Certificates and attestations for IT systems and digital business models

Build trust with customers, auditors and regulatory authorities – through independent IT audits and certifications in accordance with recognised national and international standards.

[Translate to English:] Testate und Bescheinigungen

Why certificates and attestations are crucial

With the increasing digitalisation of accounting-related processes, the use of complex IT systems and new digital business models, the requirements for compliance, security and traceability are rising significantly. Companies are faced with the task of making IT risks transparent, designing effective internal controls and providing robust evidence to auditors, customers and regulatory authorities.

GKK PARTNERS supports you in this with independent IT audits, as well as attestations and certificates in accordance with recognised national and international standards – carried out by certified IT auditors and statutory auditors, in a practical and transparent manner, and with a deep understanding of IT, regulation and audit requirements.

Clarify audit requirements

[Translate to English:] IT-Pruefung

IT audit in accordance with ISA 315

IT-Risiken erkennen und Prüfungssicherheit schaffen.

IT-related audit procedures in accordance with ISA 315 form an integral part of a risk-based audit approach within the context of the audit of the annual financial statements. They serve to understand the IT systems and IT controls relevant to financial reporting, as well as to identify and assess risks of material misstatement in the financial statements.

Through a structured assessment of IT systems and IT processes, you create transparency regarding IT-related risks in financial reporting and establish a sound basis for the assessment and targeted further development of the internal control system. You support the transparent application of professional standards and help to ensure that the audit is conducted efficiently and in a targeted manner.

Coordinate your IT audit now

Find out more about IT audits in accordance with ISA 315 ...
  • Conducting the IT audit in accordance with ISA 315 by experienced, CISA-certified IT auditors
  • Close collaboration with the audit team
  • Preparation of a management letter containing practical recommendations for action
  • Optional: Preparation of a comprehensive IT audit report for your working papers

On request, we can also carry out our IT audit outside the scope of the annual audit in accordance with IDW PS 860.

[Translate to English:] ERP-Projekt

Audit services during ERP implementations (IDW PS 850)

Implementing ERP projects in a way that stands up to audit scrutiny.

As part of an audit accompanying the project in accordance with IDW PS 850, we assess the compliance and adequacy of selected processes and controls during the implementation of ERP systems. The aim is to identify audit-relevant issues at an early stage and to support the incorporation of regulatory requirements throughout the course of the project. This creates transparency from an audit perspective and provides a solid foundation for the subsequent annual audit. By involving the statutory auditor at an early stage throughout the project, regulatory risks can be addressed whilst the project is still underway.

Ensure your ERP project is audit-ready now

Find out more about project-based auditing during ERP implementations...

Support throughout the ERP implementation project

  • Support across all relevant project phases from a technical, organisational and regulatory perspective – from planning through to go-live
  • Early identification of process-related, compliance-related and audit-related risks
  • Ensuring compliance with the requirements for regularity, security and controls in accordance with GoBD and IDW RS FAIT 1
  • Acting as an independent sounding board between business departments, IT and external implementation partners
[Translate to English:] KRITIS

KRITIS Audits

Ensure Compliance with Legal Documentation Requirements.

Operators of critical infrastructure are required to demonstrate every two years that appropriate state-of-the-art technical and organizational measures have been implemented to prevent disruptions to availability and information security. This evidence must be provided to the Federal Office for Information Security (BSI) as part of a KRITIS audit.

We support you in conducting KRITIS audits and in the structured preparation of the required supporting documentation. Our certified IT specialists ensure a technically sound audit, clear results, and smooth communication with the relevant authorities.

Prepare for your KRITIS audit now

Learn more about the KRITIS audit...
  • Kick-off and Audit Planning
  • On-Site Audit
  • Compilation of Results
  • Submission of Documentation to the BSI
  • Communication with the KRITIS Contact Point
[Translate to English:] BSI

BSI-C5-Testat

Building trust in cloud services and digital business models.

BSI C5 is a set of criteria developed by the Federal Office for Information Security (BSI) to assess the information security of cloud services. The C5 certificate serves as recognised proof that a cloud service meets key security and compliance requirements and builds trust among customers, business partners and regulatory authorities.

As part of the audit, the cloud service’s service-related internal control system is assessed – including in areas such as information security management, IT organisation, access controls, and incident and emergency management. As independent auditors, we support you in obtaining your C5 certificate in a practical, audit-proof and efficient manner.

Arrange your BSI C5 certificate now

Find out more about the BSI-C5 certificate...

Joint workshop (maturity assessment)

  • Compilation of the system description for the service-related internal control system (ICS) based on the BSI-C5 basic criteria
  • Identification of deviations from the BSI-C5 basic criteria
  • Joint definition of the target state for the system description in accordance with the C5 basic criteria
  • Delimitation of services, e.g. IT sub-service providers

Conducting the audit based on the BSI-C5 criteria

  • Auditing the system description of the service-related ICS drawn up for the provision of the cloud service
  • Conducting the audit on the basis of the statutory representatives’ statement regarding the adequacy of the controls
  • Assessing the effectiveness of the controls over the audit period (Type 2 reporting)
[Translate to English:] Softwarebescheinigung

Software certificates (IDW PS 880)

Legal certainty and trust for accounting-related software solutions.

Accounting-related software solutions must comply with the commercial and tax law requirements for proper bookkeeping. With a software attestation in accordance with IDW PS 880, you can demonstrate that your software reliably supports these requirements – for example, in accordance with GoBD.

The certification provides transparency regarding how the software operates, strengthens the trust of customers, auditors and business partners, and is often a decisive factor in the selection and purchasing decision. Our audit is conducted independently and in accordance with recognised professional standards.

Arrange your software certification now

Find out more about software certification:
  • Determining the scope of the audit for the software attestation
  • Carrying out the design and functional testing of the software
  • Documenting the results in an audit report
  • Preparing the software attestation in accordance with IDW PS 880
[Translate to English:] Outsourcing

Outsourcing Assurances (IDW PS 951, ISAE 3402)

Trust and transparency in outsourced IT and business processes.

When IT or business processes are outsourced to external service providers, customers, business partners and statutory auditors expect reliable evidence that these processes are properly managed and audited. Outsourcing certificates in accordance with IDW PS 951 or ISAE 3402 provide precisely this evidence.

With this assurance report, you demonstrate that the service-related internal control system is appropriately designed and that the relevant controls were effectively implemented during the audit period. This strengthens your customers’ trust, reduces queries during the statutory audit and is often a prerequisite for concluding contracts or participating in tenders.

Our audit is conducted independently, transparently and in accordance with recognised national and international auditing standards.

Arrange your outsourcing attestation now

Find out more about outsourcing certificates (IDW PS 951 / ISAE 3402)...

Assessment of the adequacy of the internal control system

  • Reaching a common understanding of the structure and functioning of the internal control system
  • Structured review of processes with the relevant contacts
  • Review and evaluation of the relevant internal control system documentation and guidelines
  • Assessment of whether the existing control system is, in principle, suitable for meeting the defined control objectives

Assessment of the effectiveness of the controls

  • Assessment of whether the defined controls were implemented as intended during the audit period
  • Assessment of whether the controls are suitable for effectively addressing the described risks

Preparation of the attestation

  • Reporting on the audit of the service-related internal control system
  • Issuing an IDW PS 951 Type 2 or ISAE 3402 Type 2 assurance report as robust evidence for clients and business partners

Back to the overview

CAREER
Scroll down Scroll down