Compliance and testing of internal control elements

Three professionals, a man and two women working at a workdesk on computers. One of the women pointing out data on the screen.
Three female colleagues at the table, looking into the camera
Independent assurance over compliance and the effectiveness of internal controls helps strengthen trust and decision-making

Organisations increasingly need to demonstrate that key requirements, agreements, controls and reporting practices meet expectations. Compliance opinions and testing of internal control elements help provide assurance to management, owners, lenders, regulators and other stakeholders.

Documented processes alone are not enough — organisations are often expected to provide independent confirmation that requirements have been met and controls are operating effectively in practice. Well-targeted assurance helps increase trust in financial information and reporting, confirm compliance with contractual and regulatory requirements, assess control effectiveness and identify weaknesses before they become significant issues.

At PwC, we know that complex compliance and control questions often call for multidisciplinary expertise. So we combine assurance services with experience in financial reporting, risk management, internal control, information security, compliance, technology, and regulation.

This combination creates more value for you: broader risk coverage, greater reliability, and clearer insights that help you, your management team, and other stakeholders act with confidence.


How we can help

Compliance opinions

We provide compliance assessment services based on the objective of the engagement and the client’s needs. Our team performs work in accordance with international standards, including ISRS 4400 “Agreed-Upon Procedures Engagements” and ISAE 3000 “Assurance Engagements Other than Audits or Reviews of Historical Financial Information”, and tailors the scope based on the required level of assurance.

We support organisations in areas including:

  • Assessing compliance with laws, regulations or internal requirements;
  • Reviewing and testing financial information;
  • Assessing compliance with loan agreements or banking covenants;
  • Performing agreed-upon procedures and other assurance engagements.

Funded project compliance assessment

For funded projects, it is important that project activities, costs and reporting are aligned with the funder’s conditions and relevant requirements. An independent assessment helps clarify whether the project has been implemented in accordance with agreed conditions and whether documentation and cost treatment support the proper use of funding.

PwC performs independent assessments of projects funded by European Union funds, state support measures, foreign aid or other funding sources. We tailor our approach to the specific project conditions, funder expectations and required assurance level, and we provide services according to ISRS 4400 ‘Agreed-Upon Procedures Engagements’ (Revised) and ISAE 3000 ‘Assurance Engagements Other than Audits or Reviews of Historical Financial Information’ (Revised).

We support organisations in areas including:

  • Assessing the compliance of project-related costs and reporting;
  • Assessing whether project activities and implementation are aligned with funding conditions;
  • Reviewing project documentation and supporting evidence;
  • Assessing control points arising from funder requirements;
  • Preparing independent reports or confirmations in line with project requirements.

Assessment on internal Control framework

Effective internal control is a cornerstone of risk management and the control environment. A well-designed internal control system helps organisations achieve their objectives and protect themselves from financial, operational and strategic risks. As organisations, processes and risks evolve, internal control also needs continuous review and improvement.

PwC helps organisations design and assess internal control systems based on the COSO integrated framework, taking into account the organisation’s size, complexity, business model and risk profile.

We support clients in areas including:

  • Designing internal control systems tailored to organisational needs;
  • Establishing elements of the control environment, including procedures, policies, risk assessments and other components of the internal control framework;
  • Assessing existing internal control systems;
  • Reviewing internal control elements and key controls;
  • Identifying weaknesses, gaps and improvement areas;
  • Providing recommendations to strengthen and improve the control environment.

A pictogram depicting a professional team

Experienced Estonian professionals in assurance, compliance and internal control


A pictogram depicting combined gears inside a head

Ability to combine financial, risk, control and regulatory expertise



A pictogram depicting the globe

Strong knowledge of international standards and practical implementation


A pictogram depicting a check mark

A clear and independent approach that supports decision-making and trust


Contact us

Karin Grents

Karin Grents

Leader of Governance, Risk, Compliance (GRC), and Internal Audit services, PwC Estonia

Tel: +372 614 1800

Follow us

Required fields are marked with an asterisk(*)

By clicking the "Submit" button, you consent to the processing of your personal data. You have the right to withdraw your consent at any time by sending an email to ee_info@pwc.com or ee_legal@pwc.com. The withdrawal of consent shall not affect the lawfulness of any processing carried out on the basis of your consent prior to its withdrawal. Please refer to our Privacy Statement for further information on how your personal data is processed.

Hide