
Risk Consulting
Services
Risk Consulting is a specialized field of management consulting that helps organizations develop strategies to manage business risks through internal audit & control self-assessment initiatives
McKell Risk Management Pte Ltd, established in 2017, is a progressive and forward-looking Risk Consulting firm that commits to ethical and sustainable business practices. We specialize in internal audit and risk solutions, serving all business sectors.
Dedomena Technologies operates as the Technology Risk Management (TRM) division, offering IT consulting and DPO-as-a-Service solutions. It is also the business brand name of the firm.
McKell Risk Assurance division provides services in Internal Audit, IT Audit, Control Self-Assessment, Risk Assurance, and Strategic Business Review.
Since our establishment in 2017, we have opted for organic growth, identifying and targeting businesses that would benefit from our specialized services, rather than pursuing aggressive expansion strategies.
Our niche consultancy delivers expert counsel and strategic guidance while implementing practical and tailored risk solutions that generate positive outcomes for our clients, partners, and their evolving communities.
We function independently from any ownership affiliations in connection with Public Accounting Corporations or Corporate Service Provider (CSP) entities in Singapore or overseas.



Strategic Partnership
We operate on a zero-employees and skill-based project business model that leverages AI technologies, process automation and external expertise of various professional partners and associates including accountancy, legal, technology firms and qualified individuals, instead of relying on permanent staff to deliver specific project outcomes.
Our operating model allows for rapid scaling of capabilities to meet specific demand of projects, pursue emerging opportunities, increase in productivity, achieve cost optimization through elimination of fixed costs, and deliver added value in our service offerings to our clientele.
We engage in bilateral collaboration with our external partners, as we also provide risk consulting expertise to support their projects while they assist with ours. We execute non-disclosure agreements with all our strategic partners to provide mutual assurance that our client-related information remains confidential and protected.

Fractional Professional Role
The Director welcomes invitations for him to serve in interim operational, managerial or executive role with organizations, including existing and potential clients, as well as external partners. These engagements, limited to six months in duration, allow organizations to benefit from his seasoned leadership experience and expertise in the following domains:
• Internal Audit and Risk Management • IT Audit and Consulting • Financial Planning & Analysis • Internal Control over Financial Reporting • Strategic Finance & Cost Management • Data Privacy Advisory • ESG Reporting Advisory
From a strategic perspective, this arrangement provides our clients with greater flexibility and more options regarding service types, particularly in terms of more personalized and dedicated solutions that would be optimally suited to their specific circumstances.

