Problems, Real Thinking

HITRUST: From Audit Sprints to Assurance Engine

Security threats are evolving faster than traditional compliance cycles can track. Cloud environments are growing more complex. AI is embedding itself into products and workflows at a pace most security programs were not designed to handle. In this environment, a certification earned once a year and then largely forgotten is not a security posture. It is a snapshot that becomes less accurate with every week that passes. HITRUST's evolution through 2026 reflects this reality directly, and understanding where the framework is heading matters for any organisation thinking seriously about cybersecurity assurance, third-party trust, and AI risk governance. What HITRUST Is and How It Has Evolved HITRUST was founded in 2007 to address the fragmented complexity of HIPAA and HITECH compliance in the healthcare sector. It has since expanded into a harmonised assurance model that consolidates requirements from more than 60 frameworks, regulations, and standards into a single certifiable structure known as the HITRUST Common Security Framework (CSF). [1] The list of sources harmonised within the CSF includes NIST CSF, ISO/IEC 27001, PCI DSS, CMMC, GDPR, and HIPAA. [2] This consolidation has real operational value. Rather than running parallel compliance programs for each applicable framework, organisations can address overlapping requirements through a single control baseline that is assessed and certified by an independent, HITRUST-authorised external assessor. As of May 2026, the current version of the framework is CSF v11.8.0, which introduced further consolidation of requirement statements to reduce overlap and refreshed several authoritative source mappings. [3] The Three Assessment Types: e1, i1, and r2 HITRUST offers three validated assessment and certification options, each designed for a different risk profile and level of required assurance. [4] The e1 assessment covers 44 essential cybersecurity hygiene controls. It is suited for organisations at an earlier stage of security maturity or those establishing a baseline assurance credential with lower-risk profiles. The i1 assessment provides an intermediate level of assurance with a broader control set and implementation-level evidence requirements. It is a one-year validated assessment sitting between the e1 and the more rigorous r2. The r2 assessment is the most comprehensive option. It is a two-year validated assessment that tailors controls to the organisation's specific risk factors using a maturity-based scoring approach. The r2 is typically pursued by organisations in healthcare, financial services, and other sectors where third-party assurance requirements are highest. Notably, 100% of r2 certifications directly validate service provider risks. [5] Choosing the right assessment type depends on the organisation's risk profile, the sensitivity of data being handled, and the assurance expectations of customers and business partners. Why Point-in-Time Assurance Is No Longer Sufficient The traditional audit model operates in preparation and certification cycles. An organisation prepares for an assessment, completes it, receives a certification, and then largely repeats the process when the next cycle approaches. In a stable environment, this approach is manageable. In today's environment, with continuous cloud changes, new vendor dependencies, AI integrations, and rapidly evolving attack techniques, it creates dangerous gaps between what the certificate says and what is actually happening in the control environment. The 2026 HITRUST Trust Report puts the stakes in clear terms. The report found that 99.62% of HITRUST-certified environments remained breach-free in 2025. By contrast, independent surveys indicate that more than 40% of organisations overall have experienced a security breach. [5] That gap reflects the cumulative benefit of structured, validated, and continuously monitored assurance over time, not just the benefit of a certification label. Third-party risk is compounding the pressure. According to the Verizon 2025 Data Breach Investigations Report, which analysed more than 22,000 security incidents and 12,195 confirmed breaches, third-party involvement in breaches doubled from 15% to 30% in a single year. [6] In response, over 80% of HITRUST certifications, including all r2 certifications, are specifically designed to address risks arising from service providers and supply chain dependencies. [5] HITRUST addresses the continuous monitoring gap through formal requirements built into the CSF Assurance Program. After certification, assessed entities are required to implement an ongoing monitoring programme covering configuration management, risk analysis for planned changes, and selective evaluation of security controls throughout the year. [7] This is what continuous assurance looks like in practice: an operational discipline maintained year-round, not a document produced at audit time. The Assurance Intelligence Engine A distinguishing feature of HITRUST's assurance model is its centralised quality review process. Every certification, without exception, undergoes independent quality assurance review by HITRUST before issuance. [5] The Assurance Intelligence Engine (AIE) reinforces this with automated analysis applied to assessment documentation throughout the assessment process, checking for inconsistencies and errors before submission. [8] Together, centralised