Skip to content

Technology risk · assurance · governance

Half the challenge is knowing which risks you actually face.

We test the controls behind your core systems and tell you, plainly, where they hold and where they don’t. Independent assurance for banks, telcos and development organisations across eleven African markets.

11

African markets

6

professional certifications held

4

client sectors served

2016

practising since

The practice

Rosewood is an independent technology risk and assurance firm in Nairobi. We test whether the controls inside your core systems are designed properly and operating the way you believe they are — then we write down what we found, rank it by consequence, and retest until it is closed.

Five practices cover the ground: control reviews, information security assurance including CEH-led penetration testing, technology governance, business continuity, and assurance over technology programmes while they are still in flight.

Discipline
Technology risk, assurance and governance. Independent review, not implementation.
Clients
Banks and payment providers, telcos and mobile money, development agencies, NGOs and the public sector.
Coverage
Eleven African markets, delivered from Nairobi and on site — which keeps the day rate local.
Independence
We assure technology. We do not sell it, resell it or take a margin on it, so a finding that points at a vendor changes nothing about our position.

In the field

Where the work happens, and what it leaves behind.

01/06

The Nairobi skyline at sunset, the high-rise district and Britam Tower standing above the treeline.
00 Nairobi, where the work is delivered from

00 · Nairobi

Based in Nairobi, working across eleven markets.

Engagements are delivered from Nairobi and on site. That keeps the day rate closer to a local one than a fly-in one, and it means the team has already met the regulator you are answering to.

Market coverage KE UG TZ ZW MU RW EG ZM GH ZA MZ KE · Nairobi baseDelivered 11 / 11 Kenya · Uganda · Tanzania · Zimbabwe · Mauritius Rwanda · Egypt · Zambia · Ghana · South AfricaMozambique
About the firm
Stacks of tabbed and bound working papers on a desk in an office.
SVC-01 Working papers from a control review

SVC-01 · System reviews

We test the controls, then show you the evidence.

Every control in scope is named, owned, tested and scored. Where one fails, the exceptions register says what it exposes and what it costs to leave open — so the remediation argument is already made for you.

Control matrix · extractControl Design Operation Evidence C-01C-02C-03C-04C-05operating as designed exception — raised, owned, dated
Open SVC-01
A server cabinet seen head on, densely patched with fibre and dotted with status lights.
SVC-02 Infrastructure in scope for testing

SVC-02 · Security

CEH-led penetration testing, ranked by what an attacker reaches first.

Findings arrive with reproduction steps, not just a score. Anything critical reaches you the day we confirm it, and we retest and confirm closure in writing for your evidence file.

Findings by exploitabilityCritical 03 Reachable from outside. Reported the day it is confirmed.High 07 Reachable once inside. Fixed inside the engagement.Medium 14 Needs a chain of conditions. Scheduled, not rushed.Low 21 Recorded so the next tester is not rediscovering it.Each finding ships with reproduction steps
Open SVC-02
An empty boardroom table in front of a floor-to-ceiling window looking over a city at dusk.
SVC-03 Where the technology risk position is tabled

SVC-03 · Governance

Technology risk the board can actually hold someone to.

Decision rights, escalation paths and a risk register short enough that the board reads all of it. The same figures each quarter, meaning the same thing each quarter.

Accountability, top down Board Sets appetite · accepts residual risk Executive Owns remediation · reports quarterly Operations Runs the control · keeps the evidence appetite down position up Same figures, same meaning, every quarter
Open SVC-03
An operator seen from behind at a console, facing a wall of monitors in an operations centre.
SVC-04 Monitoring through a failover rehearsal

SVC-04 · Continuity

Recovery plans somebody has rehearsed at three in the morning.

The business impact analysis says what breaks first, what it costs per hour and in what order it comes back. Then we test it, and the test results go in the file next to the plan.

Service level · incident to recovery100%0%RPORTORPO · data you can afford to loseRTO · time you can afford to be downincidentrestored
Open SVC-04
Plans spread across a table with drafting pencils, a scale rule and a plan tube resting on them.
SVC-05 The plan, while it can still be changed

SVC-05 · Programmes

Assurance while the decisions are still reversible.

We sit alongside the programme, not after it. Each gate produces a one-page risk position and the decisions it demands — a defensible yes or no on go-live, with the conditions attached.

Programme gates · assurance pointsG0CaseG1DesignG2BuildG3Go-liveG4BenefitGOHOLDConditionsattached toeither answerOne-page risk position issued at every gate
Open SVC-05

The firm

We were built out of the practice, not around it.

Founded by technology professionals who had spent their careers on the other side of the audit.

Rosewood was founded by technology professionals with risk and technology management experience across eleven African markets — Kenya, Uganda, Tanzania, Zimbabwe, Mauritius, Rwanda, Egypt, Zambia, Ghana, South Africa and Mozambique.

The team holds local and international qualifications across the spectrum of technology and its risk: qualified information risk managers, IT system auditors (CISA), information security specialists (CEH), and system management practitioners (CISM, ITIL). Qualified accountants — CPA and ACCA — sit inside the team rather than beside it, which is why our findings survive contact with finance and audit.

That mix gives us an in-depth understanding of the strategic, operational and technology management issues facing leading financial service providers, telcos, international development agencies and NGOs.

We consider the team’s experience vital in contextualising the working realities and operating challenges that face organisations. A control that cannot be operated on a Tuesday afternoon in a branch is not a control.

Qualifications held in the team

  • CISACertified Information Systems Auditor
  • CEHCertified Ethical Hacker
  • CISMCertified Information Security Manager
  • ITILITIL service management
  • CPACertified Public Accountant
  • ACCAChartered Certified Accountant

Individual professional qualifications held by members of the team. Rosewood does not claim firm-level accreditation it has not been granted.

Practices

What we can be brought in to do.

Five parallel practices. Most engagements draw on two or three of them.

Footprint

Eleven markets the team has actually worked in.

Regulators, market practice and vendor behaviour differ by country. So does the risk.

Outline map of Africa marking the eleven markets in which the Rosewood team has worked.

Eleven markets, one team. Work is delivered from Nairobi and on site, which keeps engagement costs closer to a local rate than a fly-in one.

Standards

The frameworks we work to.

Named, because buyers search by standard rather than by service.

Briefings

Regulatory and practice notes.

Written for the person who has to act on it.

Next step

Tell us what you need assurance over.

Send a short brief and we will come back within two working days with the scope we would propose, what it would cost, and how long it would take. No pitch deck.

Request our portfolio

+254 721 687846 taarifa@techrisk.co.ke