Services / Consulting and Advisory / Information Security & Technology Risk Advisory
Helping organisations understand whether their technology, systems and controls are actually protected, resilient and operating the way they’re supposed to, from security testing and architecture through to licensing exposure, system implementation and operational resilience.
A system is often labelled non-critical because the business can survive without it for a defined period. That's a reasonable starting test. It rarely asks what obligation, regulatory, contractual, or simply owed to a customer, might fall due exactly while the system is unavailable.
bmpro tests technology and controls against that kind of question: not just whether something is protected or resilient on paper, but whether it holds up against the specific obligations, dependencies and consequences the organisation actually has.
The same gap shows up in different forms. A system can be securely configured in isolation and still be exposed once it's connected to everything around it. A contract can specify what an organisation is licensed to use, and the live environment can have quietly drifted away from what that contract assumed. A control can run every month without anyone confirming it actually worked the last time it mattered.
bmpro's work here spans security testing and architecture, licensing exposure, system implementation reviews, and independent controls testing, treated as one discipline: checking whether protection and control are real in practice, not just documented as existing.
The specifics differ by capability, but the shape holds across ITGC, licensing, decisioning controls and resilience.
Define the systems, processes and controls that actually matter for this engagement, not a generic checklist.
Connect controls, risks and requirements to the systems and evidence that will prove or disprove them.
Evaluate operation through system records, configuration, logs and other primary evidence, not screenshots of policy.
Push on the evidence through targeted testing, walkthroughs and sampling to establish what actually held up.
Translate exceptions and evidence gaps into clear conclusions and a prioritised remediation roadmap.
Our teams use AI across research, analysis, testing and evidence evaluation, not as a bolt-on tool but as part of how the work gets done, increasing the depth, speed and consistency of the assurance itself. Where appropriate, evidence collection and discovery can be performed by the client's own team using read-only methods, so independence and client control aren't traded away for speed.
The layer everything else depends on is usually the one nobody tests. We assess whether the technology controls underpinning applications, data and business processes, identity and access, change management, IT operations, backup and infrastructure, are designed appropriately and actually operating, not just documented as existing.
A licensing liability rarely sits inside a single product, it emerges from how the technology estate connects. We reconstruct the contractual position, trace how software is actually deployed and consumed across applications, infrastructure and cloud, and establish the facts before a vendor does, so you have an evidence-based position on exposure rather than a defensive scramble during an audit.
Documentation says a control exists. We test whether it actually fires. That means validating business rules engine logic, APIs and decision flows directly against structured test cases, not configuration screenshots, and it extends into production: model and version management, deployment, monitoring and change control for the automated decisioning already running the business. Where that decisioning involves AI or ML specifically, it connects directly to the explainability and versioning work on our AI Advisory page.
A recovery plan is not the same as recovery capability. We start with an independent business impact analysis to establish which systems are genuinely critical, then test whether the business continuity, disaster recovery and cyber resilience assigned to each tier actually holds, through scenario testing and simulation, not just a document nobody has opened since it was signed off.
RBI, SEBI, DPDP and ICFR each reach into different parts of the technology estate, rarely the same part twice. A regulatory response spans exactly as many capabilities as the regulation actually touches, never just one.
| Regulatory driver | ITGC | App/Sys controls | Security | BC/DR | Implementation |
|---|---|---|---|---|---|
| RBI IT Governance, Risk, Controls & Assurance Directions, 2023 | ✓ | ✓ | ✓ | ✓ | |
| SEBI Cybersecurity & Cyber Resilience Framework (CSCRF), 2024 | ✓ | ✓ | |||
| DPDP Act, 2023 | ✓ | ✓ | |||
| ICFR (Companies Act / SEBI LODR) | ✓ | ✓ |
Applicability varies by entity type: RBI Directions apply to regulated banks and NBFCs, SEBI CSCRF to regulated securities-market entities, DPDP Act across sectors, and ICFR to listed companies. A client's actual footprint may sit under one, several, or none of these.
Talk to us about information security and technology risk.
Get in touch →