Business Risk Advisory

Transforming Risk into Strategic Advantage

In an era of accelerating regulatory change, geopolitical uncertainty, and AI-driven disruption, organizations can no longer afford a reactive approach to risk. Pierag's Business Risk Advisory practice helps CFOs, Boards, and Risk Leaders anticipate emerging threats, strengthen internal controls, and build governance frameworks that create measurable business value, not just regulatory compliance. From GRC consulting services and internal audit services to SOX compliance services and fraud risk management, we deliver technology-enabled, scalable risk management consulting solutions.

Capabilities
Our Core Offerings
Our Insights
Real Problems, Real Thinking
Research report | 8-10 Min Read Material weaknesses remain one of the clearest public signals of how well an organization's internal control environment is actually working. But the disclosures themselves rarely tell the full story. A single reported weakness is often the visible symptom of a deeper governance, staffing, or process gap, not an isolated control failure. To understand what is really driving these disclosures, Pierag analyzed material weakness filings from 1,000 U.S. SEC filers across 2025 and 2026. The goal was to identify which themes recur most often, how they cluster together, and what separates companies that remediate quickly from those that report the same weaknesses year after year. What Is a Material Weakness in Internal Controls? A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting (ICFR) severe enough that there is a reasonable possibility a material misstatement in the company's financial statements would not be prevented or detected on a timely basis. Under SEC rules, companies must disclose material weaknesses in their annual and quarterly filings, along with management's assessment of ICFR effectiveness. A material weakness disclosure does not necessarily mean a misstatement has occurred. It means the control environment could not reliably catch one if it did. Methodology Pierag reviewed material weakness disclosures reported by 1,000 U.S. SEC filers across fiscal years 2025 and 2026, drawn from annual and quarterly filings. Each disclosure was categorized by theme, cross-referenced against industry classification and filer type (IPO versus non-IPO), and analyzed for co-occurrence patterns, meaning how often two or more weakness themes were reported together within the same filing. The Most Commonly Reported Material Weakness Themes Two themes dominate the dataset by a clear margin: Segregation of Duties - inadequate separation between individuals who initiate, approve, and record transactions, concentrating control in too few hands. Resource Constraints - insufficient qualified accounting and finance personnel to design, operate, and monitor controls at the scale the business requires. Beyond these two leading themes, three additional categories appear consistently across industries: Employee Training and Competency Gaps - control owners who lack sufficient training in accounting standards, company-specific procedures, or the judgment required for complex transactions. IT General Controls (ITGCs) - weaknesses in access management, change management, or system configuration controls supporting financial reporting systems. Financial Reporting Process Deficiencies - breakdowns in period-end close, account reconciliation, or review procedures that support accurate reporting. Why Material Weaknesses Rarely Occur in Isolation One of the most consistent patterns in the data is co-occurrence. Companies that report one material weakness frequently report two or more in the same filing. Segregation of Duties issues, for example, are commonly reported alongside Resource Constraints, since both often stem from the same root cause: a finance function that has not scaled staffing or process design in line with the business. This clustering matters for how organizations should read their own disclosures. A material weakness reported as a single line item is often a symptom of a broader capacity or governance gap, not a standalone control fix. Addressing the individual deficiency without addressing the underlying driver tends to produce a repeat disclosure the following year. Industry-Specific Patterns Material weakness themes are not evenly distributed across sectors. Some industries show a heavier concentration of IT General Controls weaknesses, consistent with reliance on complex or highly customized financial systems. Others show a higher incidence of Resource Constraints, often reflecting leaner finance functions relative to transaction volume or reporting complexity. Understanding where an organization's own industry tends to cluster is a useful diagnostic starting point before conducting an internal gap assessment. IPO Filers vs. Non-IPO Filers The data shows a meaningful difference between newly public companies and established filers. IPO filers are more likely to report material weaknesses tied to Resource Constraints and Financial Reporting Process Deficiencies, consistent with the operational strain of building a public-company-grade control environment on a compressed timeline. Non-IPO filers, by contrast, more frequently report Segregation of Duties and IT General Controls issues, often surfacing as the business has grown in complexity faster than its control structure. What Effective Remediation Looks Like Across the filers studied, organizations making the fastest and most durable progress on remediation share a common approach: they treat material weaknesses as a signal to fix the underlying driver, not just the disclosed symptom. In practice, this means: Redesigning governance structures and reporting lines rather than adding a single approval step Investing in talent and training as a control activity, not a one-time fix Rebuilding financial reporting processes with documented, testable controls Modernizing IT systems and access controls supporting the close process Organizations that address these root causes tend to see material weaknesses resolved and stay resolved. Those that patch individual deficiencies in isolation tend to see new, related weaknesses surface