quality assurance and the AIE produce a level of consistency and credibility that self-attested compliance approaches cannot reliably achieve. HITRUST AI Security Assessment and Certification AI introduces security risks that traditional frameworks were not originally designed to address. When AI systems are embedded in products and workflows, the attack surface expands to include training data integrity, model behaviour, inference vulnerabilities, prompt injection risks, data leakage, and dependencies on third-party model providers. HITRUST launched its AI Security Assessment and Certification in May 2026 to address these risks directly. [8] The certification is built on the same Cyber Threat Adaptive methodology as the core HITRUST CSF and is aligned with NIST, ISO, and OWASP standards related to AI security. According to HITRUST's Q1 2026 Cyber Threat Adaptive analysis, the AI Security Certification maintained over 97% coverage of adversarial AI techniques observed during the period, while the e1, i1, and r2 assessments demonstrated 98.19% and 100% coverage respectively. [9] HITRUST and ISO/IEC 42001: Two Frameworks, One Complete Picture ISO/IEC 42001:2023 is the world's first international standard specifically designed for AI management systems, published in December 2023 by the International Organization for Standardization and the International Electrotechnical Commission. [10] It establishes governance structures, accountability frameworks, risk management protocols, and organisational oversight requirements for AI development and deployment. HITRUST and ISO/IEC 42001 are complementary rather than competing. ISO/IEC 42001 defines how an organisation governs its AI systems at a policy and process level. HITRUST validates that the underlying technical security controls are implemented and functioning. Organisations that need to address both AI governance and AI security will find that both frameworks together produce a more complete assurance picture than either provides independently. [10] Treating HITRUST as an Operational Discipline The most common mistake organisations make with HITRUST is treating it as a project with a start date and an end date. Preparation begins, the assessment is completed, the certificate is issued, and the program goes quiet until the next cycle approaches. This approach misses the operational value that HITRUST delivers when integrated into day-to-day security and risk processes. When HITRUST controls are embedded into ongoing monitoring, automated evidence collection, configuration management, and vendor risk workflows, the gap between preparing for an audit and maintaining an assurance posture closes significantly. When the next assessment cycle arrives, the evidence base already exists. The organisation is validating a posture that has been actively maintained throughout the year, not reconstructing documentation to demonstrate retrospective compliance. This is the shift from audit sprint to assurance engine: from asking when the next audit is, to understanding what the control environment looks like today. Pierag's Technology Risk Advisory practice supports organisations at each stage of this transition, from initial HITRUST readiness assessment through validated assessment preparation, evidence infrastructure design, and ongoing assurance programme management. References [1] HITRUST Alliance. (2026). HITRUST CSF: Cybersecurity and risk management framework. Retrieved from https://hitrustalliance.net/hitrust-framework [2] Microsoft Learn. (2026). Health Information Trust Alliance (HITRUST) Common Security Framework (CSF). Microsoft Compliance Documentation. Retrieved from https://learn.microsoft.com/en-us/compliance/regulatory/offering-hitrust [3] Accorian. (2026, May 27). HITRUST CSF v11.8.0: Key updates. Retrieved from https://www.accorian.com/hitrust-csf-v11-8-0/ [4] A-LIGN. (2026). What is HITRUST? Complete guide to HITRUST certification. Retrieved from https://www.a-lign.com/articles/everything-you-need-to-know-about-hitrust-certification [5] HITRUST Alliance. (2026, April 7). The cybersecurity trust crisis: Why 99.62% of HITRUST certified environments stay breach-free [Press release]. Retrieved from https://hitrustalliance.net/press-releases/the-cybersecurity-trust-crisis-why-99.62-of-hitrust-certified-environments-stay-breach-free-while-third-party-risk-and-exploits-surge [6] Verizon Business. (2025, April 23). 2025 Data Breach Investigations Report [Press release]. Retrieved from https://www.verizon.com/about/news/2025-data-breach-investigations-report [7] HITRUST Alliance. (n.d.). HITRUST CSF Assurance Program Requirements. Retrieved from https://hitrustalliance.net/hubfs/CSF-Assurance-Program-Requirements.pdf [8] HITRUST Alliance. (2026, May 19). HITRUST launches AI Security Assessment with certification [Press release]. Retrieved from https://hitrustalliance.net/press-releases/hitrust_launches_ai_security_assessment_and_certification [9] HITRUST Alliance. (2026, April 30). HITRUST releases its quarterly Cyber Threat Adaptive analysis: The rise of AI-enabled attacks [Press release]. Retrieved from https://hitrustalliance.net/press-releases/hitrust-releases-its-quarterly-cyber-threat-adaptive-analysis-the-rise-of-ai-enabled-attacks [10] International Organization for Standardization. (2023). ISO/IEC 42001:2023: Information technology, artificial intelligence, management systems. Retrieved from https://www.iso.org/standard/42001

