
Risk Consulting Services
We Help You Develop Strategies to Manage Your Business Risks

Mckell Risk Management Pte Ltd, established in 2017, is a Singapore-based Risk Consulting firm specializing in project-based solutions. The company delivers targeted services in strategy, internal auditing, ESG, outsourced DPO, cybersecurity advisory and information technology audit with its strategic partners under collaborative arrangements. Additionally, the firm serves its direct clientele for smaller-scale projects.
Dedomena Technologies operates as the Data Protection Consultancy and Technology Risk Management division and serves as the business brand name of the firm. The McKell Risk Assurance Services division provides services in Risk and Control Assurance, and Strategic Business Review.
Our boutique consultancy specializes in niche project-based services, emphasizing the development of enduring partnerships with collaborators and clients. We deliver expert counsel and strategic guidance while implementing practical solutions that generate positive outcomes for our partners and their evolving communities.
Outsourced DPO Services
1. Basic Services Package
o Ensuring PDPA Compliance
Data Protection Self-Assessment conducted through the PDPA Assessment Tool for Organizations (PATO) and Data Inventory Map (DIM) techniques.
Review and develop Privacy Statements, Policies and Measures, and Data Governance Frameworks.
o Fostering a Data Protection Culture
Deliver Personal Data Protection Act (PDPA) consultancy services and training programs to all staff members, in accordance with: 1) Personal Data Protection Commission's (PDPC) Advisory Guidelines on Key Concepts in the PDPA, and 2) Advisory Guidelines on the PDPA for Selected Topics.
o Cybersecurity advisory and training
Delivering comprehensive training, professional guidance and disseminating essential information regarding IT risks, information security and cybersecurity fundamentals throughout the organization.
o Efficient Handling of Data Inquiries
o Alert Management on Personal Data Risks
o Liaise with PDPC when required
o Data Breach Response Plan
2. Advanced Services Package with add-on:
o Advisory services and guided implementation of Data Protection Essentials (DPE), Data Protection Management Programme (DPMP), Data Protection by Design for ICT Systems, and Data Protection Impact Assessment (DPIA).
o Review or guided implementation of Advanced Data Protection Practices in accordance with the PDPC's Guide to Data Protection Practices for ICT Systems.
We provide our data privacy related services under the service framework of Data Protection and Technology Risk Management.
PDPA Compliance Audit
A systematic assessment of the organization’s data protection policies and procedures, conducted in accordance with internal audit methodology, evaluates compliance with Data Protection Obligations under the PDPA. This review identifies compliance gaps and risks in data protection practices through controls testing and provide recommendations for remediation plans according to the PDPA and best practices.
Strategic Business Review for PEIs
We conduct independent business review of Private Educational Institutions (PEI) as required by the credit bureau to assign them the minimum credit rating needed for their registration renewal under the Enhanced Registration Framework (ERF). Key review areas encompass the PEI’s 5-year strategic and financial sustainability plan, governance structures, risk management system, and opportunity identification.
Sustainability Reporting Services
Our sustainability reporting services provide support to organizations in developing and implementing their sustainability reporting roadmap and drafting the sustainability report that align with the GRI standards and other relevant frameworks. We also conduct internal review on the sustainability reporting process in accordance with the International Standards for the Professional Practice of Internal Auditing issued by The Institute of Internal Auditors.
IT Audit
(A) An independent technology audit encompassing audit program development, execution of test procedures, and issuance of formal reports with authoritative sign-off, detailing findings and proposing remedial measures for systems enhancement, modifications, and upgrades.
[B] Validate and formally attest to the organization's internal information security and/or cybersecurity infrastructure self-assessment by validating the assessment methodology and results.
IT Audit Assistance for Statutory Audit
Leveraging our specialized expertise in IT auditing, we provide support to our external partners, who are Public Accounting Corporations (PAC), in evaluating their audit clients' IT controls. We assess the effectiveness of these controls in safeguarding assets and preventing or detecting material misstatements, enabling them to determine the nature and extent of audit procedures in their audit planning.
We also support PAC in statutory IT audit that requires the attestation of a Public Accountant such as audit that ensures compliance with MAS's Technology Risk Management Guidelines (TRMG) for Financial Institutions.
Control Self-Assessment (CSA)
Control Self-Assessment (CSA) is an effective risk management tools recommended by the Audit Committee Guidance Committee (ACGC) Guidelines for the Board and audit committees to give an informed opinion on the state of internal controls and risk management systems of the organization.
CSA and internal audits are both methods for evaluating an organization's internal controls, but they differ in their focus and execution. CSA emphasizes proactive involvement by operational staff in assessing their own controls, while internal audits are conducted by a separate, objective function to evaluate existing controls and provide independent assurance. CSA can be used by internal auditors to gather information, focus on high-risk areas, and facilitate effective audit planning.
We work with you to tailor a pragmatic approach that best deploys CSA in your organization.
Risk Management Services
Our firm specializes in technology and operational risk management services, assisting organizations in identifying, assessing, evaluating, prioritizing, and mitigating specific risks that could adversely affect their operations, financial stability, and overall success. Through this systematic and structured approach, we help clients minimize potential losses and enhance their capacity to navigate uncertainties.
Cybersecurity Consulting
We help organizations to measure and track their progress in cybersecurity health by implementing the Cybersecurity Health Check tool developed and launched by the Cyber Security Agency of Singapore (CSA), recommending solutions to close any gaps identified and enhance cybersecurity controls in enabling organizations to attain the Cyber Essentials certification.
Internal Audit
Internal Audit Outsourcing: As the outsourced internal auditor reporting to the Board Audit Committee, we conduct objective and independent internal audits to evaluate the organization's compliance, financial, technological, and operational controls through comprehensive planning and execution.
Internal Audit Co-sourcing: We collaborate with organizations' internal audit departments, serving as external internal auditors to complement their existing expertise.
Our internal audit service engagements adhere to the International Standards for the Professional Practice of Internal Auditing, as issued by The Institute of Internal Auditors, and concentrate on one or more of the following key business processes and major risk trends:
Financial reporting controls
Financial management
Procure-to-pay (Expense Cycle) and order-to-cash (Revenue Cycle)
Human capital
Supply chain, third-party risk and contract management
Data Protection (PDPA)
IT and data governance
Information security and computer operations
Cybersecurity
Technology risk management
Digital disruption (AI)
Fraud risk management
Business continuity
Regulatory change
Corporate finance policy
Mergers and acquisitions
Sustainability reporting process
Enterprise risk management system and policy
Organizational culture
Health and safety
Clientele and Partners
Companies listed on the SGX Mainboard, along with their subsidiaries and principal third-party vendors operating in property development and investment, real estate, serviced residences, and construction engineering sectors
Catalist listed company in the water treatment industry
Heavy equipment and mining company in Indonesia
Korean global engineering and construction conglomerate
Multi-specialty hospital in Indonesia owned by
private equity firm & Indonesia-based investment management company
Payment service provider
Software platform developer
Mobile entertainment and marketing services
E-Commerce startup
EdTech
Cryptocurrency and NFT Project company
Private Education Institutions (PEI)
Corporate training services
Social Enterprise
Food and Beverages
Registered Fund Management company
MINDEF-Related Organization (MRO) including country club and media company
Commodities and Biofuels
Chemical Manufacturing
AND
Our external network of Collaborative Partners in these sectors:
Public Accounting Corporation
Risk Advisory Firm
Technology Firm
Data Analytics Consulting Firm
Licensed Cybersecurity Firm
Legal Firm