in subsequent periods. Frequently Asked Questions What is the most commonly reported material weakness among SEC filers? Segregation of Duties and Resource Constraints are the two most frequently reported material weakness themes across the 1,000 SEC filers analyzed, ahead of IT controls, employee training, and financial reporting process deficiencies. Do material weaknesses usually occur alone or together? Material weaknesses frequently co-occur. A company reporting a Segregation of Duties issue, for example, often also reports a related Resource Constraints weakness, since both typically trace back to an under-resourced finance function. Is a material weakness the same as a misstatement? No. A material weakness means the control environment could not reliably prevent or detect a material misstatement on a timely basis. It does not confirm that a misstatement actually occurred. Do IPO companies report different material weaknesses than established public companies? Yes. IPO filers more often report Resource Constraints and Financial Reporting Process Deficiencies, reflecting the strain of building public-company controls quickly. Non-IPO filers more often report Segregation of Duties and IT General Controls weaknesses. How long does it typically take to remediate a material weakness? Timelines vary by root cause and company size, but remediation that only fixes the disclosed symptom (rather than the underlying governance, staffing, or process gap) tends to result in the same or a related weakness resurfacing in a later period. Who should read this material weakness research report? The findings are most relevant to CFOs, controllers, audit committee members, and internal audit leaders responsible for ICFR design, SOX 404 compliance, and remediation planning. Get the Full Report This overview covers the top-line findings. The complete report includes the full thematic breakdown, industry-by-industry data, co-occurrence analysis, and practical considerations for management teams, audit committees, and internal audit leaders building a remediation roadmap. Building or strengthening your ICFR environment? Pierag's Business Risk Advisory teams work with audit committees and finance leaders to design controls that hold up under scrutiny, not just on paper. Talk to our team about your control environment. Related reading: Beyond Compliance: Internal Auditor's Role in Implementing SEBI's New RPT Framework | Audit Trail: Ensuring Financial Integrity and Accountability | Emerging Risks and Trends 2026
The risks that organizations once monitored from a distance are now actively reshaping business models, capital decisions, and strategic priorities. Below are the five risks that every leader should focus on: 1. Cybersecurity – Cyber incidents are no longer just an IT problem. They disrupt operations, delay customer interactions, and attract regulatory scrutiny. 2. Digital Disruption & AI – AI adoption is accelerating faster than governance frameworks can keep up. The question is no longer whether to adopt, it's who is accountable when things go wrong. 3. Business Resilience – Resilience today isn't about recovering after a disruption. It's about sustaining performance while disruption is still underway. 4. Geopolitical Uncertainty – Trade disputes, policy shifts, and regulatory changes are happening without warning. Organizations must embed these into strategic planning, not treat them as external noise. 5. Human Capital – 40% of organizations worldwide identify talent as a key risk. Having a strategy means little without the people ready to execute it. What makes these risks truly complex is how deeply interconnected they are. A cyber incident amplifies operational fragility. Geopolitical shifts strain already-stretched supply chains. Talent gaps slow down an organization's ability to respond to any of it. In this environment, Internal Audit is shifting from process reviewer to risk interpreter. Download & Read our full Point of View below.
  • 8-10 Min Read
Fraud has become a pervasive and evolving threat across industries, driven by rapid digitalization, interconnected ecosystems, and increasing regulatory scrutiny. Organizations today face a wide spectrum of risks ranging from traditional schemes such as asset misappropriation and procurement fraud to sophisticated cyber-enabled threats including phishing, synthetic identity fraud, business email compromise, and AI-driven deepfake scams. The growing scale and complexity of these schemes highlight the significant financial, operational, and reputational damage fraud can inflict, making proactive fraud risk management a strategic priority rather than a reactive control function. This Pov emphasizes that effective fraud management extends beyond strengthening internal controls. It requires a holistic, enterprise-wide approach that integrates technology, governance, and culture. While advanced analytics, AI, and digital forensics are enabling real-time detection and continuous monitoring, their impact is maximized only when supported by strong ethical leadership, whistle blower mechanisms, and a culture of integrity. Leadership tone, employee awareness, and zero tolerance for misconduct are critical to preventing fraud patterns from taking root. A structured and proactive fraud risk framework is essential to stay ahead of emerging threats. This includes periodic fraud risk assessments, scenario mapping, continuous transaction monitoring, robust investigation protocols, and ongoing employee training to identify red flags early. Increasingly, organizations must also expand oversight to third parties, digital platforms, and cloud environments, recognizing that fraud risks now extend well beyond internal processes. Looking ahead, fraud risk advisory is evolving into a strategic governance function that leverages predictive analytics, behavioral monitoring, and advanced technologies to shift the focus from post-incident investigation to prevention and resilience. By embedding fraud risk management into core business strategy and governance, organizations can protect revenue, safeguard stakeholder trust, and build long-term organizational resilience in an increasingly complex risk landscape.