DPDP Act Decoded- Applicability, Impact & Our Perspective

The notification of the DPDP Rules, 2025 represents a decisive shift in India’s data privacy and governance landscape, operationalizing the Digital Personal Data Protection Act, 2023 and establishing a comprehensive framework for how organizations must collect, process, store, retain, and share digital personal data. The rules introduce stringent expectations around consent and notice management, user rights enablement, breach notification, cross-border data transfers, vendor and third-party oversight, and enhanced security safeguards, significantly expanding the scope of compliance obligations for enterprises across sectors. For organizations, this is not merely a regulatory change but a strategic and operational transformation that requires immediate and structured action. Businesses will need to undertake enterprise-wide data discovery and mapping, redesign consent and user rights workflows, automate retention and erasure mechanisms, strengthen audit trails and breach response protocols, and embed privacy governance into board-level oversight. The phased implementation timelines further emphasize the need for early readiness planning to mitigate compliance gaps, reputational risks, and potential regulatory penalties. As data continues to become central to digital transformation and customer engagement, aligning with the DPDP Rules, 2025 will be critical to building trust, ensuring regulatory resilience, and enabling responsible data-driven growth. To understand the detailed applicability of the rules, their business impact, and our perspective on how organizations should prepare and respond, read our comprehensive POV.
  • 3-4Min Read

Audit Trail Ensuring Financial Integrity and Accountability

India’s IT landscape has experienced a dramatic shift over recent decades, moving away from traditional, paper-dependent bookkeeping methods to a vibrant, tech-powered ecosystem. Today, organizations depend on — ranging from enterprise resource planning (ERP) tools to cloud platforms — not only to boost efficiency but also to safeguard compliance, security, and data accuracy of financial reporting. This change entails additional responsibility since keeping thorough records helps to prove financial integrity and responsibility. An audit trail acts as the "black box" of an organization—a kind of financial journal that captures every activity. It records who did what, when, and how within the financial system. This creates a straightforward way to verify the accuracy and accountability of financial records. Think of it as holding a backstage pass that lets you peek behind the curtain—offering complete visibility into every transaction for transparency, tracking access to sensitive data to bolster security, and capturing system changes to ensure compliance. With their growing importance, audit trails are now a legal must-have in India, following regulatory mandates that came into effect on April 1, 2023. The push for audit trail comes straight from the Companies (Accounts) Rules, 2014, where Rule 3(1) says any organization using accounting software—whether it's ERP systems or even web portals—must have a permanent audit trail that can't be turned off. It’s got to automatically track every change, stamp it with a timestamp, and keep those records on hand for audits. Meanwhile, auditors, under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, must double-check that this feature was running all year, and wasn't tampered with. This rule isn't just for large organizations—it applies to every Indian organization. Whether it's nonprofits under Section 8 or foreign entities, it covers everything from standalone to consolidated financial statements.
  • 2-3 Min Read

Emerging Business Risks in 2026: Why Continuity and Talent Now Sit at the Top of the Agenda