Our Risk Services
*
Our Risk Services *
Outsourced DPO Services
Basic Services Package
o Ensuring PDPA Compliance
We facilitate and validate the data protection self-assessment conducted by organizations through the PDPA Assessment Tool for Organizations (PATO) and Data Inventory Map (DIM) techniques.
Advise on the development of privacy statements and PDPA compliant policies and protection measures.
o Fostering a Data Protection Culture
Provide PDPA consultancy services, and training and education programs to all staff members based on the Personal Data Protection Commission's (PDPC) Advisory Guidelines on Key Concepts in the PDPA.
o Efficient Handling of Data Inquiries
o Alert Management on Personal Data Risks
o Liaise with PDPC when required
o Develop and Implement Data Breach Response Plan
Advanced Services Package with add-on
o Advisory with guided implementation of the Data Protection Essentials (DPE), Data Protection Management Programme (DPMP), Data Protection by Design for ICT Systems, and Data Protection Impact Assessment (DPIA).
o Training and education program extended to include the Advisory Guidelines on the PDPA for Selected Topics and the Guide to Basic Anonymisation.
o Advise with guided implementation of Advanced Data Protection Practices in accordance with the PDPC's Guide to Data Protection Practices for ICT Systems.
PDPA Audit
A systematic assessment of the organization’s data protection policies and procedures, conducted based on a risk-based internal audit methodology, evaluates compliance with Data Protection Obligations under the PDPA. This review identifies compliance gaps and risks in data protection practices through controls testing and provide recommendations for remediation plans according to the PDPA and data protection best practices.
Strategic Business Review (PEIs)
We conduct independent business review of Private Educational Institutions (PEI) as required by the credit bureau to assign them the credit rating needed for their registration renewal under the Enhanced Registration Framework (ERF). Key review areas encompass the PEI’s 5-year strategic and financial sustainability plan, governance structures, cost rationalization program, risk management system, and opportunity identification.
Sustainability Reporting Services
Our sustainability reporting services provide support to organizations in developing and implementing their sustainability reporting roadmap and drafting the sustainability report that align with the GRI standards and other relevant frameworks. We also conduct internal review on the sustainability reporting process in accordance with the International Standards for the Professional Practice of Internal Auditing issued by The Institute of Internal Auditors.
IT Audit and Risk Assessment
(A) An independent technology audit encompassing audit program development, execution of test procedures, and issuance of formal reports, detailing findings and proposing remedial measures for enhancement to IT controls, systems, modifications, and upgrades.
(B) Attest to the risk and control self-assessment conducted by the organization on its IT systems by formally validating the assessment methodology and results.
(C) Our Data Protection Officer (DPO)-as-a-Service incorporates IT risk assessment components, with scope and depth tailored to meet specific client requirements.
(D) Our Internal audit services consistently encompass the evaluation of the adequacy and effectiveness of the organization’s IT controls as per regulatory and licensing requirements, and organizational business objectives.
IT Audit for Statutory Audit
IT audit that supports financial statement audit by examining the technology that handles financial data.
Singapore Standard on Auditing (SSA) 315 (Revised) requires the auditor to identify and assess the risks of material misstatement in the financial statements, through understanding the entity and its environment, including the entity’s IT control. With an in depth understanding of the entity’s IT environment, it enables the auditor to identify the IT risks, and to design and implement appropriate audit responses to address those identified risks
Leveraging our specialized IT audit expertise, we provide support to Public Accounting Corporations (PAC), in evaluating their audit clients' IT controls in their effectiveness in safeguarding assets, and preventing or detecting material misstatements, enabling the external auditors to determine the nature and extent of audit procedures.
Control Self-Assessment (CSA)
Control Self-Assessment (CSA) is an effective risk management tools recommended by the Audit Committee Guidance Committee (ACGC) Guidelines for the Board and audit committees to give an informed opinion on the state of internal controls and risk management systems of the organization.
CSA on financial reporting quality is a process where a company's employees from the finance, operation and business functions evaluate the effectiveness of their internal controls over financial reporting. It helps ensure that financial statements are accurate, reliable, and compliant with accounting standards and regulatory requirements, thereby reducing the risk of material misstatements.
CSA and internal audits are both methods for evaluating an organization's internal controls, but they differ in their focus and execution. CSA emphasizes proactive involvement by operational staff in assessing their own controls, while internal audits are conducted by a separate, objective function to evaluate existing controls and provide independent assurance. CSA can be used by internal auditors to gather information, focus on high-risk areas, and facilitate effective audit planning.
We work with you to tailor a pragmatic approach that best deploys CSA in your organization.
Risk Management Services
Our firm specializes in technology and operational risk management services, assisting organizations in identifying, assessing, evaluating, prioritizing, and mitigating specific risks that could adversely affect their operations, financial stability, and overall success. Through this systematic and structured approach, we help clients minimize potential losses and enhance their capacity to navigate uncertainties.
Cybersecurity Consulting
We help organizations to measure and track their progress in cybersecurity health by implementing the Cybersecurity Health Check tool developed and launched by the Cyber Security Agency of Singapore (CSA), recommending solutions to close any gaps identified and enhance cybersecurity controls in enabling organizations to attain the Cyber Essentials certification.
Internal Audit
Internal Audit Outsourcing
As the outsourced internal auditor reporting to the Board Audit Committee, we conduct objective and independent internal audits to evaluate your organization's compliance, financial, technological, and operational controls, and risk management systems through comprehensive audit planning and execution.
Internal Audit Co-sourcing
We serve as external internal auditors to complement your internal audit department by providing the expertise, insights and assurance you need to deliver against your objectives and meet the board's expectations.
Our internal audit service engagements adhere to the International Standards for the Professional Practice of Internal Auditing, as issued by The Institute of Internal Auditors, and concentrate on one or more of the following key business processes and risk trends:
Internal control over financial reporting
Financial management
Procure-to-pay (Expense Cycle) and order-to-cash (Revenue Cycle)
Supply chain, third-party risk and contract management
Data Protection (PDPA)
Information security and computer operations
Cybersecurity
Business continuity
Regulatory change
Sustainability reporting process
Enterprise risk management system and policy (including technology risk management)
Organizational culture and ethics
Health and safety
Clientele and External Partners
Companies listed on the SGX Mainboard, along with their subsidiaries and principal third-party vendors operating in property development and investment, real estate, serviced residences, and construction engineering sectors
Catalist listed company in the water treatment industry
Heavy equipment and mining company in Indonesia
Korean global engineering and construction conglomerate
Multi-specialty hospital in Indonesia owned by
private equity firm & Indonesia-based investment management company
Payment service provider
Software platform developer
Mobile entertainment and marketing services
E-Commerce startup
EdTech
Cryptocurrency and NFT Project company
Private Education Institutions (PEI)
Corporate training services
Social Enterprise
Food and Beverages
Registered Fund Management company
MINDEF-Related Organizations (MROs) including country club and media company
Commodities and Biofuels
Chemical Manufacturing
AND
Our external network of Strategic Collaborative Partners in these sectors:
Public Accounting Corporation
Risk Advisory Firm
Technology Firm
Finance transformation and digitalization
Licensed Cybersecurity Firm
Legal Firm
and other professional individuals who possess the Chartered Accountant and/or Certified Internal Auditor credentials