Explore the insights shaping 2025’s top risk priorities and how proactive risk management can drive resilience.
Deficiencies in internal controls can feel overwhelming and may lead to an adverse ICOFR (Internal Controls over Financial Reporting) opinion. However, timely remediation of these deficiencies can help organizations secure an unmodified opinion from auditors at year-end. Understanding and addressing internal control issues early is essential to safeguarding financial reporting integrity. Internal controls are more than just a compliance checkbox; they form the backbone of sound governance, helping organizations achieve both their strategic and financial objectives. A deficiency in internal controls arises when the design or operation of a control does not allow management or employees to prevent, detect, or correct misstatements in a timely manner. Such deficiencies can occur at any level of an organization and may affect financial reporting, operational processes, or compliance efforts. The severity of these deficiencies varies, making it crucial to categorize them appropriately to understand the level of risk they pose. When internal control deficiencies are identified, timely remediation becomes essential to minimize risks and ensure the overall effectiveness of the control environment. Remediation involves addressing the root cause of the deficiency and implementing corrective actions to strengthen controls. Management typically remediates deficiencies before the balance sheet date, allowing sufficient time for the control to operate and validate its effectiveness. This also gives both management and auditors enough time to evaluate and test the control during that period.
  • 6-9 Min Read
Point of View | 6-8 Min Read Organizations today are navigating a risk landscape that no longer sits still. Technological change, environmental pressure, and shifting societal expectations are blurring the traditional boundaries between risk categories, creating a complex, interconnected environment where a single disruption rarely stays contained to one part of the business. Developing the ability to identify, understand, and mitigate these risks has become essential for organizations aiming for resilient, sustainable growth, not just for risk teams but for leadership as a whole. This shift also creates an opening for internal audit functions specifically. Emerging risks give internal audit teams a genuine opportunity to demonstrate agility, sound judgment, and strategic insight, reinforcing their role as a driver of organizational resilience and long-term value creation, not just a compliance checkpoint. Two risk categories in particular deserve close attention heading into 2026: business continuity and human capital. Business Continuity Risk: From Contained Incidents to Domino Effects Business continuity risks are the probable disruptions that hinder an organization's ability to operate effectively and deliver essential services. These disruptions can originate from multiple sources at once, including natural disasters, technological failures, cybersecurity incidents, geopolitical conflicts, and supply chain breakdowns. The COVID-19 pandemic and the Suez Canal blockage remain two of the clearest recent examples of how severely these risks can disrupt global operations, and both illustrate a pattern that continues to define continuity risk today: these disruptions are highly interconnected and interdependent. A relatively minor disruption in one part of a supply chain or operating model can trigger a cascading effect that produces operational and financial consequences across an entire global organization. Strengthening operational resilience is no longer a defensive, back-office exercise. It is essential for maintaining stakeholder trust and sustaining long-term value delivery, particularly as investors, regulators, and customers increasingly expect organizations to demonstrate they can absorb shocks without losing continuity of service. Human Capital Risk: The Execution Gap Behind Every Strategy Human capital risk is the vulnerability organizations face in attracting, retaining, and developing their talent. Employees remain an organization's most valuable asset and one of its most vital pillars, which means failures in talent management do not stay contained to HR. They ripple directly into business continuity, innovation capacity, and competitive position. An organization can have a well-designed strategy for navigating cyber risk, geopolitical disruption, or digital transformation, but a strategy is only as strong as the people available to execute it. Talent gaps slow an organization's ability to respond to any other risk on this list, which is why human capital risk increasingly gets discussed alongside operational and continuity risk rather than treated as a separate HR concern. Why These Two Risks Are Increasingly Discussed Together Business continuity and human capital risk are not independent categories that happen to appear on the same risk register. They compound each other. A continuity event, whether a cyberattack, a supply chain disruption, or a geopolitical shock, tests an organization's talent bench directly: whether the right people with the right authority and training are in place to respond in real time. Conversely, an organization with unresolved talent gaps going into a disruption will find that disruption harder to contain and slower