Point of View | 6-8 Min Read Organizations today are navigating a risk landscape that no longer sits still. Technological change, environmental pressure, and shifting societal expectations are blurring the traditional boundaries between risk categories, creating a complex, interconnected environment where a single disruption rarely stays contained to one part of the business. Developing the ability to identify, understand, and mitigate these risks has become essential for organizations aiming for resilient, sustainable growth, not just for risk teams but for leadership as a whole. This shift also creates an opening for internal audit functions specifically. Emerging risks give internal audit teams a genuine opportunity to demonstrate agility, sound judgment, and strategic insight, reinforcing their role as a driver of organizational resilience and long-term value creation, not just a compliance checkpoint. Two risk categories in particular deserve close attention heading into 2026: business continuity and human capital. Business Continuity Risk: From Contained Incidents to Domino Effects Business continuity risks are the probable disruptions that hinder an organization's ability to operate effectively and deliver essential services. These disruptions can originate from multiple sources at once, including natural disasters, technological failures, cybersecurity incidents, geopolitical conflicts, and supply chain breakdowns. The COVID-19 pandemic and the Suez Canal blockage remain two of the clearest recent examples of how severely these risks can disrupt global operations, and both illustrate a pattern that continues to define continuity risk today: these disruptions are highly interconnected and interdependent. A relatively minor disruption in one part of a supply chain or operating model can trigger a cascading effect that produces operational and financial consequences across an entire global organization. Strengthening operational resilience is no longer a defensive, back-office exercise. It is essential for maintaining stakeholder trust and sustaining long-term value delivery, particularly as investors, regulators, and customers increasingly expect organizations to demonstrate they can absorb shocks without losing continuity of service. Human Capital Risk: The Execution Gap Behind Every Strategy Human capital risk is the vulnerability organizations face in attracting, retaining, and developing their talent. Employees remain an organization's most valuable asset and one of its most vital pillars, which means failures in talent management do not stay contained to HR. They ripple directly into business continuity, innovation capacity, and competitive position. An organization can have a well-designed strategy for navigating cyber risk, geopolitical disruption, or digital transformation, but a strategy is only as strong as the people available to execute it. Talent gaps slow an organization's ability to respond to any other risk on this list, which is why human capital risk increasingly gets discussed alongside operational and continuity risk rather than treated as a separate HR concern. Why These Two Risks Are Increasingly Discussed Together Business continuity and human capital risk are not independent categories that happen to appear on the same risk register. They compound each other. A continuity event, whether a cyberattack, a supply chain disruption, or a geopolitical shock, tests an organization's talent bench directly: whether the right people with the right authority and training are in place to respond in real time. Conversely, an organization with unresolved talent gaps going into a disruption will find that disruption harder to contain and slower to recover from. This is exactly the kind of interconnection that internal audit functions are well positioned to surface. Rather than reviewing continuity plans and workforce risk as separate audit engagements, leading internal audit teams are increasingly examining how these risks interact and where a gap in one amplifies exposure in the other. What This Means for Internal Audit and Risk Leaders in 2026 Organizations preparing their 2026 risk agendas should treat business continuity and human capital risk as connected priorities, not parallel checklist items. Practically, this means: Testing continuity plans against realistic scenarios that also account for staffing and skills availability, not just system and process recovery Reviewing whether critical roles have documented succession and cross-training coverage, particularly in functions central to incident response Assessing where talent gaps could slow the organization's response to a continuity event, and prioritizing those gaps ahead of a crisis rather than after one Giving internal audit a mandate to examine risk interconnection directly, rather than auditing each risk category in isolation Frequently Asked Questions What is business continuity risk? Business continuity risk refers to probable disruptions that hinder an organization's ability to operate effectively and deliver essential services, arising from sources such as natural disasters, technology failures, cybersecurity incidents, geopolitical conflict, or supply chain disruption. What is human capital risk? Human capital risk is the vulnerability an organization faces in attracting, retaining, and developing the talent it needs, with direct consequences for business continuity, innovation capacity, and competitive position when not managed effectively. Why are business continuity and human capital risk often discussed together? These risks compound each other. A continuity disruption tests whether an organization has the right talent in place to respond, while unresolved talent gaps make any continuity event harder to contain and slower to recover from. What role does internal audit play in managing emerging risks like these? Internal audit is increasingly positioned to examine how risks like continuity and talent interconnect, rather than auditing each in isolation, giving organizations a clearer view of where one risk gap amplifies exposure elsewhere. What real-world events illustrate business continuity risk? The COVID-19 pandemic and the 2021 Suez Canal blockage are widely cited examples of how a single disruption can cascade into significant global operational and financial consequences. Who should be paying attention to these emerging risks? Chief risk officers, heads of internal audit, COOs, and board risk committees responsible for setting the organization's 2026 risk agenda and resilience priorities. Talk to Our Team Building a risk agenda that connects continuity planning with workforce readiness, rather than treating them separately? Pierag's Business Risk Advisory practice helps organizations design internal audit and risk management approaches built for how today's risks actually interact. Talk to our team about your 2026 risk agenda. Related reading: Emerging Risks and Trends: Navigating What's Next 2026 | Beyond Net Zero: Why Climate Adaptation Is the Next ESG Frontier | Audit Trail: Ensuring Financial Integrity and Accountability
  • 2-5 Min Read
Driving Impact

