IT governance, risk & compliance

Technology risk and compliance, done right the first time.

MAKS IT Consulting helps banks, insurers, asset managers, and public companies build GRC programs, pass SOX and SOC audits, and keep IT controls aligned to NIST, COSO, and ISO.

Mitigate. Assess. Know. Secure.

15+

years in financial services and asset management

13

years at Protiviti, rising to Director

60+

applications in scope on a single GRC integration

8–10

concurrent client engagements led at once

Frameworks and tools
SOX 404J-SOXITGCPCAOBSOC 1SOC 2NISTCOSOISOFedRAMPCSAModel Audit RuleAWSAzureAuditBoard
Why clients call

When the audit, the regulator, or the board is waiting.

Your first SOX 404(b) audit is coming

You need ITGCs scoped, documented, and tested before the auditors arrive.

The last audit was rough

Findings, follow-ups, and rework. You need clean narratives and evidence that holds up.

A customer wants SOC 2

There is no roadmap yet. You need a readiness plan and someone to run it.

Nobody owns GRC

Risk and control registers are missing or stale, and policies need an owner.

You are integrating an acquisition

Dozens of applications, new owners, and controls that have to line up fast.

A regulator is involved

Consent order validation and remediation need independent, well-documented work.

Services

A full resume of GRC services.

Hands-on work across the governance, risk and compliance lifecycle - scoped to what you need, delivered by the person you hire.

01

GRC program buildout

Stand up or mature an IT governance, risk and compliance function that the business can actually run.

What's included
  • IT risk register and IT control register design and upkeep
  • Control ownership, narratives, and walkthrough standards
  • Policy design: cybersecurity, disaster recovery, change management
  • GRC tool selection and rollout (AuditBoard)
  • Control and evidence-collection automation
Frameworks and tools
NISTCOSOISOAuditBoard
DeliverablesRisk and control registers, policy set, GRC operating model, tooling roadmap
02

SOX 404, J-SOX and ITGC

End-to-end IT general controls work for public companies and companies preparing to go public.

What's included
  • Scoping of in-scope applications and infrastructure
  • Walkthroughs, narratives, and process flows
  • Design and operating effectiveness testing
  • Deficiency evaluation: deficiency, significant deficiency, material weakness
  • Coordinating external-auditor reliance to cut duplicate testing
Frameworks and tools
SOX 404(a)/(b)J-SOXITGCPCAOB
DeliverablesScoping memo, test workpapers, deficiency assessments, remediation roadmap
03

Audit and certification readiness

Get ready before the real audit, so auditors get consistent, credible answers up front.

What's included
  • SOC 1 and SOC 2 readiness assessments
  • SOX and NIST readiness assessments
  • Audit evidence execution and validation
  • External auditor and regulator liaison
  • Standardized control narratives and walkthroughs with control and app owners
Frameworks and tools
SOC 1SOC 2SOXNIST
DeliverablesReadiness gap report, evidence plan, remediation tracker
04

IT risk and change governance

Risk-informed oversight of production changes and projects, so gaps are caught before go-live.

What's included
  • Risk review of production and change requests
  • Access, segregation of duties (SOD), and logging reviews
  • User access reviews and QA across in-scope applications
  • Pre-go-live risk and control guidance for SDLC changes
  • Application and control inventory with legacy / high-risk flags
Frameworks and tools
SODChange managementAccess reviewsSDLC
DeliverablesChange approval criteria, access review results, application risk inventory
05

Cloud and third-party risk

Governance for the systems and vendors you do not run yourself.

What's included
  • Cloud governance reviews and adoption guardrails
  • Hands-on AWS and Azure configuration assessments (IAM, logging, network)
  • Shared-responsibility and control-ownership mapping
  • Vendor risk program gap assessments and remediation plans
  • SOC 1 / SOC 2 report reviews, including user-entity controls
Frameworks and tools
NIST 800-145NIST 500-322FedRAMPCSAAWSAzure
DeliverablesCloud governance roadmap, vendor risk program plan, SOC report reviews
06

Regulatory remediation and transactions

Independent validation and hands-on support when the stakes are high.

What's included
  • Consent order validation testing and remediation
  • Validation of consumer redress
  • IPO readiness and first-year SOX support
  • M&A due diligence on IT controls
  • GRC for post-acquisition integrations
Frameworks and tools
Reg EConsent ordersIPO readinessDue diligenceModel Audit Rule
DeliverablesValidation reports, steering committee updates, integration control plan
Selected experience

Work that has held up in front of auditors and regulators.

Representative engagements. Client names withheld.

Global consumer products company

Enterprise GRC buildout

Deputy to the Head of Compliance on a 6-person team for about 2.5 years. Built the IT risk and control registers, served as main contact for external auditors and regulators, wrote cybersecurity, DR, and change management policies, and selected and rolled out AuditBoard.

Large U.S. financial services firm

Consent order validation

Program manager for a roughly 14-person team on a Reg E consent order: validation testing of corrective actions, control testing, and validation of consumer redress, with updates to the steering committee and regulators.

Real estate services company, pre-IPO

First-year SOX 404(b)

Designed and implemented the ITGC framework ahead of the IPO, partnered with external auditors on the first 404(b) audit, and managed ITGC testing through the first three years as a public company.

Fortune 100 global bank

Bank application and infrastructure audits

About 18 months of application and infrastructure audits, issue validation, and remediation across capacity, data integrity, security administration, event management, and logging.

Fortune 100 insurer

Access remediation at scale

User-access remediation across 51 applications, plus a Model Audit Rule assessment for a large U.S. mutual life insurer.

Consulting engagement

Turnaround of a failing engagement

Took over an engagement running at a negative margin and brought it back to about 30% by resetting scope, staffing, and budget.

Includes engagements delivered during Amar's 13 years at Protiviti.

Industries

Built for regulated industries.

Banking
Insurance
Asset management
Consumer products
Real estate
Pharma
The MAKS approach

Mitigate. Assess. Know. Secure.

Four ideas behind every engagement - and the letters in our name.

M

Mitigate

Close the gaps that matter most first, with controls and remediation teams can actually run.

A

Assess

Inventory systems and controls, test design and operating effectiveness, and rank risk honestly.

K

Know

Give executives, audit committees, and regulators a clear, current view of risk and progress.

S

Secure

Keep controls aligned to NIST, COSO, and ISO, with evidence ready before the auditors ask.

About

Senior GRC expertise, without the big-firm layers.

MAKS IT Consulting Inc. is a New York firm led by Daleepchan (Amar) Sewnarine, a technology risk and compliance leader with more than 15 years in financial services and asset management.

Before founding MAKS, Amar spent 13 years at Protiviti, the global risk consulting firm, rising from IT Risk Consultant to Director. He ran up to 8–10 client engagements at once, owned their plans, budgets, and staffing, and built GRC functions and SOX / ITGC programs for banks, insurers, and other regulated firms.

Today he leads GRC work hands-on and reports risk directly to CISOs, CIOs, and COOs. He is as comfortable testing a control as presenting risk to the C-suite.

Certifications

  • Certified Information Systems Auditor (CISA)
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • ITIL Foundation (v3)

Education

  • B.S., Computer Science, Pace University

How we engage

  • Project-based assessments and audits
  • Co-sourced SOX and internal IT audit support
  • Ongoing GRC leadership

Facing an audit, a new framework, or a GRC gap?

Send a note and we'll get back to you.

info@maksitconsultinginc.com