to recover from. This is exactly the kind of interconnection that internal audit functions are well positioned to surface. Rather than reviewing continuity plans and workforce risk as separate audit engagements, leading internal audit teams are increasingly examining how these risks interact and where a gap in one amplifies exposure in the other. What This Means for Internal Audit and Risk Leaders in 2026 Organizations preparing their 2026 risk agendas should treat business continuity and human capital risk as connected priorities, not parallel checklist items. Practically, this means: Testing continuity plans against realistic scenarios that also account for staffing and skills availability, not just system and process recovery Reviewing whether critical roles have documented succession and cross-training coverage, particularly in functions central to incident response Assessing where talent gaps could slow the organization's response to a continuity event, and prioritizing those gaps ahead of a crisis rather than after one Giving internal audit a mandate to examine risk interconnection directly, rather than auditing each risk category in isolation Frequently Asked Questions What is business continuity risk? Business continuity risk refers to probable disruptions that hinder an organization's ability to operate effectively and deliver essential services, arising from sources such as natural disasters, technology failures, cybersecurity incidents, geopolitical conflict, or supply chain disruption. What is human capital risk? Human capital risk is the vulnerability an organization faces in attracting, retaining, and developing the talent it needs, with direct consequences for business continuity, innovation capacity, and competitive position when not managed effectively. Why are business continuity and human capital risk often discussed together? These risks compound each other. A continuity disruption tests whether an organization has the right talent in place to respond, while unresolved talent gaps make any continuity event harder to contain and slower to recover from. What role does internal audit play in managing emerging risks like these? Internal audit is increasingly positioned to examine how risks like continuity and talent interconnect, rather than auditing each in isolation, giving organizations a clearer view of where one risk gap amplifies exposure elsewhere. What real-world events illustrate business continuity risk? The COVID-19 pandemic and the 2021 Suez Canal blockage are widely cited examples of how a single disruption can cascade into significant global operational and financial consequences. Who should be paying attention to these emerging risks? Chief risk officers, heads of internal audit, COOs, and board risk committees responsible for setting the organization's 2026 risk agenda and resilience priorities. Talk to Our Team Building a risk agenda that connects continuity planning with workforce readiness, rather than treating them separately? Pierag's Business Risk Advisory practice helps organizations design internal audit and risk management approaches built for how today's risks actually interact. Talk to our team about your 2026 risk agenda. Related reading: Emerging Risks and Trends: Navigating What's Next 2026 | Beyond Net Zero: Why Climate Adaptation Is the Next ESG Frontier | Audit Trail: Ensuring Financial Integrity and Accountability
  • 2-5 Min Read
Point of View | 7-9 Min Read The Securities and Exchange Board of India has fundamentally changed how listed entities document and disclose related party transactions. Through the Industry Standards Forum, comprising ASSOCHAM, CII, and FICCI, in consultation with SEBI, the regulator introduced Industry Standards on "Minimum Information to be Provided for Review by the Audit Committee and Shareholders for Approval of Related Party Transactions." The framework applies to all listed entities in India and is designed to standardize reporting and disclosure requirements, elevating governance, transparency, and oversight of related party transactions across the board. For internal auditors, this is not a disclosure formality to note in passing. It reshapes what evidence must exist before a related party transaction can be approved, and internal audit functions are directly responsible for verifying that evidence is complete and accurate. From April 2025 to September 2025: How the Effective Date Actually Landed SEBI's RPT Industry Standards had a longer runway to implementation than originally announced. The standards were first set to apply to related party transactions entered into on or after April 1, 2025. Following stakeholder feedback requesting more preparation time, SEBI deferred the effective date, first to July 1, 2025, and then, through a revised circular issued June 26, 2025, to a final effective date of September 1, 2025. That September 1, 2025 date is when the standards actually took hold, and it is the date internal auditors and audit committees should treat as the operative compliance baseline. SEBI followed this in October 2025 with a further amendment. A circular dated October 13, 2025 introduced threshold-based relaxation in the minimum information listed entities must furnish, easing the compliance burden for transactions below specific value thresholds while keeping the core disclosure framework intact for larger and more material transactions. Identifying and