Our Technology Risk Advisory
Leadership Team

cross-icon
Gaurav Khandelwal

Gaurav Khandelwal

Partner- Risk Advisory
Gaurav is a Risk Advisory Practice Leader at Pierag Consulting, one of the fastest-growing firms in the advisory space. A Chartered Accountant by profession, he is a seasoned Governance, Risk, and Compliance professional with over 20 years of experience in consulting and industry. An ex-Big 4 leader, he is renowned for advising clients on managing risks and assisting large-scale organizations in implementing robust governance frameworks across sectors such as real estate, infrastructure, consumer products, beverages, hospitality, and healthcare. In his industry role, Gaurav was instrumental in driving the culture and implementing frameworks across governance, risk, and compliance. Under his leadership, Tata Realty won prestigious accolades, including the Risk and Compliance Awards at ICICI Lombard and the CNBC TV18 India Risk Management Awards. Earlier, in his leadership roles at Big 4, he led multiple risk-based internal audit engagements for diverse clients, including companies engaged in the operations and maintenance of roads, steel manufacturing across multiple locations, leading players in the Indian credit card market, and liquor manufacturers with several bottling units. He has also worked on enterprise risk management engagements, developing frameworks to effectively identify and address strategic and operational risks through structured monitoring and reporting mechanisms. For instance, he assisted a leading footwear company in re-assessing its ERM framework, prioritizing key risks, and co-developing a comprehensive mitigation plan. Gaurav has extensive experience in compliance program implementation, where he has been responsible for setting up compliance functions and reporting structures, ensuring comprehensive mapping of legal and regulatory requirements across functions, and strengthening ongoing compliance monitoring. Additionally, he successfully managed end-to-end IFC implementation for one of India’s leading healthcare brands, covering 24 hospitals across the country.

Key Expertise and Achievements

  • Risk-Based Internal Audits and Internal Controls Assurance
  • IFC/SOX Readiness, Implementation, and Compliance
  • Enterprise Risk Management Frameworks and Mitigation Planning
  • Business Process Reengineering and Regulatory Compliance
  • Large-scale IFC implementation in the healthcare industry (24 hospitals)
  • Award-winning governance and compliance leadership at Tata Realty.
cross-icon
Dipesh Khushalani

Dipesh Khushalani

Director- Technology Risk & Data Privacy​
Dipesh's journey is a testament to the amalgamation of passion and diverse experiences. His enthusiasm for computer games and experimentation with technology laid the groundwork for a career in this field. He has built a comprehensive skillset from his tenures at leading firms like KPMG India and SBI Cards, specializing in a wide range of areas including Privacy (GDPR, DPDPA), Cybersecurity, IT Audits, IT SOX, SOC 1 & SOC 2 reporting, and Business Continuity Planning. Dipesh is a Certified Information Systems Auditor (CISA) and holds an MBA in Information Systems and Security, along with a PG Diploma in Cyber Laws. His broad expertise extends across multiple sectors such as BFSI, NBFCs, Manufacturing, Aviation, and Telecom. Dipesh brings a holistic perspective to his work, with his interests in dramatics, filmmaking, and martial arts honing the creativity and adaptability needed to thrive in the dynamic technology risk domain.
cross-icon
Ankush Sharma