Classifying Related Party Transactions The framework's starting requirement is accurate identification of all related parties as defined under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. From there, transactions must be classified based on materiality into three categories: Material RPTs, which exceed the prescribed value or turnover thresholds Transactions involving promoters or promoter groups that exceed prescribed thresholds Residual RPTs that fall outside the above categories This classification is not a paperwork exercise. It determines the level of scrutiny, documentation, and approval a transaction requires, and misclassification at this stage undermines everything that follows in the approval process. What Internal Auditors Must Verify Internal auditors carry direct responsibility for confirming that adequate documentation exists for every related party transaction placed before the Audit Committee. The minimum information requirements include: Basic details of the related party The relationship and ownership structure connecting the related party to the listed entity The related party's financial performance Details of previous transactions with that related party The value of the proposed transaction Basic details of the proposed transaction itself For specific transaction types, additional documentation is required. This includes proposed transactions involving the sale, purchase, or supply of goods or services, or similar business transactions; loans, inter-corporate deposits, or advances given by the listed entity or its subsidiary; investments made by the listed entity or its subsidiary; and guarantees (excluding performance guarantees), sureties, indemnities, or comfort letters given by the listed entity or its subsidiary. The Internal Auditor's Practical Role Under the Framework Internal audit's role under these standards extends beyond a single compliance check. In practice, it involves: Pre-approval verification: confirming that the minimum information package for a proposed RPT is complete before it reaches the Audit Committee, not after Materiality classification review: independently testing whether transactions have been correctly classified as material, promoter-related, or residual, since misclassification changes the entire approval pathway Documentation completeness testing: sampling RPT files to confirm all required fields, financial performance data, prior transaction history, and transaction-specific disclosures are present and traceable Threshold monitoring: tracking cumulative related party transaction values across a financial year, since transactions that appear immaterial individually can cross materiality thresholds when aggregated Post-October 2025 threshold application: confirming that the relaxed minimum information requirements are being applied correctly only to transactions that genuinely qualify under the October 2025 threshold-based relaxation, rather than applied broadly by default Why This Matters Beyond Compliance Standardized RPT disclosure exists because related party transactions carry inherent conflict-of-interest risk, and inconsistent documentation historically made it difficult for Audit Committees and shareholders to evaluate whether a transaction genuinely served the listed entity's interests. Internal auditors who treat this framework as a genuine governance safeguard, rather than a box-ticking exercise, give Audit Committees the confidence to approve transactions on solid evidentiary ground and give shareholders a clearer basis for trusting that approval process. Frequently Asked Questions When did SEBI's RPT Industry Standards actually take effect? The standards were originally proposed for April 1, 2025, but were deferred twice and took final effect on September 1, 2025, following a revised circular issued June 26, 2025. What are the three categories of related party transactions under the framework? Transactions are classified as material RPTs exceeding prescribed thresholds, transactions involving promoters or promoter groups exceeding prescribed thresholds, or residual RPTs that fall outside both categories. What is the internal auditor's specific responsibility under the RPT standards? Internal auditors must verify that adequate documentation exists for each related party transaction, including related party details, relationship and ownership information, financial performance, prior transaction history, and transaction-specific disclosures, before the transaction reaches the Audit Committee. What changed in October 2025 regarding RPT disclosure requirements? SEBI issued a circular on October 13, 2025 introducing threshold-based relaxation, easing the minimum information requirements for related party transactions below specific value thresholds while keeping full disclosure requirements for larger and material transactions. Which regulation defines a related party under this framework? Related parties are identified under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. Who does the RPT Industry Standards framework apply to? The framework applies to all listed entities in India that are required to comply with Regulation 23 of the LODR Regulations, covering approval of related party transactions by the Audit Committee and, where material, by shareholders. Talk to Our Team Strengthening internal audit procedures around related party transaction documentation and materiality classification? Pierag's Business Risk Advisory practice helps internal audit functions build verification processes that hold up to SEBI's current RPT Industry Standards. Talk to our team about your RPT compliance readiness. Related reading: Audit Trail: Ensuring Financial Integrity and Accountability | Standard Setters' Updates, H2 2025 Edition
  • 7-12 Min Read
Agile Internal Audits: A Modern Transformation In an era where change is the only constant, traditional internal audit methods can struggle to keep pace. Agile Internal Audits are not just a trend, but a powerful transformation that equips organizations to proactively manage risks while seizing new opportunities. Agile Internal Audit leverages principles from agile project management, creating a modern and flexible approach to internal audits. This methodology enhances responsiveness, efficiency, and effectiveness in today’s rapidly evolving business landscape. Key Benefits of Agile Internal Audit Proactive Risk Management enables organizations to stay ahead of potential threats and navigate uncertainties with agility. Seizing Opportunities allows them to quickly adapt to emerging trends and capitalize on new business prospects. Enhanced Efficiency ensures streamlined processes that provide timely insights and support better decision-making. Agile vs. Traditional Approaches Agile is a working methodology that originated in software development to provide an efficient, iterative approach. Today, it has gained significant traction across various industries, especially in fast-paced, dynamic, and digital business environments. Agile is frequently compared to the traditional Waterfall method, which is more structured and follows a linear sequence of defined stages. While many internal audit functions traditionally adopt a Waterfall approach, there is growing recognition of the benefits of Agile. The shift towards Agile allows for a more collaborative, flexible, and iterative process in planning, scoping, and delivering audit activities. Advantages of Agile Internal Audits Enhanced Collaboration fosters close collaboration between audit teams and stakeholders, ensuring that insights are shared in real-time, leading to more relevant and actionable findings. Improved Adaptability allows internal audit teams to quickly respond to changing business environments and emerging risks, ensuring audits remain timely and impactful. Continuous Feedback and Improvement promotes ongoing evaluation of audit processes through regular interactions and feedback loops, driving continuous improvement and enhancing the overall quality of audits.
  • 5-7 Min Read
This compliance calendar serves as a vital tool for businesses and individuals in India to ensure they meet necessary legal and statutory filling requirements for Income tax, GST, FEMA, MCA, SEZ & STPI throughout the year.
  • 5-6 Min Read
Driving Impact
Business Risk Advisory
Leadership Team
cross-icon
Gaurav Khandelwal
Gaurav Khandelwal
Partner - Risk Advisory Leader
Gaurav is a Risk Advisory Practice Leader at Pierag Consulting, one of the fastest-growing firms in the advisory space. A Chartered Accountant by profession, he is a seasoned Governance, Risk, and Compliance professional with over 20 years of experience in consulting and industry. An ex-Big 4 leader, he is renowned for advising clients on managing risks and assisting large-scale organizations in implementing robust governance frameworks across sectors such as real estate, infrastructure, consumer products, beverages, hospitality, and healthcare. In his industry role, Gaurav was instrumental in driving the culture and implementing frameworks across governance, risk, and compliance. Under his leadership, Tata Realty won prestigious accolades, including the Risk and Compliance Awards at ICICI Lombard and the CNBC TV18 India Risk Management Awards. Earlier, in his leadership roles at Big 4, he led multiple risk-based internal audit engagements for diverse clients, including companies engaged in the operations and maintenance of roads, steel manufacturing across multiple locations, leading players in the Indian credit card market, and liquor manufacturers with several bottling units. He has also worked on enterprise risk management engagements, developing frameworks to effectively identify and address strategic and operational risks through structured monitoring and reporting mechanisms. For instance, he assisted a leading footwear company in re-assessing its ERM framework, prioritizing key risks, and co-developing a comprehensive mitigation plan. Gaurav has extensive experience in compliance program implementation, where he has been responsible for setting up compliance functions and reporting structures, ensuring comprehensive mapping of legal and regulatory requirements across functions, and strengthening ongoing compliance monitoring. Additionally, he successfully managed end-to-end IFC implementation for one of India’s leading healthcare brands, covering 24 hospitals across the country.

Key Expertise and Achievements

  • Risk-Based Internal Audits and Internal Controls Assurance
  • IFC/SOX Readiness, Implementation, and Compliance
  • Enterprise Risk Management Frameworks and Mitigation Planning
  • Business Process Reengineering and Regulatory Compliance
  • Large-scale IFC implementation in the healthcare industry (24 hospitals)
  • Award-winning governance and compliance leadership at Tata Realty.