Ankush Sharma

Associate Director – Technology Risk Advisory
“Clarity amidst complexity, resilience amidst uncertainty.” Guided by this belief, Ankush has built his career on transforming risks into opportunities for resilience and growth. A Chartered Accountant who cleared the exam at the young age of 21, Ankush’s entry into the profession was inspired by his mother’s dream. While becoming a CA fulfilled her vision, his own passion leaned towards technology — a pursuit that naturally drew him into the world of Technology Risk Advisory, where he could combine his financial foundation with his curiosity for IT. Ankush’s professional journey began with his articleship at Dewan P.N. Chopra & Co., followed by industrial training at Gaursons India, which gave him early exposure to audits, controls, and governance. Over the next 12+ years, his career spanned Wipro Infotech, AXA XL, British Council, Teleperformance, and now Pierag Consulting. As the first employee in Pierag’s Technology Risk practice, Ankush played a pivotal role in building and scaling the service line. His career spans both the Indian market and extensive international experience, collaborating with teams across the US, UK, and more than 100 countries. This global exposure has given him a deep understanding of diverse regulatory environments and best practices. He has advised enterprises on SOC 1/SOC 2, HITRUST, PCI DSS, TPRM, and large-scale SOX/ICOFR programs, with most engagements spanning banking, insurance, telecommunications, and e-commerce industries. From guiding Fortune 100 firms on global SOX programs to enabling India’s largest airline to achieve data privacy compliance, Ankush has consistently delivered outcomes that combine regulatory rigor with business agility, while also leading ERP transformations, cybersecurity frameworks, and global risk advisory programs where he is recognized for bringing clarity and structure to complexity. What sets Ankush apart is his visionary approach: he views every engagement not just as a compliance exercise, but as a chance to build trust, transparency, and accountability in the digital age. Colleagues recognize him as a strategist who simplifies complexity, while clients value his ability to embed governance without slowing business momentum. Outside work, Ankush embraces the open road, often embarking on road trips across India — from the mountains to the coasts — journeys that reflect his resilience, curiosity, and determination to reach new horizons. A passionate coffee lover, his weekends are devoted to family and friends over thoughtful conversations, while weekdays often find him sharing the same enthusiasm for coffee and dialogue with colleagues — moments that keep him both grounded and inspired. What began as fulfilling his mother’s dream has evolved into his own passion for technology. Today, Ankush embodies resilience, foresight, and integrity — living proof that inherited dreams and personal vision together can create a powerful path forward. Professional Qualifications and Certifications:
  • Chartered Accountant
  • Bachelor of Commerce
  • ISO 27001:2022 Lead Auditor
  • ISO 27001:2022 Lead Implementer
  • Six Sigma Green Belt
 Expertise:
  • SOX & ICOFR Compliance
  • SOC 1 / SOC 2 & HITRUST Readiness
  • ERP Risk & Controls (SAP, Oracle Fusion, NetSuite)
  • Data Privacy & Cybersecurity (GDPR, DPDP, HIPAA, PCI DSS)
  • Third-Party Risk Management
Client sectors include, but are not limited to: BFSI, ITES, Manufacturing, Pharmaceuticals, Telecommunications, E-Commerce, and Healthcare.  
cross-icon
Karan Trehan

Karan Trehan

Associate Director - Technology Risk Advisory
cross-icon
Piyush Paliwal

Piyush Paliwal

Associate Director – Technology Risk Advisory

Piyush Paliwal’s professional journey reflects his commitment to bridging technology, risk, and business needs to create value-driven solutions for clients across industries. With over 9 years of experience spanning Deloitte USI, Deloitte Canada, HCL Technologies, and now Pierag Consulting, Piyush has developed deep expertise in Technology Risk Advisory, specializing in internal controls, IT audits, compliance, and risk assessments, delivering solutions across geographies including the US, Canada, UK, South Asia, and India.

At Pierag, he leads complex engagements in areas such as Risk-based Internal Audits, SOX compliance, SOC reporting readiness, ITGC reviews, IFC/ICOFR, SSAE18 assessments, and IT Application Controls. His expertise also extends to specialized areas such as Third-Party Risk Management (TPRM), Enterprise Risk Management (ERM), Data Privacy, Cybersecurity, GRC tools, IAM solutions, and regulatory frameworks like SOX, ICFR, COSO, and COBIT—helping organizations build robust compliance and control environments.

Piyush’s work spans a broad spectrum of industries, including Telecom, Technology, Manufacturing, eCommerce, FMCG, BFSI, and Life Sciences & Healthcare. Beyond technical delivery, he has played a pivotal role in client relationship management, practice building, training, and quality reviews, as well as leading teams to navigate diverse regulatory requirements. His international experience—particularly his secondment with Deloitte Canada—has further sharpened his perspective on global compliance and risk.

He holds a Master of Business Administration (Finance) and a Bachelor of Engineering (IT). He is also a certified ISO 27001:2022 Lead Implementor and ISO 42001:2023 Lead Implementor (Intertek), demonstrating his commitment to staying ahead in information security and emerging AI governance. Piyush’s expertise in working with enterprise systems such as SAP, PeopleSoft, Windows, UNIX, SQL Server, and Oracle etc. adds further depth in aligning technology environments with internal control frameworks and regulatory guidance for complex and high-growth organizations.

Recognized as a trusted advisor, Piyush brings not just strong domain knowledge but also the ability to connect business priorities with technology controls, making him a leading voice in the Technology Risk Advisory space.

Secure Your Technology Landscape

Ensure your IT environment is resilient and compliant with evolving regulations. Our Technology Risk Advisory services help you identify gaps, enhance control effectiveness, and build confidence in your technology landscape.