cross-icon
Gaurav Popli
Gaurav Popli
Partner - Business Risk Advisory
Gaurav Popli is a Partner in the Risk Advisory practice at Pierag. With over 15 years of experience in Risk Advisory, SOX compliance, and Statutory Audit, he specializes in helping organizations go beyond risk management to build resilience and create lasting business value. His career is marked by a deep commitment to clients, having worked extensively with both US SEC-registered and privately held companies. An expert in global talent strategy, Gaurav excels at building and leading high-performing offshore teams, effectively extending support and expertise to US-based clients with efficiency and scale. Gaurav is the go-to expert for organizations aiming to strengthening their control environment. He is a recognized specialist in SOX readiness and compliance, material weakness remediation, and controls rationalization. He has assisted public companies and IPO-bound organizations through the critical process of building robust, yet agile, internal control frameworks. Gaurav has spearheaded numerous initiatives focused on improving operational efficiency and control effectiveness. His approach involves reassessing SOX scoping through targeted risk assessments, rationalizing controls to eliminate redundant activities and reduce testing efforts and aligning processes with automation. Prior to joining Pierag, Gaurav played a defining role with EY GDS in the Assurance practice, serving the US East region. As a Senior Manager, he was instrumental in leading complex listed engagements, first-year audits and startup engagements. Education & Qualifications: Gaurav is a Chartered Accountant and holds a Bachelor of Commerce degree from Shri Guru Tegh Bahadur Khalsa College, University of Delhi.
cross-icon
Adesh Mor
Adesh Mor
Associate Director - Business Risk Advisory
cross-icon
Avinash Jain
Avinash Jain
Associate Director - Business Risk Advisory
Avinash Jain, A Chartered Accountant with over a decade of experience in Internal Audit, SOX compliance, and Business Risk Consulting, he helps organizations strengthen governance, streamline reporting, and scale effectively without compromising control. Avinash is recognized for combining deep technical expertise with a pragmatic approach to risk management, delivering actionable insights that enhance resilience and operational effectiveness. Prior to joining Pierag, Avinash worked with EY and PwC India, where he led risk-based internal audits, SOX compliance reviews, and operational process audits across industries including metals & mining, automobiles, auto-ancillary, renewable energy, FMCG, EPC, and pharma. Earlier, at EXL Services, he managed offshoring assignments in SOX compliance and automation-led process control mapping for US clients. His international experience includes a year in Africa conducting internal audits and process reviews for a leading mining company. Avinash is an expert in business process improvement, with extensive work in SOP development, MIS and KPI frameworks, stock and mystery audits, process mining, and due diligence. He has advised management on key processes such as Order to Cash, Procure to Pay, HR & Payroll, Treasury, and Financial Close, and led process re-engineering and ERP transformation projects. He is proficient in SAP audit procedures, data analytics tools such as Alteryx and Power BI, and leading audit platforms including Workiva and AuditBoard. A consistent high performer, Avinash he has been recognized with multiple awards including “Exceptional Team Lead” and “Above and Beyond” for his leadership and impact.
cross-icon
Manoj Verma
Manoj Verma
Associate Director – Risk Advisory

With over 12 years of experience in Internal Audit, SOX & IFC Controls, Compliance Reviews, and Risk Advisory, He specializes in helping organizations strengthen governance, risk and compliance frameworks, enhance control efficiency, and improve operational performance through technology integration and process optimization.

Known for his structured approach and attention to detail, He works closely with businesses to deliver sustainable value by aligning risk management strategies with business priorities. His focus has consistently been on building stakeholder trust, mentoring high-performing teams, and delivering practical, actionable solutions that drive long-term impact. He has led diverse engagements across Manufacturing, FMCG, IT Software, and Outsourcing sectors (KPO/BPO), supporting clients in establishing robust risk and control environments aligned with global best practices.

He is also associated with the Board of Internal Audit at the Institute of Chartered Accountants of India (ICAI) as a Special Invitee, where he actively contributes to national-level initiatives aimed at strengthening India’s internal audit framework.

Prior to joining Pierag, He gained valuable experience with S.S. Kothari Mehta & Company and EXL Services, where he was part of their Risk Advisory practices and contributed to several high-impact projects.

 Beyond work, Manoj is passionate about mentoring young professionals, exploring new ideas that bridge business and technology, and passionate about internal audit transformation. His  belief—“Structured processes and smart automation create sustainable governance”.

 Professional Qualifications: • Chartered Accountant (ICAI) • Bachelor of Commerce

Ready to Take the Next Step in Risk Transformation?
Whether you're preparing for SOX compliance, enhancing internal controls, or transforming your enterprise risk framework, our Business Risk Advisory experts are here to help. We partner with organizations to transform risk into strategic advantage—driving resilience, compliance, and sustainable growth.